mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2026-08-09 06:14:34 +02:00
The f_tcm set_alt() path defers endpoint setup to a work item and
completes the delayed status response from process context. The delayed
work uses f_tcm private state and may complete the setup request after
disconnect or function teardown has already moved on.
Cancel and drain the delayed set_alt work when the function is unbound or
freed. For disable paths, which are reached under the composite device
lock, use a small state machine and a non-sleeping cancellation path
instead of cancel_work_sync(). If the work is already running, mark it
cancelled and let the worker own the cleanup; otherwise tcm_disable() can
cancel the queued work and clean up immediately.
Also serialize the final delayed-status completion with the cancellation
check while holding the composite device lock. This prevents a disconnect
from clearing delayed_status while the worker is about to complete the
control request.
Validation reproduced this kernel report:
BUG: KASAN: slab-use-after-free in tcm_delayed_set_alt+0x6c/0xef0
Call Trace:
<TASK>
dump_stack_lvl+0x66/0xa0
print_report+0xce/0x630
? tcm_delayed_set_alt+0x6c/0xef0
? srso_alias_return_thunk+0x5/0xfbef5
? __virt_addr_valid+0x188/0x320
? tcm_delayed_set_alt+0x6c/0xef0
kasan_report+0xe0/0x110
? tcm_delayed_set_alt+0x6c/0xef0
tcm_delayed_set_alt+0x6c/0xef0
? __pfx_tcm_delayed_set_alt+0x10/0x10
? process_one_work+0x4cb/0xb90
? rcu_is_watching+0x20/0x50
? tcm_delayed_set_alt+0x9/0xef0
process_one_work+0x4d7/0xb90
? __pfx_process_one_work+0x10/0x10
? srso_alias_return_thunk+0x5/0xfbef5
? __list_add_valid_or_report+0x37/0xf0
? __pfx_tcm_delayed_set_alt+0x10/0x10
? srso_alias_return_thunk+0x5/0xfbef5
worker_thread+0x2d8/0x570
? __pfx_worker_thread+0x10/0x10
kthread+0x1ad/0x1f0
? __pfx_kthread+0x10/0x10
ret_from_fork+0x3c9/0x540
? __pfx_ret_from_fork+0x10/0x10
? srso_alias_return_thunk+0x5/0xfbef5
? __switch_to+0x2e9/0x730
? __pfx_kthread+0x10/0x10
ret_from_fork_asm+0x1a/0x30
</TASK>
Allocated by task 544:
kasan_save_stack+0x33/0x60
kasan_save_track+0x14/0x30
__kasan_kmalloc+0x8f/0xa0
tcm_alloc+0x68/0x180
usb_get_function+0x36/0x60
config_usb_cfg_link+0x125/0x1b0
configfs_symlink+0x322/0x890
vfs_symlink+0xc2/0x270
filename_symlinkat+0x295/0x2f0
__x64_sys_symlinkat+0x62/0x90
do_syscall_64+0x115/0x6a0
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Freed by task 661:
kasan_save_stack+0x33/0x60
kasan_save_track+0x14/0x30
kasan_save_free_info+0x3b/0x60
__kasan_slab_free+0x43/0x70
kfree+0x2f9/0x530
config_usb_cfg_unlink+0x173/0x1e0
configfs_unlink+0x1fa/0x340
vfs_unlink+0x15c/0x510
filename_unlinkat+0x2ba/0x450
__x64_sys_unlinkat+0x63/0x90
do_syscall_64+0x115/0x6a0
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Fixes: c52661d60f ("usb-gadget: Initial merge of target module for UASP + BOT")
Cc: stable <stable@kernel.org>
Assisted-by: Codex:gpt-5.5
Signed-off-by: Cen Zhang <zzzccc427@gmail.com>
Link: https://patch.msgid.link/20260627104153.3822495-1-zzzccc427@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
165 lines
3.5 KiB
C
165 lines
3.5 KiB
C
/* SPDX-License-Identifier: GPL-2.0 */
|
|
#ifndef __TARGET_USB_GADGET_H__
|
|
#define __TARGET_USB_GADGET_H__
|
|
|
|
#include <linux/kref.h>
|
|
#include <linux/spinlock.h>
|
|
/* #include <linux/usb/uas.h> */
|
|
#include <linux/hashtable.h>
|
|
#include <linux/usb/composite.h>
|
|
#include <linux/usb/uas.h>
|
|
#include <linux/usb/storage.h>
|
|
#include <target/target_core_base.h>
|
|
#include <target/target_core_fabric.h>
|
|
|
|
#define USBG_NAMELEN 32
|
|
|
|
#define fuas_to_gadget(f) (f->function.config->cdev->gadget)
|
|
#define UASP_SS_EP_COMP_LOG_STREAMS 5
|
|
#define UASP_SS_EP_COMP_NUM_STREAMS (1 << UASP_SS_EP_COMP_LOG_STREAMS)
|
|
|
|
#define USBG_NUM_CMDS (UASP_SS_EP_COMP_NUM_STREAMS + 1)
|
|
|
|
enum {
|
|
USB_G_STR_INT_UAS = 0,
|
|
USB_G_STR_INT_BBB,
|
|
};
|
|
|
|
#define USB_G_ALT_INT_BBB 0
|
|
#define USB_G_ALT_INT_UAS 1
|
|
|
|
#define USB_G_DEFAULT_SESSION_TAGS USBG_NUM_CMDS
|
|
|
|
enum {
|
|
USBG_DELAYED_SET_ALT_IDLE = 0,
|
|
USBG_DELAYED_SET_ALT_QUEUED,
|
|
USBG_DELAYED_SET_ALT_RUNNING,
|
|
};
|
|
|
|
struct tcm_usbg_nexus {
|
|
struct se_session *tvn_se_sess;
|
|
};
|
|
|
|
struct usbg_tpg {
|
|
struct mutex tpg_mutex;
|
|
/* SAS port target portal group tag for TCM */
|
|
u16 tport_tpgt;
|
|
/* Pointer back to usbg_tport */
|
|
struct usbg_tport *tport;
|
|
struct workqueue_struct *workqueue;
|
|
/* Returned by usbg_make_tpg() */
|
|
struct se_portal_group se_tpg;
|
|
u32 gadget_connect;
|
|
struct tcm_usbg_nexus *tpg_nexus;
|
|
atomic_t tpg_port_count;
|
|
|
|
struct usb_function_instance *fi;
|
|
};
|
|
|
|
struct usbg_tport {
|
|
/* Binary World Wide unique Port Name for SAS Target port */
|
|
u64 tport_wwpn;
|
|
/* ASCII formatted WWPN for SAS Target port */
|
|
char tport_name[USBG_NAMELEN];
|
|
/* Returned by usbg_make_tport() */
|
|
struct se_wwn tport_wwn;
|
|
};
|
|
|
|
enum uas_state {
|
|
UASP_SEND_DATA,
|
|
UASP_RECEIVE_DATA,
|
|
UASP_SEND_STATUS,
|
|
UASP_QUEUE_COMMAND,
|
|
};
|
|
|
|
#define USBG_MAX_CMD 64
|
|
struct usbg_cmd {
|
|
/* common */
|
|
u8 cmd_buf[USBG_MAX_CMD];
|
|
u32 data_len;
|
|
struct work_struct work;
|
|
int unpacked_lun;
|
|
struct se_cmd se_cmd;
|
|
void *data_buf; /* used if no sg support available */
|
|
struct f_uas *fu;
|
|
struct kref ref;
|
|
|
|
struct usb_request *req;
|
|
|
|
u32 flags;
|
|
#define USBG_CMD_PENDING_DATA_WRITE BIT(0)
|
|
|
|
/* UAS only */
|
|
u16 tag;
|
|
u16 prio_attr;
|
|
struct sense_iu sense_iu;
|
|
struct response_iu response_iu;
|
|
enum uas_state state;
|
|
|
|
int tmr_func;
|
|
int tmr_rsp;
|
|
#define RC_RESPONSE_UNKNOWN 0xff
|
|
|
|
/* BOT only */
|
|
__le32 bot_tag;
|
|
unsigned int csw_code;
|
|
unsigned is_read:1;
|
|
|
|
};
|
|
|
|
struct uas_stream {
|
|
struct usb_request *req_in;
|
|
struct usb_request *req_out;
|
|
struct usb_request *req_status;
|
|
|
|
struct completion cmd_completion;
|
|
struct hlist_node node;
|
|
};
|
|
|
|
struct usbg_cdb {
|
|
struct usb_request *req;
|
|
void *buf;
|
|
};
|
|
|
|
struct bot_status {
|
|
struct usb_request *req;
|
|
struct bulk_cs_wrap csw;
|
|
};
|
|
|
|
struct f_uas {
|
|
struct usbg_tpg *tpg;
|
|
struct usb_function function;
|
|
u16 iface;
|
|
|
|
u32 flags;
|
|
#define USBG_ENABLED (1 << 0)
|
|
#define USBG_IS_UAS (1 << 1)
|
|
#define USBG_USE_STREAMS (1 << 2)
|
|
#define USBG_IS_BOT (1 << 3)
|
|
#define USBG_BOT_CMD_PEND (1 << 4)
|
|
#define USBG_BOT_WEDGED (1 << 5)
|
|
|
|
struct work_struct delayed_set_alt;
|
|
spinlock_t delayed_set_alt_lock; /* protects delayed_set_alt_* */
|
|
unsigned int delayed_alt;
|
|
unsigned int delayed_set_alt_state;
|
|
bool delayed_set_alt_cancel;
|
|
|
|
struct usbg_cdb cmd[USBG_NUM_CMDS];
|
|
struct usb_ep *ep_in;
|
|
struct usb_ep *ep_out;
|
|
|
|
/* UAS */
|
|
struct usb_ep *ep_status;
|
|
struct usb_ep *ep_cmd;
|
|
struct uas_stream stream[USBG_NUM_CMDS];
|
|
DECLARE_HASHTABLE(stream_hash, UASP_SS_EP_COMP_LOG_STREAMS);
|
|
|
|
/* BOT */
|
|
struct bot_status bot_status;
|
|
struct usb_request *bot_req_in;
|
|
struct usb_request *bot_req_out;
|
|
};
|
|
|
|
#endif /* __TARGET_USB_GADGET_H__ */
|