Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Chen-Yu Tsai" <wenst@chromium.org>
Cc: conor+dt@kernel.org, devicetree@vger.kernel.org, robh@kernel.org
Subject: Re: [PATCH v6 10/16] usb: hub: Power on connected M.2 E-key connectors with power sequencing API
Date: Tue, 21 Jul 2026 07:13:14 +0000	[thread overview]
Message-ID: <20260721071314.E221D1F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260721065413.2306137-11-wenst@chromium.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Race condition during sysfs unbind leads to Use-After-Free of the `hub->ports` array in `usb_hub_set_port_power()`.
--

--- Patch [10]: [PATCH v6 10/16] usb: hub: Power on connected M.2 E-key connectors with power sequencing API ---
commit 11e3aac46e37825563690ac3ff867ec8a68c9006
Author: Chen-Yu Tsai <wenst@chromium.org>

usb: hub: Power on connected M.2 E-key connectors with power sequencing API

This commit adds support for powering on M.2 E-key connectors over the power
sequencing API. It modifies the port power control functions to retrieve and
toggle power sequencing descriptors. Port devices now manage power sequences
for connected connectors that require it.

> diff --git a/drivers/usb/core/hub.c b/drivers/usb/core/hub.c
> index 10f15b40fcc55..298fb68c6afc7 100644
> --- a/drivers/usb/core/hub.c
> +++ b/drivers/usb/core/hub.c
[ ... ]
> @@ -887,15 +898,22 @@ static void hub_tt_work(struct work_struct *work)
>  int usb_hub_set_port_power(struct usb_device *hdev, struct usb_hub *hub,
>  			   int port1, bool set)
>  {
> +	struct usb_port *pwrseq_port = hub->ports[port1 - 1];
                                       ^^^^^^^^^^^^^^^^^^^^^

[Severity: High]
Can this result in a Use-After-Free of the hub->ports array?

The commit message notes that sysfs callbacks acquire the lock and check for
disconnect, preventing a use-after-free. Is this assumption accurate?

Looking at the disable_store() sysfs callback, it uses
sysfs_break_active_protection(). This breaks active sysfs protection,
causing device_unregister() in the disconnect path to return immediately
without waiting for disable_store() to finish.

If a concurrent hub_disconnect() runs, it does not acquire the hdev lock.
It sets hub->disconnected = 1, unregisters the port devices, and calls
kfree(hub->ports).

If disable_store() has already passed the hub->disconnected check while
holding the lock, could it proceed to call usb_hub_set_port_power()
and dereference the newly freed hub->ports array here?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260721065413.2306137-1-wenst@chromium.org?part=10

  reply	other threads:[~2026-07-21  7:13 UTC|newest]

Thread overview: 26+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-21  6:53 [PATCH v6 00/16] arm64: mediatek: Add M.2 E-key slot on Chromebooks Chen-Yu Tsai
2026-07-21  6:53 ` [PATCH v6 01/16] device property: Add fwnode_graph_get_port_by_id() Chen-Yu Tsai
2026-07-21  6:53 ` [PATCH v6 02/16] device property: Add fwnode_graph_get_next_port_endpoint() Chen-Yu Tsai
2026-07-21  7:09   ` sashiko-bot
2026-07-21  6:53 ` [PATCH v6 03/16] power: sequencing: Add pwrseq_power_is_on() Chen-Yu Tsai
2026-07-21  7:10   ` sashiko-bot
2026-07-21  9:08   ` Bartosz Golaszewski
2026-07-21  6:53 ` [PATCH v6 04/16] usb: hub: Use assign_bit() in usb_hub_set_port_power() Chen-Yu Tsai
2026-07-21  9:09   ` Bartosz Golaszewski
2026-07-21  6:54 ` [PATCH v6 05/16] usb: hub: Return actual error from hub_configure() in hub_probe() Chen-Yu Tsai
2026-07-21  6:54 ` [PATCH v6 06/16] usb: hub: Associate port@ fwnode with USB port device Chen-Yu Tsai
2026-07-21  6:54 ` [PATCH v6 07/16] usb: core: Move struct usb_port and related APIs to port.h Chen-Yu Tsai
2026-07-21  6:54 ` [PATCH v6 08/16] usb: hub: Pass |struct usb_port*| to usb_port_is_power_on() Chen-Yu Tsai
2026-07-21  6:54 ` [PATCH v6 09/16] usb: hub: Use usb_hub_set_port_power() to control port power everywhere Chen-Yu Tsai
2026-07-21  6:54 ` [PATCH v6 10/16] usb: hub: Power on connected M.2 E-key connectors with power sequencing API Chen-Yu Tsai
2026-07-21  7:13   ` sashiko-bot [this message]
2026-07-21 10:19   ` Andy Shevchenko
2026-07-21  6:54 ` [PATCH v6 11/16] dt-bindings: usb: mediatek,mtk-xhci: Switch to ports for USB connections Chen-Yu Tsai
2026-07-21  6:54 ` [PATCH v6 12/16] power: sequencing: pcie-m2: support matching on remote "port" node Chen-Yu Tsai
2026-07-21  6:54 ` [PATCH v6 13/16] power: sequencing: pcie-m2: Add usb and sdio targets for E-key connector Chen-Yu Tsai
2026-07-21  6:54 ` [PATCH v6 14/16] power: sequencing: pcie-m2: Split Bluetooth unit based on interface Chen-Yu Tsai
2026-07-21  7:11   ` sashiko-bot
2026-07-21  6:54 ` [PATCH v6 15/16] arm64: dts: mediatek: mt8195-cherry: Add M.2 E-key slot Chen-Yu Tsai
2026-07-21  9:09   ` Bartosz Golaszewski
2026-07-21  6:54 ` [PATCH v6 16/16] arm64: dts: mediatek: mt8188-geralt: Add WiFi/BT as " Chen-Yu Tsai
2026-07-21  9:09   ` Bartosz Golaszewski

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260721071314.E221D1F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=wenst@chromium.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox