mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@kernel.org
Cc: Justin Forbes <jmforbes@linuxtx.org>,
	Zwane Mwaikambo <zwane@arm.linux.org.uk>,
	"Theodore Ts'o" <tytso@mit.edu>,
	Randy Dunlap <rdunlap@xenotime.net>,
	Dave Jones <davej@redhat.com>,
	Chuck Wolber <chuckw@quantumlinux.com>,
	Chris Wedgwood <reviews@ml.cw.f00f.org>,
	Michael Krufky <mkrufky@linuxtv.org>,
	Chuck Ebbert <cebbert@redhat.com>,
	Domenico Andreoli <cavokz@gmail.com>, Willy Tarreau <w@1wt.eu>,
	Rodrigo Rubira Branco <rbranco@la.checkpoint.com>,
	Jake Edge <jake@lwn.net>, Eugene Teo <eteo@redhat.com>,
	torvalds@linux-foundation.org, akpm@linux-foundation.org,
	alan@lxorguk.ukuu.org.uk, Alan Stern <stern@rowland.harvard.edu>
Subject: [patch 34/43] USB: usbfs: keep async URBs until the device file is closed
Date: Fri, 20 Mar 2009 15:28:44 -0700	[thread overview]
Message-ID: <20090320222928.261453123@mini.kroah.org> (raw)
In-Reply-To: <20090320232116.GA3375@kroah.com>

[-- Attachment #1: usb-usbfs-keep-async-urbs-until-the-device-file-is-closed.patch --]
[-- Type: text/plain, Size: 2221 bytes --]

2.6.28-stable review patch.  If anyone has any objections, please let us know.

------------------

From: Alan Stern <stern@rowland.harvard.edu>

commit 6ff10464096540e14d7575a72c50d0316d003714 upstream.

The usbfs driver manages a list of completed asynchronous URBs.  But
it is too eager to free the entries on this list: destroy_async() gets
called whenever an interface is unbound or a device is removed, and it
deallocates the outstanding struct async entries for all URBs on that
interface or device.  This is wrong; the user program should be able
to reap an URB any time after it has completed, regardless of whether
or not the interface is still bound or the device is still present.

This patch (as1222) moves the code for deallocating the completed list
entries from destroy_async() to usbdev_release().  The outstanding
entries won't be freed until the user program has closed the device
file, thereby eliminating any possibility that the remaining URBs
might still be reaped.

This fixes a bug in which a program can hang in the USBDEVFS_REAPURB
ioctl when the device is unplugged.

Reported-and-tested-by: Martin Poupe <martin.poupe@upek.com>
Signed-off-by: Alan Stern <stern@rowland.harvard.edu>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>

---
 drivers/usb/core/devio.c |   12 +++++++-----
 1 file changed, 7 insertions(+), 5 deletions(-)

--- a/drivers/usb/core/devio.c
+++ b/drivers/usb/core/devio.c
@@ -359,11 +359,6 @@ static void destroy_async(struct dev_sta
 		spin_lock_irqsave(&ps->lock, flags);
 	}
 	spin_unlock_irqrestore(&ps->lock, flags);
-	as = async_getcompleted(ps);
-	while (as) {
-		free_async(as);
-		as = async_getcompleted(ps);
-	}
 }
 
 static void destroy_async_on_interface(struct dev_state *ps,
@@ -642,6 +637,7 @@ static int usbdev_release(struct inode *
 	struct dev_state *ps = file->private_data;
 	struct usb_device *dev = ps->dev;
 	unsigned int ifnum;
+	struct async *as;
 
 	usb_lock_device(dev);
 
@@ -660,6 +656,12 @@ static int usbdev_release(struct inode *
 	usb_unlock_device(dev);
 	usb_put_dev(dev);
 	put_pid(ps->disc_pid);
+
+	as = async_getcompleted(ps);
+	while (as) {
+		free_async(as);
+		as = async_getcompleted(ps);
+	}
 	kfree(ps);
 	return 0;
 }



  parent reply	other threads:[~2009-03-20 23:38 UTC|newest]

