* [PATCH] usb: usbip: stub_rx: remove outdated comment
@ 2026-10-05 12:58 Oliver Neukum
2026-10-06 16:23 ` sashiko-bot
2026-10-08 10:03 ` Shuah Khan
0 siblings, 2 replies; 3+ messages in thread
From: Oliver Neukum @ 2026-10-05 12:58 UTC (permalink / raw)
To: valentina.manea.m, shuah, i, gregkh, linux-usb; +Cc: Oliver Neukum
After removal of the BUG() statement the error exit can be reached
and logs a report. Remove a comment saying otherwise.
Fixes: 635f545a7e8be ("usbip: fix stub_rx: get_pipe() to validate endpoint number")
Signed-off-by: Oliver Neukum <oneukum@suse.com>
---
drivers/usb/usbip/stub_rx.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/drivers/usb/usbip/stub_rx.c b/drivers/usb/usbip/stub_rx.c
index 1e9ae578810d..0ccc05b76c5a 100644
--- a/drivers/usb/usbip/stub_rx.c
+++ b/drivers/usb/usbip/stub_rx.c
@@ -391,7 +391,6 @@ static int get_pipe(struct stub_device *sdev, struct usbip_header *pdu)
}
err_ret:
- /* NOT REACHED */
dev_err(&sdev->udev->dev, "CMD_SUBMIT: invalid epnum %d\n", epnum);
return -1;
}
--
2.55.0
^ permalink raw reply related [flat|nested] 3+ messages in thread* Re: [PATCH] usb: usbip: stub_rx: remove outdated comment
2026-10-05 12:58 [PATCH] usb: usbip: stub_rx: remove outdated comment Oliver Neukum
@ 2026-10-06 16:23 ` sashiko-bot
2026-10-08 10:03 ` Shuah Khan
1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-10-06 16:23 UTC (permalink / raw)
To: Oliver Neukum; +Cc: linux-usb
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] usbip: protocol desync and hung URBs on invalid endpoint
--
commit f15a0a944a703fedd99ceab9d659df84a495556c
Author: Oliver Neukum <oneukum@suse.com>
Subject: usb: usbip: stub_rx: remove outdated comment
This patch removes an outdated comment in the error handling path of
get_pipe(). The comment indicated the code was unreachable, but following the
removal of a BUG() statement, this path can now be reached and logs a report.
> diff --git a/drivers/usb/usbip/stub_rx.c b/drivers/usb/usbip/stub_rx.c
> index 1e9ae578810d9..0ccc05b76c5ab 100644
> --- a/drivers/usb/usbip/stub_rx.c
> +++ b/drivers/usb/usbip/stub_rx.c
> @@ -391,7 +391,6 @@ static int get_pipe(struct stub_device *sdev, struct usbip_header *pdu)
> }
>
> err_ret:
> - /* NOT REACHED */
> dev_err(&sdev->udev->dev, "CMD_SUBMIT: invalid epnum %d\n", epnum);
> return -1;
[Severity: High]
When get_pipe() returns -1, does it cause a protocol desync regression in
stub_recv_cmd_submit()?
If a USBIP client sends a CMD_SUBMIT with an invalid endpoint number or an
out-of-bounds number of isoc packets, get_pipe() returns -1.
Looking at drivers/usb/usbip/stub_rx.c:stub_recv_cmd_submit():
int pipe = get_pipe(sdev, pdu);
...
if (pipe == -1)
return;
When get_pipe() returns -1, stub_recv_cmd_submit() returns early without
consuming the TCP payload or issuing a connection teardown (e.g., via
usbip_event_add(ud, SDEV_EVENT_ERROR_TCP)).
For OUT transfers with a payload, the unread bytes remain in the socket
buffer. The next loop iteration reads this leftover payload as a USBIP
header, desynchronizing the protocol stream and abruptly terminating the
connection.
For IN transfers, no payload is left, but the server drops the request
without sending a RET_SUBMIT response.
Does this cause the client's URB to hang indefinitely?
If the client later unlinks this hung URB, it seems the server replies
with a RET_UNLINK status of 0 (success) because it never tracked the
dropped URB.
Could this trick the client into completing the failed URB with a false
success status, breaking the protocol state machine?
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261005125842.197848-1-oneukum@suse.com?part=1
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] usb: usbip: stub_rx: remove outdated comment
2026-10-05 12:58 [PATCH] usb: usbip: stub_rx: remove outdated comment Oliver Neukum
2026-10-06 16:23 ` sashiko-bot
@ 2026-10-08 10:03 ` Shuah Khan
1 sibling, 0 replies; 3+ messages in thread
From: Shuah Khan @ 2026-10-08 10:03 UTC (permalink / raw)
To: Oliver Neukum, valentina.manea.m, shuah, i, gregkh, linux-usb,
Shuah Khan
On 10/5/26 06:58, Oliver Neukum wrote:
> After removal of the BUG() statement the error exit can be reached
> and logs a report. Remove a comment saying otherwise.
>
> Fixes: 635f545a7e8be ("usbip: fix stub_rx: get_pipe() to validate endpoint number")
> Signed-off-by: Oliver Neukum <oneukum@suse.com>
> ---
> drivers/usb/usbip/stub_rx.c | 1 -
> 1 file changed, 1 deletion(-)
>
> diff --git a/drivers/usb/usbip/stub_rx.c b/drivers/usb/usbip/stub_rx.c
> index 1e9ae578810d..0ccc05b76c5a 100644
> --- a/drivers/usb/usbip/stub_rx.c
> +++ b/drivers/usb/usbip/stub_rx.c
> @@ -391,7 +391,6 @@ static int get_pipe(struct stub_device *sdev, struct usbip_header *pdu)
> }
>
> err_ret:
> - /* NOT REACHED */
> dev_err(&sdev->udev->dev, "CMD_SUBMIT: invalid epnum %d\n", epnum);
> return -1;
> }
Looks good to me.
Acked-by: Shuah Khan <skhan@linuxfoundation.org>
thanks,
-- Shuah
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-08 10:03 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-05 12:58 [PATCH] usb: usbip: stub_rx: remove outdated comment Oliver Neukum
2026-10-06 16:23 ` sashiko-bot
2026-10-08 10:03 ` Shuah Khan
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox