]> git.hungrycats.org Git - linux/commitdiff
usb: gadget: f_tcm: keep port count until LUN teardown completes
authorShuangpeng Bai <shuangpeng.kernel@gmail.com>
Fri, 7 Aug 2026 06:07:33 +0000 (02:07 -0400)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 2 Sep 2026 12:31:48 +0000 (14:31 +0200)
commit c39d0916da47d94909391876c9e5bd429ea7b1b9 upstream.

tcm_usbg_drop_nexus() permits session removal once tpg_port_count
reaches zero. However, usbg_port_unlink() currently decrements that
count from the fabric_pre_unlink() callback, before core_dev_del_lun()
waits for active se_lun references to drain.

If removal of the last LUN races a nexus removal, the latter can observe
a zero port count and call target_remove_session(). This frees
sess_cmd_map while an in-flight struct usbg_cmd, including its work item,
can still be accessed.

Overlapping the last-LUN unlink with nexus removal reproduces this
lifetime violation as a DEBUG_OBJECTS "free active" warning for
usbg_cmd_work, followed by a target-core BUG/Oops.

The generic target-core unlink path has no callback after
core_dev_del_lun() completes. Add an optional fabric_post_unlink()
callback and use it for the f_tcm port count. The count now remains
nonzero until core_dev_del_lun() has finished draining active LUN
references, preventing nexus removal from freeing the session during
command completion.

Fixes: c52661d60f63 ("usb-gadget: Initial merge of target module for UASP + BOT")
Cc: stable@vger.kernel.org
Signed-off-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Link: https://patch.msgid.link/20260807060733.3186624-1-shuangpeng.kernel@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/target/target_core_fabric_configfs.c
drivers/usb/gadget/function/f_tcm.c
include/target/target_core_fabric.h

index 7156a4dc1ca7d9ddebe469fa59791b52e63b653b..15172e993be7c1fc70775f10e3bd94a89f7573de 100644 (file)
@@ -690,6 +690,14 @@ static void target_fabric_port_unlink(
        }
 
        core_dev_del_lun(se_tpg, lun);
+
+       if (tf->tf_ops->fabric_post_unlink) {
+               /*
+                * Allow fabrics to release state that must remain valid until
+                * core_dev_del_lun() has drained all active LUN references.
+                */
+               tf->tf_ops->fabric_post_unlink(se_tpg, lun);
+       }
 }
 
 static void target_fabric_port_release(struct config_item *item)
index 5753c83f5578469f49ff301ddfb8fed42278a9b8..09d72bb4f8550e8a5b75bc76e9e7411a757619e7 100644 (file)
@@ -2023,7 +2023,7 @@ static const struct target_core_fabric_ops usbg_ops = {
        .fabric_enable_tpg              = usbg_enable_tpg,
        .fabric_drop_tpg                = usbg_drop_tpg,
        .fabric_post_link               = usbg_port_link,
-       .fabric_pre_unlink              = usbg_port_unlink,
+       .fabric_post_unlink             = usbg_port_unlink,
        .fabric_init_nodeacl            = usbg_init_nodeacl,
 
        .tfc_wwn_attrs                  = usbg_wwn_attrs,
index 3378ff9ee271c942536f341678d5045b3c782116..7c85ca01c3f82f16ea432730edb7fd6c44456159 100644 (file)
@@ -95,6 +95,8 @@ struct target_core_fabric_ops {
                                struct se_lun *);
        void (*fabric_pre_unlink)(struct se_portal_group *,
                                struct se_lun *);
+       void (*fabric_post_unlink)(struct se_portal_group *se_tpg,
+                                  struct se_lun *lun);
        struct se_tpg_np *(*fabric_make_np)(struct se_portal_group *,
                                struct config_group *, const char *);
        void (*fabric_drop_np)(struct se_tpg_np *);