• Jia-Ju Bai's avatar
    usb: gadget: r8a66597: Fix two possible sleep-in-atomic-context bugs in init_controller() · 0602088b
    Jia-Ju Bai authored
    The driver may sleep with holding a spinlock.
    The function call paths (from bottom to top) in Linux-4.16.7 are:
    
    [FUNC] msleep
    drivers/usb/gadget/udc/r8a66597-udc.c, 839:
    		msleep in init_controller
    drivers/usb/gadget/udc/r8a66597-udc.c, 96:
    		init_controller in r8a66597_usb_disconnect
    drivers/usb/gadget/udc/r8a66597-udc.c, 93:
    		spin_lock in r8a66597_usb_disconnect
    
    [FUNC] msleep
    drivers/usb/gadget/udc/r8a66597-udc.c, 835:
    		msleep in init_controller
    drivers/usb/gadget/udc/r8a66597-udc.c, 96:
    		init_controller in r8a66597_usb_disconnect
    drivers/usb/gadget/udc/r8a66597-udc.c, 93:
    		spin_lock in r8a66597_usb_disconnect
    
    To fix these bugs, msleep() is replaced with mdelay().
    
    This bug is found by my static analysis tool (DSAC-2) and checked by
    my code review.
    Signed-off-by: default avatarJia-Ju Bai <baijiaju1990@gmail.com>
    Signed-off-by: default avatarFelipe Balbi <felipe.balbi@linux.intel.com>
    0602088b
r8a66597-udc.c 48.3 KB