From mboxrd@z Thu Jan 1 00:00:00 1970 Delivery-date: Mon, 31 Aug 2026 15:25:36 +0200 Received: from mx1.white.stw.pengutronix.de ([185.203.200.13]) by lore.white.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1x1211-009I54-2F for lore@lore.pengutronix.de; Mon, 31 Aug 2026 15:25:36 +0200 Received: from bombadil.infradead.org (bombadil.infradead.org [IPv6:2607:7c80:54:3::133]) by mx1.white.stw.pengutronix.de (Postfix) with ESMTPS id 45DE9202497 for ; Mon, 31 Aug 2026 15:25:32 +0200 (CEST) Authentication-Results: mx1.white.stw.pengutronix.de; dkim=pass header.d=lists.infradead.org header.s=bombadil.20210309 header.b=zEXTpRbg; spf=pass (mx1.white.stw.pengutronix.de: domain of "barebox-bounces+lore=pengutronix.de@lists.infradead.org" designates 2607:7c80:54:3::133 as permitted sender) smtp.mailfrom="barebox-bounces+lore=pengutronix.de@lists.infradead.org"; dmarc=none DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:List-Subscribe:List-Help :List-Post:List-Archive:List-Unsubscribe:List-Id:To:In-Reply-To:References: Message-Id:Content-Transfer-Encoding:Content-Type:MIME-Version:Subject:Date: From:Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=cGKaHP61SS8tcnYvhVDPm8gKqIPir3TtHP9Ckd6p7qM=; b=zEXTpRbgWSD4oU1YAKRJGhEpmT yx7zEsJJ6Q/j0CjKe9erBUCTuNDE8DYDjWg+KGeKqS80+fsgq2Y+/47EzbPlxvmz0nawF/9B+TQfm SvKRkLf0caG2y05+V7vu843aS/Ysp0P055ehhVJdkWiSR/qi8YKLogn6qZaYA+FgpH29+6nmbfW8w sZSizWzJASaXG6uTwMi8ed1Uy/k1oHHbbPGi4l+POXASPnvlooZHXUwXkrnU55DDG4MTIELxU6NJn 3+viXAn8rqZWoCleaiZywPm8SBkd9S7XEwzHwD2CIh9sFFs7nEW6q3K+FtuYmKx9kyLd9WYJHIHKB OVqqMvew==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.99.1 #2 (Red Hat Linux)) id 1x11w0-00000009NzA-35TF; Mon, 31 Aug 2026 13:20:24 +0000 Received: from mx1.white.stw.pengutronix.de ([2a0a:edc0:0:b01:1d::107]) by bombadil.infradead.org with esmtps (Exim 4.99.1 #2 (Red Hat Linux)) id 1x11vx-00000009Nv2-2vq4 for barebox@lists.infradead.org; Mon, 31 Aug 2026 13:20:23 +0000 Received: from drehscheibe.grey.stw.pengutronix.de (drehscheibe.grey.stw.pengutronix.de [IPv6:2a0a:edc0:0:c01:1d::a2]) (Authenticated sender: relay-from-drehscheibe.grey.stw.pengutronix.de) by mx1.white.stw.pengutronix.de (Postfix) with ESMTPSA id CFA3220247C; Mon, 31 Aug 2026 15:20:10 +0200 (CEST) Received: from dude02.red.stw.pengutronix.de ([2a0a:edc0:0:1101:1d::28]) by drehscheibe.grey.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1x11vm-004GQy-1t; Mon, 31 Aug 2026 15:20:10 +0200 Received: from [::1] (helo=dude02.red.stw.pengutronix.de) by dude02.red.stw.pengutronix.de with esmtp (Exim 4.98.2) (envelope-from ) id 1x11vm-0000000H7Av-1uiY; Mon, 31 Aug 2026 15:20:10 +0200 From: Sascha Hauer Date: Mon, 31 Aug 2026 15:20:08 +0200 Subject: [PATCH 01/13] usb: don't report device removal after the device name is gone MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Message-Id: <20260831-usb-device-lifetime-v1-1-6adf4054b909@pengutronix.de> References: <20260831-usb-device-lifetime-v1-0-6adf4054b909@pengutronix.de> In-Reply-To: <20260831-usb-device-lifetime-v1-0-6adf4054b909@pengutronix.de> To: BAREBOX X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1788182410; l=1480; i=s.hauer@pengutronix.de; s=20230412; h=from:subject:message-id; bh=8THAC797KFBdUYEj0gMCu5bttqzmmUgjqoXRur4ycho=; b=DhmvQtCt9zhnmh1gEI3js/5E4F0PcWdK08Q5AkbyHcTZmXAmFAbAChp9sS3N6t8HRpe9R+Tro HMY7cOHppFLDO1d1T3XjE2k0CjixJtiujK6imx0+3t5H3IxcYufehd6 X-Developer-Key: i=s.hauer@pengutronix.de; a=ed25519; pk=4kuc9ocmECiBJKWxYgqyhtZOHj5AWi7+d0n/UjhkwTg= X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.9.