All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Sebastian Reichel" <sebastian.reichel@collabora.com>
Cc: neil.armstrong@linaro.org, olteanv@gmail.com,
	linux-phy@lists.infradead.org, vkoul@kernel.org
Subject: Re: [PATCH 5/5] usb: dwc3: rockchip: fix USB-C reconnect in gadget mode
Date: Tue, 15 Sep 2026 15:29:48 +0000	[thread overview]
Message-ID: <20260915152949.638B71F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260915-b4-rockchip-dwc3-rockchip-glue-v1-5-763bb546824e@collabora.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] usb: dwc3: missing runtime PM resume in role change callback
- [High] usb: dwc3: use-after-free in dwc3_rockchip_vbus_handler due to lockless access
--

commit 58b7c3d4ec9b041b0b40be86929f872c8f0552a7
Author: Sebastian Reichel <sebastian.reichel@collabora.com>

usb: dwc3: rockchip: fix USB-C reconnect in gadget mode

This commit fixes a gadget mode reconnection issue by updating the connection
status and triggering a runtime PM resume when the USB role changes. The
runtime PM reference counter is then immediately dropped so that auto-suspend
can handle keeping the device awake.

> diff --git a/drivers/usb/dwc3/dwc3-rockchip.c b/drivers/usb/dwc3/dwc3-rockchip.c
> index 7bdd6e2eb22d1..bedec3295bb16 100644
> --- a/drivers/usb/dwc3/dwc3-rockchip.c
> +++ b/drivers/usb/dwc3/dwc3-rockchip.c
> @@ -25,8 +25,17 @@ struct dwc3_rockchip {
>  	struct dwc3		dwc;
>  	struct dwc3_rk_phy_nb	usb3_phy_nb[DWC3_USB3_MAX_PORTS];
>  	u8			phy_reset_active;
> +	enum usb_role		role;
>  };
>  
> +static void dwc3_rockchip_vbus_handler(struct dwc3 *dwc, bool present)
> +{
> +	if (!dwc->gadget || !dwc->gadget_driver)
> +		return;
> +
> +	usb_udc_vbus_handler(dwc->gadget, present);

[Severity: High]
Could this lead to a use-after-free if it races with a gadget unbind?

Because this locklessly checks and dereferences dwc->gadget, and can be
called asynchronously from the PHY notifier (dwc3_usb3_phy_notify), it seems
possible that dwc->gadget could be freed by dwc3_gadget_exit() right after
the if-check passes but before usb_udc_vbus_handler() executes.

[ ... ]
> @@ -130,7 +144,16 @@ static int dwc3_rk_phy_register_notifiers(struct dwc3 *dwc)
>  	return devm_add_action_or_reset(dwc->dev, dwc3_rk_phy_unregister_notifiers, dwc_rk);
>  }
>  
> +static void dwc3_rockchip_set_role(struct dwc3 *dwc, enum usb_role role)
> +{
> +	struct dwc3_rockchip *dwc_rk = container_of(dwc, struct dwc3_rockchip, dwc);
> +
> +	dwc_rk->role = role;
> +	dwc3_rockchip_vbus_handler(dwc, role == USB_ROLE_DEVICE);
> +}

[Severity: High]
Were the runtime PM calls accidentally omitted here?

The commit message states the fix involves triggering a runtime PM resume
when the role changes, and immediately decreasing the reference counter
afterward. However, there are no calls to pm_runtime_get_sync() or
pm_runtime_put_autosuspend() in this callback. Without them, it seems the
USB controller would incorrectly remain suspended and the original issue
might persist.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260915-b4-rockchip-dwc3-rockchip-glue-v1-0-763bb546824e@collabora.com?part=5

-- 
linux-phy mailing list
linux-phy@lists.infradead.org
https://lists.infradead.org/mailman/listinfo/linux-phy

  reply	other threads:[~2026-09-15 15:29 UTC|newest]

Thread overview: 53+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-15 15:17 [PATCH 0/5] usb: dwc3: introduce Rockchip glue driver Sebastian Reichel
2026-09-15 15:17 ` Sebastian Reichel
2026-09-15 15:17 ` Sebastian Reichel
2026-09-15 15:17 ` [PATCH 1/5] phy: core: add notifier infrastructure Sebastian Reichel
2026-09-15 15:17   ` Sebastian Reichel
2026-09-15 15:17   ` Sebastian Reichel
2026-09-15 15:17 ` [PATCH 2/5] usb: dwc3: rockchip: introduce glue driver Sebastian Reichel
2026-09-15 15:17   ` Sebastian Reichel
2026-09-15 15:17   ` Sebastian Reichel
2026-09-23  1:31   ` Thinh Nguyen
2026-09-23  1:31     ` Thinh Nguyen
2026-09-23  1:31     ` Thinh Nguyen
2026-09-24 15:29     ` Sebastian Reichel
2026-09-24 15:29       ` Sebastian Reichel
2026-09-24 15:29       ` Sebastian Reichel
2026-09-23  5:53   ` Krishna Kurapati
2026-09-23  5:53     ` Krishna Kurapati
2026-09-23  5:53     ` Krishna Kurapati
2026-09-24 15:36     ` Sebastian Reichel
2026-09-24 15:36       ` Sebastian Reichel
2026-09-24 15:36       ` Sebastian Reichel
2026-09-15 15:17 ` [PATCH 3/5] usb: dwc3: core: add post PHY registration hook for platform glue Sebastian Reichel
2026-09-15 15:17   ` Sebastian Reichel
2026-09-15 15:17   ` Sebastian Reichel
2026-09-23  1:48   ` Thinh Nguyen
2026-09-23  1:48     ` Thinh Nguyen
2026-09-23  1:48     ` Thinh Nguyen
2026-09-23  5:54   ` Krishna Kurapati
2026-09-23  5:54     ` Krishna Kurapati
2026-09-23  5:54     ` Krishna Kurapati
2026-09-15 15:17 ` [PATCH 4/5] usb: dwc3: rockchip: support PHY reset notifications Sebastian Reichel
2026-09-15 15:17   ` Sebastian Reichel
2026-09-15 15:17   ` Sebastian Reichel
2026-09-15 15:31   ` sashiko-bot
2026-09-23  1:56   ` Thinh Nguyen
2026-09-23  1:56     ` Thinh Nguyen
2026-09-23  1:56     ` Thinh Nguyen
2026-09-15 15:17 ` [PATCH 5/5] usb: dwc3: rockchip: fix USB-C reconnect in gadget mode Sebastian Reichel
2026-09-15 15:17   ` Sebastian Reichel
2026-09-15 15:17   ` Sebastian Reichel
2026-09-15 15:29   ` sashiko-bot [this message]
2026-09-18  9:10   ` Igor Paunovic
2026-09-18  9:10     ` Igor Paunovic
2026-09-18  9:10     ` Igor Paunovic
2026-09-23  1:58   ` Thinh Nguyen
2026-09-23  1:58     ` Thinh Nguyen
2026-09-23  1:58     ` Thinh Nguyen
2026-09-23  8:59     ` Igor Paunovic
2026-09-23  8:59       ` Igor Paunovic
2026-09-23  8:59       ` Igor Paunovic
2026-09-24  1:47       ` Thinh Nguyen
2026-09-24  1:47         ` Thinh Nguyen
2026-09-24  1:47         ` Thinh Nguyen

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260915152949.638B71F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=linux-phy@lists.infradead.org \
    --cc=neil.armstrong@linaro.org \
    --cc=olteanv@gmail.com \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=sebastian.reichel@collabora.com \
    --cc=vkoul@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.