Thread (7 messages) flat view 7 messages, 2 authors, 7d ago

Re: [PATCH net-next v5 0/5] net: pse-pd: decouple controller lookup from MDIO probe

From: Paolo Abeni <pabeni@redhat.com>
Date: 2026-08-27 08:22:15
Also in: lkml

On 8/27/26 12:03 AM, Carlo Szelinsky wrote:
This is v5 of Corey's series [1]. It takes the PSE controller lookup out
of the MDIO probe path, so a modular PSE driver no longer makes the
PHY/DSA probe spin on -EPROBE_DEFER until the PSE module loads.

Patches 1-3 are the same three notifier patches as v4 [4], unchanged,
with Jonas's Tested-by. Patches 4 and 5 are new and fix two problems the
v4 review surfaced.

Patch 4: Aleksander reported [5] that v4 deadlocks on probe for an MDIO
bus registered from ndo_init (lantiq_etop, sni_ave, netsec): those
already hold rtnl via register_netdevice(), and v4's phy attach took
rtnl again underneath. Patch 4 swaps that rtnl for a dedicated mutex, so
the register path no longer recurses. The ethtool PSE paths take the
same mutex, so the use-after-free that rtnl used to close stays closed.
Aleksander confirmed it fixes his deadlock.

Patch 5: Paolo's review [6] pointed out that patch 3 defers the
pse_control_put() to phy_device_release(). A phy that is device_del()'d
but still pinned (an attached netdev) is off the mdio_bus_type klist, so
the PSE_UNREGISTERED notifier walk never clears its phydev->psec, and the
deferred put later touches a pcdev->pi[] the controller has already
freed. Patch 5 puts phydev->psec back in phy_device_remove(), which the
mutex from patch 4 now makes safe (the rtnl recursion that motivated the
deferral is gone), so the detach is synchronous and cannot outlive the
controller.

How it works: pse_core gets a notifier chain (REGISTERED / UNREGISTERED).
The phy layer subscribes, owns phydev->psec, and attaches the PSE handle
when the controller shows up instead of during probe. fwnode_mdio loses
its PSE awareness, so no -EPROBE_DEFER leaves it and the probe-retry loop
is gone.

Tested on a Realtek rtl93xx PoE switch with two HS104 PSE controllers on
i2c:

 - clean boot, no probe-retry loop, no watchdog reset
 - 10G SFP+ port: module hotplug works, no deadlock
 - ethtool --set-pse enable/disable cuts and restores power to a PD
 - i2c unbind -> rmmod -> modprobe: PSE detaches on unbind and re-attaches
   on reload with power restored, no reboot. No lockdep splats.

Jonas confirmed the RTL8214FC deadlock he reported is gone. Aleksander
confirmed the lantiq_etop probe deadlock is gone.

Tested-by: Carlo Szelinsky <redacted>
## Form letter - net-next-closed

net-next pull request for v7.3 has already been merged, and therefore
the net-next tree is closed for new drivers, features, code refactoring
and optimizations. We are currently accepting bug fixes only.

Please repost when net-next reopens after Aug 31st.

RFC patches sent for review only are obviously welcome at any time.

See:
https://www.kernel.org/doc/html/next/process/maintainer-netdev.html#development-cycle
-- 
pw-bot: defer
pv-bot: closed
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help