From nobody Mon Sep 28 10:43:22 2026 Received: from mta1.migadu.com (out-122.mta1.migadu.com [95.215.58.122]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 92498340A6F for ; Sun, 23 Aug 2026 03:56:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=95.215.58.122 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787457393; cv=none; b=BAA3/MHkHGrd0GgEh3fs7cQg1w8LiwlHZXxW+oLkuOT/Xo9Nz+Z36YXjPM/XI8ULx0t76EcgmVuLzxpU9P86DLkzTZmDsApem6EHrzcI5+in3A5NaatDJfRc0+jv1jYZsXixGSF408Q9GSWF4LII9FlViDk9JuXPnDWZW5uXfpg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787457393; c=relaxed/simple; bh=GvttE+5qoZxwgHSuqBfxoxt73ASry55/zhgE1ht6V44=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=FG0WhjJZX7zsbwgrofH6DdTUeUYjmiIo+ouYBLkBPMvJTwuMNd3SLx0kUp1SLx4zyFimcqESr4EEtZeaUXpsrDmo6wLFwTNoxzgS4iJ2dS8QGWPtzXwaZfIZz7vDkjecnZi4lrNaeNA8pbjOjTnnmmgnXFepgC+z6MMOqaXM0t4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=o6d/xRNB; arc=none smtp.client-ip=95.215.58.122 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="o6d/xRNB" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=GvttE+5qoZxwgHSuqBfxoxt73ASry55/zhgE1ht6V44=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1787457388; v=1; x=1788062188; b=o6d/xRNBKt5SaEMewZFAfykW10zn7tuUSGFDNndBxfGkDJi7nVVAbgy4n8Goo0jh6NNv4r2t 5N/aCvVrPHOxptTYPNQRVJYRHjVKdfWiBFoe2+Omliq5QXmKzHtNG0oTr6t5TqnspqAKP9906uc jZ3sfIfm+ZMPEIFR7vTPH8XU= X-Envelope-To: linux-kernel@vger.kernel.org Received: from localhost.localdomain (116.128.244.171) by smtp.migadu.com with ESMTPS id 07ca76bdfaf43557; Sun, 23 Aug 2026 03:56:28 +0000 X-Mizu-Trace-ID: 07ca76bdfaf43557 X-Migadu-Flow: FLOW_OUT From: Xuanqiang Luo To: netdev@vger.kernel.org, andrew@lunn.ch, maxime.chevallier@bootlin.com, kuba@kernel.org Cc: hkallweit1@gmail.com, chleroy@kernel.org, qingfang.deng@siflower.com.cn, hao.guan@siflower.com.cn, linux@armlinux.org.uk, davem@davemloft.net, edumazet@google.com, pabeni@redhat.com, linux-kernel@vger.kernel.org, Xuanqiang Luo Subject: [PATCH net v5 1/6] net: phy: split phy_probe() error paths Date: Sun, 23 Aug 2026 11:55:55 +0800 Message-ID: <20260823035600.188864-2-xuanqiang.luo@linux.dev> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260823035600.188864-1-xuanqiang.luo@linux.dev> References: <20260823035600.188864-1-xuanqiang.luo@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Xuanqiang Luo phy_probe() uses one cleanup path for failures at every initialization stage. This runs cleanup for resources that have not been initialized. After a successful probe and remove, phy_led_triggers_unregister() can leave phy_num_led_triggers non-zero after freeing the trigger array. If a subsequent probe fails before LED trigger registration, the common error path calls phy_led_triggers_unregister() with a NULL array and stale count, causing a NULL dereference. Split the cleanup by initialization stage so each failure path unwinds only the resources that may have been initialized. Unregister LED triggers before releasing the SFP upstream and ports, because the LED triggers are initialized after those resources and must be unwound first. Fixes: c8dbdc6e380e ("net: phy: register phy led_triggers during probe to a= void AB-BA deadlock") Signed-off-by: Xuanqiang Luo Reviewed-by: Maxime Chevallier --- drivers/net/phy/phy_device.c | 20 +++++++++++--------- 