* [PATCH v2] driver core: Take parent lock in async device attach
@ 2026-10-07 13:15 Mario Peter
2026-10-07 13:24 ` sashiko-bot
0 siblings, 1 reply; 2+ messages in thread
From: Mario Peter @ 2026-10-07 13:15 UTC (permalink / raw)
To: Greg Kroah-Hartman, Rafael J. Wysocki, Danilo Krummrich
Cc: Dmitry Torokhov, Alan Stern, driver-core, linux-usb, linux-kernel,
Mario Peter
On buses with need_parent_lock set (only USB), probe() must run with the
parent device locked. A synchronous attach after device_add() gets this
from the caller, e.g. usb_set_configuration() holds the udev lock while
adding interfaces. __device_attach_async_helper() runs the probe from an
async worker instead, where that lock isn't held, and only takes
device_lock(dev).
With async probing enabled for the hub driver (e.g. driver_async_probe=*
or driver_async_probe=hub), this races when a multi-TT hub is
configured. For multi-TT hubs, hub_probe() calls
usb_set_interface(hdev, 0, 1) to select the TT-per-port altsetting, and
usb_set_interface() creates the endpoint devices of the interface a
second time:
usb_set_configuration() async worker
[udev locked]
device_add(intf)
queues the probe ----------> __device_attach_async_helper()
[intf locked, udev not locked]
hub_probe()
usb_set_interface(hdev, 0, 1)
create_intf_ep_devs(intf) create_intf_ep_devs(intf)
create_intf_ep_devs() checks and sets intf->ep_devs_created without a
lock of its own. If usb_set_configuration() has created ep_81 but not
yet set the flag, usb_set_interface() skips removing the endpoint
devices of the old altsetting and creates ep_81 again. With a
synchronous probe, hub_probe() runs inside device_add() with the udev
lock held, and usb_set_configuration() then finds ep_devs_created
already set.
Single-TT hubs don't call usb_set_interface() from hub_probe() and
don't show this warning, but their probe runs without the udev lock as
well.
On an i.MX8MM board with an onboard USB2514 hub this hit 11 of 100
boots:
sysfs: cannot create duplicate filename '.../1-1/1-1:1.0/ep_81'
Call trace:
sysfs_warn_dup
usb_create_ep_devs
create_intf_ep_devs
usb_set_interface
hub_probe
usb_probe_interface
really_probe
__device_attach_async_helper
async_run_entry_fn
It also shows on v7.3-rc6 in QEMU, with dummy_hcd and a raw-gadget
program emulating a multi-TT hub: re-authorizing the hub in a loop,
while a SCHED_FIFO task preempts the writing task at random points for
3 ms, hit the warning in 29 of 6000 iterations.
Take the parent lock in __device_attach_async_helper() as well, like
__driver_attach_async_helper() does, and move
__device_driver_lock/unlock() up for that. With this the warning was
gone in 300 boots on the board and in 6000 iterations in QEMU.
Fixes: 765230b5f084 ("driver-core: add asynchronous probing support for drivers")
Assisted-by: LLM
Signed-off-by: Mario Peter <mario.peter@leica-geosystems.com>
---
v2:
- Describe the race in more detail
- Keep the multi-TT detail, but say why the hub has to be multi-TT
for this symptom
- Reproduce and test on v7.3-rc6 in QEMU
In the same QEMU setup, a debug-only device_lock_assert(&udev->dev) in
usb_probe_interface() fired on every async probe of a hub interface
without this patch (52 of 52) and never with it (0 of 102). The hub
emulator and the test scripts are small, I can post them if that helps.
Not covered: deferred_probe_work_func() also re-probes via
__device_attach() without the parent lock.
Analysis and patch done with the help of Claude Code.
v1: https://lore.kernel.org/all/20261006132335.4014316-1-mario.peter@leica-geosystems.com/
drivers/base/dd.c | 68 +++++++++++++++++++++++------------------------
1 file changed, 34 insertions(+), 34 deletions(-)
diff --git a/drivers/base/dd.c b/drivers/base/dd.c
index f6525a7ee8c5..a8912e6d5fbc 100644
--- a/drivers/base/dd.c
+++ b/drivers/base/dd.c
@@ -1029,6 +1029,38 @@ static int __device_attach_driver(struct device_driver *drv, void *_data)
return ret == 0;
}
+/*
+ * __device_driver_lock - acquire locks needed to manipulate dev->drv
+ * @dev: Device we will update driver info for
+ * @parent: Parent device. Needed if the bus requires parent lock
+ *
+ * This function will take the required locks for manipulating dev->drv.
+ * Normally this will just be the @dev lock, but when called for a USB
+ * interface, @parent lock will be held as well.
