From nobody Thu Sep 24 18:39:53 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1F87A51EE1F; Mon, 21 Sep 2026 22:26:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790029579; cv=none; b=MWj5iXoDst1k3960dAizsnLtTSFaOZ8AuyBW+ABhbtTTJOEYFJ2ZfEO9dOcZuRLXRxbZIfKkoH8tjTQ57U+WQRnapUvxoZV4LDB7el8C6mmE7Uk6ZEr1lvYYmu3aZzeC/Fuj31lDiAzzKC65VNNr09cQaDwxKZbwAC9hDY5qzSg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790029579; c=relaxed/simple; bh=tQErgxz8d4ieMH0CWIG8w2M/H+3MIf9cEE5FuXtAOus=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=BKuYLDTkB8SqkenPLnYTCxKBHHJxZs378DxQQ9wRYwJqGmOmjjX9zDyF8F5e2pENV/MZjzbmlrlnTxGt16XwBt/KKUX+nFNAy51zMhKmz7LBnBbEA6L+ukvk4AACqBX3XliHy5uXuMpC4shoNa9XDs23RyUCqrn5Y8wA3x67WFs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=bi5Clfh/; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="bi5Clfh/" Received: by smtp.kernel.org (Postfix) with ESMTPSA id EC89E1F00898; Mon, 21 Sep 2026 22:26:15 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1790029577; bh=3lI3HQC9chBAMmb+T3CdTqkPoTDWc/bRBxcstdw4V3o=; h=From:Date:Subject:References:In-Reply-To:To:Cc; b=bi5Clfh/jeLP0pgh83Ip9yAKTTg3KCzBq1fdQ9q+teHotlnzev1Jq31LENfq55gfO OFG+AxgknIxPPX2Iwdzo2fdqPSIS9rXK14srjT1XGdB/p3/dsCJm9Lh4taYY+sb4Wq CPAv6+gz5RhqR6YRPQDlFvvALvt3ydt6GyT/Kzz/Vs4djhhMomM3zj0UD9YQWEROZx hJsV/VGBvFp3imZlsn8kg4y1Y+HnOQslHtLM1Tx1bYwXneBOif/q07+Lf4OiWoSznQ qQxLeHCPgLs6jK5EFLuXbP7eyu4mw8mZRwUHf3jw9tD9UjaNuiBR7ZYODVAAC9KfCO +jl2UdDtD/k2Q== From: Michael Grzeschik Date: Tue, 22 Sep 2026 00:25:54 +0200 Subject: [PATCH 1/7] net/9p/usbg: also disable endpoints on p9_usbg_close Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260922-usb9pfsfixes-v1-1-9d8dcc52904c@kernel.org> References: <20260922-usb9pfsfixes-v1-0-9d8dcc52904c@kernel.org> In-Reply-To: <20260922-usb9pfsfixes-v1-0-9d8dcc52904c@kernel.org> To: Eric Van Hensbergen , Latchesar Ionkov , Dominique Martinet , Christian Schoenebeck , Greg Kroah-Hartman Cc: v9fs@lists.linux.dev, linux-kernel@vger.kernel.org, Michael Grzeschik , stable@vger.kernel.org X-Mailer: b4 0.16.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=869; i=mgr@kernel.org; h=from:subject:message-id; bh=tQErgxz8d4ieMH0CWIG8w2M/H+3MIf9cEE5FuXtAOus=; b=owEBbQKS/ZANAwAKAb9pWET5cfSrAcsmYgBqsa8DA1XjZ/WrRUv675v5v0nqBM0/eo2G1H9y+ lxWJEOV/dKJAjMEAAEKAB0WIQQV2+2Fpbqd6fvv0Gi/aVhE+XH0qwUCarGvAwAKCRC/aVhE+XH0 q+7AEACrMtVG7EHxL1V+ovxK2LMv0j3X6s5vWL2O9V8Alg3OMzgJSRM9T2u4GViHkO1aesvsRAN ZHV1TCqcSvYr1hPlkQME2UPTyAtjGG/3JQCnpUfgq2DKOHKi3xvFSMuXDJBCH2vdLqEf4XWbQKr qw8aU6wCifX7C4IHXHtnwqKY0Uf7YgFgAwQShY4C3XY5gqaKoFAnL5ixoHeruxZb0hJAm7PAEE4 ivyawEQQgu709taKoIOk6ScNzTGuNV3kyvmK+03cDswUENdE4R/lkCgXEVHfM+23s+LUUfESiK4 Do7lcspbhZXsLof1pE/FqJphRhmqwG0oia8EVrgUNJTDcUnZcRDIo7HXkc0NFldcVmNQ1MX+KKI QOWEg/oaVwPKwZST7wHgMfrrnRbuMk3I5gICHI4CFjbNq/h4sgqD89NoL/Q5JEHuh7j0+OsSyjf hYZjqCm7xth4HWGDpUX5laaQaWz3urYge/W7+TSolzdEKKo5kfJLgOhDMbHTkt/XyWlwgBLtIU6 G7QB/5ww3FFPv6xsR5J3L9NVIeICS5qrY9E0Bu6mo3QyU0cfZ3MeLexJalSEc9br8ybNIwnsQvK p/SPLb0JrtvlckzO1wX4aaqZfU96qxC+kaGk7jH3CMQPmmXgmH5e7y59Co2mKr7pa4DBSRHZrca pBf0m5kykdcbdEQ== X-Developer-Key: i=mgr@kernel.org; a=openpgp; fpr=957BC452CE953D7EA60CF4FC0BE9E3157A1E2C64 The close function has to fully reverse the state change of 9p_create (mount) and the potential call of set_alt(1). This includes to ensure that the usage of the endpoints is not active any more. Fixes: a3be076dc174 ("net/9p/usbg: Add new usb gadget function transport") Cc: stable@vger.kernel.org Signed-off-by: Michael Grzeschik --- net/9p/trans_usbg.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/net/9p/trans_usbg.c b/net/9p/trans_usbg.c index 9fd7801d56ab..32e18077309a 100644 --- a/net/9p/trans_usbg.c +++ b/net/9p/trans_usbg.c @@ -473,6 +473,8 @@ static void p9_usbg_close(struct p9_client *client) mutex_lock(&usb9pfs_lock); dev->inuse =3D false; mutex_unlock(&usb9pfs_lock); + + disable_usb9pfs(usb9pfs); } =20 static int p9_usbg_request(struct p9_client *client, struct p9_req_t *p9_r= eq) --=20 2.53.0 From nobody Thu Sep 24 18:39:53 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 834D25208BF; Mon, 21 Sep 2026 22:26:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790029582; cv=none; b=kxtwcTanvPNatY8q9lyXG32DMFrZ77U8E32ojWVtPSzAxuh4x9ijbKfItEMHVCLVCuwul2vC2QdDuG/4dwVL+ZrbzdM9P5FK4NSJoRpMmFo1DRJB82wImq3jDLYS5va24KJgdHyv5VpTo1xc4DO0BUkg7jk5XoB4dyw8xy6Jd/0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790029582; c=relaxed/simple; bh=GcMnaXTTftwt41AhpHqvdPr9YoCU8O93u2dGIJB9RiU=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=u8asYYU9CBFhW+S3nGFc0bvc094oincv1aMHtMMyVrIy9K48lZJ99euRlKusMnHlt24quir7ZdAWXxTsu58RI4CBMsFl/07vJW0PdYqfx/ns9Pzeg2kuqOLN+A/kBOq3z/pV5oCjg8wzttfPmApGkROagcGtpmLkiozl6hgTYrs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=TyiO0Y1v; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="TyiO0Y1v" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 