Re: [PATCH net 1/3] net: fealnx: fix teardown order in remove

From: Andrew Lunn

Date: Thu Sep 24 2026 - 13:14:38 EST


On Thu, Sep 24, 2026 at 10:44:21AM +0000, Жамбакиев Радий Рикардинович wrote:
> From: Radiy Zhambakiev <r.zhambakiev@xxxxxxxxxxxxxxxxx>
>
> fealnx_remove_one() frees the DMA rings before unregistering the
> netdev, while the interface may still be up, which leaves a
> window where freed memory can be accessed.
>
> Call unregister_netdev() first so dev_close() stops the Tx/Rx
> engines, deletes the timers, and frees the IRQ before the rings are
> freed. While at it use dev_err() instead of printk() for the
> unknown-device case.
>
> Found by Linux Verification Center (linuxtesting.org)
>
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Radiy Zhambakiev <r.zhambakiev@xxxxxxxxxxxxxxxxx>
> ---
> drivers/net/ethernet/fealnx.c | 29 ++++++++++++++++-------------
> 1 file changed, 16 insertions(+), 13 deletions(-)
>
> diff --git a/drivers/net/ethernet/fealnx.c b/drivers/net/ethernet/fealnx.c
> index bdc38aac5850..d7cd1644a375 100644
> --- a/drivers/net/ethernet/fealnx.c
> +++ b/drivers/net/ethernet/fealnx.c
> @@ -678,20 +678,23 @@ static int fealnx_init_one(struct pci_dev *pdev,
> static void fealnx_remove_one(struct pci_dev *pdev)
> {
> struct net_device *dev = pci_get_drvdata(pdev);
> + struct netdev_private *np;
> +
> + if (!dev) {
> + dev_err(&pdev->dev, "remove for unknown device\n");
> + return;
> + }

I know you are just moving code around, but is that possible? We try
avoid defensive code. It is better to actually understand the code and
stop bad things happening.

Andrew