Received: by 2002:ad5:474a:0:0:0:0:0 with SMTP id i10csp1935084imu; Sun, 18 Nov 2018 12:00:38 -0800 (PST) X-Google-Smtp-Source: AJdET5dLGL+/nSpZrWN3NNnEJudPQIOmlqjxEaGPcptUsR95ErNaVHg5wwfhrdDIarqFHFpu1+ro X-Received: by 2002:a63:990a:: with SMTP id d10mr17622752pge.279.1542571238026; Sun, 18 Nov 2018 12:00:38 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1542571237; cv=none; d=google.com; s=arc-20160816; b=EbTDMuVqEGPPixHRZ9X2VOg6Q/sWHNHPmGBhEN1sTLto4oaKHIvpyUsYoMZHd56cWF 3+ntgaeMlyzrW/MPo2QMWviGF26+Vnymz3fdRvL7YDb0Rt0mcjqTe1MWEsKSu/Zzitpk wD79hu+T19SesxcB3bNhMivrcyblB6dlIFL8vSHaYOTirziNKeRnK0hIbMKlSlRWrHNu 5Y7EXn66HibEcSFgN4+bI1P2GrudZAY0Q2vC0ljs3mvNbUuimyUBh7/yINjoJP1Sm9Nb B+xR83GrdjJmpnqPc3QlO/aGj990K1xeIz4vPEeJNhnZvaxFkA9JQyoGrdsR55mdWXMo wufQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:references:in-reply-to:message-id:date :subject:cc:to:from; bh=ZAYRDom0WiY5ZfcFYbXlxcqtExAkZamW6vEG6so/MZY=; b=GGIIFEmwHzPc2h4HK0hJBo1bTwZsfYcgjpJeW9ZB2mzkR/6qZsHodHS2x1j4zTHL1n uFLujyDMMq7bbEJbAO87FbYfUc8rL6I8z1W4/12QHTAOD+3swSPyJCWH3UVnp3/aNf3N +3zKAzRo7MJx+lpIud1biI0vnktK1Lmv2tSV1n2ODR4MZ8Cg74KXG+YSb4wjkhtmxiw0 iHpVJuWIcZrPrGocxgYt2CzTjAyqbSC+lKcJ3+LOg3UfSnI3JXlmb3xtbvoTrVoEXQYI dBt/m2QCEBXCMlzT+epvUJacBNdu6GeSl9xFLiIUMd0ydADSW+RhnAWpUm/V5w9swR86 20RA== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=iki.fi Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id y6-v6si39742249pfy.29.2018.11.18.12.00.20; Sun, 18 Nov 2018 12:00:37 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=iki.fi Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727385AbeKSGUv (ORCPT + 99 others); Mon, 19 Nov 2018 01:20:51 -0500 Received: from emh01.mail.saunalahti.fi ([62.142.5.107]:45764 "EHLO emh01.mail.saunalahti.fi" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1725955AbeKSGUu (ORCPT ); Mon, 19 Nov 2018 01:20:50 -0500 Received: from localhost.localdomain (85-76-71-135-nat.elisa-mobile.fi [85.76.71.135]) by emh01.mail.saunalahti.fi (Postfix) with ESMTP id C8AF920032; Sun, 18 Nov 2018 21:59:36 +0200 (EET) From: Aaro Koskinen To: Felipe Balbi , linux-usb@vger.kernel.org Cc: linux-kernel@vger.kernel.org, linux-omap@vger.kernel.org, Tony Lindgren , Aaro Koskinen Subject: [PATCH 2/4] USB: omap_udc: fix crashes on probe error and module removal Date: Sun, 18 Nov 2018 21:59:10 +0200 Message-Id: <20181118195912.14026-2-aaro.koskinen@iki.fi> X-Mailer: git-send-email 2.17.0 In-Reply-To: <20181118195912.14026-1-aaro.koskinen@iki.fi> References: <20181118195912.14026-1-aaro.koskinen@iki.fi> Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org We currently crash if usb_add_gadget_udc_release() fails, since the udc->done is not initialized until in the remove function. Furthermore, on module removal the udc data is accessed although the release function is already triggered by usb_del_gadget_udc() early in the function. Fix by releasing the data manually. The patch fixes omap_udc module probe with a failing gadged, and also allows the removal of omap_udc. Tested by running "modprobe omap_udc; modprobe -r omap_udc" in a loop. Signed-off-by: Aaro Koskinen --- drivers/usb/gadget/udc/omap_udc.c | 15 ++++----------- 1 file changed, 4 insertions(+), 11 deletions(-) diff --git a/drivers/usb/gadget/udc/omap_udc.c b/drivers/usb/gadget/udc/omap_udc.c index 1c77218c82af..d98782ec254d 100644 --- a/drivers/usb/gadget/udc/omap_udc.c +++ b/drivers/usb/gadget/udc/omap_udc.c @@ -2591,9 +2591,8 @@ omap_ep_setup(char *name, u8 addr, u8 type, return buf; } -static void omap_udc_release(struct device *dev) +static void omap_udc_release(void) { - complete(udc->done); kfree(udc); udc = NULL; } @@ -2900,16 +2899,14 @@ static int omap_udc_probe(struct platform_device *pdev) } create_proc_file(); - status = usb_add_gadget_udc_release(&pdev->dev, &udc->gadget, - omap_udc_release); + status = usb_add_gadget_udc(&pdev->dev, &udc->gadget); if (!status) return 0; remove_proc_file(); cleanup1: - kfree(udc); - udc = NULL; + omap_udc_release(); cleanup0: if (!IS_ERR_OR_NULL(xceiv)) @@ -2930,8 +2927,6 @@ static int omap_udc_probe(struct platform_device *pdev) static int omap_udc_remove(struct platform_device *pdev) { - DECLARE_COMPLETION_ONSTACK(done); - if (!udc) return -ENODEV; @@ -2939,8 +2934,6 @@ static int omap_udc_remove(struct platform_device *pdev) if (udc->driver) return -EBUSY; - udc->done = &done; - pullup_disable(udc); if (!IS_ERR_OR_NULL(udc->transceiver)) { usb_put_phy(udc->transceiver); @@ -2960,7 +2953,7 @@ static int omap_udc_remove(struct platform_device *pdev) release_mem_region(pdev->resource[0].start, pdev->resource[0].end - pdev->resource[0].start + 1); - wait_for_completion(&done); + omap_udc_release(); return 0; } -- 2.17.0