[PATCH net v3 5/7] net: hix5hd2: manage the netdev lifetime with devres

From: Jiale Yao

Date: Sat Oct 03 2026 - 05:01:41 EST


hix5hd2_dev_remove() manually frees the netdev before devres releases
the IRQ. The interrupt handler receives that netdev as its data pointer
and can access it during this teardown window.

Allocate the netdev through devres so its later registered IRQ is
released first.

This issue was found by a static analysis method used in our research.

Fixes: 57c5bc9ad7d7 ("net: hisilicon: add hix5hd2 mac driver")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Jiale Yao <yaojiale02@xxxxxxx>
---
drivers/net/ethernet/hisilicon/hix5hd2_gmac.c | 15 ++++++---------
1 file changed, 6 insertions(+), 9 deletions(-)

diff --git a/drivers/net/ethernet/hisilicon/hix5hd2_gmac.c b/drivers/net/ethernet/hisilicon/hix5hd2_gmac.c
index 02282dc86faf..ffcb281230eb 100644
--- a/drivers/net/ethernet/hisilicon/hix5hd2_gmac.c
+++ b/drivers/net/ethernet/hisilicon/hix5hd2_gmac.c
@@ -1100,7 +1100,7 @@ static int hix5hd2_dev_probe(struct platform_device *pdev)
struct mii_bus *bus;
int ret;

- ndev = alloc_etherdev(sizeof(struct hix5hd2_priv));
+ ndev = devm_alloc_etherdev(dev, sizeof(struct hix5hd2_priv));
if (!ndev)
return -ENOMEM;

@@ -1115,26 +1115,26 @@ static int hix5hd2_dev_probe(struct platform_device *pdev)
priv->base = devm_platform_ioremap_resource(pdev, 0);
if (IS_ERR(priv->base)) {
ret = PTR_ERR(priv->base);
- goto out_free_netdev;
+ goto out_return;
}

priv->ctrl_base = devm_platform_ioremap_resource(pdev, 1);
if (IS_ERR(priv->ctrl_base)) {
ret = PTR_ERR(priv->ctrl_base);
- goto out_free_netdev;
+ goto out_return;
}

priv->mac_core_clk = devm_clk_get(&pdev->dev, "mac_core");
if (IS_ERR(priv->mac_core_clk)) {
netdev_err(ndev, "failed to get mac core clk\n");
ret = -ENODEV;
- goto out_free_netdev;
+ goto out_return;
}

ret = clk_prepare_enable(priv->mac_core_clk);
if (ret < 0) {
netdev_err(ndev, "failed to enable mac core clk %d\n", ret);
- goto out_free_netdev;
+ goto out_return;
}

priv->mac_ifc_clk = devm_clk_get(&pdev->dev, "mac_ifc");
@@ -1271,9 +1271,7 @@ static int hix5hd2_dev_probe(struct platform_device *pdev)
clk_disable_unprepare(priv->mac_ifc_clk);
out_disable_mac_core_clk:
clk_disable_unprepare(priv->mac_core_clk);
-out_free_netdev:
- free_netdev(ndev);
-
+out_return:
return ret;
}

@@ -1291,7 +1289,6 @@ static void hix5hd2_dev_remove(struct platform_device *pdev)
hix5hd2_destroy_hw_desc_queue(priv);
of_node_put(priv->phy_node);
cancel_work_sync(&priv->tx_timeout_task);
- free_netdev(ndev);
}

static const struct of_device_id hix5hd2_of_match[] = {
--
2.34.1