Netdev List
 help / color / mirror / Atom feed
* [PATCH net 0/16] pull-request: can 2026-09-29
@ 2026-09-29 20:43 Marc Kleine-Budde
  2026-09-29 20:43 ` [PATCH net 01/16] can: dev: can_dropped_invalid_skb: drop CAN XL frames on non-CAN XL devices Marc Kleine-Budde
                   ` (17 more replies)
  0 siblings, 18 replies; 32+ messages in thread
From: Marc Kleine-Budde @ 2026-09-29 20:43 UTC (permalink / raw)
  To: netdev; +Cc: davem, kuba, linux-can, kernel

Hello netdev-team,

this is a pull request of 16 patches for net/main.

The first patch is by Vincent Mailhol and drops CAN-XL frames on non
CAN-XL devices.

A patch by zjamg restores the skb header initialization lost during
the v7.0 release cycle.

Oliver Hartkopp contributes 3 patches for the CAN net layer, the first
one fixes the net namespace integration for BCM, ISOTP and the CAN RAW
protocols. The second one converts the unreliable ARPHRD_CAN type
check to the robust can_get_ml_priv(). The third one fixes the unique
skb identifier regression under RPS, introduced in the v7.0 release
cycle, which causes lost packets.

A patch by Joshua Crofts adds a missing
pm_runtime_dont_use_autosuspend() to the m_can_pci driver.

Maximilian Zimmermann's patch for the xilinx CAN driver adds the
setting the ESI and BSR flags in the receive path if they are active.

Jiale Yao's patch for the mcp251xfd driver rejects devices without
match data.

Ji-Ze Hong fixes a struct size mismatch in the f81604 CAN driver.

The next patch is by me, targets the gs_usb driver and adds
workarounds for the HScanT USB to CAN adapter.

Cen Zhang fixes a slab-out-of-bounds read access in the kvaser_usb
driver.

A patch by Stefan Günther targets the peak_usb driver and fixes the
CAN-ID when reporting CAN errors.

Chris Strong contributes 2 patches, to fix an out of memory and packet
loss problem in the mcp251xfd CAN driver under sustained receive
traffic.

regards,
Marc

---

The following changes since commit a7bfaba4823e3c165bb2004c74eff7c096672bc7:

  ipv6: fix prefix route expiry in modify_prefix_route() (2026-09-25 17:34:11 -0700)

are available in the Git repository at:

  git://git.kernel.org/pub/scm/linux/kernel/git/mkl/linux-can.git tags/linux-can-fixes-for-7.3-20260929

for you to fetch changes up to 085eb39e46ae1b6f3934eb3785be2077aae73ac7:

  Merge patch series "can: mcp251xfd: bound RX offload batches during long IRQs" (2026-09-29 22:38:08 +0200)

----------------------------------------------------------------
linux-can-fixes-for-7.3-20260929

----------------------------------------------------------------
Cen Zhang (Microsoft Security FORGE Labs) (1):
      can: kvaser_usb: validate command format before parsing in hydra receive path

Chris Strong (2):
      can: rx-offload: add IRQ queue flush predicate
      can: mcp251xfd: flush RX offload queue during long IRQs

Fan Wu (1):
      can: gs_usb: kill RX URBs before destroying the netdevs

Ji-Ze Hong (Peter Hong) (1):
      usb: f81604: fix struct f81604_int_data size mismatch

Jiale Yao (1):
      can: mcp251xfd: mcp251xfd_probe(): reject devices without match data

Joshua Crofts (1):
      can: m_can: pci: add missing pm_runtime_dont_use_autosuspend() call

Kaixuan Li (1):
      can: isotp: check the frame type, not just the length

Marc Kleine-Budde (3):
      Merge patch series "CAN netlayer fixes for stable"
      can: gs_usb: add workarounds for HScanT USB to CAN adapter
      Merge patch series "can: mcp251xfd: bound RX offload batches during long IRQs"

Maximilian Zimmermann (1):
      can: xilinx_can: set CAN FD flags on received frames

Oliver Hartkopp (3):
      can: remove CAN filters independent from namespace
      can: convert unreliable ARPHRD_CAN type checks to robust can_get_ml_priv()
      can: fix unique skb identifier regression under RPS

Stefan Günther (1):
      can: peak_usb: fix missing CAN_ERR_FLAG when reporting error counters

Vincent Mailhol (1):
      can: dev: can_dropped_invalid_skb: drop CAN XL frames on non-CAN XL devices

zjamg (1):
      can: dev: init_can_skb(): restore skb header initialization

 drivers/net/can/dev/skb.c                         |   7 +-
 drivers/net/can/m_can/m_can_pci.c                 |   1 +
 drivers/net/can/spi/mcp251xfd/mcp251xfd-core.c    |  21 +++-
 drivers/net/can/usb/f81604.c                      |   2 +-
 drivers/net/can/usb/gs_usb.c                      | 129 ++++++++++++++++++++-
 drivers/net/can/usb/kvaser_usb/kvaser_usb_hydra.c | 135 ++++++++++++++++++++--
 drivers/net/can/usb/peak_usb/pcan_usb.c           |   2 +-
 drivers/net/can/vxcan.c                           |   3 +
 drivers/net/can/xilinx_can.c                      |   6 +
 include/linux/can/core.h                          |   3 +-
 include/linux/can/rx-offload.h                    |   7 ++
 include/linux/can/skb.h                           |   4 +-
 include/net/can.h                                 |   2 +
 net/can/af_can.c                                  |  56 ++++++---
 net/can/bcm.c                                     | 107 ++++++++++++-----
 net/can/gw.c                                      |  10 +-
 net/can/isotp.c                                   |  36 +++---
 net/can/raw.c                                     |  17 +--
 18 files changed, 461 insertions(+), 87 deletions(-)