+ */
+static void __device_driver_lock(struct device *dev, struct device *parent)
+{
+ if (parent && dev->bus->need_parent_lock)
+ device_lock(parent);
+ device_lock(dev);
+}
+
+/*
+ * __device_driver_unlock - release locks needed to manipulate dev->drv
+ * @dev: Device we will update driver info for
+ * @parent: Parent device. Needed if the bus requires parent lock
+ *
+ * This function will release the required locks for manipulating dev->drv.
+ * Normally this will just be the @dev lock, but when called for a
+ * USB interface, @parent lock will be released as well.
+ */
+static void __device_driver_unlock(struct device *dev, struct device *parent)
+{
+ device_unlock(dev);
+ if (parent && dev->bus->need_parent_lock)
+ device_unlock(parent);
+}
+
static void __device_attach_async_helper(void *_dev, async_cookie_t cookie)
{
struct device *dev = _dev;
@@ -1038,7 +1070,7 @@ static void __device_attach_async_helper(void *_dev, async_cookie_t cookie)
.want_async = true,
};
- device_lock(dev);
+ __device_driver_lock(dev, dev->parent);
/*
* Check if device has already been removed or claimed. This may
@@ -1060,7 +1092,7 @@ static void __device_attach_async_helper(void *_dev, async_cookie_t cookie)
if (dev->parent)
pm_runtime_put(dev->parent);
out_unlock:
- device_unlock(dev);
+ __device_driver_unlock(dev, dev->parent);
put_device(dev);
}
@@ -1155,38 +1187,6 @@ void device_initial_probe(struct device *dev)
subsys_put(sp);
}
-/*
- * __device_driver_lock - acquire locks needed to manipulate dev->drv
- * @dev: Device we will update driver info for
- * @parent: Parent device. Needed if the bus requires parent lock
- *
- * This function will take the required locks for manipulating dev->drv.
- * Normally this will just be the @dev lock, but when called for a USB
- * interface, @parent lock will be held as well.
- */
-static void __device_driver_lock(struct device *dev, struct device *parent)
-{
- if (parent && dev->bus->need_parent_lock)
- device_lock(parent);
- device_lock(dev);
-}
-
-/*
- * __device_driver_unlock - release locks needed to manipulate dev->drv
- * @dev: Device we will update driver info for
- * @parent: Parent device. Needed if the bus requires parent lock
- *
- * This function will release the required locks for manipulating dev->drv.
- * Normally this will just be the @dev lock, but when called for a
- * USB interface, @parent lock will be released as well.
- */
-static void __device_driver_unlock(struct device *dev, struct device *parent)
-{
- device_unlock(dev);
- if (parent && dev->bus->need_parent_lock)
- device_unlock(parent);
-}
-
/**
* device_driver_attach - attach a specific driver to a specific device
* @drv: Driver to attach
base-commit: 22430ae5d90ab288b0ee2ad99ae941f4a666b694
--
2.43.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH v2] driver core: Take parent lock in async device attach
2026-10-07 13:15 [PATCH v2] driver core: Take parent lock in async device attach Mario Peter
@ 2026-10-07 13:24 ` sashiko-bot
0 siblings, 0 replies; 2+ messages in thread
From: sashiko-bot @ 2026-10-07 13:24 UTC (permalink / raw)
To: Mario Peter; +Cc: linux-usb
> On buses with need_parent_lock set (only USB), probe() must run with the
> parent device locked. A synchronous attach after device_add() gets this
> from the caller, e.g. usb_set_configuration() holds the udev lock while
> adding interfaces. __device_attach_async_helper() runs the probe from an
> async worker instead, where that lock isn't held, and only takes
> device_lock(dev).
>
> With async probing enabled for the hub driver (e.g. driver_async_probe=*
> or driver_async_probe=hub), this races when a multi-TT hub is
> configured. For multi-TT hubs, hub_probe() calls
> usb_set_interface(hdev, 0, 1) to select the TT-per-port altsetting, and
> usb_set_interface() creates the endpoint devices of the interface a
> second time:
>
> usb_set_configuration() async worker
> [ ... ]
> gone in 300 boots on the board and in 6000 iterations in QEMU.
>
> Fixes: 765230b5f084 ("driver-core: add asynchronous probing support for drivers")
> Assisted-by: LLM
> Signed-off-by: Mario Peter <mario.peter@leica-geosystems.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261007131514.1260696-1-mario.peter@leica-geosystems.com?part=1
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-07 13:24 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-07 13:15 [PATCH v2] driver core: Take parent lock in async device attach Mario Peter
2026-10-07 13:24 ` sashiko-bot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox