[lvc-project] [PATCH net 1/3] net: fealnx: fix teardown order in remove
Andrew Lunn
andrew at lunn.ch
Thu Sep 24 19:43:44 MSK 2026
On Thu, Sep 24, 2026 at 10:44:21AM +0000, Жамбакиев Радий Рикардинович wrote:
> From: Radiy Zhambakiev <r.zhambakiev at prosoftsystems.ru>
>
> fealnx_remove_one() frees the DMA rings before unregistering the
> netdev, while the interface may still be up, which leaves a
> window where freed memory can be accessed.
>
> Call unregister_netdev() first so dev_close() stops the Tx/Rx
> engines, deletes the timers, and frees the IRQ before the rings are
> freed. While at it use dev_err() instead of printk() for the
> unknown-device case.
>
> Found by Linux Verification Center (linuxtesting.org)
>
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Cc: stable at vger.kernel.org
> Signed-off-by: Radiy Zhambakiev <r.zhambakiev at prosoftsystems.ru>
> ---
> drivers/net/ethernet/fealnx.c | 29 ++++++++++++++++-------------
> 1 file changed, 16 insertions(+), 13 deletions(-)
>
> diff --git a/drivers/net/ethernet/fealnx.c b/drivers/net/ethernet/fealnx.c
> index bdc38aac5850..d7cd1644a375 100644
> --- a/drivers/net/ethernet/fealnx.c
> +++ b/drivers/net/ethernet/fealnx.c
> @@ -678,20 +678,23 @@ static int fealnx_init_one(struct pci_dev *pdev,
> static void fealnx_remove_one(struct pci_dev *pdev)
> {
> struct net_device *dev = pci_get_drvdata(pdev);
> + struct netdev_private *np;
> +
> + if (!dev) {
> + dev_err(&pdev->dev, "remove for unknown device\n");
> + return;
> + }
I know you are just moving code around, but is that possible? We try
avoid defensive code. It is better to actually understand the code and
stop bad things happening.
Andrew
More information about the lvc-project
mailing list