From mboxrd@z Thu Jan 1 00:00:00 1970 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Subject: [v1,1/1] usb: cdc_acm: prevent race at write to acm while system resumes From: Oliver Neukum Message-Id: <1518516440.4584.4.camel@suse.com> Date: Tue, 13 Feb 2018 11:07:20 +0100 To: sathyanarayan.kuppuswamy@linux.intel.com, felipe.balbi@intel.com, heikki.krogerus@intel.com, gregkh@linuxfoundation.org Cc: Dominik Bozek , Sathyanarayanan Kuppuswamy , linux-kernel@vger.kernel.org, linux-usb@vger.kernel.org List-ID: QW0gTW9udGFnLCBkZW4gMTIuMDIuMjAxOCwgMTI6MTUgLTA4MDAgc2NocmllYgpzYXRoeWFuYXJh eWFuLmt1cHB1c3dhbXlAbGludXguaW50ZWwuY29tOgo+IEZyb206IERvbWluaWsgQm96ZWsgPGRv bWluaWt4LmJvemVrQGludGVsLmNvbT4KPiAKPiBBQ00gZHJpdmVyIG1heSBhY2NlcHQgZGF0YSB0 byB0cmFuc21pdCB3aGlsZSBzeXN0ZW0gaXMgbm90IGZ1bGx5Cj4gcmVzdW1lZC4gSW4gdGhpcyBj YXNlIEFDTSBkcml2ZXIgYnVmZmVycyBkYXRhIGFuZCBwcmVwYXJlIFVSQnMKPiBvbiB1c2IgYW5j aG9yIGxpc3QuCj4gVGhlcmUgaXMgYSBsaXR0bGUgY2hhbmNlIHRoYXQgdHdvIHRhc2tzIHB1dCBh IGNoYXIgYW5kIGluaXRpYXRlCj4gYWNtX3R0eV9mbHVzaF9jaGFycygpLiBJbiBzdWNoIGEgY2Fz ZSwgZHJpdmVyIHdpbGwgcHV0IG9uZSBVUkIKPiB0d2ljZSBvbiB1c2IgYW5jaG9yIGxpc3QuCj4g VGhpcyBwYXRjaCBhbHNvIHJlc2V0IGxlbmd0aCBvZiBkYXRhIGJlZm9yZSByZXN1ZSBvZiBhIGJ1 ZmZlci4KPiBUaGlzIG5vdCBvbmx5IHByZXZlbnQgc2VuZGluZyBydWJiaXNoLCBidXQgYWxzbyBs b3dlciByaXNjIG9mIHJhY2UuCj4gCj4gV2l0aG91dCB0aGlzIHBhdGNoIHdlIGhpdCBmb2xsb3dp bmcga2VybmVsIHBhbmljIGluIG9uZSBvZiBvdXIKPiBzdGFiaWx0eS9zdHJlc3MgdGVzdHMuCj4g Cj4gWyAgIDQ2Ljg4NDQ0Ml0gKmxpc3RfYWRkIGRvdWJsZSBhZGQqOiBuZXc9ZmZmZjliMmFiNzI4 OTMzMCwgcHJldj1mZmZmOWIyYWI3Mjg5MzMwLCBuZXh0PWZmZmY5YjJhYjgxZTI4ZTAuCj4gWyAg IDQ2Ljg4NDQ3Nl0gTW9kdWxlcyBsaW5rZWQgaW46IGhjaV91YXJ0IGJ0YmNtIGJsdWV0b290aCBy ZmtpbGxfZ3BpbyBpZ2JfYXZiKE8pIGNmZzgwMjExIHNuZF9zb2Nfc3N0X2J4dF90ZGY4NTMyIHNu ZF9zb2Nfc2tsIHNuZF9zb2Nfc2tsX2lwYyBzbmRfc29jX3NzdF9pcGMgc25kX3NvY19zc3RfZHNw IHNuZF9zb2Nfc3N0X2FjcGkgc25kX3NvY19zc3RfbWF0Y2ggc25kX2hkYV9leHRfY29yZSBzbmRf aGRhX2NvcmUgdHJ1c3R5X3RpbWVyIHRydXN0eV93YWxsIHRydXN0eV9sb2cgdHJ1c3R5X3ZpcnRp byB0cnVzdHlfaXBjIHRydXN0eV9tZW0gdHJ1c3R5X2lycSB0cnVzdHkgdmlydGlvX3Jpbmcgdmly dGlvIGludGVsX2lwdTRfbW11X2J4dEIwIGxpYjI2MDBfbW9kX2J4dEIwIGludGVsX2lwdTRfaXN5 c19tb2RfYnh0QjAgbGliMjYwMHBzeXNfbW9kX2J4dEIwIGludGVsX2lwdTRfcHN5c19tb2RfYnh0 QjAgaW50ZWxfaXB1NF9tb2RfYnh0QjAgaW50ZWxfaXB1NF93cmFwcGVyX2J4dEIwIGludGVsX2lw dTRfYWNwaSB2aWRlb2J1ZjJfZG1hX2NvbnRpZyBhczM2MzggZHc5NzE0IGxtMzY0MyBjcmxtb2R1 bGUgc21pYXBwIHNtaWFwcF9wbGwKPiBbICAgNDYuODg0NDgwXSBDUFU6IDEgUElEOiAzMyBDb21t OiBrd29ya2VyL3U4OjEgVGFpbnRlZDogRyAgICAgVSAgVyAgTyAgICA0LjkuNTYtcXVpbHQtMmU1 ZGMwYWMtZzYxOGVkNjljZWQ2ZS1kaXJ0eSAjNAo+IFsgICA0Ni44ODQ0ODldIFdvcmtxdWV1ZTog ZXZlbnRzX3VuYm91bmQgZmx1c2hfdG9fbGRpc2MKPiBbICAgNDYuODg0NDk0XSAgZmZmZmI5OGFj MDEyYmIwOCBmZmZmZmZmZmFkM2U4MmU1IGZmZmZiOThhYzAxMmJiNTggMDAwMDAwMDAwMDAwMDAw MAo+IFsgICA0Ni44ODQ0OTddICBmZmZmYjk4YWMwMTJiYjQ4IGZmZmZmZmZmYWQwYTIzZDEgMDAw MDAwMjRhZDYzNzRkZCBmZmZmOWIyYWI3Mjg5MzMwCj4gWyAgIDQ2Ljg4NDUwMF0gIGZmZmY5YjJh YjgxZTI4ZTAgZmZmZjliMmFiNzI4OTMzMCAwMDAwMDAwMDAwMDAwMDAyIDAwMDAwMDAwMDAwMDAw MDAKPiBbICAgNDYuODg0NTAxXSBDYWxsIFRyYWNlOgo+IFsgICA0Ni44ODQ1MDddICBbPGZmZmZm ZmZmYWQzZTgyZTU+XSBkdW1wX3N0YWNrKzB4NjcvMHg5Mgo+IFsgICA0Ni44ODQ1MTFdICBbPGZm ZmZmZmZmYWQwYTIzZDE+XSBfX3dhcm4rMHhkMS8weGYwCj4gWyAgIDQ2Ljg4NDUxM10gIFs8ZmZm ZmZmZmZhZDBhMjQ0Zj5dIHdhcm5fc2xvd3BhdGhfZm10KzB4NWYvMHg4MAo+IFsgICA0Ni44ODQ1 MTZdICBbPGZmZmZmZmZmYWQ0MDc0NDM+XSBfX2xpc3RfYWRkKzB4YjMvMHhjMAo+IFsgICA0Ni44 ODQ1MjFdICBbPGZmZmZmZmZmYWQ3MTEzM2M+XSAqdXNiX2FuY2hvcl91cmIqKzB4NGMvMHhhMAo+ IFsgICA0Ni44ODQ1MjRdICBbPGZmZmZmZmZmYWQ3ODJjNmY+XSAqYWNtX3R0eV9mbHVzaF9jaGFy cyorMHg4Zi8weGIwCj4gWyAgIDQ2Ljg4NDUyN10gIFs8ZmZmZmZmZmZhZDc4MmNkMT5dICphY21f dHR5X3B1dF9jaGFyKisweDQxLzB4MTAwCj4gWyAgIDQ2Ljg4NDUzMF0gIFs8ZmZmZmZmZmZhZDRj ZWQzND5dIHR0eV9wdXRfY2hhcisweDI0LzB4NDAKPiBbICAgNDYuODg0NTMzXSAgWzxmZmZmZmZm ZmFkNGQzYmY1Pl0gZG9fb3V0cHV0X2NoYXIrMHhhNS8weDIwMAo+IFsgICA0Ni44ODQ1MzVdICBb PGZmZmZmZmZmYWQ0ZDNlOTg+XSBfX3Byb2Nlc3NfZWNob2VzKzB4MTQ4LzB4MjkwCj4gWyAgIDQ2 Ljg4NDUzOF0gIFs8ZmZmZmZmZmZhZDRkNjU0Yz5dIG5fdHR5X3JlY2VpdmVfYnVmX2NvbW1vbisw eDU3Yy8weGIwMAo+IFsgICA0Ni44ODQ1NDFdICBbPGZmZmZmZmZmYWQ0ZDZhZTQ+XSBuX3R0eV9y ZWNlaXZlX2J1ZjIrMHgxNC8weDIwCj4gWyAgIDQ2Ljg4NDU0M10gIFs8ZmZmZmZmZmZhZDRkOTY2 Mj5dIHR0eV9sZGlzY19yZWNlaXZlX2J1ZisweDIyLzB4NTAKPiBbICAgNDYuODg0NTQ1XSAgWzxm