From nobody Mon Sep 28 13:17:20 2026 Received: from mta0.migadu.com (out-96.mta0.migadu.com [91.218.175.96]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 403E2374E60 for ; Fri, 21 Aug 2026 07:04:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.96 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787295842; cv=none; b=JRP7koQrQQPNELehGC0q1crjP9xxWLjsC3C+yvmXw62jGnXuVfmTvku+o7D+Wf520kqc0rKsfpm37Hk80J8UA6A4jalO/ksUYi8TxurrqQCGXNS7p0t8dAzwt5tzC8eLKx7R483YSl8ddVQ3FuYZ7Z0X/M7PNdXPl7Q6V9y2f9E= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787295842; c=relaxed/simple; bh=znURPWLxZWEMIGdoNbH1oygckZ9cvOk5K8POBG6JQB4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=qbMc/MRVN9oRIY/9UBlU2oo1Y/vUBi6Qu6443D0mCmwR5SES8WrPcokpIoCpjjrQ5wpW1ro8i73ete6kFPWxWYrIyIOmrhJBHF3x20rGSXepIPbkrFrtnhmiHNbKGiBJ0hzo9MIQQqiXpiSalo+hGGsSkln+IMGxRcxnIscfc8Y= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=SJo4Itxv; arc=none smtp.client-ip=91.218.175.96 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="SJo4Itxv" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=znURPWLxZWEMIGdoNbH1oygckZ9cvOk5K8POBG6JQB4=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1787295838; v=1; x=1787900638; b=SJo4ItxvqWq6Dj3pIjWWQlDRl7ZC+3+VfrF5shWv5QPPVyDV2PKgdYcgVOudBuqACaiHUhmh U+lLXHm+yMjrnG8MFe3gYy8gwwYfQ36X8/w5b4V1AO6UztDSvE5WO5FD+gmJViYOWG3chjc/6Rv abdNTKS1W8jJShgEs32RYj3M= X-Envelope-To: linux-kernel@vger.kernel.org Received: from localhost.localdomain (116.128.244.171) by smtp.migadu.com with ESMTPS id 827a16a903200fa8; Fri, 21 Aug 2026 07:03:58 +0000 X-Mizu-Trace-ID: 827a16a903200fa8 X-Migadu-Flow: FLOW_OUT From: Xuanqiang Luo To: netdev@vger.kernel.org, andrew@lunn.ch, maxime.chevallier@bootlin.com, kuba@kernel.org Cc: hkallweit1@gmail.com, qingfang.deng@siflower.com.cn, hao.guan@siflower.com.cn, linux@armlinux.org.uk, davem@davemloft.net, edumazet@google.com, pabeni@redhat.com, linux-kernel@vger.kernel.org, Xuanqiang Luo Subject: [PATCH net v4 1/6] net: phy: split phy_probe() error paths Date: Fri, 21 Aug 2026 15:03:22 +0800 Message-ID: <20260821070327.16147-2-xuanqiang.luo@linux.dev> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260821070327.16147-1-xuanqiang.luo@linux.dev> References: <20260821070327.16147-1-xuanqiang.luo@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Xuanqiang Luo phy_probe() uses one cleanup path for failures at every initialization stage. This runs cleanup for resources that have not been initialized. Split the cleanup by initialization stage so each failure path unwinds only the resources that may have been initialized. Unregister LED triggers before releasing the SFP upstream and ports, because the LED triggers are initialized after those resources and must be unwound first. Signed-off-by: Xuanqiang Luo --- drivers/net/phy/phy_device.c | 20 +++++++++++--------- 1 file changed, 11 insertions(+), 9 deletions(-) diff --git a/drivers/net/phy/phy_device.c b/drivers/net/phy/phy_device.c index 94b2e85e00a37..2cf70471ae089 100644 --- a/drivers/net/phy/phy_device.c +++ b/drivers/net/phy/phy_device.c @@ -3706,7 +3706,7 @@ static int phy_probe(struct device *dev) if (phydev->drv->probe) { err =3D phydev->drv->probe(phydev); if (err) - goto