Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

USB: usblp: fix a hang in poll() if disconnected

Apparently an application that opens a device and calls select()
on it, will hang if the decice is disconnected. It's a little
surprising that we had this bug for 15 years, but apparently
nobody ever uses select() with a printer: only write() and read(),
and those work fine. Well, you can also select() with a timeout.

The fix is modeled after devio.c. A few other drivers check the
condition first, then do not add the wait queue in case the
device is disconnected. We doubt that's completely race-free.
So, this patch adds the process first, then locks properly
and checks for the disconnect.

Reviewed-by: Zqiang <qiang.zhang@windriver.com>
Signed-off-by: Pete Zaitcev <zaitcev@redhat.com>
Cc: stable <stable@vger.kernel.org>
Link: https://lore.kernel.org/r/20210303221053.1cf3313e@suzdal.zaitcev.lan
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

authored by

Pete Zaitcev and committed by
Greg Kroah-Hartman
9de2c43a 414c20df

+12 -4
+12 -4
drivers/usb/class/usblp.c
··· 494 494 /* No kernel lock - fine */ 495 495 static __poll_t usblp_poll(struct file *file, struct poll_table_struct *wait) 496 496 { 497 - __poll_t ret; 497 + struct usblp *usblp = file->private_data; 498 + __poll_t ret = 0; 498 499 unsigned long flags; 499 500 500 - struct usblp *usblp = file->private_data; 501 501 /* Should we check file->f_mode & FMODE_WRITE before poll_wait()? */ 502 502 poll_wait(file, &usblp->rwait, wait); 503 503 poll_wait(file, &usblp->wwait, wait); 504 + 505 + mutex_lock(&usblp->mut); 506 + if (!usblp->present) 507 + ret |= EPOLLHUP; 508 + mutex_unlock(&usblp->mut); 509 + 504 510 spin_lock_irqsave(&usblp->lock, flags); 505 - ret = ((usblp->bidir && usblp->rcomplete) ? EPOLLIN | EPOLLRDNORM : 0) | 506 - ((usblp->no_paper || usblp->wcomplete) ? EPOLLOUT | EPOLLWRNORM : 0); 511 + if (usblp->bidir && usblp->rcomplete) 512 + ret |= EPOLLIN | EPOLLRDNORM; 513 + if (usblp->no_paper || usblp->wcomplete) 514 + ret |= EPOLLOUT | EPOLLWRNORM; 507 515 spin_unlock_irqrestore(&usblp->lock, flags); 508 516 return ret; 509 517 }