33CF41F000FF; Mon, 21 Sep 2026 22:26:18 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1790029580; bh=zph6y9NJaryVoOTe29OOcRQJCkR//nh1huNAKE/qpIw=; h=From:Date:Subject:References:In-Reply-To:To:Cc; b=TyiO0Y1vax0l9de7yRPOteF5/NXDyQdNq96LIBmd47S+3RyQL7Pi5vnCDWRLSnzAi 6WEZBjivu61z/CqReB3gSS312o7nsUMFOnyPO3q3mAerGflaLS81JKU9chV7ZgSd8r C+6EwpLjGwXEGS0Bg/yWBsGRIlX3sCIpJTctYdFEwET3qagZo5H6mMrQQbKgsQbE5c 5kh0VNMbA+h0qjrOIIrlepqKM/zGHBso4qv6OkURON69drUPkj1jlT+3Y9+qhLIDJw L+/RumqLa2mdQB9eYbzGl64mHcUEJOZq7jUrS0egCYsMCbwePMZKG93KFnnhbLi8AP 5AIdKeQ3eMriQ== From: Michael Grzeschik Date: Tue, 22 Sep 2026 00:25:55 +0200 Subject: [PATCH 2/7] net/9p/usbg: set client to Disconnected on usb9pfs_disable Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260922-usb9pfsfixes-v1-2-9d8dcc52904c@kernel.org> References: <20260922-usb9pfsfixes-v1-0-9d8dcc52904c@kernel.org> In-Reply-To: <20260922-usb9pfsfixes-v1-0-9d8dcc52904c@kernel.org> To: Eric Van Hensbergen , Latchesar Ionkov , Dominique Martinet , Christian Schoenebeck , Greg Kroah-Hartman Cc: v9fs@lists.linux.dev, linux-kernel@vger.kernel.org, Michael Grzeschik , stable@vger.kernel.org X-Mailer: b4 0.16.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=976; i=mgr@kernel.org; h=from:subject:message-id; bh=GcMnaXTTftwt41AhpHqvdPr9YoCU8O93u2dGIJB9RiU=; b=owEBbQKS/ZANAwAKAb9pWET5cfSrAcsmYgBqsa8E6bj/poLkRwIWHFxsjxAMfXWsvKvN9iPxZ yqXSNr0Z8aJAjMEAAEKAB0WIQQV2+2Fpbqd6fvv0Gi/aVhE+XH0qwUCarGvBAAKCRC/aVhE+XH0 q+p3D/9W5fDy0OUhj+QzJL/xq8Fz1ehzvCHrSc55sxunj6yI1ING65LLmFQCuDmbK88LAbEzy7x h+UyQyulJw3S3BOqz1G5oIHw3sxHEg5mivYTtv7zGs0lzfLQb7tHyXW0U23ie05EL8D2qZbOrGj 0w22AN3qUEmsfhPJIJUoUWhlJDpeYCEDYKVmTO0dvRAym5lD56bEn7Bz9RRAJ2z+jmS5SS7BXXY 6JFPiF+s7v/F3nCHFeLP48Ud5dML7STLUqWE5b+b+JuCCwFyGEKvFmrfVAm5qAZ+QIV7//VRcMS 2vTS5XbIoASBULI0SKZicUJn0mVy8W5Nv9vUy2fVJyamC8PkMokEPHOVKbnpHZ9jrjKE6Kdsrge somNmvlFe8KyIL2uXVru2DVBbh/sbUd2lBdOMkZDpY4d1rXDviasHHHsqtgRiBHGE22BUGUFQ8U YTCzaHvXDL/viHfBfCIxnTcz3uQYlJiYYdQEZALELs5VcN2QbS4OXqppVvXXERLMTkepYoOWfXY eyXVgXaFCkGKViHrJ9faUkX39pmnhdsmOX6h/Pss5lxLRmbeY+OKsYRtnNMIf56Iy1yI7GRUhec C7JBfEKTfy3B686QYBZM3cQmF98kraxMsrmheP8flZxmXrtP78MCZ5SdbbZAy9v8eWejwOhobvw 1hk9LSdCZRHy2MQ== X-Developer-Key: i=mgr@kernel.org; a=openpgp; fpr=957BC452CE953D7EA60CF4FC0BE9E3157A1E2C64 This patch is setting the client status to Disconnected, when the client is still in use. Otherwiese a disconnected usb cable would run any use of the mount to faults. Fixes: a3be076dc174 ("net/9p/usbg: Add new usb gadget function transport") Cc: stable@vger.kernel.org Signed-off-by: Michael Grzeschik --- net/9p/trans_usbg.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/net/9p/trans_usbg.c b/net/9p/trans_usbg.c index 32e18077309a..a3182d3db175 100644 --- a/net/9p/trans_usbg.c +++ b/net/9p/trans_usbg.c @@ -757,7 +757,12 @@ static int usb9pfs_set_alt(struct usb_function *f, static void usb9pfs_disable(struct usb_function *f) { struct f_usb9pfs *usb9pfs =3D func_to_usb9pfs(f); + unsigned long flags; =20 + spin_lock_irqsave(&usb9pfs->lock, flags); + if (usb9pfs->client) + usb9pfs->client->status =3D Disconnected; + spin_unlock_irqrestore(&usb9pfs->lock, flags); usb9pfs_clear_tx(usb9pfs); } =20 --=20 2.53.0 From nobody Thu Sep 24 18:39:53 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 97334521885; Mon, 21 Sep 2026 22:26:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790029583; cv=none; b=pQpuoSMjKkp+zZ0Vrmy0jDG58kue9ZizP1t9bxCS98UgyWgsk21yT7OoJLjQRkpQjRDga75DfqzH6ywP70W0S4A1AzTYcwqCB9Mp+SF6v8BtSwiRJKNddOBXCwdFEgyRPRcXBoYkVSrsi0SCWbOZI4uRHVfCAx7s3QIUvrMqNX0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790029583; c=relaxed/simple; bh=kGn4fo3O/U2M+GSCkXWn/C6CCJQkldv4VF8Y7HOGcUU=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=XxSi+56B/4SvDNVTnCKWoWiSlKMvyUiDUR/C5h3A1pmKDVIFW2WAHxcdgdqdIj1Qo8DRAGzijxXyIYVpAvJBPz72WkzXUAzUg0BZC+8hztAtNjSi0k1TDx8B88HxdHhLkEsCgvZ5jjhwljjInI6Ae9GUzJRheMwJxEzY83+38jA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=loIpKnro; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="loIpKnro" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 6FA291F00893; Mon, 21 Sep 2026 22:26:20 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1790029582; bh=ag8KW8kXzCaKg2bzp2xZ1iTg5aJBZQBvB8ODRASf4hQ=; h=From:Date:Subject:References:In-Reply-To:To:Cc; b=loIpKnroi6LGO/+zQRxc2/UxmQl6s6zUIZC8EJt8bMfWPQ3zyykLCLPy3+InMmtoY 6qMNjjArX7IqQDCYF9OARldB7XhDQ/sr+1O9sBv2jPEOfZ3F1hPvgcuTfPUAQUFjvM yluNgxnLXR5eY4ndgjyDjx0eKN1+wfZKD2NxP1/cq4VefuOyUUBC6MBG/vT2occDAo F5CBuY23R3VOb7fdjVh/94nzEECuwhR+rWv3iZ/UxzeChKHk594mThGohRsGJS0rwB j8fKRj6BLmFJnFSW6U/ksT3Pj0oWcY5vQm65k+scS/+aIUxAnUUqji+Zv/4m5qoUI+ M0CpNhyS+T/yw== From: Michael Grzeschik Date: Tue, 22 Sep 2026 00:25:56 +0200 Subject: [PATCH 3/7] net/9p/usbg: always reset completion when disconnecting Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260922-usb9pfsfixes-v1-3-9d8dcc52904c@kernel.org> References: <20260922-usb9pfsfixes-v1-0-9d8dcc52904c@kernel.org> In-Reply-To: <20260922-usb9pfsfixes-v1-0-9d8dcc52904c@kernel.org> To: Eric Van Hensbergen , Latchesar Ionkov , Dominique Martinet , Christian Schoenebeck , Greg Kroah-Hartman Cc: v9fs@lists.linux.dev, linux-kernel@vger.kernel.org, Michael Grzeschik , stable@vger.kernel.org X-Mailer: b4 0.16.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=1228; i=mgr@kernel.org; h=from:subject:message-id; bh=kGn4fo3O/U2M+GSCkXWn/C6CCJQkldv4VF8Y7HOGcUU=; b=owEBbQKS/ZANAwAKAb9pWET5cfSrAcsmYgBqsa8EIzSxwVioGL/FhkWgeGhqpcystajcKgAl7 giDwh5/IRSJAjMEAAEKAB0WIQQV2+2Fpbqd6fvv0Gi/aVhE+XH0qwUCarGvBAAKCRC/aVhE+XH0 q8wlD/9aKWpnITmVellIbfp+bB60vGpaMA4TUIqqKJru6NImwH9i1Nsoyym0gykokh3tq/N/Mae Am/QCGHQVDBwAVhyNjMCkW0BwSl+4Ar5HPxSKEGOc2yh/6lAKqBMpT38lujK/NXmvk9CV+8/okl Q7oZhaUSQv8BvLiQlYQsd1lTgKSzJYYuWBLZgJS5Ph9UBkWAemVAtOF4c9LUAkgQ66B8nXjQTRo GJ0d1WcXn3t6FVp3iev0T7X7Um4/4Rpn3NoNo9xXv0d7luktYe6+8MUMWQ/PZtH16OWIz5F4vmB m8YddWb0rsJwJdhqUrwnB9/u5Lb9yEraInI5YtOSOzequc6BViviYb6XY18LG4U68vYLP6va/jB 7VCRHt9CJHw00OrIMdnoLUlRMwxaX2nMb2+eu519Gc2T2OohAPAmnaXhPp+16ouNNgr7mtWzDNQ zvPxZWfO6e/+k3z1DX0lAqg2/hXKFAY/po9xMWsgmcLqmv5fdwX1eULc5pPpevzCnB5+KpxCMCy heeG3AU/lGSchHnudUS7TRdDEOJq/732S4WJkP5VGAD9A4dsdcJ0/sQaDbTzaHUf/IAXR/jmBsY 7pC1Wwiusssk/TvuZqXQ+az+CrCK33/77HKQ6doXgmMZTNFDtkQmBS3LOPvYz91Im+T+TwyHZsy uDMAlmRwJ7dTDYg== X-Developer-Key: i=mgr@kernel.org; a=openpgp; fpr=957BC452CE953D7EA60CF4FC0BE9E3157A1E2C64 When some tx or rx transfers were pending while closing the connection, the completion handler could catch one pending completion call. To ensure a normal start when mounting again, we have to reset the completion and flush any pending completions. Fixes: a3be076dc174 ("net/9p/usbg: Add new usb gadget function transport") Cc: stable@vger.kernel.org Signed-off-by: Michael Grzeschik --- net/9p/trans_usbg.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/net/9p/trans_usbg.c b/net/9p/trans_usbg.c index a3182d3db175..e3af8e1002d7 100644 --- a/net/9p/trans_usbg.c +++ b/net/9p/trans_usbg.c @@ -475,6 +475,7 @@ static void p9_usbg_close(struct p9_client *client) mutex_unlock(&usb9pfs_lock); =20 disable_usb9pfs(usb9pfs); + reinit_completion(&usb9pfs->send); } =20 static int p9_usbg_request(struct p9_client *client, struct p9_req_t *p9_r= eq) @@ -764,6 +765,7 @@ static void usb9pfs_disable(struct usb_function *f) usb9pfs->client->status =3D Disconnected; spin_unlock_irqrestore(&usb9pfs->lock, flags); usb9pfs_clear_tx(usb9pfs); + reinit_completion(&usb9pfs->send); } =20 static struct usb_function *usb9pfs_alloc(struct usb_function_instance *fi) --=20 2.53.0 From nobody Thu Sep 24 18:39:53 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 996F35221F7; Mon, 21 Sep 2026 22:26:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790029585; cv=none; b=DkiDx1lTPS7gKGjettt8HRTELWYCCWESucKnjqnm+48n6IgZglgtkJRRDyjmwvrTLhTjcmttcFTILB8BJ//GltPoEHQC+mqZ4vGktIDGGVV5OCIaCG/toiaboUQQ1PGfN06j4DKHzW/a4vsltzU0gvFmU3RcNvcWQigw082BKU8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790029585; c=relaxed/simple; bh=mcsQBqglQe5LgMXPMa8svJPHiK1gzWkDxAl4HIIOb1M=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=arsizn1ITMw54L0G05j/z9VVRzuy/pgnp7PlPR6MXjMrEd0zYoFtA8y1l6LxoHHtHAHNqhGXXq2pPA5WVaALIcYqGd1Dgcn8tFE1gKaEsTE3w9bAL8sIRhrzdF+Ukn9+loQX/tRW+HgOvOPDkX1CGxiYgcoxJVbt16KkPY/fl9k= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=kv/sdtK1; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="kv/sdtK1" Received: by smtp.kernel.org (Postfix) with ESMTPSA id AB8EA1F00899; Mon, 21 Sep 2026 22:26:22 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1790029584; bh=5+Fyuc49s+vjU+93EZfc3k6Jk0Or86f0Xu+uLTgkMxQ=; h=From:Date:Subject:References:In-Reply-To:To:Cc; b=kv/sdtK1xOZbVDkDxR65wWiThmAez49E5+3MayGZd+SKeTAgMvIVdSlGFziP4iabZ eX3Jlz+nzAm8iGjAO/sfXS9exVGxqt+QsGnx/qO1mHCUMaJXRxqvDqE65QoRIVDz6q GqITDQcLLDqtX90qmx/34CBMf3hDw4zUDOvkhfkypG+gERSx/Oi+1SUqS+75QErbQO h20GB34CR6Ay0hZMVGsfSbBmlhoVbbcKFz0PHwVXSPv5pmpvok6kM7XMT2P5bufx9T 7rL/OrGgXo0DZ0pTk7kFgN2M3INk+R8y8pSOrMfj97/mlOYxcIZ7dbGidAQC//h2kL DrWEvXVTK0OVQ== From: Michael Grzeschik Date: Tue, 22 Sep 2026 00:25:57 +0200 Subject: [PATCH 4/7] net/9p/usbg: call disable_usb9pfs() from usb9pfs_disable() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260922-usb9pfsfixes-v1-4-9d8dcc52904c@kernel.org> References: <20260922-usb9pfsfixes-v1-0-9d8dcc52904c@kernel.org> In-Reply-To: <20260922-usb9pfsfixes-v1-0-9d8dcc52904c@kernel.org> To: Eric Van Hensbergen , Latchesar Ionkov , Dominique Martinet , Christian Schoenebeck , Greg Kroah-Hartman Cc: v9fs@lists.linux.dev, linux-kernel@vger.kernel.org, Michael Grzeschik , stable@vger.kernel.org X-Mailer: b4 0.16.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=1896; i=mgr@kernel.org; h=from:subject:message-id; bh=mcsQBqglQe5LgMXPMa8svJPHiK1gzWkDxAl4HIIOb1M=; b=owEBbQKS/ZANAwAKAb9pWET5cfSrAcsmYgBqsa8E1skDKacbduM2XkWqJ0dDcTWUAdVlD7JTx /MFxPxykJ+JAjMEAAEKAB0WIQQV2+2Fpbqd6fvv0Gi/aVhE+XH0qwUCarGvBAAKCRC/aVhE+XH0 q2u4EACtNjIqfLQ3qTpKZax1FJSbF+Wrb6JndQ+Vzx535Kj0F82mh2lS7Xsgtpt6vrxmjjR6u/Y vnxS6GvPO2FwxQEbCXcG+OnPmqlMfHBW8Ap7NMDVp7XuhlinMBrWAbwOYRF45PsmOy6pUu4Se8Z vLJ5ZfLy8u1mmBcHr6oI3I/P8ylBKw/SXtNpgWFK9TSRSZvhg12FiBeEjC0BMc1TlGzXoiR5lUM jkXcMsWM+kY6WeJMVX0SchPbRmQC5SQDQXHBo0+saD4YQyzi6KOU+/UkoPU3YzbEwypmooTsDIg vbcmNm9DA6oKsQ6PAU0hBSa64usooHoHUvwHo2esNr7bzxBAIla8MD0JMT91+PxObAX+xTjzcAz 5FH25TvDmMayy6oRT6hV6Vew0pBMDgQMeECHuVSirFhZY9X7CaxYJzOS5GV3JYtNO84TV8ObMZJ rlUsOHv+cw4fssZCXnaVBUbp4ndk6KH4kCeW09s6p2p7YnV/hxzPX+X4sDMLa6yoD7OG7WgHeMZ ikYdCO+KoY3wDK1j85LJ3EWr5zezXCyiXFEeb7C6/ZkZTPY/SBYAJK573qvXv68xoymjjdxhdJe ilb3amJPd4HxkCF3LSVmHcS5QMwFq1k+Y64497+hPhCjizooltuqNcuUheF0h5gkhdY1EXO6JeE oCyV38Cdpl5+i4A== X-Developer-Key: i=mgr@kernel.org; a=openpgp; fpr=957BC452CE953D7EA60CF4FC0BE9E3157A1E2C64 usb9pfs_disable() is the usb_function ->disable callback, invoked by the composite gadget core whenever the host resets or unconfigures the gadget. The gadget function API requires this callback to disable its endpoints; every other in-tree function driver does so from its ->disable hook. usb9pfs_disable() never called disable_usb9pfs(), so the IN/OUT endpoints and their usb_request objects were left active and allocated across a host-driven disable. When the host later reconfigures the device, enable_usb9pfs() calls alloc_requests() again and unconditionally overwrites usb9pfs->in_req/out_req, permanently leaking the previous allocations, while the endpoints themselves are left enabled underneath the function's own idea of being disabled. Call disable_usb9pfs() before reinit_completion(&usb9pfs->send), mirroring the same sequence already used in p9_usbg_close(). Placing it before the reinit_completion() also ensures usb_ep_disable() has synchronously flushed any requests still queued in hardware before the completion is reset, closing the same race that motivated resetting the completion here in the first place. Fixes: a3be076dc174 ("net/9p/usbg: Add new usb gadget function transport") Assisted-by: Claude:claude-opus-4.8 Cc: stable@vger.kernel.org Signed-off-by: Michael Grzeschik --- net/9p/trans_usbg.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/net/9p/trans_usbg.c b/net/9p/trans_usbg.c index e3af8e1002d7..af113746d2fc 100644 --- a/net/9p/trans_usbg.c +++ b/net/9p/trans_usbg.c @@ -765,6 +765,10 @@ static void usb9pfs_disable(struct usb_function *f) usb9pfs->client->status =3D Disconnected; spin_unlock_irqrestore(&usb9pfs->lock, flags); usb9pfs_clear_tx(usb9pfs); + + if (usb9pfs->in_ep->enabled) + disable_usb9pfs(usb9pfs); + reinit_completion(&usb9pfs->send); } =20 --=20 2.53.0 From nobody Thu Sep 24 18:39:53 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3053351FCCD; Mon, 21 Sep 2026 22:26:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790029588; cv=none; b=TQVoFbhyr3v6VT+VAJhOjyb+PLJPpeXGcb1Pw9wOz4DJGCI1UpSXIgv7PTnoC89rNTXRyryTgZleXxen6Z/EW+3amykTmgPAmrRxum/gT8vTHjaXoXiqrqNwS+l2EnnEK19pFn7nwFKEdNuAQ00Xdok17Mqjkn0k/zdt+eg5bWM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790029588; c=relaxed/simple; bh=a9VaJ3QSuYnRcJfJa3Qiis5x7rXIMRzgITmGIITpyJw=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=iYKpIPyf0XBWn/SyV5EqyDGv6rCiTZogFYwSdnToFLMjNxodtk292bj/DxGcX3yuXvXyxVGk8vNbsEmLBYIqyrbws25VuodLAI1jqvKFjyHwyf0C6YOCdTc960FnyQLETzzOk9yD4mITk3+sl+SQ5qo7X07bgISl7z0siCgse7U= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=hGTrE5Pn; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="hGTrE5Pn" Received: by smtp.kernel.org (Postfix) with ESMTPSA id E818B1F000FF; Mon, 21 Sep 2026 22:26:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1790029586; bh=+muYbjwy3j2gZE7/fS8OhPeMUFv1qoJ562D9mwJs6co=; h=From:Date:Subject:References:In-Reply-To:To:Cc; b=hGTrE5Pn5B9decxeUJq9FtMhrpAL4u5DkmcQe1RC8tnWZmcbSNdQQN1CBgJSacHsR XKPENXDRUswiGWQzXN5IIT+2NLT60nOsz1+qzh5BsH9WrbzDiolL1zAK5UVd6sw4Ab JImWT8TvVbG6DB3A4Q36zqeznsBGIfX2xJu0WGA2PW5v5xywsuMU0c9W0GRffVbjFL 4HbbBYcKcHYZClljz07JCuZG+YikLFumOMLVnAzFuIE1uVKK0+SQMZBAH8ZHTJe2/X 7op6mLtN+udhbmK487OravmtuNPUUwMk6S9oTgBXbKP2rqpb2dnYmlSV0pG8i5GATp BGU+NAPr4hZGQ== From: Michael Grzeschik Date: Tue, 22 Sep 2026 00:25:58 +0200 Subject: [PATCH 5/7] net/9p/usbg: fix out_req buffer leak in disable_usb9pfs Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260922-usb9pfsfixes-v1-5-9d8dcc52904c@kernel.org> References: <20260922-usb9pfsfixes-v1-0-9d8dcc52904c@kernel.org> In-Reply-To: <20260922-usb9pfsfixes-v1-0-9d8dcc52904c@kernel.org> To: Eric Van Hensbergen , Latchesar Ionkov , Dominique Martinet , Christian Schoenebeck , Greg Kroah-Hartman Cc: v9fs@lists.linux.dev, linux-kernel@vger.kernel.org, Michael Grzeschik , stable@vger.kernel.org X-Mailer: b4 0.16.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=1129; i=mgr@kernel.org; h=from:subject:message-id; bh=a9VaJ3QSuYnRcJfJa3Qiis5x7rXIMRzgITmGIITpyJw=; b=owEBbQKS/ZANAwAKAb9pWET5cfSrAcsmYgBqsa8EL37t8jJpHsHtoku20l3IlgJAU77v944bp 7r+8Fa4+4OJAjMEAAEKAB0WIQQV2+2Fpbqd6fvv0Gi/aVhE+XH0qwUCarGvBAAKCRC/aVhE+XH0 qzKzD/91PJ3CDfE9AJHR/gOsNcixWdfPwSwjgUAUNt95ZqGpal5+lurqktsWvvxTjur28qj7bCz iGh0yTvQCvONHHLrYTUoxs8BhGQGejNMQY79stodoSJJEOrkP350kYFVpF1IXwOuSsoVDW6NwO6 BHNmh3eJaFefYDnf1FgmIrViNjaK+DqCyxc/kbg9sbxrzbZn9pJoL9OhBYnhRYN4SHoMTGs81qe 1r1Rgl6FcpgbhRb/YuHgCYy/au5ErWQ+bQzYP6npYieGIEUtqp24Rv4rV157SnjNwDiTHF1jOCC Jmy21fPdoVDe60PChVdEuMkitm7O9sCee13bAHhsR8h2Phcoc+JyfYo4D2djORcZFjXKBTii13N lGYubglkuYhHWOfdD6iQwX4wGfxj44lHU8kMKT8PO3kCv3ZsViEW3DKx/txv64IaSbmjFl8Q9NS /15F6Ni5jtloI7t5gG2xG1UBC7NSTLpedkiBopa5aKJIJVt9hNQ00oI1QkdF3GxjBwZbfmRgH2S u6VpkN2IRBX0XNjVKE0Udcg+RjPsFek8pMbBthJ8KAGpXHp6hSeGEqXuEPtsEF2iGR0T9Fpx1c2 Pt7OPuN0ORecSXHkdYg7U4c1pVvHq0KihDMS5RFskaWiE+FCL+twAxSBCkJzIltj5pbXqb+XEsH 4gVG28V+aTnTOSg== X-Developer-Key: i=mgr@kernel.org; a=openpgp; fpr=957BC452CE953D7EA60CF4FC0BE9E3157A1E2C64 usb9pfs->out_req is allocated with alloc_ep_req(), which also allocates the request's data buffer (req->buf). disable_usb9pfs() frees it with plain usb_ep_free_request(), which only frees the usb_request structure itself and leaks req->buf on every close. Use free_ep_req() instead, matching the allocator, as documented by its own comment ("Requests allocated via alloc_ep_req() *must* be freed by free_ep_req()"). Fixes: a3be076dc174 ("net/9p/usbg: Add new usb gadget function transport") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-4.8 Signed-off-by: Michael Grzeschik --- net/9p/trans_usbg.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/net/9p/trans_usbg.c b/net/9p/trans_usbg.c index af113746d2fc..9bcad638d827 100644 --- a/net/9p/trans_usbg.c +++ b/net/9p/trans_usbg.c @@ -284,7 +284,7 @@ static void disable_usb9pfs(struct f_usb9pfs *usb9pfs) } =20 if (usb9pfs->out_req) { - usb_ep_free_request(usb9pfs->out_ep, usb9pfs->out_req); + free_ep_req(usb9pfs->out_ep, usb9pfs->out_req); usb9pfs->out_req =3D NULL; } =20 --=20 2.53.0 From nobody Thu Sep 24 18:39:53 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6B4763C871D; Mon, 21 Sep 2026 22:26:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790029590; cv=none; b=FNKG31Vtcast4DVuFiEUFerLamFJClK/+0IPtWAmidq+UNBMdIcjhIJnYIZiUpxyvoJfC/JE24zideap2O2uNEaKYViYCo1rZDalXZQaKaob0BsS9INO7W1iab+WtHkpbef18ioLcbzS+3aLdp4vzHcf8qL8fIui9Br6xnxfldQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790029590; c=relaxed/simple; bh=OKulNGQNsdM6XuPCN4GDKW/MJrI43JdXh3oXwy/0qlg=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=D15UomghfIPhL4bFFbV5msVjra9UVYqWHgy/60hsdArcleAgVhH9mBWchoGPOeOTgugqMsKsu98kSmIc7A/YfUwa441vK6mKllVsRUKTd+bJvCJG1AcCmlbuP08BPz3dfCIddVwfzBZ1LTA26jPUlD1Jz10RlsxMN6weY4WDilQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=S8p0fGNl; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="S8p0fGNl" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 2F6DF1F00893; Mon, 21 Sep 2026 22:26:27 