out; + goto out_reset; } =20 phy_disable_interrupts(phydev); @@ -3727,7 +3727,7 @@ static int phy_probe(struct device *dev) err =3D genphy_read_abilities(phydev); =20 if (err) - goto out; + goto out_reset; =20 if (!linkmode_test_bit(ETHTOOL_LINK_MODE_Autoneg_BIT, phydev->supported)) @@ -3744,7 +3744,7 @@ static int phy_probe(struct device *dev) =20 err =3D phy_setup_ports(phydev); if (err) - goto out; + goto out_sfp_release; =20 phy_advertise_supported(phydev); =20 @@ -3753,7 +3753,7 @@ static int phy_probe(struct device *dev) */ err =3D genphy_c45_read_eee_adv(phydev, phydev->advertising_eee); if (err) - goto out; + goto out_sfp_release; =20 /* Get the EEE modes we want to prohibit. */ of_set_phy_eee_broken(phydev); @@ -3806,20 +3806,22 @@ static int phy_probe(struct device *dev) if (IS_ENABLED(CONFIG_PHYLIB_LEDS) && !phy_driver_is_genphy(phydev)) { err =3D of_phy_leds(phydev); if (err) - goto out; + goto out_unreg_led_triggers; } =20 return 0; =20 -out: +out_unreg_led_triggers: + if (!phydev->is_on_sfp_module) + phy_led_triggers_unregister(phydev); + +out_sfp_release: sfp_bus_del_upstream(phydev->sfp_bus); phydev->sfp_bus =3D NULL; =20 phy_cleanup_ports(phydev); =20 - if (!phydev->is_on_sfp_module) - phy_led_triggers_unregister(phydev); - +out_reset: /* Re-assert the reset signal on error */ phy_device_reset(phydev, 1); =20 --=20 2.43.0 From nobody Mon Sep 28 13:17:20 2026 Received: from mta0.migadu.com (out-106.mta0.migadu.com [91.218.175.106]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 11BAC2F361E for ; Fri, 21 Aug 2026 07:04:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.106 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787295854; cv=none; b=EhKaRFGK6Vvx7yR+FksZnJjer0ctM6r8SDuCFIOzzlU0bkQ4frvaLK3goFa0XJwxDtz27KKrlaocRB0pNwj0qUT0qmwrFGmmHQDXC8gR4AjUJzHK5NKzs/21JjemSfDBk5BLKy3UrWGWJ5kyTvhBobbpLfvnOs/aU+N64tQ+SiQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787295854; c=relaxed/simple; bh=Bk38YP6PQK5x2Z8nz1fXzY2/xBvqrJYX8lASUUZlYjs=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=A071BEyf8nPYg2123afAzlXycP+a0m9O+r5lXwAaeCM6Jqzh/JvvytjmpQLynj1zTx0FVQGWFoUaG8dzL3JhMcMpU382px7+/l1V4IoDL+qKDHrbtwELIXSyCzgv5chdHyAjg8p7BV+/dVw7lDiYEBqnye4jn4LlrtWtCPST9JQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=lGfSrR4U; arc=none smtp.client-ip=91.218.175.106 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="lGfSrR4U" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=Bk38YP6PQK5x2Z8nz1fXzY2/xBvqrJYX8lASUUZlYjs=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1787295850; v=1; x=1787900650; b=lGfSrR4UgQFigXUD9Gw7KYktX9PPn3GN3dRl7L/m2ftYViRC4eK3g33JtYw/iku21so//GjB ZrBBKQd7fg+xiy/s1hieJnCOAkWjflXz4fq4QoujThvOp9hmaEe7cw/WMNnATRiK2SiLzPboOdL qCHzaPJr9TJzTPtUsTXIuqrs= X-Envelope-To: linux-kernel@vger.kernel.org Received: from localhost.localdomain (116.128.244.171) by smtp.migadu.com with ESMTPS id 993578c3b13afedd; Fri, 21 Aug 2026 07:04:10 +0000 X-Mizu-Trace-ID: 993578c3b13afedd X-Migadu-Flow: FLOW_OUT From: Xuanqiang Luo To: netdev@vger.kernel.org, andrew@lunn.ch, maxime.chevallier@bootlin.com, kuba@kernel.org Cc: hkallweit1@gmail.com, qingfang.deng@siflower.com.cn, hao.guan@siflower.com.cn, linux@armlinux.org.uk, davem@davemloft.net, edumazet@google.com, pabeni@redhat.com, linux-kernel@vger.kernel.org, Xuanqiang Luo Subject: [PATCH net v4 2/6] net: phy: unregister SFP upstream before port cleanup Date: Fri, 21 Aug 2026 15:03:23 +0800 Message-ID: <20260821070327.16147-3-xuanqiang.luo@linux.dev> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260821070327.16147-1-xuanqiang.luo@linux.dev> References: <20260821070327.16147-1-xuanqiang.luo@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Xuanqiang Luo Commit 4497f5028675 ("net: phy: Clean the phy_ports after unregistering the downstream SFP bus") established that an SFP upstream must be unregistered before its phy_ports are destroyed because SFP callbacks may access these ports. phy_setup_ports() does not follow this order when a later port setup step fails after phy_sfp_probe() succeeds. It destroys the SFP phy_port and leaves phy_probe() to unregister the upstream later, creating a race between port destruction and SFP upstream callbacks. The error unwind is also split across three functions. If phy_setup_sfp_port() fails, phy_sfp_probe() leaves the upstream registered and relies on phy_probe() to remove it after phy_setup_ports() returns. Make each layer unwind the resources it successfully set up. Unregister only the upstream in phy_sfp_probe() when SFP port setup fails, since the failed port has already been destroyed. Add phy_sfp_release() for a successful SFP probe, and make phy_setup_ports() use it before cleaning up the remaining ports. Once phy_setup_ports() has rolled back all port setup, make phy_probe() skip this cleanup. Fixes: 589e934d2735 ("net: phy: Introduce PHY ports representation") Reviewed-by: Andrew Lunn Signed-off-by: Xuanqiang Luo --- drivers/net/phy/phy_device.c | 49 ++++++++++++++++++++++++++++-------- 1 file changed, 38 insertions(+), 11 deletions(-) diff --git a/drivers/net/phy/phy_device.c b/drivers/net/phy/phy_device.c index 2cf70471ae089..4b9b2300422fb 100644 --- a/drivers/net/phy/phy_device.c +++ b/drivers/net/phy/phy_device.c @@ -1723,12 +1723,41 @@ static int phy_sfp_probe(struct phy_device *phydev) phydev->sfp_bus =3D NULL; } =20 - if (!ret && phydev->sfp_bus) + if (!ret && phydev->sfp_bus) { ret =3D phy_setup_sfp_port(phydev); + if (ret) { + sfp_bus_del_upstream(phydev->sfp_bus); + phydev->sfp_bus =3D NULL; + } + } =20 return ret; } =20 +/** + * phy_sfp_release - release resources set up by phy_sfp_probe() + * @phydev: the PHY device + * + * Release the SFP resources set up by a successful phy_sfp_probe(). Unreg= ister + * the upstream before destroying its phy_port, so SFP upstream callbacks = cannot + * race with port destruction. + */ +static void phy_sfp_release(struct phy_device *phydev) +{ + struct phy_port *port, *tmp; + + sfp_bus_del_upstream(phydev->sfp_bus); + phydev->sfp_bus =3D NULL; + + list_for_each_entry_safe(port, tmp, &phydev->ports, head) { + if (!port->is_sfp) + continue; + + phy_del_port(phydev, port); + phy_port_destroy(port); + } +} + static bool phy_drv_supports_irq(const struct phy_driver *phydrv) { return phydrv->config_intr && phydrv->handle_interrupt; @@ -3547,13 +3576,13 @@ static int phy_setup_ports(struct phy_device *phyde= v) if (!phydev->is_genphy_driven) { ret =3D