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20260831_062021_922662_CF064212 X-CRM114-Status: GOOD ( 11.04 ) X-Spam-Score: -1.9 (-) X-Spam-Report: Spam detection software, running on the system "bombadil.infradead.org", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: usb_remove_device() logs the removal after unregister_device() has run. That is too late: unregister_device() starts with bobject_del(), which frees the device name, and ends with free_device_res(), w [...] Content analysis details: (-1.9 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.0 SPF_HELO_PASS SPF: HELO matches SPF record -0.0 SPF_PASS SPF: sender matches SPF record -1.9 BAYES_00 BODY: Bayes spam probability is 0 to 1% [score: 0.0000] 0.0 DMARC_MISSING Missing DMARC policy X-BeenThere: barebox@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "barebox" X-Rspamd-Server: mx1 X-Stat-Signature: 44azj3xrzes436nfyfcxeucs4m3r7cpa X-Rspamd-Queue-Id: 45DE9202497 X-Spamd-Result: default: False [-57.81 / 15.00]; RECEIVED_AUTHENTICATED_BY_MX1(-50.00)[]; BAYES_HAM(-3.00)[99.99%]; DWL_DNSWL_MED(-2.00)[infradead.org:dkim]; KNOWN_LIST_ID(-1.00)[barebox.lists.infradead.org]; RCVD_IN_DNSWL_MED(-0.60)[2607:7c80:54:3::133:from,2a0a:edc0:0:c01:1d::a2:received,2a0a:edc0:0:1101:1d::28:received]; RCVD_DKIM_ARC_DNSWL_MED(-0.50)[]; R_SPF_ALLOW(-0.20)[+mx:c]; MAILLIST(-0.20)[mailman]; R_DKIM_ALLOW(-0.20)[lists.infradead.org:s=bombadil.20210309]; MIME_GOOD(-0.10)[text/plain]; HAS_LIST_UNSUB(-0.01)[]; TO_DN_ALL(0.00)[]; MIME_TRACE(0.00)[0:+]; RCVD_TLS_LAST(0.00)[]; ARC_NA(0.00)[]; RECEIVED_HELO_LOCALHOST(0.00)[]; DMARC_NA(0.00)[pengutronix.de]; TAGGED_FROM(0.00)[lore=pengutronix.de]; FORGED_RECIPIENTS_MAILLIST(0.00)[]; RCPT_COUNT_ONE(0.00)[1]; RCVD_COUNT_FIVE(0.00)[5]; FROM_NEQ_ENVFROM(0.00)[s.hauer@pengutronix.de,barebox-bounces@lists.infradead.org]; FROM_HAS_DN(0.00)[]; DKIM_TRACE(0.00)[lists.infradead.org:+]; NEURAL_HAM(-0.00)[-1.000]; RCVD_VIA_SMTP_AUTH(0.00)[]; MID_RHS_MATCH_FROM(0.00)[]; ASN(0.00)[asn:7247, ipnet:2607:7c80:54::/48, country:US]; FORGED_SENDER_MAILLIST(0.00)[] X-Rspamd-Action: no action usb_remove_device() logs the removal after unregister_device() has run. That is too late: unregister_device() starts with bobject_del(), which frees the device name, and ends with free_device_res(), which frees unique_name. dev_printf() then reads both back via dev_name() to build the message prefix, so both the success and the error message are use-after-free reads. Print before unregistering instead. While at it, drop the error branch: unregister_device() returns 0 unconditionally, so it never ran. This is not observable today because nothing ever calls usb_remove_device(), but that is about to change. Signed-off-by: Sascha Hauer Assisted-by: Claude:claude-opus-5 --- drivers/usb/core/usb.c | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/drivers/usb/core/usb.c b/drivers/usb/core/usb.c index 3f379197dc..3daa6b1d1d 100644 --- a/drivers/usb/core/usb.c +++ b/drivers/usb/core/usb.c @@ -625,10 +625,13 @@ void usb_remove_device(struct usb_device *usbdev) list_del(&usbdev->list); dev_count--; - if (unregister_device(&usbdev->dev)) - dev_err(&usbdev->dev, "failed to unregister\n"); - else - dev_info(&usbdev->dev, "removed\n"); + /* + * unregister_device() frees the device name, so there is nothing + * left to print afterwards. + */ + dev_info(&usbdev->dev, "removed\n"); + + unregister_device(&usbdev->dev); usb_free_device(usbdev); } -- 2.47.3