1 file changed, 11 insertions(+), 9 deletions(-) diff --git a/drivers/net/phy/phy_device.c b/drivers/net/phy/phy_device.c index 94b2e85e00a37..2cf70471ae089 100644 --- a/drivers/net/phy/phy_device.c +++ b/drivers/net/phy/phy_device.c @@ -3706,7 +3706,7 @@ static int phy_probe(struct device *dev) if (phydev->drv->probe) { err =3D phydev->drv->probe(phydev); if (err) - goto out; + goto out_reset; } =20 phy_disable_interrupts(phydev); @@ -3727,7 +3727,7 @@ static int phy_probe(struct device *dev) err =3D genphy_read_abilities(phydev); =20 if (err) - goto out; + goto out_reset; =20 if (!linkmode_test_bit(ETHTOOL_LINK_MODE_Autoneg_BIT, phydev->supported)) @@ -3744,7 +3744,7 @@ static int phy_probe(struct device *dev) =20 err =3D phy_setup_ports(phydev); if (err) - goto out; + goto out_sfp_release; =20 phy_advertise_supported(phydev); =20 @@ -3753,7 +3753,7 @@ static int phy_probe(struct device *dev) */ err =3D genphy_c45_read_eee_adv(phydev, phydev->advertising_eee); if (err) - goto out; + goto out_sfp_release; =20 /* Get the EEE modes we want to prohibit. */ of_set_phy_eee_broken(phydev); @@ -3806,20 +3806,22 @@ static int phy_probe(struct device *dev) if (IS_ENABLED(CONFIG_PHYLIB_LEDS) && !phy_driver_is_genphy(phydev)) { err =3D of_phy_leds(phydev); if (err) - goto out; + goto out_unreg_led_triggers; } =20 return 0; =20 -out: +out_unreg_led_triggers: + if (!phydev->is_on_sfp_module) + phy_led_triggers_unregister(phydev); + +out_sfp_release: sfp_bus_del_upstream(phydev->sfp_bus); phydev->sfp_bus =3D NULL; =20 phy_cleanup_ports(phydev); =20 - if (!phydev->is_on_sfp_module) - phy_led_triggers_unregister(phydev); - +out_reset: /* Re-assert the reset signal on error */ phy_device_reset(phydev, 1); =20 --=20 2.43.0 From nobody Mon Sep 28 10:43:22 2026 Received: from mta1.migadu.com (out-131.mta1.migadu.com [95.215.58.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4C76C37B00C for ; Sun, 23 Aug 2026 03:56:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=95.215.58.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787457400; cv=none; b=M+3YxrmdFF1Qhc6irxy9n8oxCTPdSNKd+5nHGFTRI8W3JSw2mT/EB860Gj6IOLbHbe0h6uYae0l8ViRpJIKYw3hHcSg9obSCebiM60/AlVPdjeM45SHSbhlq9dPELrSOMEmn0dNUnUatJCZo9Vo/rfQgUXucNjwotz861GpMSkE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787457400; c=relaxed/simple; bh=Bk38YP6PQK5x2Z8nz1fXzY2/xBvqrJYX8lASUUZlYjs=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=uRP7IyGmTHry3V18xJdzAgyKbqmpDbNwcdzBB75r4NCkmHOz2VWhgfYWLEvZRv83lbbXubpQcejxCPNPnrnQPwD2rV9BcK56caC/pkx8jQbbgdJsw1HyXZK6bafVON6EhUemLMMTyI93u6w9WFtZSmdqG9+iFFskxHpPujnQWCc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=qt+pgQFh; arc=none smtp.client-ip=95.215.58.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="qt+pgQFh" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=Bk38YP6PQK5x2Z8nz1fXzY2/xBvqrJYX8lASUUZlYjs=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1787457394; v=1; x=1788062194; b=qt+pgQFhXNnmFDos4RPSFfC/DORUJwCQnUYOI96ypjFWTcuIY1Fc5h6YtYL/jJrUXfJZ+eOw rQ1vnDiNJkzesBiO63pxBulbH8G2CntA6khMQ4LB8OYIjIvhIXx7heG2uzoUa5hKXSL00xv3skp xsvLxsl3Z1VfHnYDz/y41jUc= X-Envelope-To: linux-kernel@vger.kernel.org Received: from localhost.localdomain (116.128.244.171) by smtp.migadu.com with ESMTPS id 8a5fef75f9c9bb57; Sun, 23 Aug 2026 03:56:34 +0000 X-Mizu-Trace-ID: 8a5fef75f9c9bb57 X-Migadu-Flow: FLOW_OUT From: Xuanqiang Luo To: netdev@vger.kernel.org, andrew@lunn.ch, maxime.chevallier@bootlin.com, kuba@kernel.org Cc: hkallweit1@gmail.com, chleroy@kernel.org, qingfang.deng@siflower.com.cn, hao.guan@siflower.com.cn, linux@armlinux.org.uk, davem@davemloft.net, edumazet@google.com, pabeni@redhat.com, linux-kernel@vger.kernel.org, Xuanqiang Luo Subject: [PATCH net v5 2/6] net: phy: unregister SFP upstream before port cleanup Date: Sun, 23 Aug 2026 11:55:56 +0800 Message-ID: <20260823035600.188864-3-xuanqiang.luo@linux.dev> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260823035600.188864-1-xuanqiang.luo@linux.dev> References: <20260823035600.188864-1-xuanqiang.luo@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Xuanqiang Luo Commit 4497f5028675 ("net: phy: Clean the phy_ports after unregistering the downstream SFP bus") established that an SFP upstream must be unregistered before its phy_ports are destroyed because SFP callbacks may access these ports. phy_setup_ports() does not follow this order when a later port setup step fails after phy_sfp_probe() succeeds. It destroys the SFP phy_port and leaves phy_probe() to unregister the upstream later, creating a race between port destruction and SFP upstream callbacks. The error unwind is also split across three functions. If phy_setup_sfp_port() fails, phy_sfp_probe() leaves the upstream registered and relies on phy_probe() to remove it after phy_setup_ports() returns. Make each layer unwind the resources it successfully set up. Unregister only the upstream in phy_sfp_probe() when SFP port setup fails, since the failed port has already been destroyed. Add phy_sfp_release() for a successful SFP probe, and make phy_setup_ports() use it before cleaning up the remaining ports. Once phy_setup_ports() has rolled back all port setup, make phy_probe() skip this cleanup. Fixes: 589e934d2735 ("net: phy: Introduce PHY ports representation") Reviewed-by: Andrew Lunn Signed-off-by: Xuanqiang Luo Reviewed-by: Maxime Chevallier --- drivers/net/phy/phy_device.c | 49 ++++++++++++++++++++++++++++-------- 1 file changed, 38 insertions(+), 11 deletions(-) diff --git a/drivers/net/phy/phy_device.c b/drivers/net/phy/phy_device.c index 2cf70471ae089..4b9b2300422fb 100644 --- a/drivers/net/phy/phy_device.c +++ b/drivers/net/phy/phy_device.c @@ -1723,12 +1723,41 @@ static int phy_sfp_probe(struct phy_device *phydev) phydev->sfp_bus =3D NULL; } =20 - if (!ret && phydev->sfp_bus) + if (!ret && phydev->sfp_bus) { ret =3D phy_setup_sfp_port(phydev); + if (ret) { + sfp_bus_del_upstream(phydev->sfp_bus); + phydev->sfp_bus =3D NULL; + } + } =20 return ret; } =20 +/** + * phy_sfp_release - release resources set up by phy_sfp_probe() + * @phydev: the PHY device + * + * Release the SFP resources set up by a successful phy_sfp_probe(). Unreg= ister + * the upstream before destroying its phy_port, so SFP upstream callbacks = cannot + * race with port destruction. + */ +static void phy_sfp_release(struct phy_device *phydev) +{ + struct phy_port *port, *tmp; + + sfp_bus_del_upstream(phydev->sfp_bus); + phydev->sfp_bus =3D NULL; + + list_for_each_entry_safe(port, tmp, &phydev->ports, head) { + if (!port->is_sfp) + continue; + + phy_del_port(phydev, port); + phy_port_destroy(port); + } +} + static