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1790029589; bh=UI47TIVtLzbGIeud91lzb20fyAckColjg1IGadw2GWg=; h=From:Date:Subject:References:In-Reply-To:To:Cc; b=S8p0fGNllgPGkr/lH4wI5/4w8B/D3Gu2IvWSW97Ox5sfTEedVD5ALQ3R+IP6ecsF7 BvWzU5yCrNbxH6uA4rIr6JQ6OPVfL8aKwCGfaFX6+33bAftmeoIaa+d8m4zMRYH7/U wNS59JKK4jVZoAqSVI1Bm0Y5Ay054sYm0q33YkLCd8ZxLAaM9uNtQUoTvf4yObDQzo ypKaNMCFRtBnzVJCsYebQwBLqe1xIlnomVEHx5FX+0ulOPbJtSEihPuNVQtmVY6t48 DWqbC8AmpXarLUf7zUOHHH60KKMYGiqOCdMifEXviXxDqgrl0yTBzAyg/OzSWIL9nH IuK4h7crk4FdA== From: Michael Grzeschik Date: Tue, 22 Sep 2026 00:25:59 +0200 Subject: [PATCH 6/7] net/9p/usbg: remove bogus context initialization in alloc_requests Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260922-usb9pfsfixes-v1-6-9d8dcc52904c@kernel.org> References: <20260922-usb9pfsfixes-v1-0-9d8dcc52904c@kernel.org> In-Reply-To: <20260922-usb9pfsfixes-v1-0-9d8dcc52904c@kernel.org> To: Eric Van Hensbergen , Latchesar Ionkov , Dominique Martinet , Christian Schoenebeck , Greg Kroah-Hartman Cc: v9fs@lists.linux.dev, linux-kernel@vger.kernel.org, Michael Grzeschik , stable@vger.kernel.org X-Mailer: b4 0.16.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2355; i=mgr@kernel.org; h=from:subject:message-id; bh=OKulNGQNsdM6XuPCN4GDKW/MJrI43JdXh3oXwy/0qlg=; b=owEBbQKS/ZANAwAKAb9pWET5cfSrAcsmYgBqsa8EQBCQFOf8wPlyWWuIaje4iGl5+s/R9W6zk j7QyI5ytM2JAjMEAAEKAB0WIQQV2+2Fpbqd6fvv0Gi/aVhE+XH0qwUCarGvBAAKCRC/aVhE+XH0 q66gD/9ynAweytCdzGfhMvdscDChL2YS8Wq0B8rt241+8wXkTYv0pnvMLlsNNtfNSDq0XL/1A9K YC3NKQfCYK09U/DPAnuwZ3HNTqvSkWAKiWPvE/jHoTpx/R+yw2Kn0veGFZq+dYY/OjKERTvQW5u TN1lJPo3Glra1p9lMFijE/475zM1NRzIeBNqLWL2WXmPmLS5T23j9bUoB23BbJHuB0GNOa+Nq+j DK2ssv9CAQ2BaoT6kuSQb61LkS4EzkTJ2q+VtqKTR3MYyTfgDQ5948rW9Sdc4CPFEo2dRShHrlv hEokLbkBkkNLD68q8r3unF71jee2L9K1kt9Smi7NmAQ+LVZdafdcsP6fKPD0O0ML0SBR1UHz0C5 iBe1P0utqfTxxu+NK1ex/JPZvdMA3+i2wV6WXKUfUZq2eXvO/NXHnIC5Kn21mhs2wt/qIq/tAK7 zIfOTjArzTSWfYwgdgtskURmIuKfpmYQRRrQYhzKC/9bAuDLQL+p88U/vk1mXZsS2vE04aRevx+ Cva5kfdsTKKKuMVxD2Rjg7BtMxDr0aGdRD61U6GldJj3jgk0BTft5PJsvWdkaDqcH+egN0Sqpti KI9GYJ0gptScT1EcFwSdRmPM9CzICgtV95H73SqNlvFJQ1LB3N7UglJg0uA7ohAcUWIMW/1tcbC nuLFiztIiej0O8A== X-Developer-Key: i=mgr@kernel.org; a=openpgp; fpr=957BC452CE953D7EA60CF4FC0BE9E3157A1E2C64 alloc_requests() initializes usb9pfs->in_req->context to point at the struct f_usb9pfs instance itself. usb9pfs_queue_tx() later overwrites this with the real struct p9_req_t pointer before every transmit, and usb9pfs_tx_complete() clears it back to NULL after each completion, so in_req->context only ever holds a valid p9_req_t once a request has actually been queued. usb9pfs_clear_tx(), however, can run at any time (mount close, gadget disable) independent of whether a request was ever queued. If it runs before the first usb9pfs_transmit(), it reads the leftover sentinel value, type-confuses the struct f_usb9pfs pointer as a struct p9_req_t, and both writes through it (req->t_err =3D -ECONNRESET) and hands it to p9_client_cb(), which manipulates req->wq and req->refcount at bogus offsets inside f_usb9pfs. This reliably corrupts memory or panics whenever the transport is torn down before any 9p request has been transmitted, e.g. mounting and immediately unmounting, or a cable disconnect racing the very first request. usb9pfs->out_req->context is set the same way but is never read by this transport (usb9pfs_rx_complete() identifies the instance via ep->driver_data instead), so it serves no purpose either. Both endpoints' ->driver_data are already set to usb9pfs in enable_endpoint(), which is what the completion handlers actually use to recover the f_usb9pfs instance. Just drop the leftover ->context assignments; usb_ep_alloc_request()/alloc_ep_req() already return zeroed requests, so in_req->context correctly starts out NULL. Fixes: a3be076dc174 ("net/9p/usbg: Add new usb gadget function transport") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-4.8 Signed-off-by: Michael Grzeschik --- net/9p/trans_usbg.c | 4 ---- 1 file changed, 4 deletions(-) diff --git a/net/9p/trans_usbg.c b/net/9p/trans_usbg.c index 9bcad638d827..544690a5c717 100644 --- a/net/9p/trans_usbg.c +++ b/net/9p/trans_usbg.c @@ -314,10 +314,6 @@ static int alloc_requests(struct usb_composite_dev *cd= ev, usb9pfs->in_req->complete =3D usb9pfs_tx_complete; usb9pfs->out_req->complete =3D usb9pfs_rx_complete; =20 - /* length will be set in complete routine */ - usb9pfs->in_req->context =3D usb9pfs; - usb9pfs->out_req->context =3D usb9pfs; - return 0; =20 fail_in: --=20 2.53.0 From nobody Thu Sep 24 