Re: [PATCH v2] usb-storage: ene_ub6250: fix race between scan work and probe
Alan Stern <[email protected]>
| Newsgroups | org.kernel.vger.stable,org.kernel.vger.linux-usb |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Aug 21, 2026 at 05:04:16PM +0800, Liu Qi wrote: > ene_ub6250_probe() calls usb_stor_probe2(), which starts the usb-storage > infrastructure and schedules the delayed scan work. The driver then > calls ene_get_card_type(), which sends an ENE command through > ene_send_scsi_cmd() and the usb-storage bulk transfer helpers. > > Both the delayed scan work, through usb_stor_Bulk_max_lun(), and > ene_get_card_type() use us->current_urb. The scan work serializes this > access with us->dev_mutex, but the ENE card-type probe does not. If the > scan work runs while ene_get_card_type() is still using us->current_urb, > usb_submit_urb() warns that the URB is already active. > > Serialize ene_get_card_type() with us->dev_mutex, matching the locking > used by the scan path. > > Reported-by: [email protected] > Closes: https://syzkaller.appspot.com/bug?extid=22ea20ef3afb6785b122 > Assisted-by: Qwen:Qwen3.6 > Signed-off-by: Liu Qi <[email protected]> > --- Acked-by: Alan Stern <[email protected]> > drivers/usb/storage/ene_ub6250.c | 2 ++ > 1 file changed, 2 insertions(+) > > diff --git a/drivers/usb/storage/ene_ub6250.c b/drivers/usb/storage/ene_ub6250.c > index 2cffc559a..13b332d1d 100644 > --- a/drivers/usb/storage/ene_ub6250.c > +++ b/drivers/usb/storage/ene_ub6250.c > @@ -2358,7 +2358,9 @@ static int ene_ub6250_probe(struct usb_interface *intf, > return result; > > /* probe card type */ > + mutex_lock(&us->dev_mutex); > result = ene_get_card_type(us, REG_CARD_STATUS, info->bbuf); > + mutex_unlock(&us->dev_mutex); > if (result != USB_STOR_XFER_GOOD) { > usb_stor_disconnect(intf); > return USB_STOR_TRANSPORT_ERROR; > -- > 2.43.0