From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oa1-f49.google.com (mail-oa1-f49.google.com [209.85.160.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4870D481FAB for ; Tue, 25 Aug 2026 14:29:49 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.49 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787668191; cv=none; b=m7IfGaMJhY+nLwNouWb4tyCEK8aefDjK6Wex9mT859RjIpaDPIQX3U6BKJGeeTHL8qmpPRTJrSOAPKnaBA05/MuWkjlOrU7hmYqtUxQfsppAHS1exPoALbzXnEQoI34dqls/yt5n/kSB6xye7QsOvpBIfPg7Js41gp4Uhq7ZVEg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787668191; c=relaxed/simple; bh=fP7ZVgo77mek34H/l/6QdsjYQ6XTfRYxEZcesK31tCg=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=HciF6LNeD6dDaBzgnslA+mjreQVb7wNqBSnI4tqomVBMfS2W0q3KKwJP6Ki6JhF8G3EcogKAEcs57AaFGZGpT3iUBB/bzIhm8UYzSvwRQYYsBVcJjGH7X+Cfnv9sLHLOWXlNShg8ZCmeDRo+s9xeHp5JImQnBqkWXE1iq5lrqJk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=M50q8YPA; arc=none smtp.client-ip=209.85.160.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="M50q8YPA" Received: by mail-oa1-f49.google.com with SMTP id 586e51a60fabf-451a49abd8aso4154407fac.3 for ; Tue, 25 Aug 2026 07:29:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787668188; x=1788272988; darn=vger.kernel.org; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=n3AWeXIUE0hbARghyBBXHPbPROSf2bjB7jztp6AV4jQ=; b=M50q8YPAvwd9gxWyrVqC7MCgQTaefzyFIW5RROnZO5N1ojETYBv37YmW0NlHRxaY6+ k7u/L89be7/2I9yfCcINfhLCwMGcc9EguifVwDJgALwFqD82W5533Zx16d/l0QwDNDTx 0oCfpOdUnNCf2e2aOuLdMxHoUEIYmkTUysElZ+JT3C68dglNgiPX+bxyAi8T1q9AYtbj +tzDtvKHPFyOg4wH8W9I/rZBn4mv2q2jxB3ohcZlLB5GYdpqhT3vE9jefWsdhGG6Z7Gv Fk6CM2WziCYMZqhRDc74tdFenZfNJDsVO+AM4BIoQTbr1bpcC84ygd0YI38kbMLiAxyO eLtw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787668188; x=1788272988; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=n3AWeXIUE0hbARghyBBXHPbPROSf2bjB7jztp6AV4jQ=; b=gsC9R2Sh2Hdh+GyNmgd+hq/qAo8ov86mzAlFFezkQ9LgX0US5JNCj8CVxaQo6LhpRA VtCiq8vRlbKr/GiB9kZOSvsWQtnSTw5wwh2bE+SUQx0sUMc7T8nrG5+og/os6GVY+ebf yfn+NSEEojQlleJvEzdQrLgx0FdIgnwGIemcqNjmMbgzflndbSNSBCByT7uEivwnD36j nn7da4FgGQyx0yS7Y6t+cDJbnYy9/90dBxQJ+z+Cf8zwkkR1MYvRgNVhzWvHjTYsp/FT IYbcK2h/c37hU1a8VnRS9lbMaqm3XVYxOgKG0e5wo4wSKcdJoQoWeW+zw37uOCA3Mn6Q EG0A== X-Forwarded-Encrypted: i=1; AHgh+RpbX27EQa+LoG7BglA7KUtmDuMLzOIJWQHecHyF9YxdbvvgxYP6yzjpw31r852olpAJ3LMSepIpwNNImV4=@vger.kernel.org X-Gm-Message-State: AFuF++nFKeBOwJNTqFNo52hm1NNW/EvdRpM/N0qQeL8PDsI6NWHm65Ve DktlaLinEGjSfcxJJ9xtEfzcfIw/BX8iuk/VMczrFg/5SINnae2cEDBa X-Gm-Gg: AR+sD12s+LhB9scmy0cG4l6zFOEt6xGYEwCFWdQNGcHPOXkWqZCXCIoqEhHYUPsbf1j G4gkFZpvUMg2WMqMQFT3AFXZ/VrBi8kNh7h0BKTlvDoCO7o0Y/aYWn3TydORepVPdaaKALSYJec eoTrUSdJTkiACNkpFFkL+sk+cBIvWvLHukR10IkAiTo4f5S75kC1ugQLxcODdQw/b43U1VgK86f wc6wgpBvBxBgpyyoPGKf3kViAvynEYhh9v5NNNjMXBSmXSR9Jgr5QP1SvrXdsH3AQm0Val561TY +q3RX+nknuWSJls6u7TqupgQzRUb2+dO+QbcodDRtAri3YtznhWL2Wt5UC5IAlzMdr651H4DoXN pTN0XRto9631w+SPSZG4crlwdUZVAK8H9/4W2m2N3UsjpCLavyFHZWhrrmxjwkTawF/ns2v5xh7 g5R++T7zFhRAkhCx0IfcMsw9ZnokTy2WTMzp3j+w9YsBdmwNbhyzsyfdt2VNuSPBojLo7ign5NO 4kZ4CS8LK/Ylu6NG9NpaPYVtmMBXyel95EKkzksGxJA X-Received: by 2002:a4a:ec46:0:b0:6b1:63f4:daef with SMTP id 006d021491bc7-6b1905225f2mr5942939eaf.30.1787668187777; Tue, 25 Aug 2026 07:29:47 -0700 (PDT) Received: from localhost ([2409:40c4:13d:8046:4d30:e4cc:47a7:83a3]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-327f909c6c9sm43089493eec.6.2026.08.25.07.29.46 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 25 Aug 2026 07:29:47 -0700 (PDT) Date: Tue, 25 Aug 2026 19:59:43 +0530 From: Lovekesh Solanki To: Alan Stern Cc: jjy600901@snu.ac.kr, brauner@kernel.org, eulgyukim@snu.ac.kr, gregkh@linuxfoundation.org, jack@suse.cz, kees@kernel.org, linux-kernel@vger.kernel.org, linux-usb@vger.kernel.org, mjguzik@gmail.com, viro@zeniv.linux.org.uk, stable@vger.kernel.org Subject: Re: [PATCH] USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl() Message-ID: References: <20260824113510.1141236-1-jjy600901@snu.ac.kr> <20260825105801.319997-1-lovekeshsolanki00@gmail.com> <903f6c28-57f1-4aa2-a111-910fcfbee52b@rowland.harvard.edu> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <903f6c28-57f1-4aa2-a111-910fcfbee52b@rowland.harvard.edu> Thanks for the review, On Tue, Aug 25, 2026 at 09:14:37AM -0400, Alan Stern wrote: > Why does it matter that you read dev->gadget before the state check > rather than after? If it doesn't matter, there's no reason to mention > it in the patch description. The order of reading it doesn't matter. The important part is to read it while holding the lock, perhaps the wording is unclear, I'll reword it in v2. > Also, why does it matter that gadgetfs_bind() writes dev->gadget without > holding the lock? Again, the description shouldn't mention things that > don't matter. Because ioctl can get a stale dev->gadget before dev->lock, while dev->state is checked after acquiring the lock, which is the cause. Is the reference to gadgetfs_bind() unncessary? Or this part of the explanation is irrelvant? > Why did you add this test for gadget being non-NULL? Is there any way > it could possibly be NULL at this point? It seems it doesn't matter since if read is correct it can't be NULL, it was an initial attempt to fix but its unnecessary now, I'll remove that as well. Regards, Lovekesh