mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Russ Dill <russ.dill@gmail.com>
To: linux-kernel@vger.kernel.org
Subject: Use of usb_find_interface in open is racy
Date: Tue, 17 Nov 2009 14:06:07 -0700	[thread overview]
Message-ID: <f9d2a5e10911171306r416eaf2k45c3256370e82eda@mail.gmail.com> (raw)

Many usb drivers that create character devices use "struct
usb_class_driver", a set of fops, and a usb_find_interface in their
open call. A prime example is drivers/usb/usb-skeleton.c. A race
occurs when userspace receives a hotplug event for the addition for
the interface and then opens the associated device file before the
device is added to the driver's klist_devices.

The usb core senses a new usb device (usb_new_device) and calls
device_add. This eventually gets down to really_probe and the
usb-skeleton probe function, skel_probe. skel_probe calls
usb_register_dev() which registers the associated character device for
skel_class. The hotplug events for the class device get emitted.

User space receives the hotplug event for the class device, makes the
device node and notifies another program that opens the device node.
The program opens the device node which calls into usb_open and then
skel_open. skel_open calls usb_find_interface. usb_find_interfaces
searches the klist_devices of skel_driver, finds no device associated
with the minor number and returns NULL. skel_open returns -ENODEV.

Control returns to really_probe and really_probe calls driver_bound
which adds the device to the list of devices associated with
skel_driver (klist_devices).

I'm not sure what the right way to solve this is. A call to
wait_for_device_probe() in the skel_open call before calling
usb_find_interface fixes the problem, but it is a rather large hammer.

             reply	other threads:[~2009-11-17 21:06 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-11-17 21:06 Russ Dill [this message]
2009-11-18 10:41 ` Jiri Kosina
2009-11-18 14:27   ` Oliver Neukum
2009-11-18 15:35     ` Alan Stern
2009-11-18 16:58       ` Russ Dill
2009-11-18 16:51     ` Russ Dill
2009-11-18 15:31   ` Alan Stern
2009-11-18 15:39     ` Greg KH
2009-11-18 17:01       ` Russ Dill
2009-11-18 18:02       ` [PATCH] Close usb_find_interface race Russ Dill
2009-11-18 18:16         ` Greg KH
2009-11-18 16:57     ` Use of usb_find_interface in open is racy Russ Dill

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=f9d2a5e10911171306r416eaf2k45c3256370e82eda@mail.gmail.com \
    --to=russ.dill@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®