[PATCH net] net: calxeda: cancel timeout work before freeing rings
From: Hongyan Xu
Date: Mon Sep 28 2026 - 09:53:39 EST
The transmit timeout paths queue tx_timeout_work, which accesses the DMA
rings and NAPI state. xgmac_stop() can free the rings without waiting
for a queued timeout worker, so the worker may subsequently use freed
storage.
Stop transmit and interrupt publication, cancel the timeout work, and
only then disable NAPI and release the rings.
Fixes: 85c10f282861 ("net: add calxeda xgmac ethernet driver")
Signed-off-by: Hongyan Xu <getshell@xxxxxxxxxx>
---
drivers/net/ethernet/calxeda/xgmac.c | 8 +++-----
1 file changed, 3 insertions(+), 5 deletions(-)
diff --git a/drivers/net/ethernet/calxeda/xgmac.c b/drivers/net/ethernet/calxeda/xgmac.c
index a2410fba6be2..63296469bd85 100644
--- a/drivers/net/ethernet/calxeda/xgmac.c
+++ b/drivers/net/ethernet/calxeda/xgmac.c
@@ -1046,12 +1046,10 @@ static int xgmac_stop(struct net_device *dev)
{
struct xgmac_priv *priv = netdev_priv(dev);
- if (readl(priv->base + XGMAC_DMA_INTR_ENA))
- napi_disable(&priv->napi);
-
- writel(0, priv->base + XGMAC_DMA_INTR_ENA);
-
netif_tx_disable(dev);
+ writel(0, priv->base + XGMAC_DMA_INTR_ENA);
+ cancel_work_sync(&priv->tx_timeout_work);
+ napi_disable(&priv->napi);
/* Disable the MAC core */
xgmac_mac_disable(priv->base);
--
2.50.1.windows.1