[PATCH net] net/mlx4: shut down catas recovery timer during teardown
From: Runyu Xiao
Date: Sun Oct 04 2026 - 08:13:35 EST
The catas error timer can rearm itself while the device is being
stopped. If poll_catas() is running when timer_delete_sync() drops the
timer-base lock, it can call mod_timer() after the deletion. The delete
can then return with the timer queued again, allowing a subsequent callback
to access teardown-owned MMIO state after it has been unmapped.
On PFs, poll_catas() accesses catas_err.map; on VFs, it accesses the
mapped communication channel. Use timer_shutdown_sync() to prevent the
callback from rearming the timer once teardown starts.
mlx4_start_catas_poll() calls timer_setup() when device registration is
restarted after reload or port reconfiguration, so the timer is
reinitialized before it is used again.
The change was validated by source review and a target-object build.
Runtime validation on mlx4 hardware was not available.
Fixes: ee49bd9397cd ("mlx4_core: Reset device when internal error is detected")
Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: LLM
Signed-off-by: Runyu Xiao <runyu.xiao@xxxxxxxxxx>
---
drivers/net/ethernet/mellanox/mlx4/catas.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/mellanox/mlx4/catas.c b/drivers/net/ethernet/mellanox/mlx4/catas.c
index edcc6f662..62574b790 100644
--- a/drivers/net/ethernet/mellanox/mlx4/catas.c
+++ b/drivers/net/ethernet/mellanox/mlx4/catas.c
@@ -305,7 +305,7 @@ void mlx4_stop_catas_poll(struct mlx4_dev *dev)
{
struct mlx4_priv *priv = mlx4_priv(dev);
- timer_delete_sync(&priv->catas_err.timer);
+ timer_shutdown_sync(&priv->catas_err.timer);
if (priv->catas_err.map) {
iounmap(priv->catas_err.map);
--
2.34.1