Re: [PATCH 1/2] usb: gadget: u_ether: Fix NULL pointer deref in debug logging

From: Aldo Ariel Panzardo

Date: Sat Oct 10 2026 - 10:30:35 EST


On Wed, Sep 23, 2026 at 03:58:35PM +0800, Kuen-Han Tsai wrote:
> Replace the composite.h logging macros in u_ether.c with the standard
> netdev_*() helpers. Because dev->net remains valid for the entire
> lifetime of struct eth_dev and netdev_printk() natively handles
> unparented network devices [...]

Confirmed against mainline. The DBG()/VDBG()/ERROR()/INFO() macros in
<linux/usb/composite.h> expand to dev_*(&(d)->gadget->dev, ...), so each
use in u_ether.c dereferences dev->gadget; once unbind clears it, logging
on the surviving net_device faults, as in the eth_stop() path you show.

The conversion is complete and safe. u_ether.c has 26 such macro uses (18
DBG, 3 VDBG, 1 ERROR, 4 INFO; no WARNING), and the patch converts all 26
one-to-one to the matching netdev_*(dev->net, ...). dev->net is the
net_device whose private area holds the eth_dev (netdev_priv); it is set
at creation and freed together with it via free_netdev(), so it is valid
wherever dev is. The remaining &g->dev logging in the setup paths uses
the local gadget argument, and the dev->gadget->dev access in
eth_get_drvinfo() is not a logging macro and is outside this change's
scope, so nothing is left logging through a stale dev->gadget.

Reviewed-by: Aldo Ariel Panzardo <qwe.aldo@xxxxxxxxx>