bool phy_drv_supports_irq(const struct phy_driver *phydrv) { return phydrv->config_intr && phydrv->handle_interrupt; @@ -3547,13 +3576,13 @@ static int phy_setup_ports(struct phy_device *phyde= v) if (!phydev->is_genphy_driven) { ret =3D phy_sfp_probe(phydev); if (ret) - goto out; + goto err_ports; } =20 if (phydev->n_ports < phydev->max_n_ports) { ret =3D phy_default_setup_single_port(phydev); if (ret) - goto out; + goto err_sfp; } =20 linkmode_zero(ports_supported); @@ -3580,7 +3609,9 @@ static int phy_setup_ports(struct phy_device *phydev) =20 return 0; =20 -out: +err_sfp: + phy_sfp_release(phydev); +err_ports: phy_cleanup_ports(phydev); return ret; } @@ -3744,7 +3775,7 @@ static int phy_probe(struct device *dev) =20 err =3D phy_setup_ports(phydev); if (err) - goto out_sfp_release; + goto out_reset; =20 phy_advertise_supported(phydev); =20 @@ -3816,9 +3847,7 @@ static int phy_probe(struct device *dev) phy_led_triggers_unregister(phydev); =20 out_sfp_release: - sfp_bus_del_upstream(phydev->sfp_bus); - phydev->sfp_bus =3D NULL; - + phy_sfp_release(phydev); phy_cleanup_ports(phydev); =20 out_reset: @@ -3842,9 +3871,7 @@ static int phy_remove(struct device *dev) =20 phydev->state =3D PHY_DOWN; =20 - sfp_bus_del_upstream(phydev->sfp_bus); - phydev->sfp_bus =3D NULL; - + phy_sfp_release(phydev); phy_cleanup_ports(phydev); =20 if (phydev->drv && phydev->drv->remove) --=20 2.43.0 From nobody Mon Sep 28 10:43:22 2026 Received: from mta1.migadu.com (out-139.mta1.migadu.com [95.215.58.139]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4ACBE3B1EE2 for ; Sun, 23 Aug 2026 03:56:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=95.215.58.139 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787457404; cv=none; b=eYuqZsM3M2ZetPsnYxhJnYFZ7nVgACpm6TZYqcW667VgvTgRX6eIuooMqxQeRtdnGvSCH8iYRrJ+VjxItBGHAUmBSEFPLAbKhqzNBwOPC5syjYMohIKYlYQscZBvgIowd/r2i13i+mLcJheDhh6bghu5KesjFI+Kf31IyEHgXeE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787457404; c=relaxed/simple; bh=kceR1WD9rU0gLSlXC/8jFxD0IxMnAmNomzwTUhSuZpg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=g6iAE2wrMsHhHb7zmxoVDTTCddPlUAbDzgWeNj1diVtqfoWwgwAQS6SZVzBRyaeh111YyOY42UQOEdF2TPT8zsic9Uw25Kp+7Ewss5OiBDvOBvyBEB7K4Bh/wI9ZbCY5JiT6cXiPv5kYqm9kWqO+vOBUBGcGcYFl4zJUDBsoijQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=OZ/Jj2Dp; arc=none smtp.client-ip=95.215.58.139 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="OZ/Jj2Dp" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=kceR1WD9rU0gLSlXC/8jFxD0IxMnAmNomzwTUhSuZpg=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1787457400; v=1; x=1788062200; b=OZ/Jj2DpaNGFLDO2frg6VbFamdIdTSE6bH9koxfnkySpX9UXlWaBI4lAftYyT7BZOC1THMLu Cw5CRvmAT3M1WUjkHQnD4EGqf2lDXMfOy+hczfBjAKR3dER4gii/gaJs9/aT0K3BKq0xvr8I6Em 3RbZPnonVAm/Bi4k+S+8qd6A= X-Envelope-To: linux-kernel@vger.kernel.org Received: from localhost.localdomain (116.128.244.171) by smtp.migadu.com with ESMTPS id c291d9e0db372878; Sun, 23 Aug 2026 03:56:40 +0000 X-Mizu-Trace-ID: c291d9e0db372878 X-Migadu-Flow: FLOW_OUT From: Xuanqiang Luo To: netdev@vger.kernel.org, andrew@lunn.ch, maxime.chevallier@bootlin.com, kuba@kernel.org Cc: hkallweit1@gmail.com, chleroy@kernel.org, qingfang.deng@siflower.com.cn, hao.guan@siflower.com.cn, linux@armlinux.org.uk, davem@davemloft.net, edumazet@google.com, pabeni@redhat.com, linux-kernel@vger.kernel.org, Xuanqiang