From: Johan Hovold <johan@kernel.org>
To: Alan Stern <stern@rowland.harvard.edu>
Cc: Greg KH <greg@kroah.com>, "Geoffrey D. Bennett" <g@b4.vu>,
USB mailing list <linux-usb@vger.kernel.org>
Subject: Re: [PATCH] USB: core: WARN if pipe direction != setup packet direction
Date: Fri, 21 May 2021 15:17:46 +0200 [thread overview]
Message-ID: <YKey+pWP8iKkCV1Q@hovoldconsulting.com> (raw)
In-Reply-To: <YKdpThmE1xenUjhI@hovoldconsulting.com>
On Fri, May 21, 2021 at 10:03:26AM +0200, Johan Hovold wrote:
> On Thu, May 20, 2021 at 04:20:56PM -0400, Alan Stern wrote:
> > When a control URB is submitted, the direction indicated by URB's pipe
> > member is supposed to match the direction indicated by the setup
> > packet's bRequestType member. A mismatch could lead to trouble,
> > depending on which field the host controller drivers use for
> > determining the actual direction.
> >
> > This shouldn't ever happen; it would represent a careless bug in a
> > kernel driver somewhere. This patch adds a dev_WARN to let people
> > know about the potential problem.
> >
> > Suggested-by: "Geoffrey D. Bennett" <g@b4.vu>
> > Signed-off-by: Alan Stern <stern@rowland.harvard.edu>
> >
> > ---
> >
> >
> > [as1960]
> >
> >
> > drivers/usb/core/urb.c | 3 +++
> > 1 file changed, 3 insertions(+)
> >
> > Index: usb-devel/drivers/usb/core/urb.c
> > ===================================================================
> > --- usb-devel.orig/drivers/usb/core/urb.c
> > +++ usb-devel/drivers/usb/core/urb.c
> > @@ -407,6 +407,9 @@ int usb_submit_urb(struct urb *urb, gfp_
> > return -ENOEXEC;
> > is_out = !(setup->bRequestType & USB_DIR_IN) ||
> > !setup->wLength;
> > + if (usb_pipeout(urb->pipe) != is_out)
> > + dev_WARN(&dev->dev, "BOGUS control dir, pipe %x doesn't match bRequestType %x\n",
> > + urb->pipe, setup->bRequestType);
> > } else {
> > is_out = usb_endpoint_dir_out(&ep->desc);
> > }
>
> While I agree with intention here, I'm worried that this will start
> flooding the logs of users.
>
> So first, this should probably be rate limited.
This could actually be done using WARN_ON_ONCE() as we don't have to
worry about syzbot fuzzing descriptors here (all control endpoints are
bidirectional).
> Second, did you try to estimate how many call sites that get this wrong?
> I always felt a bit pedantic when pointing out that the pipe direction
> should match the request type to driver author's during review when (in
> almost all cases?) this hasn't really mattered. I fear we may have
> accumulated a fairly large number of these mismatches over the years but
> I haven't verified that.
I did a quick review of all ctrlpipe-macro uses in usb/misc and
usb/serial and found two instances.
A simple grep pattern looking for explicit USB_DIR/ctrlpipe mismatches
caught another five tree wide (not including the
sound/usb/mixer_scarlett_gen2.c which Geoffrey reported), but there are
likely more of those out there as the request type is often not that
explicit.
I've prepared patches for the above, excluding the sound driver Geoffrey
said he was fixing.
Johan
next prev parent reply other threads:[~2021-05-21 13:18 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-05-20 20:20 [PATCH] USB: core: WARN if pipe direction != setup packet direction Alan Stern
2021-05-21 8:03 ` Johan Hovold
2021-05-21 12:14 ` Greg KH
2021-05-21 13:17 ` Johan Hovold [this message]
2021-05-21 14:41 ` Alan Stern
2021-05-22 2:16 ` [PATCH v2] " Alan Stern
2021-05-22 7:56 ` Johan Hovold
2021-05-24 11:39 ` Johan Hovold
2021-05-24 14:47 ` Alan Stern
2021-05-25 12:40 ` Johan Hovold
2021-05-25 15:12 ` Alan Stern
2021-05-26 7:49 ` Johan Hovold
2021-05-21 14:38 ` [PATCH] " Alan Stern
2021-05-22 7:56 ` Johan Hovold
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=YKey+pWP8iKkCV1Q@hovoldconsulting.com \
--to=johan@kernel.org \
--cc=g@b4.vu \
--cc=greg@kroah.com \
--cc=linux-usb@vger.kernel.org \
--cc=stern@rowland.harvard.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox