Re: [PATCH] usb: gadget: u_audio: reject srate request for unconfigured direction
From: Deepanshu Kartikey
Date: Wed Sep 30 2026 - 04:18:42 EST
On Tue, Sep 29, 2026 at 6:53 PM Greg KH <gregkh@xxxxxxxxxxxxxxxxxxx> wrote:
>
> On Fri, Aug 21, 2026 at 05:18:54PM +0530, Deepanshu Kartikey wrote:
> > u_audio_get_playback_srate() unconditionally locks and reads
> > uac->p_prm.lock/srate, but g_audio_setup() only initializes
> > p_prm.lock when p_chmask is set. On a UAC2 instance configured
> > without a playback direction, this results in acquiring a
> > never spin_lock_init()'d lock when a GET_CUR sample rate
> > request targets playback, triggering a lockdep "trying to
> > register non-static key" warning.
> >
> > Reject the request with -EOPNOTSUPP when p_chmask is not set,
> > before touching prm->lock.
> >
> > Fixes: eb3a1ce6f5ed ("usb: gadget: u_audio: Add capture/playback srate getter")
> > Reported-by: syzbot+e1d0e66badecc32d45eb@xxxxxxxxxxxxxxxxxxxxxxxxx
> > Closes: http://syzkaller.appspot.com/bug?extid=e1d0e66badecc32d45eb
> > Signed-off-by: Deepanshu Kartikey <kartikey406@xxxxxxxxx>
> > ---
>
> How was this tested?
I have not been able to test this since there is no
repro present in syzbot.
I verified the fix by static analysis of the call path in the report
(afunc_setup -> in_rq_cur -> u_audio_get_playback_srate) and confirmed
in g_audio_setup() that uac->p_prm.lock is only passed through
spin_lock_init() inside the "if (p_chmask)" block, so it is left
uninitialized whenever p_chmask is 0. Leading to lock splat issue.
This patch is compile test only
> Did you forget a Assisted-by: tag?
Sure I will add assisted by tag
thanks
Deepanshu