From: Krzysztof Kozlowski <krzk@kernel.org>
To: Haotian Zhang <vulab@iscas.ac.cn>
Cc: linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org,
David Mosberger-Tang <davidm@egauge.net>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Subject: Re: [PATCH] usb: host: max3421-hcd: stop SPI thread before freeing its DMA buffers
Date: Fri, 9 Oct 2026 08:07:22 +0200 [thread overview]
Message-ID: <20261009-durable-adaptable-bumblebee-a032da@quoll> (raw)
In-Reply-To: <20261009044431.3115704-1-vulab@iscas.ac.cn>
On Fri, 09 Oct 2026 12:44:31 +0800, Haotian Zhang wrote:
> In max3421_probe(), the error path frees the kmalloc'd tx and rx buffers
> with kfree() before calling kthread_stop() on max3421_hcd->spi_thread.
> The SPI thread entry point max3421_spi_thread() immediately starts using
> those buffers through spi_rd8()/spi_wr8(), so when usb_add_hcd() or
> request_irq() fails and the thread is still running, it can access the
> freed buffers, giving a use-after-free.
>
> Stop the SPI thread first and only free the tx/rx buffers afterwards.
>
> Fixes: 05dfa5c9bc37 ("usb: host: max3421-hcd: fix "spi_rd8" uses dynamic stack allocation warning")
> Assisted-by: DeepSeek-V4.1-Flash
> Signed-off-by: Haotian Zhang <vulab@iscas.ac.cn>
> ---
> drivers/usb/host/max3421-hcd.c | 8 ++++++--
> 1 file changed, 6 insertions(+), 2 deletions(-)
>
Multiple things here:
1. Your team ignored completely previous feedback.
2. You use multiple identities with this email, thus I actually doubt we speak
with actual person.
3. Finally, same feedback:
You sent multiple independent patches, to multiple independent
subsystems. The amount of these patches clearly suggest this was
AI generated and most likely not tested.
More importantly, you sent all this work without properly organizing
relevant patches into patchsets. This makes reviewing difficult
and might cause multiple reviewers to address the same issue.
Replying to the entire set is impossible and requires handling each
patch independently, instead of applying or discarding the set.
Maintainers also won't see the bigger picture of your work. Quite
worrying.
This is on the verge of hostile patch: bomb us with so many
contributions, we won't be able to handle them in efficient manner,
like responding ONCE to ask you to slow down. Considering all this
is untested and LLM generated, I have even more doubts whether this
should be considered for review.
Please read kernel documentation BEFORE posting more work. It will
explain you how to identify subsystems, how to organize your work per
subsystem (so a patchset grouping multiple patches with a short cover
letter), how to document usage of LLM and how what you should not do
if this was posted in a good faith.
Best regards,
Krzysztof
prev parent reply other threads:[~2026-10-09 6:07 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-09 4:44 [PATCH] usb: host: max3421-hcd: stop SPI thread before freeing its DMA buffers Haotian Zhang
2026-10-09 4:51 ` sashiko-bot
2026-10-09 6:07 ` Krzysztof Kozlowski [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261009-durable-adaptable-bumblebee-a032da@quoll \
--to=krzk@kernel.org \
--cc=davidm@egauge.net \
--cc=gregkh@linuxfoundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-usb@vger.kernel.org \
--cc=vulab@iscas.ac.cn \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox