* [PATCH] wifi: zd1211rw: reject secondary interfaces to prevent conflicts
@ 2026-07-29 8:04 syzbot
2026-07-29 18:53 ` Jeff Johnson
2026-07-31 17:36 ` Jeff Johnson
0 siblings, 2 replies; 3+ messages in thread
From: syzbot @ 2026-07-29 8:04 UTC (permalink / raw)
To: syzkaller-bugs, Slawomir Stepien, linux-wireless, Daniel Drake
Cc: johannes.berg, kees, linux-kernel, nihaal, syzbot
From: Slawomir Stepien <sst@poczta.fm>
The zd1211rw driver is designed for single-function Wi-Fi dongles and
hardcodes its USB endpoints. When a malformed USB device exposes multiple
interfaces that match the driver's device ID, the driver blindly binds to
all of them.
During probe(), the driver calls usb_reset_device(), which iterates over
all interfaces and invokes the pre_reset() callback for each bound
interface. Since multiple interfaces are bound to zd1211rw, pre_reset() is
called sequentially for each instance, acquiring their respective
&mac->chip.mutex. Because all instances initialize their mutexes with the
same lock class, lockdep detects a task acquiring a lock of the same class
it already holds and flags it as a possible recursive deadlock:
WARNING: possible recursive locking detected
kworker/0:1/11 is trying to acquire lock:
ffff88810371dde0 (&chip->mutex){+.+.}-{4:4}, at:
zd_chip_disable_rxtx+0x20/0x50
drivers/net/wireless/zydas/zd1211rw/zd_chip.c:1465
but task is already holding lock:
ffff8881138ddde0 (&chip->mutex){+.+.}-{4:4}, at: pre_reset+0x28c/0x380
drivers/net/wireless/zydas/zd1211rw/zd_usb.c:1505
Fix this by explicitly rejecting secondary interfaces (bInterfaceNumber !=
0) during probe(). This ensures that only a single instance of the driver
binds to the device, eliminating the recursive locking scenario.
Fixes: e85d0918b54f ("[PATCH] ZyDAS ZD1211 USB-WLAN driver")
Assisted-by: Gemini:gemini-3.5-flash Gemini:gemini-3.1-pro-preview syzbot
Reported-by: syzbot+0ec3d1a6cf1fbe79c153@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=0ec3d1a6cf1fbe79c153
Link: https://syzkaller.appspot.com/ai_job?id=00724ef7-fd77-4cde-9779-895b8f63c2f6
Signed-off-by: Slawomir Stepien <sst@poczta.fm>
---
diff --git a/drivers/net/wireless/zydas/zd1211rw/zd_usb.c b/drivers/net/wireless/zydas/zd1211rw/zd_usb.c
index 966d8ccb0..2bb2df12c 100644
--- a/drivers/net/wireless/zydas/zd1211rw/zd_usb.c
+++ b/drivers/net/wireless/zydas/zd1211rw/zd_usb.c
@@ -1353,6 +1353,13 @@ static int probe(struct usb_interface *intf, const struct usb_device_id *id)
struct zd_usb *usb;
struct ieee80211_hw *hw = NULL;
+ /* ZD1211 devices are single-function. Reject secondary interfaces
+ * to prevent multiple instances from conflicting on hardcoded endpoints
+ * and triggering recursive locking warnings.
+ */
+ if (intf->cur_altsetting->desc.bInterfaceNumber != 0)
+ return -ENODEV;
+
print_id(udev);
if (id->driver_info & DEVICE_INSTALLER)
base-commit: 1590cf0329716306e948a8fc29f1d3ee87d3989f
--
See https://goo.gle/syzbot-ai-patches for information about AI-generated patches.
You can comment on the patch as usual, syzbot will try to address
the comments and send a new version of the patch if necessary.
syzbot engineers can be reached at syzkaller@googlegroups.com.
