> -----Original Message-----
> From: Intel-wired-lan <[email protected]> On Behalf Of Petr 
> Oros
> Sent: Monday, April 13, 2026 12:14 PM
> To: [email protected]
> Cc: Michal Swiatkowski <[email protected]>; Greenwalt, Paul 
> <[email protected]>; Daniel Zahka <[email protected]>; Kitszel, 
> Przemyslaw <[email protected]>; Nikolay Aleksandrov 
> <[email protected]>; Eric Dumazet <[email protected]>; linux-
> [email protected]; Loktionov, Aleksandr <[email protected]>; 
> Andrew Lunn <[email protected]>; Nguyen, Anthony L 
> <[email protected]>; Ertman, David M <[email protected]>; 
> Keller, Jacob E <[email protected]>; Jakub Kicinski <[email protected]>; 
> Paolo 
> Abeni <[email protected]>; David S. Miller <[email protected]>; 
> [email protected]
> Subject: [Intel-wired-lan] [PATCH iwl-net] ice: fix infinite recursion in 
> ice_cfg_tx_topo via ice_init_dev_hw
> 
> On certain E810 configurations where firmware supports Tx scheduler topology 
> switching (tx_sched_topo_comp_mode_en), ice_cfg_tx_topo() may need to apply a 
> new 5-layer or 9-layer topology from the DDP package. If the AQ command to 
> set the topology fails (e.g. due to invalid DDP data or firmware 
> limitations), the global configuration lock must still be cleared via a CORER 
> reset.
> 
> Commit 86aae43f21cf ("ice: don't leave device non-functional if Tx scheduler 
> config fails") correctly fixed this by refactoring
> ice_cfg_tx_topo() to always trigger CORER after acquiring the global lock and 
> re-initialize hardware via ice_init_hw() afterwards.
> 
> However, commit 8a37f9e2ff40 ("ice: move ice_deinit_dev() to the end of 
> deinit paths") later moved ice_init_dev_hw() into ice_init_hw(), breaking the 
> reinit path introduced by 86aae43f21cf. This creates an infinite recursive 
> call chain:
> 
>   ice_init_hw()
>     ice_init_dev_hw()
>       ice_cfg_tx_topo()         # topology change needed
>         ice_deinit_hw()
>         ice_init_hw()           # reinit after CORER
>           ice_init_dev_hw()     # recurse
>             ice_cfg_tx_topo()
>               ...               # stack overflow
> 
> Fix by moving ice_init_dev_hw() back out of ice_init_hw() and calling it 
> explicitly from ice_probe() and ice_devlink_reinit_up(). The third caller, 
> ice_cfg_tx_topo(), intentionally does not need ice_init_dev_hw() during its 
> reinit, it only needs the core HW reinitialization. This breaks the recursion 
> cleanly without 
> adding flags or guards.
> 
> The deinit ordering changes from commit 8a37f9e2ff40 ("ice: move
> ice_deinit_dev() to the end of deinit paths") which fixed slow rmmod are 
> preserved, only the init-side placement of ice_init_dev_hw() is reverted.

> Fixes: 8a37f9e2ff40 ("ice: move ice_deinit_dev() to the end of deinit paths")
> Signed-off-by: Petr Oros <[email protected]>
> ---
>  drivers/net/ethernet/intel/ice/devlink/devlink.c | 2 ++
>  drivers/net/ethernet/intel/ice/ice_common.c      | 2 --
>  drivers/net/ethernet/intel/ice/ice_main.c        | 2 ++
>  3 files changed, 4 insertions(+), 2 deletions(-)

Tested-by: Alexander Nowlin <[email protected]>

Reply via email to