ZmZmZmZmZmFkNGQ5YzA1Pl0gZmx1c2hfdG9fbGRpc2MrMHhjNS8weGUwCj4gWyAgIDQ2Ljg4NDU0 OV0gIFs8ZmZmZmZmZmZhZDBiY2ZlOD5dIHByb2Nlc3Nfb25lX3dvcmsrMHgxNDgvMHg0NDAKPiBb ICAgNDYuODg0NTUxXSAgWzxmZmZmZmZmZmFkMGJkYzE5Pl0gd29ya2VyX3RocmVhZCsweDY5LzB4 NGEwCj4gWyAgIDQ2Ljg4NDU1NF0gIFs8ZmZmZmZmZmZhZDBiZGJiMD5dID8gbWF4X2FjdGl2ZV9z dG9yZSsweDgwLzB4ODAKPiBbICAgNDYuODg0NTU2XSAgWzxmZmZmZmZmZmFkMGMyZTEwPl0ga3Ro cmVhZCsweDExMC8weDEzMAo+IFsgICA0Ni44ODQ1NTldICBbPGZmZmZmZmZmYWQwYzJkMDA+XSA/ IGt0aHJlYWRfcGFyaysweDYwLzB4NjAKPiBbICAgNDYuODg0NTYzXSAgWzxmZmZmZmZmZmFkYWQ5 OTE3Pl0gcmV0X2Zyb21fZm9yaysweDI3LzB4NDAKPiBbICAgNDYuODg0NTY2XSAtLS1bIGVuZCB0 cmFjZSAzYmQ1OTkwNThiOGE5ZWIzIF0tLS0KPiAKPiBTaWduZWQtb2ZmLWJ5OiBTYXRoeWFuYXJh eWFuYW4gS3VwcHVzd2FteSA8c2F0aHlhbmFyYXlhbmFuLmt1cHB1c3dhbXlAaW50ZWwuY29tPgpB Y2tlZC1ieTogT2xpdmVyIE5ldWt1bSA8b25ldWt1bUBzdXNlLmNvbT4KLS0tClRvIHVuc3Vic2Ny aWJlIGZyb20gdGhpcyBsaXN0OiBzZW5kIHRoZSBsaW5lICJ1bnN1YnNjcmliZSBsaW51eC11c2Ii IGluCnRoZSBib2R5IG9mIGEgbWVzc2FnZSB0byBtYWpvcmRvbW9Admdlci5rZXJuZWwub3JnCk1v cmUgbWFqb3Jkb21vIGluZm8gYXQgIGh0dHA6Ly92Z2VyLmtlcm5lbC5vcmcvbWFqb3Jkb21vLWlu Zm8uaHRtbAo= From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Google-Smtp-Source: AH8x227fWN5OSMh8cQicz6Tlf7bHr07uBxRinhJ9pSZloPWWThXRNrkfSZE/RH1uFmMZthZRYGBh ARC-Seal: i=1; a=rsa-sha256; t=1518516767; cv=none; d=google.com; s=arc-20160816; b=Il47KvEDRhS6UU9CZ6a+aDClwNziDBC5aRLRjTeu2maGja8PD0AR0EOhLW9H6Vycdc ZJ4bOqEiJSSx51uctB9LHxsY5B4Uo1DKO8vv1yw9/PXSARq97K1ZjF0EHLF3MWPq/EaF diX2Q3d5wJCdlBS2Zb52Sau4ZkvEfN9MEYLYXuPy0bEjaLj3iQpwjKEvY5Z7bWJzAr3a ++gxoUQ7UHzEkOihmydh1OU+oBm5V1bCCGc1aMb1244I+pfQoTe5gyJm7Fbe50IBKzM2 dkIGLd2iEe+Gi8+RX/O2J4dErpnhvMWhuHXqj1v6UTR5p3T3B20EjRvbkdQOonpOV9BS HReA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:mime-version:references:in-reply-to:date :cc:to:from:subject:message-id:arc-authentication-results; bh=8AV4PNHFR0JhBJgVRILczxrUlz1URBNVnY3bDG6Sg7E=; b=GQSUKsHPN5t785Se4JlD6d2VtDsC1S94AxkpMRFYt9sb/1HW8krelHVgkajKU6eidn EKpJdsqx++b5/zQldCxf2lKTzV0a2lbJKnvyKszZuZMQVYsynLryYHXJjCTNmLq3H4Zt JlXD7iRS5EGCf4YZE7JfXLF43Mcmswd9LleqJwwO062qCpuS9gxd8p0jwwT6oWtJ+fFm