18:39:53 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B4F5D522EF4; Mon, 21 Sep 2026 22:26:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790029593; cv=none; b=H9Wli2cbj1ioBHhYnNopNx4lzneR9lrEm2DMpamEwdn+zzREURVMsGHjwSoEWDW6A4TKi9H2vVVSmuunGVXy/nQDBqfHcSSRbrmKbZiHsb2zgr/4bOGC9oJR0txiSycg4Fh6h/ZstlRY/nd53HhqWAg3VpsFTfeU/PPjWGqWbN0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790029593; c=relaxed/simple; bh=g1hpG9X//J1B6B1nTr4FN0ADnVa+8yixPSkWZ3UiIwo=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=E1UhcC8dhWkNSOS1tgTSrZTntnmEeuRymkivko5o8y8ausauVyuiUzayrDpkHSm/z8d6mRHf9+M1bEy9fll1uLeEI2lO2Xl8SFVJalHqcehUAPA2hsMS8l1yAMJ9Tjp4LOODJ8LcT/WVYTK1O81kMnn77u6FTGrKJANBI9+hk4o= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=RLo/+Yff; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="RLo/+Yff" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 6C0081F000FF; Mon, 21 Sep 2026 22:26:29 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1790029591; bh=UlfYxFsZ+OYZEit5B/5bYhaHCFI3AdBcSjKvlFEhjOk=; h=From:Date:Subject:References:In-Reply-To:To:Cc; b=RLo/+Yff2I75BNQhmJGclMQ+ZHsjgQLL8lfMjNWgNveEVWlUbQ3/fBP+L/IcvDd6f +I8ttwU26M6AuTo17vAYnaDOte+bIhDxoejs9ZFeS546DmbpBTjyMknJ+Z6VS8UhqK uwGBu7yx1gdOk/NG7W/mqx7EBI5DaysU79/9TliK5+QdY8Hg6Cc9d0BuASgkWa5kQ4 7RBnE4/XQCmluN9l2CNmG6TOJPJj/BAZL5ONpcnY3OpY7a6JMOxk+DuFWDD7vZy1rQ 3tOWi6vBlRA+i3k8k2mdnQQWgQHFA+E7Nv8wJ8rx8Q6Eo+8RN+lTAB1ZDe87v947R9 CoByEUn8UFKoA== From: Michael Grzeschik Date: Tue, 22 Sep 2026 00:26:00 +0200 Subject: [PATCH 7/7] net/9p/usbg: clear stale client pointer on close Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260922-usb9pfsfixes-v1-7-9d8dcc52904c@kernel.org> References: <20260922-usb9pfsfixes-v1-0-9d8dcc52904c@kernel.org> In-Reply-To: <20260922-usb9pfsfixes-v1-0-9d8dcc52904c@kernel.org> To: Eric Van Hensbergen , Latchesar Ionkov , Dominique Martinet , Christian Schoenebeck , Greg Kroah-Hartman Cc: v9fs@lists.linux.dev, linux-kernel@vger.kernel.org, Michael Grzeschik , Hyungjung Joo , stable@vger.kernel.org X-Mailer: b4 0.16.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=6091; i=mgr@kernel.org; h=from:subject:message-id; bh=tC038ezHdlUfFI/3EG7MxZmCGxI5Nw5bzI3ZV5Lf6+Q=; b=owEBbQKS/ZANAwAKAb9pWET5cfSrAcsmYgBqsa8FLxLE6pEVIETB6e7CJeH3L9SkipP5VoNzo SNQOLrufeeJAjMEAAEKAB0WIQQV2+2Fpbqd6fvv0Gi/aVhE+XH0qwUCarGvBQAKCRC/aVhE+XH0 qyPaEACDyC9s+vkbbAx1IalaiVxI8ZnVzGuhn9brUYjgs8n3BoMWc/LapekRt+nYoz99jCbJh4O piQ4iCLFIpRmc9czXR0AdijNoUA/+dSbFY6UOqZHNEbIkAsViH/V6VnCriHw/Ou0bNfmDH5igRg k0ObGtQSx1KMyfiq2MOoEO3z+KFlS7XGySFYh1b6ep5wHnAb3ryu9QDQQ03p7c+vRG5JfzrnkBB ASsfecWEeazJhRP1SYeBLxShsoSnshcVv63PTDSNDdNDS6DwGrev4MXenE+UnJO9w74uSLZLHyh 9oX4xh7jZ+LyMMWjy3G8sgzKKlpC2568DJX8PRCXLNa+BBANOnKzyc+fnrkYSd6cBh8oHco8QMM k1cYOgMofLglHdqybaNsH3aD0a3joF2kcJMgAo9LN8gypWjLAV8uAwbXymV95Y67UKMLJPjHlsW G0rzzsAVCgQTorSRmemTu1rB09Kx0u+gZXyrIDDXoQF359/qQPz5W2vUxj7QmLHCSKBNIGsO+Y/ RsPovqYCvDiTF8lLNrO1iSHPiK9tJl01RLaGGWpFw+PM7W9FekLPhb+zOEYtOiytaGjTV/bLAy1 vQLNjWGbWwG5EV3/nOS1299z83mLadLIQ4bXp3oaY3gDEuu0JWxrLt7qblYDKeryX2kv/D+no7Y AizUOF1x+i6nbIQ== X-Developer-Key: i=mgr@kernel.org; a=openpgp; fpr=957BC452CE953D7EA60CF4FC0BE9E3157A1E2C64 From: Hyungjung Joo p9_usbg_close() tears down the client transport, but usb9pfs keeps using usb9pfs->client from asynchronous TX and RX completion handlers. A late completion can therefore dereference a client that has already been freed during mount teardown. Clear usb9pfs->client under usb9pfs->lock when closing the transport, detach any pending TX request from in_req->context, and make the TX/RX completion handlers bail out once the transport has been detached. This keeps late completions from touching a freed or rebound p9_client. Fixes: a3be076dc174 ("net/9p/usbg: Add new usb gadget function transport") Cc: stable@vger.kernel.org Signed-off-by: Hyungjung Joo Signed-off-by: Michael Grzeschik --- net/9p/trans_usbg.c | 61 +++++++++++++++++++++++++++++++++++++++----------= ---- 1 file changed, 45 insertions(+), 16 deletions(-) diff --git a/net/9p/trans_usbg.c b/net/9p/trans_usbg.c index 544690a5c717..c6306b073089 100644 --- a/net/9p/trans_usbg.c +++ b/net/9p/trans_usbg.c @@ -149,7 +149,8 @@ static void usb9pfs_tx_complete(struct usb_ep *ep, stru= ct usb_request *req) { struct f_usb9pfs *usb9pfs =3D ep->driver_data; struct usb_composite_dev *cdev =3D usb9pfs->function.config->cdev; - struct p9_req_t *p9_tx_req =3D req->context; + struct p9_client *client; + struct p9_req_t *p9_tx_req; unsigned long flags; =20 /* reset zero packages */ @@ -165,18 +166,25 @@ static void usb9pfs_tx_complete(struct usb_ep *ep, st= ruct usb_request *req) ep->name, req->status, req->actual, req->length); =20 spin_lock_irqsave(&usb9pfs->lock, flags); - WRITE_ONCE(p9_tx_req->status, REQ_STATUS_SENT); + client =3D usb9pfs->client; + p9_tx_req =3D req->context; + req->context =3D NULL; =20 - p9_req_put(usb9pfs->client, p9_tx_req); + if (!client || !p9_tx_req) + goto unlock_complete; =20 - req->context =3D NULL; + WRITE_ONCE(p9_tx_req->status, REQ_STATUS_SENT); =20 + p9_req_put(client, p9_tx_req); + +unlock_complete: spin_unlock_irqrestore(&usb9pfs->lock, flags); =20 complete(&usb9pfs->send); } =20 -static struct p9_req_t *usb9pfs_rx_header(struct f_usb9pfs *usb9pfs, void = *buf) +static struct p9_req_t *usb9pfs_rx_header(struct f_usb9pfs *usb9pfs, + struct p9_client *client, void *buf) { struct p9_req_t *p9_rx_req; struct p9_fcall rc; @@ -202,7 +210,7 @@ static struct p9_req_t *usb9pfs_rx_header(struct f_usb9= pfs *usb9pfs, void *buf) "mux %p pkt: size: %d bytes tag: %d\n", usb9pfs, rc.size, rc.tag); =20 - p9_rx_req =3D p9_tag_lookup(usb9pfs->client, rc.tag); + p9_rx_req =3D p9_tag_lookup(client, rc.tag); if (!p9_rx_req || p9_rx_req->status !=3D REQ_STATUS_SENT) { p9_debug(P9_DEBUG_ERROR, "Unexpected packet tag %d\n", rc.tag); return NULL; @@ -212,7 +220,7 @@ static struct p9_req_t *usb9pfs_rx_header(struct f_usb9= pfs *usb9pfs, void *buf) p9_debug(P9_DEBUG_ERROR, "requested packet size too big: %d for tag %d with capacity %zd\n", rc.size, rc.tag, p9_rx_req->rc.capacity); - p9_req_put(usb9pfs->client, p9_rx_req); + p9_req_put(client, p9_rx_req); return NULL; } =20 @@ -220,7 +228,7 @@ static struct p9_req_t *usb9pfs_rx_header(struct f_usb9= pfs *usb9pfs, void *buf) p9_debug(P9_DEBUG_ERROR, "No recv fcall for tag %d (req %p), disconnecting!\n", rc.tag, p9_rx_req); - p9_req_put(usb9pfs->client, p9_rx_req); + p9_req_put(client, p9_rx_req); return NULL; } =20 @@ -231,8 +239,10 @@ static void usb9pfs_rx_complete(struct usb_ep *ep, str= uct usb_request *req) { struct f_usb9pfs *usb9pfs =3D ep->driver_data; struct usb_composite_dev *cdev =3D usb9pfs->function.config->cdev; + struct p9_client *client; struct p9_req_t *p9_rx_req; unsigned int req_size =3D req->actual; + unsigned long flags; int status =3D REQ_STATUS_RCVD; =20 if (req->status) { @@ -241,9 +251,16 @@ static void usb9pfs_rx_complete(struct usb_ep *ep, str= uct usb_request *req) return; } =20 - p9_rx_req =3D usb9pfs_rx_header(usb9pfs, req->buf); - if (!p9_rx_req) + spin_lock_irqsave(&usb9pfs->lock, flags); + client =3D usb9pfs->client; + if (!client) { + spin_unlock_irqrestore(&usb9pfs->lock, flags); return; + } + + p9_rx_req =3D usb9pfs_rx_header(usb9pfs, client, req->buf); + if (!p9_rx_req) + goto out_unlock; =20 if (req_size > p9_rx_req->rc.capacity) { dev_err(&cdev->gadget->dev, @@ -257,8 +274,11 @@ static void usb9pfs_rx_complete(struct usb_ep *ep, str= uct usb_request *req) =20 p9_rx_req->rc.size =3D req_size; =20 - p9_client_cb(usb9pfs->client, p9_rx_req, status); - p9_req_put(usb9pfs->client, p9_rx_req); + p9_client_cb(client, p9_rx_req, status); + p9_req_put(client, p9_rx_req); + +out_unlock: + spin_unlock_irqrestore(&usb9pfs->lock, flags); =20 complete(&usb9pfs->received); } @@ -412,7 +432,9 @@ static int p9_usbg_create(struct p9_client *client, str= uct fs_context *fc) client->status =3D Disconnected; else client->status =3D Connected; + spin_lock_irq(&usb9pfs->lock); usb9pfs->client =3D client; + spin_unlock_irq(&usb9pfs->lock); =20 client->trans_mod->maxsize =3D usb9pfs->buflen; =20 @@ -423,12 +445,19 @@ static int p9_usbg_create(struct p9_client *client, s= truct fs_context *fc) =20 static void usb9pfs_clear_tx(struct f_usb9pfs *usb9pfs) { + struct p9_client *client; struct p9_req_t *req; + unsigned long flags; =20 - guard(spinlock_irqsave)(&usb9pfs->lock); + spin_lock_irqsave(&usb9pfs->lock, flags); + client =3D usb9pfs->client; + usb9pfs->client =3D NULL; + req =3D usb9pfs->in_req ? usb9pfs->in_req->context : NULL; + if (usb9pfs->in_req) + usb9pfs->in_req->context =3D NULL; + spin_unlock_irqrestore(&usb9pfs->lock, flags); =20 - req =3D usb9pfs->in_req->context; - if (!req) + if (!req || !client) return; =20 usb9pfs->in_req->context =3D NULL; @@ -439,7 +468,7 @@ static void usb9pfs_clear_tx(struct f_usb9pfs *usb9pfs) if (!req->t_err) req->t_err =3D -ECONNRESET; =20 - p9_client_cb(usb9pfs->client, req, REQ_STATUS_ERROR); + p9_client_cb(client, req, REQ_STATUS_ERROR); usb9pfs->in_req->context =3D NULL; } =20 --=20 2.53.0