From nobody Thu Sep 24 13:38:58 2026 Received: from mail-qk2-f12.google.com (mail-qk2-f12.google.com [74.125.230.204]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BBD85428841 for ; Wed, 23 Sep 2026 05:31:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.230.204 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790141483; cv=none; b=l2ftSpbT1Lr4peju9acJrSPSg/s0Y+EYqG7S+Tt8CGYpFibAFH5TKY+OGDokOdlbFA/rnC8MryHA8BE5oBx5gw7mrqZCKUBa0XugfZnTcP9IRRrJXawEdCaUFGtPSeoVEQDv57TVvVR08jzhjJc4jVjWrGq8RUyJjXhJJsSSGKQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790141483; c=relaxed/simple; bh=ehFRQ3FZleExfRY9jjlGGdk7L45AX2N0aVofYNFEIo0=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=cil+pBvu5mWoF+C/CfDIkZUsbRq2q4VcY7S3rChccXKx7hLqpHR27723IkgYSoRPRWQOY9bMbzdj7dWtckI6EyjfHKXj+sV7kqQtDfHeoYR9S6PnktKE0U9p1a2K7XxO3DnGeIUkJ8p5Zkj02Mf/UH5C42QRY4JQQqOqud2Khfg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=j3vOoP8p; arc=none smtp.client-ip=74.125.230.204 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="j3vOoP8p" Received: by mail-qk2-f12.google.com with SMTP id d75a77b69052e-52fb7692a57so8298391cf.1 for ; Tue, 22 Sep 2026 22:31:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790141481; x=1790746281; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=SFpOg8k0FRJ6+H0KfdVDioIX8p2jh6VxkW8sAx0q0/Q=; b=j3vOoP8pRQ9BrhOxrhsotlGge/xt20Jlxm5Nt86aYCLgHFxNiMPd9NHQn4oBsUKTV1 0yTWOQWWhv41ByQcNsxtKcXxhl/Iow41OJo/XSeAkwMgWj9BLy1jKvBKxnPsbovWUxOV X5tnVC+sbaU1pnEwMgxuIkc/4Zh1joO+c47jBPoGFjZMZj6Cv+rFT+EFeaK/N2FOPSj/ 8JzxcZ3R2b10bGr05jqSXnwU3epbhzDFZIIVP4UsXWha2mt4NVGqjwVD4+vNLlW5n1Ub w0m0b8avXtYVbMDrrAPmfhXaJ2Z7yYXCto5JnBwz9RfEGk/UAild135OWfzvxXyVFXKk Phhg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790141481; x=1790746281; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=SFpOg8k0FRJ6+H0KfdVDioIX8p2jh6VxkW8sAx0q0/Q=; b=mLdtGKvdYDrZSjCd7WcjrfZPylF+kl8B1QcwSHB48dM5TCId0Z5Ate8y78NmT1/0w+ bnhm7Hdgh7hV4QZBA2UfRgDn4GxuKbpxelaY3Ny12es8H1gQr/K0krn+jbFUwxcd1dKT Cxa4lh+PCssLn8t0ZBkBKj7HOui8KIBa6uzixPmxdlYY4mEPUF5XEYSwXUPDrlNSWjek Cq8b/yMksE6EPequkVB+wYu3WXiwz5VXmnpFOO39NhBBk37QgC2cv2WYJal1KiUsYf0M ckcUgo1tQAnWgA1sFNUFQXgaBKHtWS/m0lA54cXhd3OPQLq3AXFMl4N3N2901R6OX6cG BhdQ== X-Forwarded-Encrypted: i=1; AKwUvBzPRg9dbtd5OieEII0R6NO4BzTyaMF9zCzc7V4uaHh2sJY2aj75XKjYWvJa1U+KfCUxOd/pF78T5R+GXmk=@vger.kernel.org X-Gm-Message-State: AFuF++nD6dzrmfvFtT2TlDKR0srWZ08ZeegFzcY81cpEkunUHn9Ci/GH RuO4AdRQ3Ec7CbBKwpNQIwGrsNdGeLt4iX1IGgdk/TLNBUDrekqTJcI= X-Gm-Gg: AYBFou0nJSmRqb7ql7EeqlSsnAj7GcSfFj+45F4G09UJYdEDxc/xnTRThhj03U1yH5H SFd2GHEf/9rZ2ElcbHwnE67SI+tjSrwlInX9bebncHPRnmKUM9+3+AsF3W6WjsDH0ld4QYFRFb5 vdhshz2CNjNOlhPShtnuBf8e/yJZNaYW8WEgFu+GwMlRH/dawrXXJsNYuH+WQxuxhjsPROlRlif xsSpfFC64/zBpMhg4lrWIP/HOKuit3vW+sIsel/Yx8nuZZ7V796s2TOjWjOIgZVWyQB5+25stNW la0T8e6sTpLT18K3asQfT6TjpTjMSRawGS4mI7y6YdUErkAB5Jcro2e3svYjmWl2X1baX18DOAl mkbmqiymJmyOe33exIpJZycSiUqPvoiMdlq3LJXCEz2IaqprmXo2lOF5oZCH79BNsgo3NnLx9Ki 3LTks66IzZ5q176rvgn4Lxj8a+Hrump//4bzP3gH17is2Gx3lnw44U+Uq3MRAYVKCmzbeIEKsWZ BHUDhFJXV5DAWeo20/75aWGic/bkYmhKo0MsbhQyZj7Wk5pAld6FcD124kjWK6M8Fy790WwUBJm