Re: [PATCH v2] usb-storage: ene_ub6250: don't let the card-type probe hang forever
From: Greg KH
Date: Thu Oct 01 2026 - 07:20:53 EST
On Thu, Oct 01, 2026 at 05:15:23PM +0800, xy521521@xxxxxxxxx wrote:
> From: Hongyu Xie <xiehongyu1@xxxxxxxxxx>
>
> ene_ub6250_probe() queries the card type with ene_get_card_type() while
> holding us->dev_mutex (the locking added by commit 445fc368c6bc
> ("usb-storage: ene_ub6250: fix race between scan work and probe")).
> The query is a bulk-only transaction: CBW, 1-byte data-in and CSW, each
> transferred by usb_stor_bulk_transfer_buf(), which waits for URB
> completion with MAX_SCHEDULE_TIMEOUT.
>
> That unbounded wait is safe only while a SCSI command is being handled,
> because the command's abort machinery (usb_stor_stop_transport() via
> US_FLIDX_ABORTING) is the only thing that can terminate it. At probe
> time no SCSI command exists, so a device that passes enumeration but
> never services bulk transfers wedges the probe forever:
>
> hub_event: usb_stor_msg_common() <- ene_send_scsi_cmd
> <- ene_ub6250_probe (holds us->dev_mutex)
> events_freezable: usb_stor_scan_dwork (blocked on us->dev_mutex)
>
> syzbot reports the second worker as "INFO: task hung in
> usb_stor_scan_dwork"; the hub_event worker is stuck in the same wait
> but sleeps interruptibly, which the hung-task detector ignores.
>
> Bound the three probe-time transfers with a 30 s timeout through a new
> usb_stor_bulk_transfer_buf_timeout() helper, so a dead device fails the
> probe cleanly and the existing error path unwinds via
> usb_stor_disconnect().
>
> Fixes: 445fc368c6bc ("usb-storage: ene_ub6250: fix race between scan work and probe")
> Reported-by: syzbot+30552b4cbe99d6d91306@xxxxxxxxxxxxxxxxxxxxxxxxx
> Closes: https://syzkaller.appspot.com/bug?extid=30552b4cbe99d6d91306
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Hongyu Xie <xiehongyu1@xxxxxxxxxx>
> ---
>
> Changes in v2 (formatting only, no functional change):
> - fix checkpatch --strict "alignment should match open parenthesis"
> complaints on the newly added continuation lines
> - rename the fDir parameter of ene_send_scsi_cmd[_timeout]() to fdir
> to silence the CamelCase check
Don't do coding style changes while trying to make a bugfix, as that is
mixing up too many different things.
Please make this a patch series, with the bugfix first, and then if you
want to fix up the coding style issues, that should be a follow-on
patch.
thanks,
greg k-h