phy_sfp_probe(phydev); if (ret) - goto out; + goto err_ports; } =20 if (phydev->n_ports < phydev->max_n_ports) { ret =3D phy_default_setup_single_port(phydev); if (ret) - goto out; + goto err_sfp; } =20 linkmode_zero(ports_supported); @@ -3580,7 +3609,9 @@ static int phy_setup_ports(struct phy_device *phydev) =20 return 0; =20 -out: +err_sfp: + phy_sfp_release(phydev); +err_ports: phy_cleanup_ports(phydev); return ret; } @@ -3744,7 +3775,7 @@ static int phy_probe(struct device *dev) =20 err =3D phy_setup_ports(phydev); if (err) - goto out_sfp_release; + goto out_reset; =20 phy_advertise_supported(phydev); =20 @@ -3816,9 +3847,7 @@ static int phy_probe(struct device *dev) phy_led_triggers_unregister(phydev); =20 out_sfp_release: - sfp_bus_del_upstream(phydev->sfp_bus); - phydev->sfp_bus =3D NULL; - + phy_sfp_release(phydev); phy_cleanup_ports(phydev); =20 out_reset: @@ -3842,9 +3871,7 @@ static int phy_remove(struct device *dev) =20 phydev->state =3D PHY_DOWN; =20 - sfp_bus_del_upstream(phydev->sfp_bus); - phydev->sfp_bus =3D NULL; - + phy_sfp_release(phydev); phy_cleanup_ports(phydev); =20 if (phydev->drv && phydev->drv->remove) --=20 2.43.0 From nobody Mon Sep 28 13:17:20 2026 Received: from mta0.migadu.com (out-119.mta0.migadu.com [91.218.175.119]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 993A638E5C4 for ; Fri, 21 Aug 2026 07:04:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.119 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787295866; cv=none; b=Jh69H1+3S8K6+8rb0mvdk6RT4RBb+h4IeP1RIC+ni38RX+59Bo/HecTZKLhYhI5tBADC32RuuvcN6Rppk2o6xVFO4M94qWshhsEYrMS6WWnPvAXVO8XFaRnwLfnOB0aM06srVHbNxxd8DRuuqeTrOg6ChCHbFFnjfxvWzgmsRIE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787295866; c=relaxed/simple; bh=kceR1WD9rU0gLSlXC/8jFxD0IxMnAmNomzwTUhSuZpg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=ClfUJ4mxl1AOoHmxkSvAvAXfhmXopljc/HyKcgkjLN/uBijW2DOaq7gEBaquoMNB1scz99LBMHP0fhRXctbSb9vCs3/zwgq7jE/9Squg9198M0PGyyL0TLXLhInfuV3pLLMZxCUhjGLMYL7i+yra3jMQJplsHUEkrtkWQdZPkx8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=oycgPuzR; arc=none smtp.client-ip=91.218.175.119 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="oycgPuzR" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=kceR1WD9rU0gLSlXC/8jFxD0IxMnAmNomzwTUhSuZpg=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1787295862; v=1; x=1787900662; b=oycgPuzRwKh52aLMDsEZGP2B7DNzzLOlimxwAb1WLqbiyUtWS+HKUV3oSi3dbAQyYOe3soit exN5SF4zaXkK+z2H1Xod3Q4c26PE2eRiy6HuRsprISWCkwKk9Uw3m/z8QFsTHZySqHHDpR9IoSQ Qi0voUwU7ztbWv5I04tNb6mU= X-Envelope-To: linux-kernel@vger.kernel.org Received: from localhost.localdomain (116.128.244.171) by smtp.migadu.com with ESMTPS id b72289759244c0af; Fri, 21 Aug 2026 07:04:22 +0000 X-Mizu-Trace-ID: b72289759244c0af X-Migadu-Flow: FLOW_OUT From: Xuanqiang Luo To: netdev@vger.kernel.org, andrew@lunn.ch, maxime.chevallier@bootlin.com, kuba@kernel.org Cc: hkallweit1@gmail.com, qingfang.deng@siflower.com.cn, hao.guan@siflower.com.cn, linux@armlinux.org.uk, davem@davemloft.net, edumazet@google.com, pabeni@redhat.com, linux-kernel@vger.kernel.org, Xuanqiang Luo Subject: [PATCH net v4 3/6] net: phy: set PHY_READY after LED setup Date: Fri, 21 Aug 2026 15:03:24 +0800 Message-ID: <20260821070327.16147-4-xuanqiang.luo@linux.dev> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260821070327.16147-1-xuanqiang.luo@linux.dev> References: <20260821070327.16147-1-xuanqiang.luo@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Xuanqiang Luo phy_probe() sets PHY_READY before calling of_phy_leds(). If LED setup fails, the error path releases the initialized resources while the PHY state remains READY even though probing failed. Set PHY_READY only after LED setup succeeds. Fixes: 01e5b728e9e4 ("net: phy: Add a binding for PHY LEDs") Reviewed-by: Andrew Lunn Signed-off-by: Xuanqiang Luo --- drivers/net/phy/phy_device.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/drivers/net/phy/phy_device.c b/drivers/net/phy/phy_device.c index 4b9b2300422fb..891df46d0597f 100644 --- a/drivers/net/phy/phy_device.c +++ b/drivers/net/phy/phy_device.c @@ -3824,9 +3824,6 @@ static int phy_probe(struct device *dev) phydev->supported); } =20 - /* Set the state to READY by default */ - phydev->state =3D PHY_READY; - /* Register the PHY LED triggers */ if (!phydev->is_on_sfp_module) phy_led_triggers_register(phydev); @@ -3840,6 +3837,9 @@ static int phy_probe(struct device *dev) goto out_unreg_led_triggers; } =20 + /* Set the state to READY by default */ + phydev->state =3D PHY_READY; + return 0; =20 out_unreg_led_triggers: --=20 2.43.0 From nobody Mon Sep 28 13:17:20 2026 Received: from mta0.migadu.com (out-125.mta0.migadu.com [91.218.175.125]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 936BB380FC6 for ; Fri, 21 Aug 2026 07:04:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.125 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787295874; cv=none; b=eQAhyYoGVKgMgfF2klnz/6dxLcMSJkEtD20mK2MOJSJxdsyAOicIeOn+RPQVU9ERfNAdLrcbUIRp3hg71KoXjU6EjA6zL6OzrffPKzbHCldylmdIXS3XrANPObperpLGMBrm1olUVrQmTl5hsl1B2ZS0Zzx6RRtCFCDKYd+9Q4s= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787295874; c=relaxed/simple; bh=Pibs+c7tZQLPitx0IfvSOl7lc/8t3c9y/LRGCRLWcAg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=jR6bSMU78JPDh76veaMcBf7dHrHMr0z3MxKahsKgoL3fHMdXt12Knj4CHPWALrhwJixOr9ZGG9xz42ktZchzuYomuCnryAvjC1U1NOIUhXhBMKJrnvSd1SHrUTuZunUBbOeybkd5QpJbdcmEkCPNtoXMhKpBCRgm3bvooB+3wjo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=MTHWYhtW; arc=none smtp.client-ip=91.218.175.125 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="MTHWYhtW" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=Pibs+c7tZQLPitx0IfvSOl7lc/8t3c9y/LRGCRLWcAg=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1787295870; v=1; x=1787900670; b=MTHWYhtWpHB6uD6WIJMV+Pm0KLduchzRrZSH7whY9uHrfFOlLBULYoK9nVdyy4ORd62MxBcJ OJ5XjnnZytZeeOPnh9OuG+5Db+3p0wzMNyig8HgZR+os/HNQMhJgGEgmB23ofzlSfbsVm4bRXBn DXmsU94XqdnJqJhuiV5aLVEc= X-Envelope-To: linux-kernel@vger.kernel.org Received: from localhost.localdomain (116.128.244.171) by smtp.migadu.com with ESMTPS id be9ba88dc2e76e90; Fri, 21 Aug 2026 07:04:30 +0000 X-Mizu-Trace-ID: be9ba88dc2e76e90 X-Migadu-Flow: FLOW_OUT From: Xuanqiang Luo To: netdev@vger.kernel.org, andrew@lunn.ch, maxime.chevallier@bootlin.com, kuba@kernel.org Cc: hkallweit1@gmail.com, qingfang.deng@siflower.com.cn, hao.guan@siflower.com.cn, linux@armlinux.org.uk, davem@davemloft.net, edumazet@google.com, pabeni@redhat.com, linux-kernel@vger.kernel.org, Xuanqiang