^ permalink raw reply	[flat|nested] 32+ messages in thread

* [PATCH net 01/16] can: dev: can_dropped_invalid_skb: drop CAN XL frames on non-CAN XL devices
  2026-09-29 20:43 [PATCH net 0/16] pull-request: can 2026-09-29 Marc Kleine-Budde
@ 2026-09-29 20:43 ` Marc Kleine-Budde
  2026-09-29 21:13   ` netdev-bot+sinfo
  2026-09-29 20:43 ` [PATCH net 02/16] can: dev: init_can_skb(): restore skb header initialization Marc Kleine-Budde
                   ` (16 subsequent siblings)
  17 siblings, 1 reply; 32+ messages in thread
From: Marc Kleine-Budde @ 2026-09-29 20:43 UTC (permalink / raw)
  To: netdev
  Cc: davem, kuba, linux-can, kernel, Vincent Mailhol, stable,
	Marc Kleine-Budde

From: Vincent Mailhol <mailhol@kernel.org>

Sending a PF_PACKET bypasses the CAN framework logic and can directly
reach a CAN driver's xmit() function. The PF_PACKET framework only
checks that skb->len does not exceed the net_device MTU.

For a CAN device that is not CAN XL capable, anything above CANFD_MTU
(72 bytes) is therefore dropped before it reaches the driver. However,
CAN XL frames are variable length. can_is_canxl_skb() accepts lengths in
the range CANXL_HDR_SIZE + CANXL_MIN_DLEN up to CANXL_MTU, i.e. 13 to
2060 bytes.

As a result, an ETH_P_CANXL skb with a length between 13 and 72 bytes
can pass both the MTU and the can_dropped_invalid_skb() checks.

A driver that does not support CAN XL will interpret canxl_frame->flags
as a length because of the overlap with can_frame->len. And because
CANXL_XLF is set, the resulting length is between 128 and 255. For
drivers that do not check can_frame->len before copying can_frame->data,
as most drivers do, this results in a buffer overflow of up to 247
bytes.

Drop ETH_P_CANXL skbs if the device does not have the CAN_CAP_XL
capability. Keep can_is_canxl_skb() for the validation of CAN XL skbs.

Closes: https://sashiko.dev/#/patchset/20260731-master-v5-0-5b27029dee20@qq.com?part=1
Fixes: fb08cba12b52 ("can: canxl: update CAN infrastructure for CAN XL frames")
Signed-off-by: Vincent Mailhol <mailhol@kernel.org>
Link: https://patch.msgid.link/20260731-drop_canxl_frames-v1-1-7387b70353b3@kernel.org
Cc: stable@kernel.org
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
---
 drivers/net/can/dev/skb.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/net/can/dev/skb.c b/drivers/net/can/dev/skb.c
index 95fcdc1026f8..4f7a189de265 100644
--- a/drivers/net/can/dev/skb.c
+++ b/drivers/net/can/dev/skb.c
@@ -4,6 +4,7 @@
  * Copyright (C) 2008-2009 Wolfgang Grandegger <wg@grandegger.com>
  */
 
+#include <linux/can/can-ml.h>
 #include <linux/can/dev.h>
 #include <linux/module.h>
 #include <net/can.h>
@@ -384,7 +385,7 @@ bool can_dropped_invalid_skb(struct net_device *dev, struct sk_buff *skb)
 		break;
 
 	case ETH_P_CANXL:
-		if (!can_is_canxl_skb(skb))
+		if (!can_cap_enabled(dev, CAN_CAP_XL) || !can_is_canxl_skb(skb))
 			goto inval_skb;
 		break;
 

base-commit: a7bfaba4823e3c165bb2004c74eff7c096672bc7
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [PATCH net 02/16] can: dev: init_can_skb(): restore skb header initialization
  2026-09-29 20:43 [PATCH net 0/16] pull-request: can 2026-09-29 Marc Kleine-Budde
  2026-09-29 20:43 ` [PATCH net 01/16] can: dev: can_dropped_invalid_skb: drop CAN XL frames on non-CAN XL devices Marc Kleine-Budde
@ 2026-09-29 20:43 ` Marc Kleine-Budde
  2026-09-29 20:43 ` [PATCH net 03/16] can: remove CAN filters independent from namespace Marc Kleine-Budde
                   ` (15 subsequent siblings)
  17 siblings, 0 replies; 32+ messages in thread
From: Marc Kleine-Budde @ 2026-09-29 20:43 UTC (permalink / raw)
  To: netdev
  Cc: davem, kuba, linux-can, kernel, zjamg, stable, Oliver Hartkopp,
	Quchaosheng, Shaunak Datar, Marc Kleine-Budde

From: zjamg <ndaugoing@gmail.com>

Commit 9f10374bb024 ("can: remove private CAN skb headroom infrastructure")
removed the skb_reset_mac_header()/skb_reset_network_header()/
skb_reset_transport_header() calls from init_can_skb(). As a result, RX
skbs from alloc_can_skb() and friends again carry mac_header = 0xFFFF.
When such an skb reaches packet_rcv_spkt() (SOCK_PACKET), the push length
calculation overflows and triggers skb_under_panic -> kernel BUG -> full
machine panic.

The same issue was originally reported in 2014 on linux-can and fixed by
commit 969439016d2c ("can: add missing initialisations in CAN related
skbuffs"). packet_rcv_spkt() itself has never been hardened: only
packet_rcv() and tpacket_rcv() gained dev_has_header() checks in
commit d549699048b4 ("net/packet: fix packet receive on L3 devices
without visible hard header").