Luo Subject: [PATCH net v5 3/6] net: phy: set PHY_READY after LED setup Date: Sun, 23 Aug 2026 11:55:57 +0800 Message-ID: <20260823035600.188864-4-xuanqiang.luo@linux.dev> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260823035600.188864-1-xuanqiang.luo@linux.dev> References: <20260823035600.188864-1-xuanqiang.luo@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Xuanqiang Luo phy_probe() sets PHY_READY before calling of_phy_leds(). If LED setup fails, the error path releases the initialized resources while the PHY state remains READY even though probing failed. Set PHY_READY only after LED setup succeeds. Fixes: 01e5b728e9e4 ("net: phy: Add a binding for PHY LEDs") Reviewed-by: Andrew Lunn Signed-off-by: Xuanqiang Luo --- drivers/net/phy/phy_device.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/drivers/net/phy/phy_device.c b/drivers/net/phy/phy_device.c index 4b9b2300422fb..891df46d0597f 100644 --- a/drivers/net/phy/phy_device.c +++ b/drivers/net/phy/phy_device.c @@ -3824,9 +3824,6 @@ static int phy_probe(struct device *dev) phydev->supported); } =20 - /* Set the state to READY by default */ - phydev->state =3D PHY_READY; - /* Register the PHY LED triggers */ if (!phydev->is_on_sfp_module) phy_led_triggers_register(phydev); @@ -3840,6 +3837,9 @@ static int phy_probe(struct device *dev) goto out_unreg_led_triggers; } =20 + /* Set the state to READY by default */ + phydev->state =3D PHY_READY; + return 0; =20 out_unreg_led_triggers: --=20 2.43.0 From nobody Mon Sep 28 10:43:22 2026 Received: from mta0.migadu.com (out-141.mta0.migadu.com [91.218.175.141]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 01FD73B42C5 for ; Sun, 23 Aug 2026 03:56:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.141 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787457408; cv=none; b=IJ4EYC9tKhWvVO8UH85W/lLydRrY/6WTu4RAz1zYPmu0zQEwVg7d27EqiJS0+w1YfSTUYx2VCMlhjTz915HJRNjLUPnZHYnjL07Z3O/tq6zkiNsuRDa4sHi6FNpVPICcV4X9Wj3K4CSZCBjM9sxCvJBGYf18Nx8MYUs6x+P/rLs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787457408; c=relaxed/simple; bh=Pibs+c7tZQLPitx0IfvSOl7lc/8t3c9y/LRGCRLWcAg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=XVzM3hfRWGHcbqiWywuVbVt9YPnmBBidEkbKo4zOg7n5NzvaNkH3ZkLEWl4+VPteKDinb5SdhQtaaW1BgQQztu2uS0wysxlJUCT6t/Sq7rQlk8qDyn35Dk56jebV4CWSrwOGxmkTBIHaAub7btSRO40fkaeH+/b195EsoicTzN8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=iS8dKNTs; arc=none smtp.client-ip=91.218.175.141 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="iS8dKNTs" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=Pibs+c7tZQLPitx0IfvSOl7lc/8t3c9y/LRGCRLWcAg=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1787457405; v=1; x=1788062205; b=iS8dKNTsiuTkLJpS5PtGQOZ4knPlw0ZxGWVZmsGLo+6N6lyMRPM2OtxoKVYIriV4bV20N0wk f7Vlrsmx2M2v1OqDqGG2ekgWkDpsUcUGFTn2bqRM6BhAngKcX7ez00mxbPHKKnNwqK+Z/oHkjU6 kEqrtYT+cKKXI0MTEPTcSpwI= X-Envelope-To: linux-kernel@vger.kernel.org Received: from localhost.localdomain (116.128.244.171) by smtp.migadu.com with ESMTPS id 01a76de9a4044b4a; Sun, 23 Aug 2026 03:56:44 +0000 X-Mizu-Trace-ID: 01a76de9a4044b4a X-Migadu-Flow: FLOW_OUT From: Xuanqiang Luo To: netdev@vger.kernel.org, andrew@lunn.ch, maxime.chevallier@bootlin.com, kuba@kernel.org Cc: hkallweit1@gmail.com, chleroy@kernel.org, qingfang.deng@siflower.com.cn, hao.guan@siflower.com.cn, linux@armlinux.org.uk, davem@davemloft.net, edumazet@google.com, pabeni@redhat.com, linux-kernel@vger.kernel.org, Xuanqiang Luo Subject: [PATCH net v5 4/6] net: phy: call driver remove when core initialization fails Date: Sun, 23 Aug 2026 11:55:58 +0800 Message-ID: <20260823035600.188864-5-xuanqiang.luo@linux.dev> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260823035600.188864-1-xuanqiang.luo@linux.dev> References: <20260823035600.188864-1-xuanqiang.luo@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Xuanqiang Luo phy_probe() may fail while querying features or completing other core initialization after the PHY driver probe callback has succeeded. The driver core does not run the remove path after a probe error, so resources that the PHY driver releases in its remove callback are leaked. Call the PHY driver remove callback on these failures. Fixes: efbdfdc29bdd ("net: phy: Add support for asking the PHY its abilitie= s") Reviewed-by: Andrew Lunn Signed-off-by: Xuanqiang Luo --- drivers/net/phy/phy_device.c | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/drivers/net/phy/phy_device.c b/drivers/net/phy/phy_device.c index 891df46d0597f..691396794decd 100644 --- a/drivers/net/phy/phy_device.c +++ b/drivers/net/phy/phy_device.c @@ -3758,7 +3758,7 @@ static int phy_probe(struct device *dev) err =3D genphy_read_abilities(phydev); =20 if (err) - goto out_reset; + goto out_remove; =20 if (!linkmode_test_bit(ETHTOOL_LINK_MODE_Autoneg_BIT, phydev->supported)) @@ -3775,7 +3775,7 @@ static int phy_probe(struct device *dev) =20 err =3D phy_setup_ports(phydev); if (err) - goto out_reset; + goto out_remove; =20 phy_advertise_supported(phydev); =20 @@ -3850,6 +3850,10 @@ static int phy_probe(struct device *dev) phy_sfp_release(phydev); phy_cleanup_ports(phydev); =20 +out_remove: + if (phydev->drv->remove) + phydev->drv->remove(phydev); + out_reset: /* Re-assert the reset signal on error */ phy_device_reset(phydev, 1); --=20 2.43.0 From nobody Mon Sep 28 10:43:22 2026 Received: from mta1.migadu.com (out-150.mta1.migadu.com [95.215.58.150]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B0E35379C28 for ; Sun, 23 Aug 2026 03:56:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=95.215.58.150 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787457413; cv=none; b=sVO0s3IRl1MJRhoeqk8DMHNSjW7fryzvaMkjtoBUpelUZXXXl9ypkKorzIjbXRLGMDRvMjLe3i5D9fPE8NPIEP6ZS4WBTsl3eyXfPJpjzrJWe/7RCVq+Fvc0+ZEOMUT53piLgGF7wXFcwcgvnSdFguzPt/B3Xf5QO2VgnWkXfSc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787457413; c=relaxed/simple; bh=BVqz1oSIQi/XvJyGJbj+unnm7ap4CuuN+D9EOZHYO0Y=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=FaZDCQdOzLKf2D/G/t9zTTb6GEWtTwlFPC8dhVlQmhw+UiDc2W9AoOYfUgG4O/xf+ItrDKeX5EEJf7ujuupEJsoF+/EfOXGFvm//OMO35hcKuvI9adORZQsQC/KUZYqCJzH5zdxEc0ODmq7y2qZ9pAA3i+Na9aFuk44mbYUkkdQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=dgKgoHeN; arc=none smtp.client-ip=95.215.58.150 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="dgKgoHeN" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=BVqz1oSIQi/XvJyGJbj+unnm7ap4CuuN+D9EOZHYO0Y=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1787457409; v=1; x=1788062209; b=dgKgoHeNhX1e9aHyr32OmPSzeLukB/0md6dSHBSbAxkFHjEX378Z+i+vPb0i68wXFoO/Nliu 4miD+l0iQMSGdsJj0DKvPZegs8zkYPiXU8/is2E24s+46i/EvZXSDO3fGOHYGN0MbwPi7zWIX7a s7HmAOm3rew9nTP0iFPQn30A= X-Envelope-To: linux-kernel@vger.kernel.org Received: from localhost.localdomain (116.128.244.171) by smtp.migadu.com with ESMTPS id 48c5bcb9f7b66140; Sun, 23 Aug 2026 03:56:49 +0000 X-Mizu-Trace-ID: 48c5bcb9f7b66140 X-Migadu-Flow: FLOW_OUT From: Xuanqiang Luo To: netdev@vger.kernel.org, andrew@lunn.ch, maxime.chevallier@bootlin.com, kuba@kernel.org Cc: hkallweit1@gmail.com, chleroy@kernel.org, qingfang.deng@siflower.com.cn, hao.guan@siflower.com.cn, linux@armlinux.org.uk, davem@davemloft.net, edumazet@google.com, pabeni@redhat.com, linux-kernel@vger.kernel.org, Xuanqiang Luo Subject: [PATCH net v5 5/6] net: phy: propagate errors from default port setup Date: Sun, 23 Aug 2026 11:55:59 +0800 Message-ID: <20260823035600.188864-6-xuanqiang.luo@linux.dev> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260823035600.188864-1-xuanqiang.luo@linux.dev> References: <20260823035600.188864-1-xuanqiang.luo@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Xuanqiang Luo phy_default_setup_single_port() ignores errors from phy_add_port() and always reports success. If a PHY driver attach_mdi_port() callback fails, the phy_port is leaked and PHY probing continues without the expected default port. Destroy the port and return the error. Fixes: 589e934d2735 ("net: phy: Introduce PHY ports representation") Reviewed-by: Maxime Chevallier Signed-off-by: Xuanqiang Luo --- drivers/net/phy/phy_device.c | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/drivers/net/phy/phy_device.c b/drivers/net/phy/phy_device.c index 691396794decd..8cb0d60fcbba9 100644 --- a/drivers/net/phy/phy_device.c +++ b/drivers/net/phy/phy_device.c @@ -3483,6 +3483,7 @@ static int phy_default_setup_single_port(struct phy_d= evice *phydev) { struct phy_port *port =3D phy_port_alloc(); unsigned long mode; + int ret; =20 if (!port) return -ENOMEM; @@ -3509,9 +3510,11 @@ static int phy_default_setup_single_port(struct phy_= device *phydev) port->pairs =3D max_t(int, port->pairs, ethtool_linkmode_n_pairs(mode)); =20 - phy_add_port(phydev, port); + ret =3D phy_add_port(phydev, port); + if (ret) + phy_port_destroy(port); =20 - return 0; + return ret; } =20 static int of_phy_ports(struct phy_device *phydev) --=20 2.43.0 From nobody Mon Sep 28 10:43:22 2026 Received: from mta0.migadu.com (out-153.mta0.migadu.com [91.218.175.153]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 751C33B1EE2 for ; Sun, 23 Aug 2026 03:56:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.153 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787457417; cv=none; b=qcklD4vx3s4UoOqzw345EQc9aJuOC7E8WpSfoxhX4SUh5mS8GiXx/2ROoO7eE1xqde9qHISNEfzO0f+/u/1BiqKjuCPj+A2wL06suIUOnLCRnaUfT0rZnqiIRr/H7REusayRwzd+RxRR7AVWpDsLL2osJBGPAKb1HluL3ezavks= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787457417; c=relaxed/simple; bh=WWrAQqmLGA9HCXQj7NV+IJjhrsHfcuNd/jPdj6nKXOY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=qKHnyPjDJwE4fuGJ/mmou+fz/u/U8rtXvDhl85Ueouxomrk1yYBIyc+i/HThwhtYOoDPNnBo9a3tUkNTzmCUeYeJaAB+Cs5X5lWrTh9pGFdJ7fm9oMy8r0IWQHhq5yMlhs4QV+vcg194JcFkOEAqV3Ji5Mdnyhse9dzOmW6k3C8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=r9fxohMY; arc=none smtp.client-ip=91.218.175.153 