From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-ed1-f43.google.com (mail-ed1-f43.google.com [209.85.208.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6B8AD342173 for ; Sun, 23 Aug 2026 17:26:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.43 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787505990; cv=none; b=dnzJ1H/YGtLoD+Yn7u67NGkeOtKUbLKH/7S9x0J1Uk7o/6IinJqZ52istkTBLefv0omIdq1aSCuLihyv04EzeNScOUJva9Abv2GXOcbZ1zp3sTYExy363Ssbludy0LOe+nN92qg5z8D+Aeftib8RMtYfpwP5uJsosGT6qPFjXRM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787505990; c=relaxed/simple; bh=29YSMDq1xsvjYZSH6oU1x0SwCRi5UTfYHAlKS18g8U8=; h=Date:From:To:Cc:Subject:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=YUEbWiKA6rgfhJiSpbhaKag1qsrXEP44f4lgXK9nV5M7ZFhMM7nxKsoZICH3Y3Clvq7dJwe/DypVDAMHM8Hglu+naeoi4WeVSK/B4eIlQJkoh9fR+s3Kktj+0+qHmT1JbA58mqrCmz/FhwSJtMU2ZIDyubVpXvqSrAtCBKYUvgE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=M+bFTLx0; arc=none smtp.client-ip=209.85.208.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="M+bFTLx0" Received: by mail-ed1-f43.google.com with SMTP id 4fb4d7f45d1cf-6a386a34603so6457996a12.1 for ; Sun, 23 Aug 2026 10:26:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787505982; x=1788110782; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=q+MIT6zuMA9ZcVF8p5pidNPzNcAArCU0/LLpKmnvVyI=; b=M+bFTLx0FcIPKd/Xsc1Mwzgipr+04X8+aEt1wKqjoH6F17ikrometJRkkGKwhleCJc PG6Hb7ezs1Q6bPaU6JeMwdQaxISsoDaGT/f1iQKRq8SsNmgr5IxmhxpNi1jqEWui9Vf2 vCf9E8F4BEZcfNy9M1jABdFbgESeXtxAQKIVNk/spb7kIRYvFFrHLjmd1qgi+wapalFq rBizAp9PlX6/8eFBZb+CGAmrVomGDPUgolf8ObcMMiDzkujms4oZdx5ZnpuSnmjbMX3v EqWyWhSoWbBuahGyplOuq87ACdtFk3iTLul3lB61d0UgdEKbOJ/G8ULGuS5oYr6gBl5Y 2WEQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787505982; x=1788110782; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=q+MIT6zuMA9ZcVF8p5pidNPzNcAArCU0/LLpKmnvVyI=; b=HtGR1kFzOSpmOCfvoGKcVy6esFk93+Xnez3f3FhoNGz3fVHjIFWYb9Dt0SlXLlv+ed FGvZCB5fmEfd+qGfpTxlEH3z8O3tWkSLdh0Oy9IGH37KmYICClBezZ/3GE+mm4LnzjO5 JUgQlcwsGvnPjqteQZWYEf8Bk9naEbSWAi46wgFn7xx3i9bF+nWBbbUuehM4haEhMKyd /S++mzfjrKgbylxbsJOBBItUVAR+VOu1+6Suzrg0a/dab7esr0zOltl/PYXck44ohdoA B3tRaGBiqhiAUZSQrc03YjCPvAXKbHEDoCju+WC5kD6ZnUpPfRvP37Vymd81brGPcpZS PcGg== X-Forwarded-Encrypted: i=1; AHgh+Ro/XlvGjB12YeSSgj+4X/c9lCWNX7StJCL3kFrlcvlC/OJuDqOo0L52zoqDY50ynhksODqEX9oZJbm+/cA=@vger.kernel.org X-Gm-Message-State: AFuF++n+jReFGCEAsXGMFR54Nq63asSG8nfwNIvCnlk8SNyGGtB+W5sn tpNhIZKkT4jsgHdiL/YYcgppbQj1GFzyN1oekGQbviWAgzUebsIz9nlv5NJoRQ== X-Gm-Gg: AR+sD12gwnZZ4NxHBhAbjNiwhJCMCgs7dpUgkEodekef0cl0kYufb/4iBOJbwHuWO3I LrVHaofhlgUDL2cjZ7T1gvgdtgqfuOsS6KtQYtRZoHxjxVtq3LDbe22XFjisXWf/UdJNgjKxOa2 oHKwr5JH0mqa0ekl/tpKQXaXDoPHBULkYUyV0Hv3lxvyfRTLwxbqzjLHdY8NQ1MvqF3dPVLRLWS DdipEBGj3JiyiQ1LteV7j8Edt+mfbdN6XULLZwA0TiTxCUORJGck9r1L6l/ZB04drQWaeA/YzNq 2MAxLnPLo2cMZtHDuOxFHQb9hGTeE7o1kyFz/j2fw4xA/nuAP8cDXzHhIGgR4QFWUH6E6492C89 3UcVjL4hR+OnsGMRAxbOL5BIGc4VmOVD4WN3dwDapnnkACh9pjObmdKDemLrKmr+yK7tJHt+Bu+ NRfXQ3UJ3l59DYUJALU0bVj4JUPvp3i5IE6PENmOih4qC1DDQZx6VpcGW/2G3PbeaymKhCFc9dh 5Ca0Q== X-Received: by 2002:a05:6402:4617:b0:6a1:f3b5:f7dc with SMTP id 4fb4d7f45d1cf-6a41129a4f4mr26577169a12.4.1787505982076; Sun, 23 Aug 2026 10:26:22 -0700 (PDT) Received: from foxbook (bfk5.neoplus.adsl.tpnet.pl. [83.28.48.5]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-6a59e001305sm4349899a12.4.2026.08.23.10.26.19 (version=TLS1_2 cipher=AES128-SHA bits=128/128); Sun, 23 Aug 2026 10:26:21 -0700 (PDT) Date: Sun, 23 Aug 2026 19:26:17 +0200 From: Michal Pecio To: Alan Stern Cc: Greg Kroah-Hartman , Oliver Neukum , Ming Lei , linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org Subject: Re: [PATCH] usb: hcd: Cancel BH giveback works on removal Message-ID: <20260823192617.2194ac8e.michal.pecio@gmail.com> In-Reply-To: References: <20260823125831.6ea35650.michal.pecio@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit On Sun, 23 Aug 2026 10:31:28 -0400, Alan Stern wrote: > On Sun, Aug 23, 2026 at 12:58:31PM +0200, Michal Pecio wrote: > > Turns out, we do actually need to flush them, because workers use the > > 'high_prio_bh' and 'low_prio_bh' members of 'usb_hcd' for a brief time > > after all URBs are completed to track pending completions and possibly > > reschedule themselves, see usb_giveback_urb_bh() implementation. > > > > Flushing would suffice if the works don't reschedule themselves, but > > cancel_work_sync() is more robust against stray completions. > > > > Syzbot may have found the issue due to unlucky hard IRQ timing. It can > > be reproduced by adding udelay(3000) in the work function, disabling RH > > autosuspend to maintain the status URB and unbinding a real HC: > > > > [10818.828029] ehci-pci 0000:00:12.0: USB bus 1 deregistered > > [10818.828077] hcd_release freeing high_prio_bh ffff88814a950978 > > [10818.829211] usb_giveback_urb_bh still running on bh ffff88814a950978 > > > > Reported-by: syzbot+cade843a1e4af0651f5e@syzkaller.appspotmail.com > > Link: https://lore.kernel.org/linux-usb/6a8a5047.dbb3a75c.13dd47.003e.GAE@google.com/ > > Fixes: 94dfd7edfd5c ("USB: HCD: support giveback of URB in tasklet context") > > While that is logically correct, in fact the patch won't apply as-is to > any commit earlier than 8fea0c8fda30129b ("usb: core: hcd: Convert from > tasklet to BH workqueue"). Hmm, it's a fairly recent one, so this will only work on v6.12+. Maybe not a big deal considering Greg's recent opinion about unbind issues, though TBH I'm not really convinced about unbind's irrelevance in this era where everything (including USB HCs) is hotpluggable. I'm OK with this patch being dropped (I will maintain it for myself), stripped of Cc:stable or limited to branches where it applies. And I probably won't bother backporting it all they way to stone age. Regards, Michal