Luo Subject: [PATCH net v4 4/6] net: phy: call driver remove when core initialization fails Date: Fri, 21 Aug 2026 15:03:25 +0800 Message-ID: <20260821070327.16147-5-xuanqiang.luo@linux.dev> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260821070327.16147-1-xuanqiang.luo@linux.dev> References: <20260821070327.16147-1-xuanqiang.luo@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Xuanqiang Luo phy_probe() may fail while querying features or completing other core initialization after the PHY driver probe callback has succeeded. The driver core does not run the remove path after a probe error, so resources that the PHY driver releases in its remove callback are leaked. Call the PHY driver remove callback on these failures. Fixes: efbdfdc29bdd ("net: phy: Add support for asking the PHY its abilitie= s") Reviewed-by: Andrew Lunn Signed-off-by: Xuanqiang Luo --- drivers/net/phy/phy_device.c | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/drivers/net/phy/phy_device.c b/drivers/net/phy/phy_device.c index 891df46d0597f..691396794decd 100644 --- a/drivers/net/phy/phy_device.c +++ b/drivers/net/phy/phy_device.c @@ -3758,7 +3758,7 @@ static int phy_probe(struct device *dev) err =3D genphy_read_abilities(phydev); =20 if (err) - goto out_reset; + goto out_remove; =20 if (!linkmode_test_bit(ETHTOOL_LINK_MODE_Autoneg_BIT, phydev->supported)) @@ -3775,7 +3775,7 @@ static int phy_probe(struct device *dev) =20 err =3D phy_setup_ports(phydev); if (err) - goto out_reset; + goto out_remove; =20 phy_advertise_supported(phydev); =20 @@ -3850,6 +3850,10 @@ static int phy_probe(struct device *dev) phy_sfp_release(phydev); phy_cleanup_ports(phydev); =20 +out_remove: + if (phydev->drv->remove) + phydev->drv->remove(phydev); + out_reset: /* Re-assert the reset signal on error */ phy_device_reset(phydev, 1); --=20 2.43.0 From nobody Mon Sep 28 13:17:20 2026 Received: from mta1.migadu.com (out-99.mta1.migadu.com [95.215.58.99]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E0F8239280D for ; Fri, 21 Aug 2026 07:04:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=95.215.58.99 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787295881; cv=none; b=W82zM1LJ5Jr2Rr4JL7FfPuYY+7FejCsFJanOxnqZzalYQeGg5n7RX2LzA7GGEtzj5b0C9kORko+WIyaMWneM4NrXAw4kzaZbvxTzQ1cgJS863GZjJO7RJT75BE+71Y424ytOvnJoTHiZUnmz23wtP92nT2Q+ES/jwMp7ghwF0Pg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787295881; c=relaxed/simple; bh=zBNB+lv/4uFx+0jKJ/L0bskD//2Tm9LY0LvconbI2o8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=OkW44CiTVeZd9pmHx0/ycHSzF8a/dKUS7L4NhR9ruEfSwuleW4XTmkOlu8avcCc+6hYoey2bwvdVX1mwRgiJsCrHwo0GroCPYY5pADHb3Zk/4nPKK3EL6RFWhXKsxKsd+w7wgyJ0yytOFqiGj4FuzZbeAE58wo16qqm7V4kw6V8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=Yb232Erp; arc=none smtp.client-ip=95.215.58.99 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="Yb232Erp" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=zBNB+lv/4uFx+0jKJ/L0bskD//2Tm9LY0LvconbI2o8=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1787295877; v=1; x=1787900677; b=Yb232Erp7/tetdnO+c17tY1dNO6eyTffSF6SUssv5chlCXF25ymjgTOk8pyUbyomipGV5k0W