Linux USB
 help / color / mirror / Atom feed
* [PATCH] usb: host: max3421-hcd: stop SPI thread before freeing its DMA buffers
@ 2026-10-09  4:44 Haotian Zhang
  2026-10-09  4:51 ` sashiko-bot
  2026-10-09  6:07 ` Krzysztof Kozlowski
  0 siblings, 2 replies; 3+ messages in thread
From: Haotian Zhang @ 2026-10-09  4:44 UTC (permalink / raw)
  To: Greg Kroah-Hartman, David Mosberger-Tang; +Cc: linux-usb, linux-kernel

In max3421_probe(), the error path frees the kmalloc'd tx and rx buffers
with kfree() before calling kthread_stop() on max3421_hcd->spi_thread.
The SPI thread entry point max3421_spi_thread() immediately starts using
those buffers through spi_rd8()/spi_wr8(), so when usb_add_hcd() or
request_irq() fails and the thread is still running, it can access the
freed buffers, giving a use-after-free.

Stop the SPI thread first and only free the tx/rx buffers afterwards.

Fixes: 05dfa5c9bc37 ("usb: host: max3421-hcd: fix "spi_rd8" uses dynamic stack allocation warning")
Assisted-by: DeepSeek-V4.1-Flash
Signed-off-by: Haotian Zhang <vulab@iscas.ac.cn>
---
 drivers/usb/host/max3421-hcd.c | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

diff --git a/drivers/usb/host/max3421-hcd.c b/drivers/usb/host/max3421-hcd.c
index 73e76d0e6973..f7cd3e8d8cae 100644
--- a/drivers/usb/host/max3421-hcd.c
+++ b/drivers/usb/host/max3421-hcd.c
@@ -1922,10 +1922,14 @@ max3421_probe(struct spi_device *spi)
 	}
 
 	if (hcd) {
-		kfree(max3421_hcd->tx);
-		kfree(max3421_hcd->rx);
+		/*
+		 * The SPI thread uses the tx/rx buffers, so it must be
+		 * stopped before they are freed.
+		 */
 		if (!IS_ERR_OR_NULL(max3421_hcd->spi_thread))
 			kthread_stop(max3421_hcd->spi_thread);
+		kfree(max3421_hcd->tx);
+		kfree(max3421_hcd->rx);
 		usb_put_hcd(hcd);
 	}
 	return retval;
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH] usb: host: max3421-hcd: stop SPI thread before freeing its DMA buffers
  2026-10-09  4:44 [PATCH] usb: host: max3421-hcd: stop SPI thread before freeing its DMA buffers Haotian Zhang
@ 2026-10-09  4:51 ` sashiko-bot
  2026-10-09  6:07 ` Krzysztof Kozlowski
  1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-10-09  4:51 UTC (permalink / raw)
  To: Haotian Zhang; +Cc: linux-usb

> In max3421_probe(), the error path frees the kmalloc'd tx and rx buffers
> with kfree() before calling kthread_stop() on max3421_hcd->spi_thread.
> The SPI thread entry point max3421_spi_thread() immediately starts using
> those buffers through spi_rd8()/spi_wr8(), so when usb_add_hcd() or
> request_irq() fails and the thread is still running, it can access the
> freed buffers, giving a use-after-free.
> 
> Stop the SPI thread first and only free the tx/rx buffers afterwards.
> 
> Fixes: 05dfa5c9bc37 ("usb: host: max3421-hcd: fix "spi_rd8" uses dynamic stack allocation warning")
> Assisted-by: DeepSeek-V4.1-Flash
> Signed-off-by: Haotian Zhang <vulab@iscas.ac.cn>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261009044431.3115704-1-vulab@iscas.ac.cn?part=1


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] usb: host: max3421-hcd: stop SPI thread before freeing its DMA buffers
  2026-10-09  4:44 [PATCH] usb: host: max3421-hcd: stop SPI thread before freeing its DMA buffers Haotian Zhang
  2026-10-09  4:51 ` sashiko-bot
@ 2026-10-09  6:07 ` Krzysztof Kozlowski
  1 sibling, 0 replies; 3+ messages in thread
From: Krzysztof Kozlowski @ 2026-10-09  6:07 UTC (permalink / raw)
  To: Haotian Zhang
  Cc: linux-usb, linux-kernel, David Mosberger-Tang, Greg Kroah-Hartman


On Fri, 09 Oct 2026 12:44:31 +0800, Haotian Zhang wrote:
> In max3421_probe(), the error path frees the kmalloc'd tx and rx buffers
> with kfree() before calling kthread_stop() on max3421_hcd->spi_thread.
> The SPI thread entry point max3421_spi_thread() immediately starts using
> those buffers through spi_rd8()/spi_wr8(), so when usb_add_hcd() or
> request_irq() fails and the thread is still running, it can access the
> freed buffers, giving a use-after-free.
> 
> Stop the SPI thread first and only free the tx/rx buffers afterwards.
> 
> Fixes: 05dfa5c9bc37 ("usb: host: max3421-hcd: fix "spi_rd8" uses dynamic stack allocation warning")
> Assisted-by: DeepSeek-V4.1-Flash
> Signed-off-by: Haotian Zhang <vulab@iscas.ac.cn>
> ---
>  drivers/usb/host/max3421-hcd.c | 8 ++++++--
>  1 file changed, 6 insertions(+), 2 deletions(-)
> 



Multiple things here:
1. Your team ignored completely previous feedback.

2. You use multiple identities with this email, thus I actually doubt we speak
   with actual person.

3. Finally, same feedback:
You sent multiple independent patches, to multiple independent
subsystems. The amount of these patches clearly suggest this was
AI generated and most likely not tested.

More importantly, you sent all this work without properly organizing
relevant patches into patchsets. This makes reviewing difficult
and might cause multiple reviewers to address the same issue.
Replying to the entire set is impossible and requires handling each
patch independently, instead of applying or discarding the set.
Maintainers also won't see the bigger picture of your work. Quite
worrying.

This is on the verge of hostile patch: bomb us with so many
contributions, we won't be able to handle them in efficient manner,
like responding ONCE to ask you to slow down.  Considering all this
is untested and LLM generated, I have even more doubts whether this
should be considered for review.

Please read kernel documentation BEFORE posting more work. It will
explain you how to identify subsystems, how to organize your work per
subsystem (so a patchset grouping multiple patches with a short cover
letter), how to document usage of LLM and how what you should not do
if this was posted in a good faith.

Best regards,
Krzysztof





^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-10-09  6:07 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-09  4:44 [PATCH] usb: host: max3421-hcd: stop SPI thread before freeing its DMA buffers Haotian Zhang
2026-10-09  4:51 ` sashiko-bot
2026-10-09  6:07 ` Krzysztof Kozlowski

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox