forked fromtorvalds/linux
- Notifications
You must be signed in to change notification settings - Fork0
Commitaea850c
usbcore/driver: Fix specific driver selection
This commit resolves a bug in the selection/discovery of morespecific USB device drivers for devices that are currently bound togeneric USB device drivers.The bug is in the logic that determines whether a device currentlybound to a generic USB device driver should be re-probed by amore specific USB device driver or not. The code in__usb_bus_reprobe_drivers() used to have the following lines: if (usb_device_match_id(udev, new_udriver->id_table) == NULL && (!new_udriver->match || new_udriver->match(udev) != 0)) return 0; ret = device_reprobe(dev);As the reader will notice, the code checks whether the USB device inconsideration matches the identifier table (id_table) of a specificUSB device_driver (new_udriver), followed by a similar check, but thistime with the USB device driver's match function. However, the matchfunction's return value is not checked correctly. When match() returnszero, it means that the specific USB device driver is *not* applicableto the USB device in question, but the code then goes on to reprobe thedevice with the new USB device driver under consideration. All this tosay, the logic is inverted.This bug was found by code inspection and instrumentation whileinvestigating the root cause of the issue reported by Andrey Konovalov,where usbip took over syzkaller's virtual USB devices in an undesiredmanner. The report is linked below.Fixes:d5643d2 ("USB: Fix device driver race")Cc: <stable@vger.kernel.org> # 5.8Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>Cc: Alan Stern <stern@rowland.harvard.edu>Cc: Bastien Nocera <hadess@hadess.net>Cc: Shuah Khan <shuah@kernel.org>Cc: Valentina Manea <valentina.manea.m@gmail.com>Cc: <syzkaller@googlegroups.com>Tested-by: Andrey Konovalov <andreyknvl@google.com>Signed-off-by: M. Vefa Bicakci <m.v.b@runbox.com>Link:https://lore.kernel.org/r/20200922110703.720960-3-m.v.b@runbox.comSigned-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>1 parentd640761 commitaea850c
1 file changed
+1
-1
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
924 | 924 | | |
925 | 925 | | |
926 | 926 | | |
927 | | - | |
| 927 | + | |
928 | 928 | | |
929 | 929 | | |
930 | 930 | | |
| |||
0 commit comments
Comments
(0)