Module Name: src Committed By: skrll Date: Mon Feb 22 07:46:00 UTC 2016
Modified Files: src/sys/dev/usb: ugen.c Log Message: Only clear the endpoint information in ugen_set_interface only if setting the new altno suceeds. Avoids the null de-ref in PR/50597 and PR/50810 To generate a diff of this commit: cvs rdiff -u -r1.129 -r1.130 src/sys/dev/usb/ugen.c Please note that diffs are not public domain; they are subject to the copyright notices on the relevant files.
Modified files: Index: src/sys/dev/usb/ugen.c diff -u src/sys/dev/usb/ugen.c:1.129 src/sys/dev/usb/ugen.c:1.130 --- src/sys/dev/usb/ugen.c:1.129 Sun Feb 21 09:50:10 2016 +++ src/sys/dev/usb/ugen.c Mon Feb 22 07:46:00 2016 @@ -1,4 +1,4 @@ -/* $NetBSD: ugen.c,v 1.129 2016/02/21 09:50:10 skrll Exp $ */ +/* $NetBSD: ugen.c,v 1.130 2016/02/22 07:46:00 skrll Exp $ */ /* * Copyright (c) 1998, 2004 The NetBSD Foundation, Inc. @@ -37,7 +37,7 @@ #include <sys/cdefs.h> -__KERNEL_RCSID(0, "$NetBSD: ugen.c,v 1.129 2016/02/21 09:50:10 skrll Exp $"); +__KERNEL_RCSID(0, "$NetBSD: ugen.c,v 1.130 2016/02/22 07:46:00 skrll Exp $"); #ifdef _KERNEL_OPT #include "opt_compat_netbsd.h" @@ -270,6 +270,19 @@ ugen_attach(device_t parent, device_t se return; } +Static void +ugen_clear_endpoints(struct ugen_softc *sc) +{ + + /* Clear out the old info, but leave the selinfo and cv initialised. */ + for (int i = 0; i < USB_MAX_ENDPOINTS; i++) { + for (int dir = OUT; dir <= IN; dir++) { + struct ugen_endpoint *sce = &sc->sc_endpoints[i][dir]; + memset(sce, 0, UGEN_ENDPOINT_NONZERO_CRUFT); + } + } +} + Static int ugen_set_config(struct ugen_softc *sc, int configno) { @@ -281,7 +294,7 @@ ugen_set_config(struct ugen_softc *sc, i u_int8_t niface, nendpt; int ifaceno, endptno, endpt; usbd_status err; - int dir, i; + int dir; DPRINTFN(1,("ugen_set_config: %s to configno %d, sc=%p\n", device_xname(sc->sc_dev), configno, sc)); @@ -310,13 +323,7 @@ ugen_set_config(struct ugen_softc *sc, i if (err) return (err); - /* Clear out the old info, but leave the selinfo and cv initialised. */ - for (i = 0; i < USB_MAX_ENDPOINTS; i++) { - for (dir = OUT; dir <= IN; dir++) { - sce = &sc->sc_endpoints[i][dir]; - memset(sce, 0, UGEN_ENDPOINT_NONZERO_CRUFT); - } - } + ugen_clear_endpoints(sc); for (ifaceno = 0; ifaceno < niface; ifaceno++) { DPRINTFN(1,("ugen_set_config: ifaceno %d\n", ifaceno)); @@ -1336,16 +1343,6 @@ ugen_set_interface(struct ugen_softc *sc err = usbd_endpoint_count(iface, &nendpt); if (err) return (err); - /* XXX should only do this after setting new altno has succeeded */ - for (endptno = 0; endptno < nendpt; endptno++) { - ed = usbd_interface2endpoint_descriptor(iface,endptno); - endpt = ed->bEndpointAddress; - dir = UE_GET_DIR(endpt) == UE_DIR_IN ? IN : OUT; - sce = &sc->sc_endpoints[UE_GET_ADDR(endpt)][dir]; - sce->sc = NULL; - sce->edesc = NULL; - sce->iface = NULL; - } /* change setting */ err = usbd_set_interface(iface, altno); @@ -1355,6 +1352,9 @@ ugen_set_interface(struct ugen_softc *sc err = usbd_endpoint_count(iface, &nendpt); if (err) return (err); + + ugen_clear_endpoints(sc); + for (endptno = 0; endptno < nendpt; endptno++) { ed = usbd_interface2endpoint_descriptor(iface,endptno); KASSERT(ed != NULL);