From: Greg KH <gregkh@linuxfoundation.org>
To: xy521521@gmail.com
Cc: stern@rowland.harvard.edu, Hongyu Xie <xiehongyu1@kylinos.cn>,
linux-usb@vger.kernel.org, usb-storage@lists.one-eyed-alien.net,
linux-kernel@vger.kernel.org,
syzbot+30552b4cbe99d6d91306@syzkaller.appspotmail.com,
stable@vger.kernel.org
Subject: Re: [PATCH v2] usb-storage: ene_ub6250: don't let the card-type probe hang forever
Date: Thu, 1 Oct 2026 13:20:08 +0200 [thread overview]
Message-ID: <2026100128-crystal-islamic-b783@gregkh> (raw)
In-Reply-To: <20261001091523.16934-1-xy521521@gmail.com>
On Thu, Oct 01, 2026 at 05:15:23PM +0800, xy521521@gmail.com wrote:
> From: Hongyu Xie <xiehongyu1@kylinos.cn>
>
> ene_ub6250_probe() queries the card type with ene_get_card_type() while
> holding us->dev_mutex (the locking added by commit 445fc368c6bc
> ("usb-storage: ene_ub6250: fix race between scan work and probe")).
> The query is a bulk-only transaction: CBW, 1-byte data-in and CSW, each
> transferred by usb_stor_bulk_transfer_buf(), which waits for URB
> completion with MAX_SCHEDULE_TIMEOUT.
>
> That unbounded wait is safe only while a SCSI command is being handled,
> because the command's abort machinery (usb_stor_stop_transport() via
> US_FLIDX_ABORTING) is the only thing that can terminate it. At probe
> time no SCSI command exists, so a device that passes enumeration but
> never services bulk transfers wedges the probe forever:
>
> hub_event: usb_stor_msg_common() <- ene_send_scsi_cmd
> <- ene_ub6250_probe (holds us->dev_mutex)
> events_freezable: usb_stor_scan_dwork (blocked on us->dev_mutex)
>
> syzbot reports the second worker as "INFO: task hung in
> usb_stor_scan_dwork"; the hub_event worker is stuck in the same wait
> but sleeps interruptibly, which the hung-task detector ignores.
>
> Bound the three probe-time transfers with a 30 s timeout through a new
> usb_stor_bulk_transfer_buf_timeout() helper, so a dead device fails the
> probe cleanly and the existing error path unwinds via
> usb_stor_disconnect().
>
> Fixes: 445fc368c6bc ("usb-storage: ene_ub6250: fix race between scan work and probe")
> Reported-by: syzbot+30552b4cbe99d6d91306@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=30552b4cbe99d6d91306
> Cc: stable@vger.kernel.org
> Signed-off-by: Hongyu Xie <xiehongyu1@kylinos.cn>
> ---
>
> Changes in v2 (formatting only, no functional change):
> - fix checkpatch --strict "alignment should match open parenthesis"
> complaints on the newly added continuation lines
> - rename the fDir parameter of ene_send_scsi_cmd[_timeout]() to fdir
> to silence the CamelCase check
Don't do coding style changes while trying to make a bugfix, as that is
mixing up too many different things.
Please make this a patch series, with the bugfix first, and then if you
want to fix up the coding style issues, that should be a follow-on
patch.
thanks,
greg k-h
prev parent reply other threads:[~2026-10-01 11:20 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 14:46 [PATCH] " xy521521
2026-10-01 9:15 ` [PATCH v2] " xy521521
2026-10-01 11:20 ` Greg KH [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2026100128-crystal-islamic-b783@gregkh \
--to=gregkh@linuxfoundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-usb@vger.kernel.org \
--cc=stable@vger.kernel.org \
--cc=stern@rowland.harvard.edu \
--cc=syzbot+30552b4cbe99d6d91306@syzkaller.appspotmail.com \
--cc=usb-storage@lists.one-eyed-alien.net \
--cc=xiehongyu1@kylinos.cn \
--cc=xy521521@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®