mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Greg KH <gregkh@linuxfoundation.org>
To: xy521521@gmail.com
Cc: stern@rowland.harvard.edu, Hongyu Xie <xiehongyu1@kylinos.cn>,
	linux-usb@vger.kernel.org, usb-storage@lists.one-eyed-alien.net,
	linux-kernel@vger.kernel.org,
	syzbot+30552b4cbe99d6d91306@syzkaller.appspotmail.com,
	stable@vger.kernel.org
Subject: Re: [PATCH v2] usb-storage: ene_ub6250: don't let the card-type probe hang forever
Date: Thu, 1 Oct 2026 13:20:08 +0200	[thread overview]
Message-ID: <2026100128-crystal-islamic-b783@gregkh> (raw)
In-Reply-To: <20261001091523.16934-1-xy521521@gmail.com>

On Thu, Oct 01, 2026 at 05:15:23PM +0800, xy521521@gmail.com wrote:
> From: Hongyu Xie <xiehongyu1@kylinos.cn>
> 
> ene_ub6250_probe() queries the card type with ene_get_card_type() while
> holding us->dev_mutex (the locking added by commit 445fc368c6bc
> ("usb-storage: ene_ub6250: fix race between scan work and probe")).
> The query is a bulk-only transaction: CBW, 1-byte data-in and CSW, each
> transferred by usb_stor_bulk_transfer_buf(), which waits for URB
> completion with MAX_SCHEDULE_TIMEOUT.
> 
> That unbounded wait is safe only while a SCSI command is being handled,
> because the command's abort machinery (usb_stor_stop_transport() via
> US_FLIDX_ABORTING) is the only thing that can terminate it.  At probe
> time no SCSI command exists, so a device that passes enumeration but
> never services bulk transfers wedges the probe forever:
> 
>     hub_event:         usb_stor_msg_common() <- ene_send_scsi_cmd
>                        <- ene_ub6250_probe  (holds us->dev_mutex)
>     events_freezable:  usb_stor_scan_dwork  (blocked on us->dev_mutex)
> 
> syzbot reports the second worker as "INFO: task hung in
> usb_stor_scan_dwork"; the hub_event worker is stuck in the same wait
> but sleeps interruptibly, which the hung-task detector ignores.
> 
> Bound the three probe-time transfers with a 30 s timeout through a new
> usb_stor_bulk_transfer_buf_timeout() helper, so a dead device fails the
> probe cleanly and the existing error path unwinds via
> usb_stor_disconnect().
> 
> Fixes: 445fc368c6bc ("usb-storage: ene_ub6250: fix race between scan work and probe")
> Reported-by: syzbot+30552b4cbe99d6d91306@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=30552b4cbe99d6d91306
> Cc: stable@vger.kernel.org
> Signed-off-by: Hongyu Xie <xiehongyu1@kylinos.cn>
> ---
> 
> Changes in v2 (formatting only, no functional change):
> - fix checkpatch --strict "alignment should match open parenthesis"
>   complaints on the newly added continuation lines
> - rename the fDir parameter of ene_send_scsi_cmd[_timeout]() to fdir
>   to silence the CamelCase check

Don't do coding style changes while trying to make a bugfix, as that is
mixing up too many different things.

Please make this a patch series, with the bugfix first, and then if you
want to fix up the coding style issues, that should be a follow-on
patch.

thanks,

greg k-h

      reply	other threads:[~2026-10-01 11:20 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-29 14:46 [PATCH] " xy521521
2026-10-01  9:15 ` [PATCH v2] " xy521521
2026-10-01 11:20   ` Greg KH [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2026100128-crystal-islamic-b783@gregkh \
    --to=gregkh@linuxfoundation.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-usb@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=stern@rowland.harvard.edu \
    --cc=syzbot+30552b4cbe99d6d91306@syzkaller.appspotmail.com \
    --cc=usb-storage@lists.one-eyed-alien.net \
    --cc=xiehongyu1@kylinos.cn \
    --cc=xy521521@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®