[PATCH net] net: e100: cancel timeout work during removal
From: Hongyan Xu
Date: Mon Sep 28 2026 - 09:46:59 EST
Transmit timeout and command submission paths can queue tx_timeout_task.
The worker accesses the MMIO mapping and netdev private state, but
device removal releases both without draining a pending instance.
Cancel the work after unregister_netdev(), when the network stack can no
longer publish it and after any RTNL serialization used by the worker
has completed.
Fixes: 2acdb1e05c1a ("[PATCH] e100: Execute tx_timeout task outside interrupt context")
Signed-off-by: Hongyan Xu <getshell@xxxxxxxxxx>
---
drivers/net/ethernet/intel/e100.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/net/ethernet/intel/e100.c b/drivers/net/ethernet/intel/e100.c
index 29960762e64a..710c2c30d9ed 100644
--- a/drivers/net/ethernet/intel/e100.c
+++ b/drivers/net/ethernet/intel/e100.c
@@ -2988,6 +2988,7 @@ static void e100_remove(struct pci_dev *pdev)
if (netdev) {
struct nic *nic = netdev_priv(netdev);
unregister_netdev(netdev);
+ cancel_work_sync(&nic->tx_timeout_task);
e100_free(nic);
pci_iounmap(pdev, nic->csr);
dma_pool_destroy(nic->cbs_pool);
--
2.50.1.windows.1