Thread overview: 46+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20090320222810.386844059@mini.kroah.org>
2009-03-20 23:21 ` [patch 00/43] 2.6.28.9-stable review Greg KH
2009-03-20 22:28   ` [patch 01/43] [IA64] Build fix for __early_pfn_to_nid() undefined link error Greg KH
2009-03-20 22:28   ` [patch 02/43] Fix misreporting of #cores as #hyperthreads for Q9550 Greg KH
2009-03-20 22:28   ` [patch 03/43] eventfd: remove fput() call from possible IRQ context Greg KH
2009-03-20 22:28   ` [patch 04/43] S390: __div64_31 broken for CONFIG_MARCH_G5 Greg KH
2009-03-20 22:28   ` [patch 05/43] ALSA: Fix vunmap and free order in snd_free_sgbuf_pages() Greg KH
2009-03-20 22:28   ` [patch 06/43] ALSA: mixart, fix lock imbalance Greg KH
2009-03-20 22:28   ` [patch 07/43] ALSA: pcm_oss, fix locking typo Greg KH
2009-03-20 22:28   ` [patch 08/43] ALSA: hda - Fix DMA mask for ATI controllers Greg KH
2009-03-20 22:28   ` [patch 09/43] ALSA: hda - Workaround for buggy DMA position on " Greg KH
2009-03-20 22:28   ` [patch 10/43] ALSA: opl3sa2 - Fix NULL dereference when suspending snd_opl3sa2 Greg KH
2009-03-20 22:28   ` [patch 11/43] nfsd: nfsd should drop CAP_MKNOD for non-root Greg KH
2009-03-20 22:28   ` [patch 12/43] NFSD: provide encode routine for OP_OPENATTR Greg KH
2009-03-20 22:28   ` [patch 13/43] dm ioctl: validate name length when renaming Greg KH
2009-03-20 22:28   ` [patch 14/43] dm io: respect BIO_MAX_PAGES limit Greg KH
2009-03-20 22:28   ` [patch 15/43] dm crypt: fix kcryptd_async_done parameter Greg KH
2009-03-20 22:28   ` [patch 16/43] dm crypt: wait for endio to complete before destruction Greg KH
2009-03-20 22:28   ` [patch 17/43] ata_piix: add workaround for Samsung DB-P70 Greg KH
2009-03-20 22:28   ` [patch 18/43] V4L/DVB (10218): cx23885: Fix Oops for mixed install of analog and digital only cards Greg KH
2009-03-20 22:28   ` [patch 19/43] thinkpad-acpi: fix module autoloading for older models Greg KH
2009-03-20 22:28   ` [patch 20/43] Add -fwrapv to gcc CFLAGS Greg KH
2009-03-20 22:28   ` [patch 21/43] Move cc-option to below arch-specific setup Greg KH
2009-03-20 22:28   ` [patch 22/43] USB: storage: Unusual USB device Prolific 2507 variation added Greg KH
2009-03-20 22:28   ` [patch 23/43] USB: Add Vendor/Product ID for new CDMA U727 to option driver Greg KH
2009-03-20 22:28   ` [patch 24/43] USB: option.c: add ZTE 622 modem device Greg KH
2009-03-20 22:28   ` [patch 25/43] USB: Add device id for Option GTM380 to option driver Greg KH
2009-03-20 22:28   ` [patch 26/43] USB: Option: let cdc-acm handle Sony Ericsson F3507g / Dell 5530 Greg KH
2009-03-20 22:28   ` [patch 27/43] USB: Updated unusual-devs entry for USB mass storage on Nokia 6233 Greg KH
2009-03-20 22:28   ` [patch 28/43] USB: unusual_devs: Add support for GI 0431 SD-Card interface Greg KH
2009-03-20 22:28   ` [patch 29/43] USB: serial: add FTDI USB/Serial converter devices Greg KH
2009-03-20 22:28   ` [patch 30/43] USB: serial: ftdi: enable UART detection on gnICE JTAG adaptors blacklist interface0 Greg KH
2009-03-20 22:28   ` [patch 31/43] USB: serial: new cp2101 device id Greg KH
2009-03-20 22:28   ` [patch 32/43] USB: usbtmc: fix stupid bug in open() Greg KH
2009-03-20 22:28   ` [patch 33/43] USB: usbtmc: add protocol 1 support Greg KH
2009-03-20 22:28   ` Greg KH [this message]
2009-03-20 22:28   ` [patch 35/43] USB: EHCI: expedite unlinks when the root hub is suspended Greg KH
2009-03-20 22:28   ` [patch 36/43] USB: EHCI: Fix isochronous URB leak Greg KH
2009-03-20 22:28   ` [patch 37/43] powerpc: Remove extra semicolon in fsl_soc.c Greg KH
2009-03-20 22:28   ` [patch 38/43] drm/i915: set vblank enabled flag correctly across IRQ install/uninstall Greg KH
2009-03-21  0:09     ` Eric Anholt
2009-03-21  0:43       ` Greg KH
2009-03-20 22:28   ` [patch 39/43] drm/i915: dont enable vblanks on disabled pipes Greg KH
2009-03-20 22:28   ` [patch 40/43] drm/i915: Dont double-unpin buffers if we take a signal in evict_everything() Greg KH
2009-03-20 22:28   ` [patch 41/43] drm/i915: Dont print to dmesg when taking signal during object_pin Greg KH
2009-03-20 22:28   ` [patch 42/43] drm/i915: Dont allow objects to get bound while VT switched Greg KH
2009-03-20 22:28   ` [patch 43/43] menu: fix embedded menu snafu Greg KH

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20090320222928.261453123@mini.kroah.org \
    --to=gregkh@suse.de \
    --cc=akpm@linux-foundation.org \
    --cc=alan@lxorguk.ukuu.org.uk \
    --cc=cavokz@gmail.com \
    --cc=cebbert@redhat.com \
    --cc=chuckw@quantumlinux.com \
    --cc=davej@redhat.com \
    --cc=eteo@redhat.com \
    --cc=jake@lwn.net \
    --cc=jmforbes@linuxtx.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mkrufky@linuxtv.org \
    --cc=rbranco@la.checkpoint.com \
    --cc=rdunlap@xenotime.net \
    --cc=reviews@ml.cw.f00f.org \
    --cc=stable@kernel.org \
    --cc=stern@rowland.harvard.edu \
    --cc=torvalds@linux-foundation.org \
    --cc=tytso@mit.edu \
    --cc=w@1wt.eu \
    --cc=zwane@arm.linux.org.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

Powered by JetHome