Fixes: 9f10374bb024 ("can: remove private CAN skb headroom infrastructure")
Cc: stable@vger.kernel.org
Reviewed-by: Oliver Hartkopp <socketcan@hartkopp.net>
Acked-by: Oliver Hartkopp <socketcan@hartkopp.net>
Signed-off-by: zjamg <ndaugoing@gmail.com>
Tested-by: Quchaosheng <quchaosheng000406@163.com>
Link: https://patch.msgid.link/20260917123716.63116-1-ndaugoing@gmail.com
Reported-by: Shaunak Datar <shaunakkdatar@gmail.com>
Closes: https://lore.kernel.org/all/20260918151606.765490-1-shaunakkdatar@gmail.com
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
---
 drivers/net/can/dev/skb.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/net/can/dev/skb.c b/drivers/net/can/dev/skb.c
index 4f7a189de265..bc0787535b52 100644
--- a/drivers/net/can/dev/skb.c
+++ b/drivers/net/can/dev/skb.c
@@ -211,6 +211,10 @@ static void init_can_skb(struct sk_buff *skb)
 {
 	skb->pkt_type = PACKET_BROADCAST;
 	skb->ip_summed = CHECKSUM_UNNECESSARY;
+
+	skb_reset_mac_header(skb);
+	skb_reset_network_header(skb);
+	skb_reset_transport_header(skb);
 }
 
 struct sk_buff *alloc_can_skb(struct net_device *dev, struct can_frame **cf)
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [PATCH net 03/16] can: remove CAN filters independent from namespace
  2026-09-29 20:43 [PATCH net 0/16] pull-request: can 2026-09-29 Marc Kleine-Budde
  2026-09-29 20:43 ` [PATCH net 01/16] can: dev: can_dropped_invalid_skb: drop CAN XL frames on non-CAN XL devices Marc Kleine-Budde
  2026-09-29 20:43 ` [PATCH net 02/16] can: dev: init_can_skb(): restore skb header initialization Marc Kleine-Budde
@ 2026-09-29 20:43 ` Marc Kleine-Budde
  2026-09-29 20:43 ` [PATCH net 04/16] can: convert unreliable ARPHRD_CAN type checks to robust can_get_ml_priv() Marc Kleine-Budde
                   ` (14 subsequent siblings)
  17 siblings, 0 replies; 32+ messages in thread
From: Marc Kleine-Budde @ 2026-09-29 20:43 UTC (permalink / raw)
  To: netdev
  Cc: davem, kuba, linux-can, kernel, Oliver Hartkopp, Norbert Szetei,
	stable, Marc Kleine-Budde

From: Oliver Hartkopp <socketcan@hartkopp.net>

When the devices namespace is changed the socket namespace and the device
namespace might differ. The net_eq(dev_net(dev), sock_net(sk)) check in
the CAN protocols netdev notifiers therefore led to skipping the required
removal of the CAN filters from the (namespace changed) CAN devices.

This patch removes the namespace equality check in the netdev notifiers for
BCM, ISOTP and RAW sockets. Since the struct net_device pointer is globally
unique, the notifier should always process the unregister event and remove
the CAN filters if it matches the original socket's bound device pointer.

In bcm.c netdevice comparisons were performed by checking the interface
index (bo->ifindex and op->ifindex) which is not namespace-safe either.
Introduce tracked netdevice pointers (bo->dev and op->tx_dev) for these
referenced devices to enable namespace-save device comparisons.
Additional put all bo->dev accesses in bcm_notify() under lock_sock().

In isotp.c the two missing can_rx_unregister() calling sites are converted
to use dev_net(dev) instead of sock_net(sk) to get the correct namespace.

Fixes: 8e8cda6d737d ("can: initial support for network namespaces")
Reported-by: Norbert Szetei <norbert@doyensec.com>
Link: https://lore.kernel.org/linux-can/CEA6A38A-2646-4ADA-95B4-CBAE2F301A8E@doyensec.com/
Cc: stable@vger.kernel.org
Signed-off-by: Oliver Hartkopp <socketcan@hartkopp.net>
Tested-by: Norbert Szetei <norbert@doyensec.com>
Link: https://patch.msgid.link/20260929163424.16382-2-socketcan@hartkopp.net
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
---
 net/can/bcm.c   | 100 ++++++++++++++++++++++++++++++++++++------------
 net/can/isotp.c |   7 +---
 net/can/raw.c   |   3 --
 3 files changed, 78 insertions(+), 32 deletions(-)

diff --git a/net/can/bcm.c b/net/can/bcm.c
index 3d637a1e0ac1..cd3522ec32c0 100644
--- a/net/can/bcm.c
+++ b/net/can/bcm.c
@@ -130,6 +130,8 @@ struct bcm_op {
 	struct sock *sk;
 	struct net_device *rx_reg_dev;
 	netdevice_tracker rx_reg_dev_tracker;
+	struct net_device *tx_dev;
+	netdevice_tracker tx_dev_tracker;
 	spinlock_t bcm_tx_lock; /* protect tx data and timer updates */
 	spinlock_t bcm_rx_update_lock; /* protect filter/timer data updates */
 };
@@ -138,6 +140,8 @@ struct bcm_sock {
 	struct sock sk;
 	int bound;
 	int ifindex;
+	struct net_device *dev;
+	netdevice_tracker dev_tracker;
 	struct list_head notifier;
 	struct list_head rx_ops;
 	struct list_head tx_ops;
@@ -935,6 +939,9 @@ static void bcm_free_op_work(struct work_struct *work)
 	if ((op->last_frames) && (op->last_frames != &op->last_sframe))
 		kfree(op->last_frames);
 