LkI5r7D2ChoSmWZeGmCUsCltA2Ke9yejDCCN9MuZ36XWk0cnU3idBY5J+Q83aYSbZplf JzBQoiPo8lkcCj2l73iXC1mH7MBwSSCh62GjD8cjyqqjXyK+5W/bWir++2fVbZM71teX VPng== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of oneukum@suse.com designates 195.135.220.15 as permitted sender) smtp.mailfrom=oneukum@suse.com Authentication-Results: mx.google.com; spf=pass (google.com: domain of oneukum@suse.com designates 195.135.220.15 as permitted sender) smtp.mailfrom=oneukum@suse.com Message-ID: <1518516440.4584.4.camel@suse.com> Subject: Re: [PATCH v1 1/1] usb: cdc_acm: prevent race at write to acm while system resumes From: Oliver Neukum To: sathyanarayan.kuppuswamy@linux.intel.com, felipe.balbi@intel.com, heikki.krogerus@intel.com, gregkh@linuxfoundation.org Cc: Dominik Bozek , Sathyanarayanan Kuppuswamy , linux-kernel@vger.kernel.org, linux-usb@vger.kernel.org Date: Tue, 13 Feb 2018 11:07:20 +0100 In-Reply-To: <1518466503-36918-1-git-send-email-sathyanarayan.kuppuswamy@linux.intel.com> References: <1518466503-36918-1-git-send-email-sathyanarayan.kuppuswamy@linux.intel.com> Content-Type: text/plain; charset="UTF-8" X-Mailer: Evolution 3.20.5 Mime-Version: 1.0 Content-Transfer-Encoding: 7bit X-getmail-retrieved-from-mailbox: INBOX X-GMAIL-THRID: =?utf-8?q?1592227538406824462?= X-GMAIL-MSGID: =?utf-8?q?1592280237828286847?= X-Mailing-List: linux-kernel@vger.kernel.org List-ID: Am Montag, den 12.02.2018, 12:15 -0800 schrieb sathyanarayan.kuppuswamy@linux.intel.com: > From: Dominik Bozek > > ACM driver may accept data to transmit while system is not fully > resumed. In this case ACM driver buffers data and prepare URBs > on usb anchor list. > There is a little chance that two tasks put a char and initiate > acm_tty_flush_chars(). In such a case, driver will put one URB > twice on usb anchor list. > This patch also reset length of data before resue of a buffer. > This not only prevent sending rubbish, but also lower risc of race. > > Without this patch we hit following kernel panic in one of our > stabilty/stress tests. > > [ 46.884442] *list_add double add*: new=ffff9b2ab7289330, prev=ffff9b2ab7289330, next=ffff9b2ab81e28e0. > [ 46.884476] Modules linked in: hci_uart btbcm bluetooth rfkill_gpio igb_avb(O) cfg80211 snd_soc_sst_bxt_tdf8532 snd_soc_skl snd_soc_skl_ipc snd_soc_sst_ipc snd_soc_sst_dsp snd_soc_sst_acpi snd_soc_sst_match snd_hda_ext_core snd_hda_core trusty_timer trusty_wall trusty_log trusty_virtio trusty_ipc trusty_mem trusty_irq trusty virtio_ring virtio intel_ipu4_mmu_bxtB0 lib2600_mod_bxtB0 intel_ipu4_isys_mod_bxtB0 lib2600psys_mod_bxtB0 intel_ipu4_psys_mod_bxtB0 intel_ipu4_mod_bxtB0 intel_ipu4_wrapper_bxtB0 intel_ipu4_acpi videobuf2_dma_contig as3638 dw9714 lm3643 crlmodule smiapp smiapp_pll > [ 46.884480] CPU: 1 PID: 33 Comm: kworker/u8:1 Tainted: G U W O 4.9.56-quilt-2e5dc0ac-g618ed69ced6e-dirty #4 > [ 46.884489] Workqueue: events_unbound flush_to_ldisc > [ 46.884494] ffffb98ac012bb08 ffffffffad3e82e5 ffffb98ac012bb58 0000000000000000 > [ 46.884497] ffffb98ac012bb48 ffffffffad0a23d1 00000024ad6374dd ffff9b2ab7289330 > [ 46.884500] ffff9b2ab81e28e0 ffff9b2ab7289330 0000000000000002 0000000000000000 > [ 46.884501] Call Trace: > [ 46.884507] [] dump_stack+0x67/0x92 > [ 46.884511] [] __warn+0xd1/0xf0 > [ 46.884513] [] warn_slowpath_fmt+0x5f/0x80 > [ 46.884516] [] __list_add+0xb3/0xc0 > [ 46.884521] [] *usb_anchor_urb*+0x4c/0xa0 > [ 46.884524] [] *acm_tty_flush_chars*+0x8f/0xb0 > [ 46.884527] [] *acm_tty_put_char*+0x41/0x100 > [ 46.884530] [] tty_put_char+0x24/0x40 > [ 46.884533] [] do_output_char+0xa5/0x200 > [ 46.884535] [] __process_echoes+0x148/0x290 > [ 46.884538] [] n_tty_receive_buf_common+0x57c/0xb00 > [ 46.884541] [] n_tty_receive_buf2+0x14/0x20 > [ 46.884543] [] tty_ldisc_receive_buf+0x22/0x50 > [ 46.884545] [] flush_to_ldisc+0xc5/0xe0 > [ 46.884549] [] process_one_work+0x148/0x440 > [ 46.884551] [] worker_thread+0x69/0x4a0 > [ 46.884554] [] ? max_active_store+0x80/0x80 > [ 46.884556] [] kthread+0x110/0x130 > [ 46.884559] [] ? kthread_park+0x60/0x60 > [ 46.884563] [] ret_from_fork+0x27/0x40 > [ 46.884566] ---[ end trace 3bd599058b8a9eb3 ]--- > > Signed-off-by: Sathyanarayanan Kuppuswamy Acked-by: Oliver Neukum