[PATCH net v2 0/2] net: phy: xilinx-gmii2rgmii: Fix PHY data ownership and removal
From: Vineeth Karumanchi
Date: Wed Oct 07 2026 - 01:49:18 EST
The Xilinx GMII-to-RGMII converter copies the attached PHY driver and
replaces its read_status and set_loopback callbacks. This series addresses
two problems in that arrangement: overwriting driver data belonging to
the external PHY, and leaving phydev->drv pointing at freed converter
memory after converter removal.
Patch 1 retrieves the converter private data from its embedded phy_driver
using container_of_const(), preserving the external PHY's MDIO driver-data
field. It fixes the overwrite introduced by commit 168f7a161608 ("net: phy:
gmii2rgmii: Dont use priv field in phy device").
Patch 2 stores private data on the converter's own MDIO device and adds a
remove callback. It restores the original PHY driver under phydev->lock
only if the converter's copy is still installed, and releases the reference
acquired by of_phy_find_device(). This addresses the stale pointer observed
during PHY state-machine polling after converter-only unbind. The missing
removal cleanup dates back to commit f411a6160bd4 ("net: phy: Add
gmiitorgmii converter support"). Apply the patches in order.
Changes in v2:
- Patch 1: unchanged.
- Patch 2: restore the original PHY driver only if phydev->drv still
points to the converter's copy.
- Patch 2: update the comment and commit message to describe serialization
against PHY callbacks that hold phydev->lock.
Link to v1: https://lore.kernel.org/netdev/20261001074718.3944521-1-vineeth.karumanchi@xxxxxxx/
Vineeth Karumanchi (2):
net: phy: xilinx-gmii2rgmii: Avoid overwriting PHY drvdata
net: phy: xilinx-gmii2rgmii: Restore PHY driver on remove
drivers/net/phy/xilinx_gmii2rgmii.c | 29 +++++++++++++++++++++++++----
1 file changed, 25 insertions(+), 4 deletions(-)
base-commit: 23609bce9e1de525d1d0e73fc68c6e7971d0b49e
--
2.43.0