jdgdW7ogrCSC7VrrlLQd8P5uzVql1NHC3F6qFNFZweYVpggakxmKvSX9o92jDUdj8Xj0EQ0OUwH WlWttqWpOn3E+SITsqdABUtg= X-Envelope-To: linux-kernel@vger.kernel.org Received: from localhost.localdomain (116.128.244.171) by smtp.migadu.com with ESMTPS id 5995ade47ca2e225; Fri, 21 Aug 2026 07:04:37 +0000 X-Mizu-Trace-ID: 5995ade47ca2e225 X-Migadu-Flow: FLOW_OUT From: Xuanqiang Luo To: netdev@vger.kernel.org, andrew@lunn.ch, maxime.chevallier@bootlin.com, kuba@kernel.org Cc: hkallweit1@gmail.com, qingfang.deng@siflower.com.cn, hao.guan@siflower.com.cn, linux@armlinux.org.uk, davem@davemloft.net, edumazet@google.com, pabeni@redhat.com, linux-kernel@vger.kernel.org, Xuanqiang Luo Subject: [PATCH net v4 5/6] net: phy: propagate errors from default port setup Date: Fri, 21 Aug 2026 15:03:26 +0800 Message-ID: <20260821070327.16147-6-xuanqiang.luo@linux.dev> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260821070327.16147-1-xuanqiang.luo@linux.dev> References: <20260821070327.16147-1-xuanqiang.luo@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Xuanqiang Luo phy_default_setup_single_port() ignores errors from phy_add_port() and always reports success. If a PHY driver attach_mdi_port() callback fails, the phy_port is leaked and PHY probing continues without the expected default port. Destroy the port and return the error. Fixes: 589e934d2735 ("net: phy: Introduce PHY ports representation") Reviewed-by: Andrew Lunn Signed-off-by: Xuanqiang Luo --- drivers/net/phy/phy_device.c | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/drivers/net/phy/phy_device.c b/drivers/net/phy/phy_device.c index 691396794decd..8cb0d60fcbba9 100644 --- a/drivers/net/phy/phy_device.c +++ b/drivers/net/phy/phy_device.c @@ -3483,6 +3483,7 @@ static int phy_default_setup_single_port(struct phy_d= evice *phydev) { struct phy_port *port =3D phy_port_alloc(); unsigned long mode; + int ret; =20 if (!port) return -ENOMEM; @@ -3509,9 +3510,11 @@ static int phy_default_setup_single_port(struct phy_= device *phydev) port->pairs =3D max_t(int, port->pairs, ethtool_linkmode_n_pairs(mode)); =20 - phy_add_port(phydev, port); + ret =3D phy_add_port(phydev, port); + if (ret) + phy_port_destroy(port); =20 - return 0; + return ret; } =20 static int of_phy_ports(struct phy_device *phydev) --=20 2.43.0 From nobody Mon Sep 28 13:17:20 2026 Received: from mta0.migadu.com (out-136.mta0.migadu.com [91.218.175.136]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 945F1357CEA for ; Fri, 21 Aug 2026 07:04:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.136 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787295894; cv=none; b=czFZZHobnrpO3HC89lEtX9qVlQJwaXKI+3XLdTg6CFQ3S6QQkUabFv0tsjkN5n+d7J3CZ/FrcFN9sYKBvO6gHMQkW0FwCQO4+AQ7zOLvn3hXwKA7aVxkqqDvvgjBIgw1Xmlmp+IEUG9lIEcLscge3zsBGWT8FloEOTcqGQlbmz8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787295894; c=relaxed/simple; bh=DPdelFgodIfEtmagZl8+Evmyjeurak0kZ5Io6d7ielI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=TErI77Yl9h69vcvOESe/2608JmIwSEFw9SJo8fXxmAxAlslVEWs7o13zsEJmXwSZNqkSurs7VyDJDJzxMhm67jdXA66+s94GENGEBwWq9bOLXoUdKVlla7y3M3biZlvKkjUdE0M6hThPw/AUxh6ssEitz7xNsH48sCVVll9Gr5E= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=SREtXM3p; arc=none