+	if (op->tx_dev)
+		netdev_put(op->tx_dev, &op->tx_dev_tracker);
+
 	/* the last possible access to op->timer/op->thrtimer has now
 	 * happened above via hrtimer_cancel() - op->sk is no longer
 	 * needed by any pending timer callback, so drop our reference
@@ -1074,6 +1081,7 @@ static int bcm_tx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg,
 	struct bcm_sock *bo = bcm_sk(sk);
 	struct bcm_op *op;
 	struct canfd_frame *cf;
+	struct net_device *tx_dev;
 	bool add_op_to_list = false;
 	unsigned int i;
 	int err;
@@ -1105,6 +1113,22 @@ static int bcm_tx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg,
 		if (msg_head->nframes > op->nframes)
 			return -E2BIG;
 
+		/* Re-resolve and re-hold the target device if a concurrent
+		 * NETDEV_UNREGISTER already cleared it (see bcm_notify()).
+		 * op->ifindex and sock_net(sk) is unchanged.
+		 */
+		if (!op->tx_dev) {
+			tx_dev = dev_get_by_index(sock_net(sk), ifindex);
+			if (tx_dev) {
+				op->tx_dev = tx_dev;
+				netdev_hold(tx_dev, &op->tx_dev_tracker,
+					    GFP_KERNEL);
+				dev_put(tx_dev);
+			} else {
+				return -ENODEV;
+			}
+		}
+
 		/* get new CAN frames content into a staging buffer before
 		 * locking: validate and normalize the frames there so that
 		 * bcm_can_tx() / bcm_tx_timeout_handler() never observe a
@@ -1171,6 +1195,18 @@ static int bcm_tx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg,
 		if (!op)
 			return -ENOMEM;
 
+		tx_dev = dev_get_by_index(sock_net(sk), ifindex);
+		if (tx_dev) {
+			op->tx_dev = tx_dev;
+			netdev_hold(tx_dev, &op->tx_dev_tracker, GFP_KERNEL);
+			dev_put(tx_dev);
+		} else {
+			/* prepare op->frames for goto free_op */
+			op->frames = &op->sframe;
+			err = -ENODEV;
+			goto free_op;
+		}
+
 		spin_lock_init(&op->bcm_tx_lock);
 		op->can_id = msg_head->can_id;
 		op->cfsiz = CFSIZ(msg_head->flags);
@@ -1186,8 +1222,10 @@ static int bcm_tx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg,
 						   op->cfsiz,
 						   GFP_KERNEL);
 			if (!op->frames) {
-				kfree(op);
-				return -ENOMEM;
+				/* prepare op->frames for goto free_op */
+				op->frames = &op->sframe;
+				err = -ENOMEM;
+				goto free_op;
 			}
 		} else
 			op->frames = &op->sframe;
@@ -1269,6 +1307,9 @@ static int bcm_tx_setup(struct bcm_msg_head *msg_head, struct msghdr *msg,
 	return msg_head->nframes * op->cfsiz + MHSIZ;
 
 free_op:
+	if (op->tx_dev)
+		netdev_put(op->tx_dev, &op->tx_dev_tracker);
+
 	if (op->frames != &op->sframe)
 		kfree(op->frames);
 	kfree(op);
@@ -1792,15 +1833,13 @@ static void bcm_notify(struct bcm_sock *bo, unsigned long msg,
 {
 	struct sock *sk = &bo->sk;
 	struct bcm_op *op;
-	int notify_enodev = 0;
+	int sk_err = 0;
 
-	if (!net_eq(dev_net(dev), sock_net(sk)))
-		return;
+	lock_sock(sk);
 
 	switch (msg) {
 
 	case NETDEV_UNREGISTER:
-		lock_sock(sk);
 
 		/* rx_ops: remove device specific receive entries */
 		list_for_each_entry(op, &bo->rx_ops, list) {
@@ -1810,7 +1849,7 @@ static void bcm_notify(struct bcm_sock *bo, unsigned long msg,
 			/* release an ANYDEV op's claim (see bcm_rx_handler())
 			 * on this now confirmed-gone interface.
 			 */
-			if (!op->ifindex) {
+			if (!op->ifindex && net_eq(dev_net(dev), sock_net(sk))) {
 				spin_lock_bh(&op->bcm_rx_update_lock);
 				if (op->if_detected == dev->ifindex)
 					op->if_detected = 0;
@@ -1819,15 +1858,18 @@ static void bcm_notify(struct bcm_sock *bo, unsigned long msg,
 		}
 
 		/* tx_ops: stop device specific cyclic transmissions on the
-		 * vanishing ifindex. Cancelling the timer is enough to stop
+		 * vanishing device. Cancelling the timer is enough to stop
 		 * cyclic bcm_can_tx() calls as there is no re-arming.
 		 */
 		list_for_each_entry(op, &bo->tx_ops, list)
-			if (op->ifindex == dev->ifindex)
+			if (op->tx_dev == dev) {
 				hrtimer_cancel(&op->timer);
+				netdev_put(op->tx_dev, &op->tx_dev_tracker);
+				op->tx_dev = NULL;
+			}
 
 		/* remove device reference, if this is our bound device */
-		if (bo->bound && bo->ifindex == dev->ifindex) {
+		if (bo->bound && bo->dev == dev) {
 #if IS_ENABLED(CONFIG_PROC_FS)
 			if (sock_net(sk)->can.bcmproc_dir && bo->bcm_proc_read) {
 				remove_proc_entry(bo->procname, sock_net(sk)->can.bcmproc_dir);
@@ -1841,24 +1883,23 @@ static void bcm_notify(struct bcm_sock *bo, unsigned long msg,
 			 */
 			WRITE_ONCE(bo->bound, 0);
 			bo->ifindex = 0;
-			notify_enodev = 1;
-		}
-
-		release_sock(sk);
-
-		if (notify_enodev) {
-			sk->sk_err = ENODEV;
-			if (!sock_flag(sk, SOCK_DEAD))
-				sk_error_report(sk);
+			netdev_put(bo->dev, &bo->dev_tracker);
+			bo->dev = NULL;
+			sk_err = ENODEV;
 		}
 		break;
 
 	case NETDEV_DOWN:
-		if (bo->bound && bo->ifindex == dev->ifindex) {
-			sk->sk_err = ENETDOWN;
-			if (!sock_flag(sk, SOCK_DEAD))
-				sk_error_report(sk);
-		}
+		if (bo->bound && bo->dev == dev)
+			sk_err = ENETDOWN;
+	}
+
+	release_sock(sk);
+
+	if (sk_err) {
+		sk->sk_err = sk_err;
+		if (!sock_flag(sk, SOCK_DEAD))
+			sk_error_report(sk);
 	}
 }
 
@@ -1984,6 +2025,10 @@ static int bcm_release(struct socket *sock)
 	if (bo->bound) {
 		WRITE_ONCE(bo->bound, 0);
 		bo->ifindex = 0;
+		if (bo->dev) {
+			netdev_put(bo->dev, &bo->dev_tracker);
+			bo->dev = NULL;
+		}
 	}
 
 	sock_orphan(sk);
@@ -2031,11 +2076,14 @@ static int bcm_connect(struct socket *sock, struct sockaddr_unsized *uaddr, int
 		}
 
 		bo->ifindex = dev->ifindex;
+		bo->dev = dev;
+		netdev_hold(dev, &bo->dev_tracker, GFP_KERNEL);
 		dev_put(dev);
 
 	} else {
 		/* no interface reference for ifindex = 0 ('any' CAN device) */
 		bo->ifindex = 0;
+		bo->dev = NULL;
 	}
 
 #if IS_ENABLED(CONFIG_PROC_FS)
@@ -2046,6 +2094,10 @@ static int bcm_connect(struct socket *sock, struct sockaddr_unsized *uaddr, int
 						     net->can.bcmproc_dir,
 						     bcm_proc_show, sk);
 		if (!bo->bcm_proc_read) {
+			if (bo->dev) {
+				netdev_put(bo->dev, &bo->dev_tracker);
+				bo->dev = NULL;
+			}
 			ret = -ENOMEM;
 			goto fail;
 		}
diff --git a/net/can/isotp.c b/net/can/isotp.c
index 155530aedce2..0835a4758a72 100644
--- a/net/can/isotp.c
+++ b/net/can/isotp.c
@@ -1492,11 +1492,11 @@ static int isotp_release(struct socket *sock)
 	 */
 	if (so->bound && so->dev) {
 		if (isotp_register_rxid(so))
-			can_rx_unregister(net, so->dev, so->rxid,
+			can_rx_unregister(dev_net(so->dev), so->dev, so->rxid,
 					  SINGLE_MASK(so->rxid),
 					  isotp_rcv, sk);
 
-		can_rx_unregister(net, so->dev, so->txid,
+		can_rx_unregister(dev_net(so->dev), so->dev, so->txid,
 				  SINGLE_MASK(so->txid),
 				  isotp_rcv_echo, sk);
 		netdev_put(so->dev, &so->dev_tracker);
@@ -1848,9 +1848,6 @@ static void isotp_notify(struct isotp_sock *so, unsigned long msg,
 {
 	struct sock *sk = &so->sk;
 
-	if (!net_eq(dev_net(dev), sock_net(sk)))
-		return;
-
 	if (so->dev != dev)
 		return;
 
diff --git a/net/can/raw.c b/net/can/raw.c
index 82d9c0499c95..c5596fc9aac5 100644
--- a/net/can/raw.c
+++ b/net/can/raw.c
@@ -302,9 +302,6 @@ static void raw_notify(struct raw_sock *ro, unsigned long msg,
 {
 	struct sock *sk = &ro->sk;
 
-	if (!net_eq(dev_net(dev), sock_net(sk)))
-		return;
-
 	if (ro->dev != dev)
 		return;
 
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [PATCH net 04/16] can: convert unreliable ARPHRD_CAN type checks to robust can_get_ml_priv()
  2026-09-29 20:43 [PATCH net 0/16] pull-request: can 2026-09-29 Marc Kleine-Budde
                   ` (2 preceding siblings ...)
  2026-09-29 20:43 ` [PATCH net 03/16] can: remove CAN filters independent from namespace Marc Kleine-Budde
@ 2026-09-29 20:43 ` Marc Kleine-Budde
  2026-09-29 20:43 ` [PATCH net 05/16] can: fix unique skb identifier regression under RPS Marc Kleine-Budde
                   ` (13 subsequent siblings)
  17 siblings, 0 replies; 32+ messages in thread
From: Marc Kleine-Budde @ 2026-09-29 20:43 UTC (permalink / raw)
  To: netdev
  Cc: davem, kuba, linux-can, kernel, Oliver Hartkopp, stable,
	Oleksij Rempel, Marc Kleine-Budde

From: Oliver Hartkopp <socketcan@hartkopp.net>

Commit 4e096a18867a ("net: introduce CAN specific pointer in the struct
net_device") introduced an explicit way to assign the midlayer private
pointer (dev->ml_priv) to named users like ML_PRIV_CAN.

