summaryrefslogtreecommitdiffstats
path: root/include/misc
diff options
context:
space:
mode:
authorAlan Stern <stern@rowland.harvard.edu>2026-09-20 17:37:34 -0400
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2026-10-01 07:16:02 +0200
commitb263ff9b0fc5c1f371d65c4eb196b31263d039ff (patch)
tree83b9d659d9ea919ee2a3fab93f5bb71cadcda166 /include/misc
parentaef5a7e207656ad6abdeeaa0bfc8ee9a1f9c02f6 (diff)
downloadlinux-stable-b263ff9b0fc5c1f371d65c4eb196b31263d039ff.tar.gz
linux-stable-b263ff9b0fc5c1f371d65c4eb196b31263d039ff.zip
USB: gadget: dummy-hcd: Fix wait for outstanding request completions
The dummy-hcd driver emulates synchronize_irq() by waiting until its private callback_usage counter drops to 0 (with the private lock not held). This counter is incremented whenever a gadget driver callback occurs (which requires the private lock to be dropped), but not when a request completion handler is called. This is an oversight. Request completion is triggered by timer interrupts (emulating device IRQs in a real UDC), and the interrupt handlers are supposed to have completed when the synchronize_irq() emulation routine returns -- they aren't supposed to be in the middle of a completion callback. If this happens it can lead to a gadget driver's unbind routine running before all outstanding request completions have finished, maybe even allowing the gadget driver's module to be unloaded while a completion handler is still running. Fix the oversight by incrementing the callback_usage value across request completion callbacks. Link: https://lore.kernel.org/linux-usb/7a87e293-633c-4100-aa8d-91560ba5e5c5@rowland.harvard.edu/ Fixes: 7dbd8f4cabd9 ("USB: dummy-hcd: Fix erroneous synchronization change") Tested-by: Minseo Kim <neck3922@gmail.com> Signed-off-by: Alan Stern <stern@rowland.harvard.edu> Cc: stable <stable@kernel.org> Link: https://patch.msgid.link/f23b9e1a-f110-441a-a1d8-95f442ec09d5@rowland.harvard.edu Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'include/misc')
0 files changed, 0 insertions, 0 deletions