From: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
To: u-boot@lists.denx.de
Subject: [PATCH v1] usb: kbd: destroy device after console is stopped
Date: Thu, 28 Jan 2021 19:52:36 +0200 [thread overview]
Message-ID: <YBL55Kgqj/ON5pqs@smile.fi.intel.com> (raw)
In-Reply-To: <YBL4iSXDHvVP1XSl@smile.fi.intel.com>
On Thu, Jan 28, 2021 at 07:46:49PM +0200, Andy Shevchenko wrote:
> On Thu, Jan 28, 2021 at 06:19:56PM +0100, Nicolas Saenz Julienne wrote:
> > Hi Andy,
> >
> > On Thu, 2021-01-28 at 18:55 +0200, Andy Shevchenko wrote:
> > > In case of IOMUX enabled it assumes that console devices in the list
> > > are available to get them stopped properly via ->stop() callback.
> > > However, the USB keyboard driver violates this assumption and tries
> > > to play tricks so the device get destroyed while being listed as
> > > an active console.
> > >
> > > Swap the order of device deregistration and IOMUX update to avoid
> > > the use-after-free.
> > >
> > > Fixes: 3cbcb2892809 ("usb: Fix usb_kbd_deregister when console-muxing is used")
> > > Fixes: 8a8348703081 ("dm: usb: Add a remove() method for USB keyboards")
> > > Reported-by: Nicolas Saenz Julienne <nsaenzjulienne@suse.de>
> > > Signed-off-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
> > > ---
> > > v2: Nicolas, can you test this one instead of yours?
> >
> > Sadly this doesn't seem to work, and breaks a bunch of other tests in the
> > process. You can try it yourself by running: './test/py/test.py --bd sandbox
> > --build'
>
> Thanks for trying.
>
> Unfortunately I have unrelated bug somewhere:
> Traceback (most recent call last):
> File "/home/andy/prj/u-boot/./test/py/test.py", line 20, in <module>
> sys.exit(load_entry_point('pytest', 'console_scripts', 'pytest')(args))
> TypeError: console_main() takes 0 positional arguments but 1 was given
Seems test cases are broken in U-Boot.
I'm not sure how you were able to run them.
--
With Best Regards,
Andy Shevchenko
next prev parent reply other threads:[~2021-01-28 17:52 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-01-28 16:55 [PATCH v1] usb: kbd: destroy device after console is stopped Andy Shevchenko
2021-01-28 17:19 ` Nicolas Saenz Julienne
2021-01-28 17:46 ` Andy Shevchenko
2021-01-28 17:52 ` Andy Shevchenko [this message]
2021-01-28 17:58 ` Tom Rini
2021-01-28 18:18 ` Andy Shevchenko
2021-01-28 18:24 ` Tom Rini
2021-01-28 18:44 ` Andy Shevchenko
2021-01-28 18:10 ` Andy Shevchenko
2021-01-28 20:35 ` Andy Shevchenko
2021-01-28 20:46 ` Tom Rini
2021-01-28 21:52 ` Andy Shevchenko
2021-01-28 21:56 ` Andy Shevchenko
2021-02-03 12:25 ` Nicolas Saenz Julienne
2021-02-11 15:11 ` Andy Shevchenko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=YBL55Kgqj/ON5pqs@smile.fi.intel.com \
--to=andriy.shevchenko@linux.intel.com \
--cc=u-boot@lists.denx.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.