xqgrlQJucRf1XYrgUCCGvxlq7/EHDLgrjGl+Pkgkp7pWtqBc4YMyOSKZ9xmDnNNY6A7OCLFqwRD XD6HpXyFyZMzo X-Received: by 2002:a05:6214:4a81:b0:910:3de8:177a with SMTP id 6a1803df08f44-9140c368a32mr24771786d6.16.1790141480528; Tue, 22 Sep 2026 22:31:20 -0700 (PDT) Received: from localhost.localdomain (h16.44.55.139.dynamic.ip.windstream.net. [139.55.44.16]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-9140c2a71cdsm13876646d6.3.2026.09.22.22.31.18 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Tue, 22 Sep 2026 22:31:19 -0700 (PDT) From: Myeonghun Pak To: Mathias Nyman , Greg Kroah-Hartman , Thierry Reding , Jonathan Hunter Cc: Myeonghun Pak , linux-usb@vger.kernel.org, linux-tegra@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Ijae Kim Subject: [PATCH] usb: host: xhci-tegra: Unregister OTG notifier before cancelling id_work Date: Wed, 23 Sep 2026 01:31:17 -0400 Message-ID: <20260923053118.92147-1-mhun512@gmail.com> X-Mailer: git-send-email 2.47.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" tegra_xusb_remove() cancels id_work, then calls otg_set_host() with a NULL host. That leaves id_nb registered until devm_usb_phy_release2() runs after .remove() returns, so a role change can queue id_work again and use the HCD released by usb_put_hcd(). Unregister id_nb first. atomic_notifier_chain_unregister() finishes callbacks already on the chain, and cancel_work_sync() drains the work they queued. devm_usb_phy_release2() unregisters again. A second unregister finds no entry; the wrapper discards the internal -ENOENT. The devres entry is still required for usb_put_phy(). This issue was identified during our ongoing static-analysis research while reviewing kernel code. Fixes: f836e7843036 ("usb: xhci-tegra: Add OTG support") Cc: stable@vger.kernel.org # 5.7+ Assisted-by: LLM Co-developed-by: Ijae Kim Signed-off-by: Ijae Kim Signed-off-by: Myeonghun Pak --- drivers/usb/host/xhci-tegra.c | 17 +++++++++++++---- 1 file changed, 13 insertions(+), 4 deletions(-) diff --git a/drivers/usb/host/xhci-tegra.c b/drivers/usb/host/xhci-tegra.c index 6f235d1e117e..f5894f2a5991 100644 --- a/drivers/usb/host/xhci-tegra.c +++ b/drivers/usb/host/xhci-tegra.c @@ -1542,11 +1542,20 @@ static void tegra_xusb_deinit_usb_phy(struct tegra_= xusb *tegra) { unsigned int i; =20 - cancel_work_sync(&tegra->id_work); - - for (i =3D 0; i < tegra->num_usb_phys; i++) - if (tegra->usbphy[i]) + /* + * id_nb is registered on the PHY notifier chain by + * devm_usb_get_phy_by_node(), so devres would only drop it after + * tegra_xusb_remove() has returned. Unregister it here, before the + * work is cancelled, so that it cannot be queued again. + */ + for (i =3D 0; i < tegra->num_usb_phys; i++) { + if (tegra->usbphy[i]) { + usb_unregister_notifier(tegra->usbphy[i], &tegra->id_nb); otg_set_host(tegra->usbphy[i]->otg, NULL); + } + } + + cancel_work_sync(&tegra->id_work); } =20 static int tegra_xusb_setup_wakeup(struct platform_device *pdev, struct te= gra_xusb *tegra) base-commit: 238650ef6c7c7cca08e032527329424c9fbd70e5 --=20 2.53.0