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH] wifi: zd1211rw: reject secondary interfaces to prevent conflicts
2026-07-29 8:04 [PATCH] wifi: zd1211rw: reject secondary interfaces to prevent conflicts syzbot
@ 2026-07-29 18:53 ` Jeff Johnson
2026-07-31 17:36 ` Jeff Johnson
1 sibling, 0 replies; 3+ messages in thread
From: Jeff Johnson @ 2026-07-29 18:53 UTC (permalink / raw)
To: syzbot, syzkaller-bugs, Slawomir Stepien, linux-wireless,
Daniel Drake
Cc: johannes.berg, kees, linux-kernel, nihaal, syzbot
On 7/29/2026 1:04 AM, syzbot wrote:
> @@ -1353,6 +1353,13 @@ static int probe(struct usb_interface *intf, const struct usb_device_id *id)
> struct zd_usb *usb;
> struct ieee80211_hw *hw = NULL;
>
> + /* ZD1211 devices are single-function. Reject secondary interfaces
this does not follow linux block comment style
/* should be on a separate line
(at one time networking code had a different style, but not now)
> + * to prevent multiple instances from conflicting on hardcoded endpoints
> + * and triggering recursive locking warnings.
> + */
> + if (intf->cur_altsetting->desc.bInterfaceNumber != 0)
> + return -ENODEV;
> +
> print_id(udev);
>
> if (id->driver_info & DEVICE_INSTALLER)
>
>
> base-commit: 1590cf0329716306e948a8fc29f1d3ee87d3989f
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] wifi: zd1211rw: reject secondary interfaces to prevent conflicts
2026-07-29 8:04 [PATCH] wifi: zd1211rw: reject secondary interfaces to prevent conflicts syzbot
2026-07-29 18:53 ` Jeff Johnson
@ 2026-07-31 17:36 ` Jeff Johnson
1 sibling, 0 replies; 3+ messages in thread
From: Jeff Johnson @ 2026-07-31 17:36 UTC (permalink / raw)
To: syzbot, syzkaller-bugs, Slawomir Stepien, linux-wireless,
Daniel Drake
Cc: johannes.berg, kees, linux-kernel, nihaal, syzbot, workflows
On 7/29/2026 1:04 AM, syzbot wrote:
> From: Slawomir Stepien <sst@poczta.fm>
>
> The zd1211rw driver is designed for single-function Wi-Fi dongles and
> hardcodes its USB endpoints. When a malformed USB device exposes multiple
> interfaces that match the driver's device ID, the driver blindly binds to
> all of them.
>
> During probe(), the driver calls usb_reset_device(), which iterates over
> all interfaces and invokes the pre_reset() callback for each bound
> interface. Since multiple interfaces are bound to zd1211rw, pre_reset() is
> called sequentially for each instance, acquiring their respective
> &mac->chip.mutex. Because all instances initialize their mutexes with the
> same lock class, lockdep detects a task acquiring a lock of the same class
> it already holds and flags it as a possible recursive deadlock:
>
> WARNING: possible recursive locking detected
> kworker/0:1/11 is trying to acquire lock:
> ffff88810371dde0 (&chip->mutex){+.+.}-{4:4}, at:
> zd_chip_disable_rxtx+0x20/0x50
> drivers/net/wireless/zydas/zd1211rw/zd_chip.c:1465
>
> but task is already holding lock:
> ffff8881138ddde0 (&chip->mutex){+.+.}-{4:4}, at: pre_reset+0x28c/0x380
> drivers/net/wireless/zydas/zd1211rw/zd_usb.c:1505
>
> Fix this by explicitly rejecting secondary interfaces (bInterfaceNumber !=
> 0) during probe(). This ensures that only a single instance of the driver
> binds to the device, eliminating the recursive locking scenario.
>
> Fixes: e85d0918b54f ("[PATCH] ZyDAS ZD1211 USB-WLAN driver")
> Assisted-by: Gemini:gemini-3.5-flash Gemini:gemini-3.1-pro-preview syzbot
> Reported-by: syzbot+0ec3d1a6cf1fbe79c153@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=0ec3d1a6cf1fbe79c153
> Link: https://syzkaller.appspot.com/ai_job?id=00724ef7-fd77-4cde-9779-895b8f63c2f6
> Signed-off-by: Slawomir Stepien <sst@poczta.fm>
E-mail from syzbot but SOB from a human?
I read the trailer, but this seems to violate:
https://docs.kernel.org/process/coding-assistants.html
Namely:
AI agents MUST NOT add Signed-off-by tags. Only humans can legally certify the
Developer Certificate of Origin (DCO).
+workflows list
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-07-31 17:36 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-29 8:04 [PATCH] wifi: zd1211rw: reject secondary interfaces to prevent conflicts syzbot
2026-07-29 18:53 ` Jeff Johnson
2026-07-31 17:36 ` Jeff Johnson
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox