From: sashiko-bot@kernel.org
To: "Sebastian Reichel" <sebastian.reichel@collabora.com>
Cc: neil.armstrong@linaro.org, olteanv@gmail.com,
linux-phy@lists.infradead.org, vkoul@kernel.org
Subject: Re: [PATCH 5/5] usb: dwc3: rockchip: fix USB-C reconnect in gadget mode
Date: Tue, 15 Sep 2026 15:29:48 +0000 [thread overview]
Message-ID: <20260915152949.638B71F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260915-b4-rockchip-dwc3-rockchip-glue-v1-5-763bb546824e@collabora.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] usb: dwc3: missing runtime PM resume in role change callback
- [High] usb: dwc3: use-after-free in dwc3_rockchip_vbus_handler due to lockless access
--
commit 58b7c3d4ec9b041b0b40be86929f872c8f0552a7
Author: Sebastian Reichel <sebastian.reichel@collabora.com>
usb: dwc3: rockchip: fix USB-C reconnect in gadget mode
This commit fixes a gadget mode reconnection issue by updating the connection
status and triggering a runtime PM resume when the USB role changes. The
runtime PM reference counter is then immediately dropped so that auto-suspend
can handle keeping the device awake.
> diff --git a/drivers/usb/dwc3/dwc3-rockchip.c b/drivers/usb/dwc3/dwc3-rockchip.c
> index 7bdd6e2eb22d1..bedec3295bb16 100644
> --- a/drivers/usb/dwc3/dwc3-rockchip.c
> +++ b/drivers/usb/dwc3/dwc3-rockchip.c
> @@ -25,8 +25,17 @@ struct dwc3_rockchip {
> struct dwc3 dwc;
> struct dwc3_rk_phy_nb usb3_phy_nb[DWC3_USB3_MAX_PORTS];
> u8 phy_reset_active;
> + enum usb_role role;
> };
>
> +static void dwc3_rockchip_vbus_handler(struct dwc3 *dwc, bool present)
> +{
> + if (!dwc->gadget || !dwc->gadget_driver)
> + return;
> +
> + usb_udc_vbus_handler(dwc->gadget, present);
[Severity: High]
Could this lead to a use-after-free if it races with a gadget unbind?
Because this locklessly checks and dereferences dwc->gadget, and can be
called asynchronously from the PHY notifier (dwc3_usb3_phy_notify), it seems
possible that dwc->gadget could be freed by dwc3_gadget_exit() right after
the if-check passes but before usb_udc_vbus_handler() executes.
[ ... ]
> @@ -130,7 +144,16 @@ static int dwc3_rk_phy_register_notifiers(struct dwc3 *dwc)
> return devm_add_action_or_reset(dwc->dev, dwc3_rk_phy_unregister_notifiers, dwc_rk);
> }
>
> +static void dwc3_rockchip_set_role(struct dwc3 *dwc, enum usb_role role)
> +{
> + struct dwc3_rockchip *dwc_rk = container_of(dwc, struct dwc3_rockchip, dwc);
> +
> + dwc_rk->role = role;
> + dwc3_rockchip_vbus_handler(dwc, role == USB_ROLE_DEVICE);
> +}
[Severity: High]
Were the runtime PM calls accidentally omitted here?
The commit message states the fix involves triggering a runtime PM resume
when the role changes, and immediately decreasing the reference counter
afterward. However, there are no calls to pm_runtime_get_sync() or
pm_runtime_put_autosuspend() in this callback. Without them, it seems the
USB controller would incorrectly remain suspended and the original issue
might persist.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260915-b4-rockchip-dwc3-rockchip-glue-v1-0-763bb546824e@collabora.com?part=5
--
linux-phy mailing list
linux-phy@lists.infradead.org
https://lists.infradead.org/mailman/listinfo/linux-phy
next prev parent reply other threads:[~2026-09-15 15:29 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-15 15:17 [PATCH 0/5] usb: dwc3: introduce Rockchip glue driver Sebastian Reichel
2026-09-15 15:17 ` [PATCH 1/5] phy: core: add notifier infrastructure Sebastian Reichel
2026-09-15 15:17 ` [PATCH 2/5] usb: dwc3: rockchip: introduce glue driver Sebastian Reichel
2026-09-23 1:31 ` Thinh Nguyen
2026-09-24 15:29 ` Sebastian Reichel
2026-09-23 5:53 ` Krishna Kurapati
2026-09-24 15:36 ` Sebastian Reichel
2026-09-15 15:17 ` [PATCH 3/5] usb: dwc3: core: add post PHY registration hook for platform glue Sebastian Reichel
2026-09-23 1:48 ` Thinh Nguyen
2026-09-23 5:54 ` Krishna Kurapati
2026-09-15 15:17 ` [PATCH 4/5] usb: dwc3: rockchip: support PHY reset notifications Sebastian Reichel
2026-09-15 15:31 ` sashiko-bot
2026-09-23 1:56 ` Thinh Nguyen
2026-09-15 15:17 ` [PATCH 5/5] usb: dwc3: rockchip: fix USB-C reconnect in gadget mode Sebastian Reichel
2026-09-15 15:29 ` sashiko-bot [this message]
2026-09-18 9:10 ` Igor Paunovic
2026-09-23 1:58 ` Thinh Nguyen
2026-09-23 8:59 ` Igor Paunovic
2026-09-24 1:47 ` Thinh Nguyen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260915152949.638B71F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-phy@lists.infradead.org \
--cc=neil.armstrong@linaro.org \
--cc=olteanv@gmail.com \
--cc=sashiko-reviews@lists.linux.dev \
--cc=sebastian.reichel@collabora.com \
--cc=vkoul@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox