[syzbot] [kernel?] WARNING in device_remove

syzbot <[email protected]>
Newsgroups org.kernel.vger.linux-usb,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Hello,

syzbot found the following issue on:

HEAD commit:    5d5fd841c346 Merge 7.2-rc5 into usb-next
git tree:       https://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb.git usb-testing
console output: https://syzkaller.appspot.com/x/log.txt?x=12d922c6580000
kernel config:  https://syzkaller.appspot.com/x/.config?x=6ec4d592e55f7960
dashboard link: https://syzkaller.appspot.com/bug?extid=7371a1a749c42016f046
compiler:       gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/2ed536ae4daf/disk-5d5fd841.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/ab40098ccbf1/vmlinux-5d5fd841.xz
kernel image: https://storage.googleapis.com/syzbot-assets/66d5c395f47c/bzImage-5d5fd841.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: [email protected]

usb 7-1: USB disconnect, device number 4
------------[ cut here ]------------
!work->func
WARNING: kernel/workqueue.c:4335 at __flush_work+0xa5d/0xcb0 kernel/workqueue.c:4335, CPU#0: kworker/0:6/5370
Modules linked in:
CPU: 0 UID: 0 PID: 5370 Comm: kworker/0:6 Not tainted syzkaller #0 PREEMPT(lazy) 
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
Workqueue: usb_hub_wq hub_event

RIP: 0010:__flush_work+0xa5d/0xcb0 kernel/workqueue.c:4335
Code: 35 00 00 00 00 e8 13 2c 12 00 e8 6e 8d 1b 00 c6 44 24 0f 00 e9 91 fd ff ff e8 0f 00 36 00 90 0f 0b 90 eb eb e8 04 00 36 00 90 <0f> 0b 90 eb e0 e8 f9 ff 35 00 e8 f4 ff 35 00 48 8b 3c 24 e8 6b b8
RSP: 0018:ffffc90004097228 EFLAGS: 00010287
RAX: 0000000000021e96 RBX: dffffc0000000000 RCX: ffffc90011b77000
RDX: 0000000000100000 RSI: ffffffff817e043c RDI: ffff888118583c00
R10: 0000000000000001 R11: 0000000000000000 R12: 0000000000000000
R13: ffff88811a5c88f0 R14: 0000000000000001 R15: 0000000000000001
FS:  0000000000000000(0000) GS:ffff888268636000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000000110c322071 CR3: 000000013af66000 CR4: 00000000003506f0
Call Trace:
 <TASK>
 __cancel_work_sync kernel/workqueue.c:4494 [inline]
 cancel_work_sync+0xd1/0xf0 kernel/workqueue.c:4531
 device_remove+0xcb/0x180 drivers/base/dd.c:616
 __device_release_driver drivers/base/dd.c:1349 [inline]
 device_release_driver_internal+0x44e/0x620 drivers/base/dd.c:1372
 bus_remove_device+0x2bc/0x560 drivers/base/bus.c:664
 device_del+0x376/0x9b0 drivers/base/core.c:3961
 hid_remove_device drivers/hid/hid-core.c:3071 [inline]
 hid_destroy_device+0x19c/0x240 drivers/hid/hid-core.c:3093
 usbhid_disconnect+0xa0/0xe0 drivers/hid/usbhid/hid-core.c:1479
 device_remove drivers/base/dd.c:618 [inline]
 device_remove+0x12a/0x180 drivers/base/dd.c:610
 __device_release_driver drivers/base/dd.c:1349 [inline]
 device_release_driver_internal+0x44e/0x620 drivers/base/dd.c:1372
 bus_remove_device+0x2bc/0x560 drivers/base/bus.c:664
 device_del+0x376/0x9b0 drivers/base/core.c:3961
 usb_disable_device+0x367/0x810 drivers/usb/core/message.c:1478
 hub_port_connect drivers/usb/core/hub.c:5412 [inline]
 hub_port_connect_change drivers/usb/core/hub.c:5712 [inline]
 port_event drivers/usb/core/hub.c:5876 [inline]
 hub_event+0x1d0c/0x4af0 drivers/usb/core/hub.c:5958
 process_one_work+0xa23/0x1940 kernel/workqueue.c:3322
 process_scheduled_works kernel/workqueue.c:3405 [inline]
 worker_thread+0x5ef/0xe50 kernel/workqueue.c:3486
 kthread+0x370/0x450 kernel/kthread.c:436
 ret_from_fork+0x69a/0xc80 arch/x86/kernel/process.c:158
 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
 </TASK>


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at [email protected].

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.