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="r9fxohMY" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=WWrAQqmLGA9HCXQj7NV+IJjhrsHfcuNd/jPdj6nKXOY=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1787457414; v=1; x=1788062214; b=r9fxohMYZ5xulc3f4ZnKoD5+N5E2wo79OGlwnWkyo8OTgXiZNy+Xo+NOWJDEsBQX7Wl0BYB1 noDA4G6J8IcviqPMUe+FGX6j3mJ1+Pgs6HzPJJ//ajK+AkJGmP8Del1lzlFN2X2RG+zTSrigKqe v8MeuM1evhWlBRONjakD+yM0= X-Envelope-To: linux-kernel@vger.kernel.org Received: from localhost.localdomain (116.128.244.171) by smtp.migadu.com with ESMTPS id 1cda12b79cfeea00; Sun, 23 Aug 2026 03:56:54 +0000 X-Mizu-Trace-ID: 1cda12b79cfeea00 X-Migadu-Flow: FLOW_OUT From: Xuanqiang Luo To: netdev@vger.kernel.org, andrew@lunn.ch, maxime.chevallier@bootlin.com, kuba@kernel.org Cc: hkallweit1@gmail.com, chleroy@kernel.org, qingfang.deng@siflower.com.cn, hao.guan@siflower.com.cn, linux@armlinux.org.uk, davem@davemloft.net, edumazet@google.com, pabeni@redhat.com, linux-kernel@vger.kernel.org, Xuanqiang Luo Subject: [PATCH net v5 6/6] net: phy: avoid double-free after LED trigger registration failure Date: Sun, 23 Aug 2026 11:56:00 +0800 Message-ID: <20260823035600.188864-7-xuanqiang.luo@linux.dev> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260823035600.188864-1-xuanqiang.luo@linux.dev> References: <20260823035600.188864-1-xuanqiang.luo@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Xuanqiang Luo phy_led_triggers_register() frees phy_led_triggers when a speed trigger registration fails, but leaves the pointer set to the freed allocation before clearing phy_num_led_triggers. phy_probe() ignores the registration error. If a later probe step fails, its error path calls phy_led_triggers_unregister(); normal teardown during an unbind or MDIO bus removal calls the same helper from phy_remove(). In either case, the trigger count is zero, so the per-trigger unregister loop is skipped, but the dangling pointer is still freed unconditionally. Clear the pointer when partial registration cleanup frees the array, and make phy_led_triggers_unregister() free the array only when its pointer is non-NULL. Fixes: b7f0ee992adf ("net: phy: leds: fix memory leak") Signed-off-by: Xuanqiang Luo --- drivers/net/phy/phy_led_triggers.c | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/drivers/net/phy/phy_led_triggers.c b/drivers/net/phy/phy_led_t= riggers.c index 4eb7716bb9d6c..ff6e518395be0 100644 --- a/drivers/net/phy/phy_led_triggers.c +++ b/drivers/net/phy/phy_led_triggers.c @@ -126,6 +126,7 @@ int phy_led_triggers_register(struct phy_device *phy) while (i--) phy_led_trigger_unregister(&phy->phy_led_triggers[i]); kfree(phy->phy_led_triggers); + phy->phy_led_triggers =3D NULL; out_unreg_link: phy_led_trigger_unregister(phy->led_link_trigger); out_free_link: @@ -141,10 +142,12 @@ void phy_led_triggers_unregister(struct phy_device *p= hy) { int i; =20 - for (i =3D 0; i < phy->phy_num_led_triggers; i++) - phy_led_trigger_unregister(&phy->phy_led_triggers[i]); - kfree(phy->phy_led_triggers); - phy->phy_led_triggers =3D NULL; + if (phy->phy_led_triggers) { + for (i =3D 0; i < phy->phy_num_led_triggers; i++) + phy_led_trigger_unregister(&phy->phy_led_triggers[i]); + kfree(phy->phy_led_triggers); + phy->phy_led_triggers =3D NULL; + } =20 if (phy->led_link_trigger) { phy_led_trigger_unregister(phy->led_link_trigger); --=20 2.43.0