Re: [PATCH] usb: gadget: f_midi: initialize work in f_midi_alloc()

From: Takashi Iwai

Date: Sun Aug 16 2026 - 06:45:33 EST


On Sat, 15 Aug 2026 07:40:06 +0200,
Jeffin Philip wrote:
>
> f_midi_alloc initializes free_ref to 1 and it can only be incremented
> when a sound card is registered via f_midi_register_card().
> f_midi_register_card() is only called in f_midi_bind() which actually
> performs INIT_WORK. If f_midi_bind() is never run, work is not
> initialized and the if condition in f_midi_free becomes true,
> this results in a warning later in __flush_work as work->func = 0.
> Fix this by moving INIT_WORK from f_midi_bind() to f_midi_alloc().
>
> Reported-by: syzbot+d5fa3d224505c8610702@xxxxxxxxxxxxxxxxxxxxxxxxx
> Closes: https://syzkaller.appspot.com/bug?extid=d5fa3d224505c8610702
> Fixes: 8653d71ce376 ("usb/gadget: f_midi: Replace tasklet with work")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Jeffin Philip <jeffinphilip14@xxxxxxxxx>

Reviewed-by: Takashi Iwai <tiwai@xxxxxxx>


thanks,

Takashi