With this extension the CAN device specific ml_priv assignment became a
robust indicator to identify a valid CAN device, when can_get_ml_priv()
returns a valid pointer.

This has been used directly by the referenced commit in the CAN specific
j1939 and proc code but not in the other parts of the CAN subsystem.

With the TUN/TAP driver a device's ARPHRD type can be controlled by
userspace independently of its midlayer private data (ml_priv). The
TUNSETLINK ioctl allows a down TUN/TAP device to overwrite its hardware
type to become ARPHRD_CAN while dev->ml_priv remains NULL (uninitialized).

Instead of checking dev->type being the unreliable ARPHRD_CAN value convert
the missing "valid CAN devices" checks to can_get_ml_priv().

Fixes: 4e096a18867a ("net: introduce CAN specific pointer in the struct net_device")
Cc: stable@kernel.org
Cc: Oleksij Rempel <o.rempel@pengutronix.de>
Signed-off-by: Oliver Hartkopp <socketcan@hartkopp.net>
Link: https://patch.msgid.link/20260929163424.16382-3-socketcan@hartkopp.net
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
---
 net/can/af_can.c | 12 ++++++------
 net/can/bcm.c    |  7 ++++---
 net/can/gw.c     |  7 ++++---
 net/can/isotp.c  |  5 +++--
 net/can/raw.c    |  4 ++--
 5 files changed, 19 insertions(+), 16 deletions(-)

diff --git a/net/can/af_can.c b/net/can/af_can.c
index 7bc86b176b4d..ef435f22ac93 100644
--- a/net/can/af_can.c
+++ b/net/can/af_can.c
@@ -226,7 +226,7 @@ int can_send(struct sk_buff *skb, int loop)
 		goto inval_skb;
 	}
 
-	if (unlikely(skb->dev->type != ARPHRD_CAN)) {
+	if (unlikely(!can_get_ml_priv(skb->dev))) {
 		err = -EPERM;
 		goto inval_skb;
 	}
@@ -452,7 +452,7 @@ int can_rx_register(struct net *net, struct net_device *dev, canid_t can_id,
 
 	/* insert new receiver  (dev,canid,mask) -> (func,data) */
 
-	if (dev && (dev->type != ARPHRD_CAN || !can_get_ml_priv(dev)))
+	if (dev && !can_get_ml_priv(dev))
 		return -ENODEV;
 
 	if (dev && !net_eq(net, dev_net(dev)))
@@ -519,7 +519,7 @@ void can_rx_unregister(struct net *net, struct net_device *dev, canid_t can_id,
 	struct can_rcv_lists_stats *rcv_lists_stats = net->can.rcv_lists_stats;
 	struct can_dev_rcv_lists *dev_rcv_lists;
 
-	if (dev && dev->type != ARPHRD_CAN)
+	if (dev && !can_get_ml_priv(dev))
 		return;
 
 	if (dev && !net_eq(net, dev_net(dev)))
@@ -687,7 +687,7 @@ static void can_receive(struct sk_buff *skb, struct net_device *dev)
 static int can_rcv(struct sk_buff *skb, struct net_device *dev,
 		   struct packet_type *pt, struct net_device *orig_dev)
 {
-	if (unlikely(dev->type != ARPHRD_CAN || !can_get_ml_priv(dev) ||
+	if (unlikely(!can_get_ml_priv(dev) ||
 		     !can_skb_ext_find(skb) || !can_is_can_skb(skb))) {
 		pr_warn_once("PF_CAN: dropped non conform CAN skbuff: dev type %d, len %d\n",
 			     dev->type, skb->len);
@@ -703,7 +703,7 @@ static int can_rcv(struct sk_buff *skb, struct net_device *dev,
 static int canfd_rcv(struct sk_buff *skb, struct net_device *dev,
 		     struct packet_type *pt, struct net_device *orig_dev)
 {
-	if (unlikely(dev->type != ARPHRD_CAN || !can_get_ml_priv(dev) ||
+	if (unlikely(!can_get_ml_priv(dev) ||
 		     !can_skb_ext_find(skb) || !can_is_canfd_skb(skb))) {
 		pr_warn_once("PF_CAN: dropped non conform CAN FD skbuff: dev type %d, len %d\n",
 			     dev->type, skb->len);
@@ -719,7 +719,7 @@ static int canfd_rcv(struct sk_buff *skb, struct net_device *dev,
 static int canxl_rcv(struct sk_buff *skb, struct net_device *dev,
 		     struct packet_type *pt, struct net_device *orig_dev)
 {
-	if (unlikely(dev->type != ARPHRD_CAN || !can_get_ml_priv(dev) ||
+	if (unlikely(!can_get_ml_priv(dev) ||
 		     !can_skb_ext_find(skb) || !can_is_canxl_skb(skb))) {
 		pr_warn_once("PF_CAN: dropped non conform CAN XL skbuff: dev type %d, len %d\n",
 			     dev->type, skb->len);
diff --git a/net/can/bcm.c b/net/can/bcm.c
index cd3522ec32c0..940b917e3830 100644
--- a/net/can/bcm.c
+++ b/net/can/bcm.c
@@ -54,6 +54,7 @@
 #include <linux/if_arp.h>
 #include <linux/skbuff.h>
 #include <linux/can.h>
+#include <linux/can/can-ml.h>
 #include <linux/can/core.h>
 #include <linux/can/skb.h>
 #include <linux/can/bcm.h>
@@ -1760,7 +1761,7 @@ static int bcm_sendmsg(struct socket *sock, struct msghdr *msg, size_t size)
 				goto out_release;
 			}
 
