Re: [PATCH net v3 1/7] net: macb: manage the netdev lifetime with devres

From: Théo Lebrun

Date: Sun Oct 04 2026 - 08:49:40 EST


Hello Jiale,

On Sun Oct 4, 2026 at 2:14 PM CEST, jiale yao wrote:
> At 2026-10-04 16:45:58, "Théo Lebrun" <theo.lebrun@xxxxxxxxxxx> wrote:
>>Hello Jiale,
>>
>>Those LLM bugs are code churn, that's why you are seeing pushback.
>>Please don't ignore the pushback. For example on V2 you got asked to
>>reply to an automated message, which you didn't do.
>>
>>https://lore.kernel.org/netdev/20260927153020.5311dba6@xxxxxxxxxx/

You've skipped over part of my message.

>>On Sat Oct 3, 2026 at 10:59 AM CEST, Jiale Yao wrote:
>>> macb_remove() frees the netdev while its managed IRQs are only
>>> released after the remove callback returns. An interrupt in that window
>>> can dereference the freed netdev or queue data.
>>
>>Please indicate how an interrupt could land in that window.
>>Thinking about it for a brief instant, I cannot think of one.
>
> I reproduced this on QEMU aarch64 virt + KASAN:
> I added a macb node via an extended device tree, with its interrupt
> line shared with virtio-rng. Keeping the rng busy triggers a steady
> stream of interrupts during unbind/rebind, and macb_interrupt() hits the
> window after `free_netdev()` on the first attempt.

But that never happens in the real world. We use shared interrupts
because we want to supports boards with a single interrupt lane for
all queues.

I've been thinking about removing the IRQF_SHARED flag recently, because
it tricks Sashiko (and you) into thinking that we might share our IRQ
lane with anything and anyone.

Thanks,

--
Théo Lebrun, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com