smtp.client-ip=91.218.175.136 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="SREtXM3p" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=DPdelFgodIfEtmagZl8+Evmyjeurak0kZ5Io6d7ielI=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1787295889; v=1; x=1787900689; b=SREtXM3pyTyDHbTiWPVU+wSrLg84N31GVxa4umXzGlZMPj2ElXMX5FqYr8NgJh441s4oB89H PEMAUxNCUq0MqAGB1Zgi/K349F5P6+g4p+bH6J89Zc9eAYlYigqJ7tsCgHB7RHuf2Mi31RDyxbm Uf3PIp3VUDMFOtx07NUdGluQ= X-Envelope-To: linux-kernel@vger.kernel.org Received: from localhost.localdomain (116.128.244.171) by smtp.migadu.com with ESMTPS id 9b0adc2a607b779f; Fri, 21 Aug 2026 07:04:49 +0000 X-Mizu-Trace-ID: 9b0adc2a607b779f X-Migadu-Flow: FLOW_OUT From: Xuanqiang Luo To: netdev@vger.kernel.org, andrew@lunn.ch, maxime.chevallier@bootlin.com, kuba@kernel.org Cc: hkallweit1@gmail.com, qingfang.deng@siflower.com.cn, hao.guan@siflower.com.cn, linux@armlinux.org.uk, davem@davemloft.net, edumazet@google.com, pabeni@redhat.com, linux-kernel@vger.kernel.org, Xuanqiang Luo Subject: [PATCH net v4 6/6] net: phy: avoid double-free after LED trigger registration failure Date: Fri, 21 Aug 2026 15:03:27 +0800 Message-ID: <20260821070327.16147-7-xuanqiang.luo@linux.dev> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260821070327.16147-1-xuanqiang.luo@linux.dev> References: <20260821070327.16147-1-xuanqiang.luo@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Xuanqiang Luo When a speed trigger registration fails, phy_led_triggers_register() frees phy_led_triggers but leaves the pointer set to the freed allocation. It then clears phy_num_led_triggers. phy_probe() ignores this error. If device-tree LED setup then fails, its error path calls phy_led_triggers_unregister(). The zero trigger count skips the per-trigger unregister loop, but the helper still frees the dangling pointer. Clear the pointer after partial registration cleanup and make phy_led_triggers_unregister() walk and free the array only while it is present. Fixes: b7f0ee992adf ("net: phy: leds: fix memory leak") Signed-off-by: Xuanqiang Luo --- drivers/net/phy/phy_led_triggers.c | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/drivers/net/phy/phy_led_triggers.c b/drivers/net/phy/phy_led_t= riggers.c index 4eb7716bb9d6c..ff6e518395be0 100644 --- a/drivers/net/phy/phy_led_triggers.c +++ b/drivers/net/phy/phy_led_triggers.c @@ -126,6 +126,7 @@ int phy_led_triggers_register(struct phy_device *phy) while (i--) phy_led_trigger_unregister(&phy->phy_led_triggers[i]); kfree(phy->phy_led_triggers); + phy->phy_led_triggers =3D NULL; out_unreg_link: phy_led_trigger_unregister(phy->led_link_trigger); out_free_link: @@ -141,10 +142,12 @@ void phy_led_triggers_unregister(struct phy_device *p= hy) { int i; =20 - for (i =3D 0; i < phy->phy_num_led_triggers; i++) - phy_led_trigger_unregister(&phy->phy_led_triggers[i]); - kfree(phy->phy_led_triggers); - phy->phy_led_triggers =3D NULL; + if (phy->phy_led_triggers) { + for (i =3D 0; i < phy->phy_num_led_triggers; i++) + phy_led_trigger_unregister(&phy->phy_led_triggers[i]); + kfree(phy->phy_led_triggers); + phy->phy_led_triggers =3D NULL; + } =20 if (phy->led_link_trigger) { phy_led_trigger_unregister(phy->led_link_trigger); --=20 2.43.0