Re: [PATCH net 1/2] net: cpsw: unregister secondary netdev on probe failure
From: netdev-bot+sashiko
Date: Sun Oct 04 2026 - 10:10:38 EST
Thank you for your contribution! Sashiko AI review found 1 potential
issue(s) to consider.
Critical: 0 · High: 1 · Medium: 0 · Low: 0
If you believe none of the issues are legitimate, please reply to each
issue of Medium severity or higher and explain why the AI is wrong.
If any of them are legitimate and you plan to respin, please let patchwork
know by including "pw-bot: cr" as a separate line at the end of your reply
(one such reply per series is enough).
- [High] In this patch, the cpsw_probe() error label
clean_unregister_netdev_ret in drivers/net/ethernet/ti/cpsw.c now…
--
net: cpsw: unregister secondary netdev on probe failure
This patch records whether cpsw_probe() registered the secondary
dual-EMAC netdev. If it did, the clean_unregister_netdev_ret error path
now unregisters it before the primary netdev. This avoids the reg_state
BUG_ON in free_netdev() when devres frees a netdev that is still
registered after a late IRQ request failure.
> diff --git a/drivers/net/ethernet/ti/cpsw.c b/drivers/net/ethernet/ti/cpsw.c
> index aa3531e844e87..4fc59f9f23fcb 100644
> --- a/drivers/net/ethernet/ti/cpsw.c
> +++ b/drivers/net/ethernet/ti/cpsw.c
[ ... ]
> @@ -1764,6 +1766,8 @@ static int cpsw_probe(struct platform_device *pdev)
> return 0;
>
> clean_unregister_netdev_ret:
> + if (secondary_registered)
> + unregister_netdev(cpsw->slaves[1].ndev);
> unregister_netdev(ndev);
[Severity: High]
Can rx_mode_work still be pending on either netdev when devres frees it?
Both netdevs are registered before the devm_request_irq() calls, so an
interface can be brought up during that window. Bringing it up, or
changing its address lists, reaches cpsw_ndo_set_rx_mode(), which does:
schedule_work(&priv->rx_mode_work);
cpsw_ndo_stop() does not cancel this work.
cpsw_remove() follows each unregister with a disable:
priv = netdev_priv(ndev);
unregister_netdev(ndev);
disable_work_sync(&priv->rx_mode_work);
This error path does not. After probe returns the error, devres calls
free_netdev() on the devm-allocated netdevs. A queued or rtnl-blocked
cpsw_ndo_set_rx_mode_work() would then dereference the freed priv,
priv->cpsw and priv->ndev. The workqueue core would also touch the freed
work_struct.
The primary netdev already had this gap. For the secondary netdev, the
free_netdev() BUG_ON used to fire first. This patch removes that BUG_ON,
so the use-after-free on the secondary netdev can now be reached.
The next patch in the series, "net: cpsw: cancel RX mode work on probe
failure", appears to fix this. It adds disable_work_sync() after both
unregister_netdev() calls here, which matches cpsw_remove(). Its commit
message quotes a KASAN report of "slab-use-after-free in
cpsw_ndo_set_rx_mode_work".
Could that change be folded into this patch, so the two are not applied
separately?
--
Sashiko AI review · https://netdev-ai.bots.linux.dev/sashiko/#/patchset/cover.1791035789.git.kmehltretter%40gmail.com