[PATCH net v3 0/7] net: ethernet: release managed IRQs before freeing netdevs

From: Jiale Yao

Date: Sat Oct 03 2026 - 05:07:16 EST


Several Ethernet platform drivers request interrupts with
devm_request_irq() but allocate and free their netdevs manually.
Device-managed resources are released only after the driver's remove
callback returns, so these callbacks can free the IRQ data while the
interrupt handlers can still be invoked. A late or shared interrupt in
this window can dereference freed memory.

For six drivers, make the netdev allocation device managed. Since each IRQ
is requested after its netdev is allocated, devres ordering releases the
IRQ before the netdev. SXGBE also keeps its hardware operations object
alive through the same ordering because its handlers dereference that
object directly.

FEC additionally masks its hardware interrupt sources and disables the
Linux IRQs before unregistering the netdev, preventing handlers from
accessing registers after the clocks and other resources are released.

RAVB keeps its netdev manually managed because its remove callback has an
existing runtime PM error path which can return before unregistering it.
Instead, place its IRQs in a dedicated devres group and release that group
after unregistering the netdev and on probe failures. The runtime PM error
path is intentionally left unchanged and will be addressed separately
after this series.

These issues were found by a static analysis method used in our research.
Each patch handles one driver and is independently buildable.

Changes in v3:
- Target the net tree and document how the issues were found.
- Mask and disable FEC interrupts before dependent resources are released,
and remove the obsolete failed_ioremap label.
- Limit the RAVB change to IRQ/netdev teardown ordering, correct its Fixes
tag, and defer the separate runtime PM error-path change.

Changes in v2:
- Keep commit message tags together without blank lines between them, as
requested by Francesco.

Jiale Yao (7):
net: macb: manage the netdev lifetime with devres
net: fec: release IRQs before dependent resources
net: hip04: manage the netdev lifetime with devres
net: hisi_femac: manage the netdev lifetime with devres
net: hix5hd2: manage the netdev lifetime with devres
net: ravb: release managed IRQs before freeing netdev
net: sxgbe: manage IRQ data lifetimes with devres

drivers/net/ethernet/cadence/macb_main.c | 17 +++++------
drivers/net/ethernet/freescale/fec_main.c | 28 +++++++++++--------
drivers/net/ethernet/hisilicon/hip04_eth.c | 4 +--
drivers/net/ethernet/hisilicon/hisi_femac.c | 15 ++++------
drivers/net/ethernet/hisilicon/hix5hd2_gmac.c | 15 ++++------
drivers/net/ethernet/renesas/ravb_main.c | 18 +++++++++---
.../net/ethernet/samsung/sxgbe/sxgbe_main.c | 26 ++++++-----------
7 files changed, 60 insertions(+), 63 deletions(-)

--
2.34.1