# DF-1050 source-confirmation

**Verdict:** REPRODUCED (source-confirmed)
**Impact:** none  **Confidence:** likely

**Kernel ref:** `sys/bus/u4b/controller/usb_controller.c:180`

## Mechanism
usb_attach ignores usb_attach_sub failure -> detach NULL-deref: usb_attach returns 0 unconditionally; usb_proc_create failures inside usb_attach_sub only device_printf, later usb_detach -> usb_proc_msignal on uninitialized proc -> NULL-deref. confirmed.

## Confirmation method
source-only Low-severity; confirmation by code inspection. Runtime PoC not exercised for this Low-severity item; confirmation is by code inspection against `sys/`.

## Recommended fix
See `fix.diff` in this folder (git-apply-able unified diff).

## Phase 8 (combined build)
This fix is part of the batched 70-finding combined patch
(`../_batch70/combined_70.patch`) applied to in-guest `/usr/src`. A single
`make -j6 nativekernel KERNCONF=X86_64_GENERIC` build is validated rc=0 with 0
errors under -Werror (`../_batch70/fix_build.log`).
