[PATCH net 0/2] net: cpsw: fix failed-probe cleanup

From: Karl Mehltretter

Date: Sat Oct 03 2026 - 10:09:43 EST


The legacy CPSW driver registers its netdevs before requesting IRQs. A late
IRQ request failure leaves two lifetime problems in the probe error path:

1. In dual-EMAC mode, the secondary netdev remains registered when devres
calls free_netdev().
2. A registered interface can queue rx_mode_work that survives the devm
allocation holding its netdev and private data.

Patch 1 tracks successful secondary registration and unregisters the netdev
on the late error path. Patch 2 drains both interfaces' work after
unregistering them, as cpsw_remove() already does.

Runtime validation used a KASAN-enabled ARM kernel and a local QEMU
Arm virt CPSW probe stub. It provides one or two fixed-link ports. Its
device tree assigns the same non-shareable SPI to RX and TX. The TX request
therefore returns -EBUSY after registration. Test instrumentation opens the
relevant netdev and holds its real rx_mode_work until after the forced
failure.

Each result was reproduced twice:

- Single EMAC, original cleanup: KASAN slab-use-after-free.
- Single EMAC, work-cancel fix: clean poweroff.
- Dual EMAC, original cleanup: free_netdev() reg_state BUG.
- Dual EMAC, patch 1 only: KASAN slab-use-after-free in eth1's work.
- Dual EMAC, both patches: clean poweroff.

Build testing used this series on the net tree at
6dc989ea46b96ce170840174b4a38c4a387fb005:

make ARCH=arm LLVM=1 W=1 -j12 vmlinux modules

Clang/LLD 21.1.8 completed both ARM builds and all enabled modules with
configs derived from allyesconfig and allmodconfig. CONFIG_WERROR and
resource-heavy debug options (KASAN, UBSAN, KFENCE, KCOV/GCOV, KUnit,
kallsyms, KGDB/kmemleak, tracing, lock debugging, and allocation profiling)
were disabled. cpsw.c produced no warning. The literal allyesconfig build
first stopped on warnings in untouched files promoted by CONFIG_WERROR;
with WERROR disabled, its instrumented link exceeded the test host's memory.

Testing on real CPSW hardware would be welcome.

Karl Mehltretter (2):
net: cpsw: unregister secondary netdev on probe failure
net: cpsw: cancel RX mode work on probe failure

drivers/net/ethernet/ti/cpsw.c | 10 ++++++++++
1 file changed, 10 insertions(+)


base-commit: 6dc989ea46b96ce170840174b4a38c4a387fb005
--
2.53.0