android_kernel_motorola_sm6375/drivers/usb
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Alan Stern ea748ebb90 USB: gadget: dummy-hcd: Fix locking bug in RT-enabled kernels
[ Upstream commit 8d63c83d8eb922f6c316320f50c82fa88d099bea ]

Yunseong Kim and the syzbot fuzzer both reported a problem in
RT-enabled kernels caused by the way dummy-hcd mixes interrupt
management and spin-locking.  The pattern was:

	local_irq_save(flags);
	spin_lock(&dum->lock);
	...
	spin_unlock(&dum->lock);
	...		// calls usb_gadget_giveback_request()
	local_irq_restore(flags);

The code was written this way because usb_gadget_giveback_request()
needs to be called with interrupts disabled and the private lock not
held.

While this pattern works fine in non-RT kernels, it's not good when RT
is enabled.  RT kernels handle spinlocks much like mutexes; in particular,
spin_lock() may sleep.  But sleeping is not allowed while local
interrupts are disabled.

To fix the problem, rewrite the code to conform to the pattern used
elsewhere in dummy-hcd and other UDC drivers:

	spin_lock_irqsave(&dum->lock, flags);
	...
	spin_unlock(&dum->lock);
	usb_gadget_giveback_request(...);
	spin_lock(&dum->lock);
	...
	spin_unlock_irqrestore(&dum->lock, flags);

This approach satisfies the RT requirements.

Signed-off-by: Alan Stern <stern@rowland.harvard.edu>
Cc: stable <stable@kernel.org>
Fixes: b4dbda1a22 ("USB: dummy-hcd: disable interrupts during req->complete")
Reported-by: Yunseong Kim <ysk@kzalloc.com>
Closes: <https://lore.kernel.org/linux-usb/5b337389-73b9-4ee4-a83e-7e82bf5af87a@kzalloc.com/>
Reported-by: syzbot+8baacc4139f12fa77909@syzkaller.appspotmail.com
Closes: <https://lore.kernel.org/linux-usb/68ac2411.050a0220.37038e.0087.GAE@google.com/>
Tested-by: syzbot+8baacc4139f12fa77909@syzkaller.appspotmail.com
CC: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
CC: stable@vger.kernel.org
Reviewed-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Link: https://lore.kernel.org/r/bb192ae2-4eee-48ee-981f-3efdbbd0d8f0@rowland.harvard.edu
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-02 13:34:32 +02:00
..
atm usb: atm: cxacru: Merge cxacru_upload_firmware() into cxacru_heavy_init() 2025-08-28 16:21:30 +02:00
c67x00
cdns3 usb: cdns3: Fix deadlock when using NCM gadget 2025-05-02 07:39:27 +02:00
chipidea usb: chipidea: udc: fix sleeping function called from invalid context 2025-08-28 16:21:22 +02:00
class cdc-acm: fix race between initial clearing halt and open 2025-08-28 16:21:34 +02:00
common
core usb: hub: Fix flushing of delayed work used for post resume purposes 2025-10-02 13:34:27 +02:00
dwc2 usb: dwc2: gadget: remove of_node reference upon udc_stop 2025-03-13 12:43:14 +01:00
dwc3 usb: dwc3: Ignore late xferNotReady event to prevent halt timeout 2025-08-28 16:21:32 +02:00
early usb: early: xhci-dbc: Fix early_ioremap leak 2025-08-28 16:21:19 +02:00
gadget USB: gadget: dummy-hcd: Fix locking bug in RT-enabled kernels 2025-10-02 13:34:32 +02:00
host usb: xhci: Fix slot_id resource race conflict 2025-08-28 16:21:37 +02:00
image
isp1760
misc USB: chaoskey: Fix possible deadlock chaoskey_list_lock 2024-12-14 19:44:34 +01:00
mon
mtu3
musb usb: musb: omap2430: fix device leak at unbind 2025-08-28 16:21:35 +02:00
phy usb: phy: mxs: disconnect line when USB charger is attached 2025-08-28 16:21:18 +02:00
renesas_usbhs usb: renesas_usbhs: Reorder clock handling and power management in probe 2025-06-27 11:02:48 +01:00
roles usb: roles: set switch registered flag early on 2025-03-13 12:43:14 +01:00
serial USB: serial: option: add Telit Cinterion LE910C4-WWX new compositions 2025-10-02 13:34:28 +02:00
storage USB: storage: Ignore driver CD mode for Realtek multi-mode Wi-Fi dongles 2025-08-28 16:21:32 +02:00
typec usb: typec: fusb302: cache PD RX state 2025-08-28 16:21:34 +02:00
usbip
Kconfig
Makefile
usb-skeleton.c