Re: [PATCH] usb: atm: use request_firmware_direct() for firmware probing

From: Simon Horman

Date: Tue Sep 29 2026 - 10:32:43 EST


On Thu, Sep 24, 2026 at 08:06:54AM +0300, Matvey Valigura wrote:
> When disconnecting a device while firmware is not present on the system,
> usbatm_usb_disconnect() waits for the heavy_init thread to finish:
> wait_for_completion(&instance->thread_exited);
>
> If CONFIG_FW_LOADER_USER_HELPER_FALLBACK is enabled, missing firmware
> causes request_firmware() to fall back to sysfs/udevd. This creates a
> circular dependency during disconnect:
> 1. usb_disconnect() holds device_lock(&udev->dev).
> 2. usbatm_usb_disconnect() waits for instance->thread to exit.
> 3. instance->thread waits for request_firmware() sysfs fallback.
> 4. udevd receives the firmware uevent and attempts to read sysfs
> attributes (e.g. serial), blocking on device_lock(&udev->dev).
>
> Furthermore, the fallback wait uses wait_for_completion_killable_timeout(),
> which ignores the non-fatal SIGTERM signal sent by usbatm_usb_disconnect().
> Because speedtch and cxacru probe multiple candidate firmware files
> sequentially, each file stalls for the 60-second fallback timeout,
> triggering hung task timeouts (>120s) reported by syzbot.
>
> Switch to request_firmware_direct() to probe firmware files directly from
> the filesystem without falling back to user-mode helper.
>
> Reported-by: syzbot+9ca2c9f85bd8b5e46516@xxxxxxxxxxxxxxxxxxxxxxxxx
> Closes: https://syzkaller.appspot.com/bug?extid=9ca2c9f85bd8b5e46516
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Matvey Valigura <valigurasm@xxxxxxxxx>
> ---
> drivers/usb/atm/cxacru.c | 2 +-
> drivers/usb/atm/speedtch.c | 6 +++---
> 2 files changed, 4 insertions(+), 4 deletions(-)

I am assuming that in practice users do not load firmware for these devices
from user-space.

Reviewed-by: Simon Horman <horms@xxxxxxxxxx>