-			if (dev->type != ARPHRD_CAN) {
+			if (!can_get_ml_priv(dev)) {
 				dev_put(dev);
 				ret = -ENODEV;
 				goto out_release;
@@ -1908,7 +1909,7 @@ static int bcm_notifier(struct notifier_block *nb, unsigned long msg,
 {
 	struct net_device *dev = netdev_notifier_info_to_dev(ptr);
 
-	if (dev->type != ARPHRD_CAN)
+	if (!can_get_ml_priv(dev))
 		return NOTIFY_DONE;
 	if (msg != NETDEV_UNREGISTER && msg != NETDEV_DOWN)
 		return NOTIFY_DONE;
@@ -2069,7 +2070,7 @@ static int bcm_connect(struct socket *sock, struct sockaddr_unsized *uaddr, int
 			ret = -ENODEV;
 			goto fail;
 		}
-		if (dev->type != ARPHRD_CAN) {
+		if (!can_get_ml_priv(dev)) {
 			dev_put(dev);
 			ret = -ENODEV;
 			goto fail;
diff --git a/net/can/gw.c b/net/can/gw.c
index 0ec99f68aa45..d9912dea738b 100644
--- a/net/can/gw.c
+++ b/net/can/gw.c
@@ -52,6 +52,7 @@
 #include <linux/if_arp.h>
 #include <linux/skbuff.h>
 #include <linux/can.h>
+#include <linux/can/can-ml.h>
 #include <linux/can/core.h>
 #include <linux/can/skb.h>
 #include <linux/can/gw.h>
@@ -609,7 +610,7 @@ static int cgw_notifier(struct notifier_block *nb,
 	struct net_device *dev = netdev_notifier_info_to_dev(ptr);
 	struct net *net = dev_net(dev);
 
-	if (dev->type != ARPHRD_CAN)
+	if (!can_get_ml_priv(dev))
 		return NOTIFY_DONE;
 
 	if (msg == NETDEV_UNREGISTER) {
@@ -1160,7 +1161,7 @@ static int cgw_create_job(struct sk_buff *skb,  struct nlmsghdr *nlh,
 	if (!gwj->src.dev)
 		goto out;
 
-	if (gwj->src.dev->type != ARPHRD_CAN)
+	if (!can_get_ml_priv(gwj->src.dev))
 		goto out;
 
 	gwj->dst.dev = __dev_get_by_index(net, gwj->ccgw.dst_idx);
@@ -1168,7 +1169,7 @@ static int cgw_create_job(struct sk_buff *skb,  struct nlmsghdr *nlh,
 	if (!gwj->dst.dev)
 		goto out;
 
-	if (gwj->dst.dev->type != ARPHRD_CAN)
+	if (!can_get_ml_priv(gwj->dst.dev))
 		goto out;
 
 	/* is sending the skb back to the incoming interface intended? */
diff --git a/net/can/isotp.c b/net/can/isotp.c
index 0835a4758a72..d3f79efc9c1e 100644
--- a/net/can/isotp.c
+++ b/net/can/isotp.c
@@ -65,6 +65,7 @@
 #include <linux/if_arp.h>
 #include <linux/skbuff.h>
 #include <linux/can.h>
+#include <linux/can/can-ml.h>
 #include <linux/can/core.h>
 #include <linux/can/skb.h>
 #include <linux/can/isotp.h>
@@ -1606,7 +1607,7 @@ static int isotp_bind(struct socket *sock, struct sockaddr_unsized *uaddr, int l
 		err = -ENODEV;
 		goto out;
 	}
-	if (dev->type != ARPHRD_CAN) {
+	if (!can_get_ml_priv(dev)) {
 		err = -ENODEV;
 		goto out_put_dev;
 	}
@@ -1890,7 +1891,7 @@ static int isotp_notifier(struct notifier_block *nb, unsigned long msg,
 {
 	struct net_device *dev = netdev_notifier_info_to_dev(ptr);
 
-	if (dev->type != ARPHRD_CAN)
+	if (!can_get_ml_priv(dev))
 		return NOTIFY_DONE;
 	if (msg != NETDEV_UNREGISTER && msg != NETDEV_DOWN)
 		return NOTIFY_DONE;
diff --git a/net/can/raw.c b/net/can/raw.c
index c5596fc9aac5..7c48ff36e6cd 100644
--- a/net/can/raw.c
+++ b/net/can/raw.c
@@ -341,7 +341,7 @@ static int raw_notifier(struct notifier_block *nb, unsigned long msg,
 {
 	struct net_device *dev = netdev_notifier_info_to_dev(ptr);
 
-	if (dev->type != ARPHRD_CAN)
+	if (!can_get_ml_priv(dev))
 		return NOTIFY_DONE;
 	if (msg != NETDEV_UNREGISTER && msg != NETDEV_DOWN)
 		return NOTIFY_DONE;
@@ -484,7 +484,7 @@ static int raw_bind(struct socket *sock, struct sockaddr_unsized *uaddr, int len
 			err = -ENODEV;
 			goto out;
 		}
-		if (dev->type != ARPHRD_CAN) {
+		if (!can_get_ml_priv(dev)) {
 			err = -ENODEV;
 			goto out_put_dev;
 		}
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [PATCH net 05/16] can: fix unique skb identifier regression under RPS
  2026-09-29 20:43 [PATCH net 0/16] pull-request: can 2026-09-29 Marc Kleine-Budde
                   ` (3 preceding siblings ...)
  2026-09-29 20:43 ` [PATCH net 04/16] can: convert unreliable ARPHRD_CAN type checks to robust can_get_ml_priv() Marc Kleine-Budde
@ 2026-09-29 20:43 ` Marc Kleine-Budde
  2026-09-29 20:43 ` [PATCH net 06/16] can: isotp: check the frame type, not just the length Marc Kleine-Budde
                   ` (12 subsequent siblings)
  17 siblings, 0 replies; 32+ messages in thread
From: Marc Kleine-Budde @ 2026-09-29 20:43 UTC (permalink / raw)
  To: netdev
  Cc: davem, kuba, linux-can, kernel, Oliver Hartkopp, Joerg Willmann,
	stable, Marc Kleine-Budde

From: Oliver Hartkopp <socketcan@hartkopp.net>

Commit d4fb6514ff8e ("can: use skb hash instead of private variable in
headroom") moved the per-skb unique identifier used for raw_rcv()
duplicate detection into skb->hash.

With RPS enabled, get_rps_cpu() calls skb_get_hash() before the frame
reaches the CAN subsystem. Since CAN skbs have no L3/L4 headers, the
flow dissector assigns every CAN frame the same non-zero software
hash. can_set_skb_uid() only generated a new identifier when
skb->hash was 0, so it kept this constant hash. When the SLAB
allocator later reused the same skb address, raw_rcv() mistook the
next legitimate frame for a duplicate and dropped it.

Fix this by storing the CAN UID in the CAN skb extension
(struct can_skb_ext::can_skb_uid) instead of skb->hash, decoupling it
from any hash the network stack may compute. can_set_skb_uid() keeps
its "assign only if unset" behaviour, which preserves UIDs set before
transmission (e.g. by isotp to identify echo frames) across the local
loopback path.

Frames whose extension is still shared with another clone (e.g. via
tc mirred or netem duplicate) are given a private extension copy
before the UID is assigned, so that independently received clones
never end up with the same UID.

can-gw and vxcan additionally clear the UID of forwarded/duplicated
frames so each newly routed frame gets its own unique identifier.

Fixes: d4fb6514ff8e ("can: use skb hash instead of private variable in headroom")
Reported-by: Joerg Willmann <joe@clnt.de>
Closes: https://lore.kernel.org/linux-can/2859AD3D-C805-41A0-9036-C5E8EE152419@clnt.de/
Cc: stable@vger.kernel.org
Tested-by: Oliver Hartkopp <socketcan@hartkopp.net>
Signed-off-by: Oliver Hartkopp <socketcan@hartkopp.net>
Link: https://patch.msgid.link/20260929163424.16382-4-socketcan@hartkopp.net
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
---
 drivers/net/can/vxcan.c  |  3 +++
 include/linux/can/core.h |  3 ++-
 include/linux/can/skb.h  |  4 +++-
 include/net/can.h        |  2 ++
 net/can/af_can.c         | 50 +++++++++++++++++++++++++++++-----------
 net/can/gw.c             |  3 +++
 net/can/isotp.c          | 16 ++++++++-----
 net/can/raw.c            | 10 +++++---
 8 files changed, 66 insertions(+), 25 deletions(-)

diff --git a/drivers/net/can/vxcan.c b/drivers/net/can/vxcan.c
index 9e2e25d02471..51148a81d1d9 100644
--- a/drivers/net/can/vxcan.c
+++ b/drivers/net/can/vxcan.c
@@ -79,6 +79,9 @@ static netdev_tx_t vxcan_xmit(struct sk_buff *oskb, struct net_device *dev)
 
 	/* reset CAN GW hop counter */
 	csx->can_gw_hops = 0;
+	/* start with new CAN skb UID in the other namespace */
+	csx->can_skb_uid = 0;
+
 	skb->pkt_type   = PACKET_BROADCAST;
 	skb->dev        = peer;
 	skb->ip_summed  = CHECKSUM_UNNECESSARY;
diff --git a/include/linux/can/core.h b/include/linux/can/core.h
index 3287232e3cad..2de74c2b78b6 100644
--- a/include/linux/can/core.h
+++ b/include/linux/can/core.h
@@ -17,6 +17,7 @@
 #include <linux/can.h>
 #include <linux/skbuff.h>
 #include <linux/netdevice.h>
+#include <net/can.h>
 
 #define DNAME(dev) ((dev) ? (dev)->name : "any")
 
@@ -58,7 +59,7 @@ extern void can_rx_unregister(struct net *net, struct net_device *dev,
 			      void *data);
 
 extern int can_send(struct sk_buff *skb, int loop);
-void can_set_skb_uid(struct sk_buff *skb);
+void can_set_skb_uid(struct can_skb_ext *csx);
 void can_sock_destruct(struct sock *sk);
 
 #endif /* !_CAN_CORE_H */
diff --git a/include/linux/can/skb.h b/include/linux/can/skb.h
index a70a02967071..5d27843862fc 100644
--- a/include/linux/can/skb.h
+++ b/include/linux/can/skb.h
@@ -43,8 +43,10 @@ static inline struct can_skb_ext *can_skb_ext_add(struct sk_buff *skb)
 	struct can_skb_ext *csx = skb_ext_add(skb, SKB_EXT_CAN);
 
 	/* skb_ext_add() returns uninitialized space */
-	if (csx)
+	if (csx) {
 		csx->can_gw_hops = 0;
+		csx->can_skb_uid = 0;
+	}
 
 	return csx;
 }
diff --git a/include/net/can.h b/include/net/can.h
index 6db9e826f0e0..2b8af2598732 100644
--- a/include/net/can.h
+++ b/include/net/can.h
@@ -17,12 +17,14 @@
  * @can_framelen: cached echo CAN frame length for bql
  * @can_gw_hops: can-gw CAN frame time-to-live counter
  * @can_ext_flags: CAN skb extensions flags
+ * @can_skb_uid: CAN skb UID for raw_rcv and isotp echo handling
  */
 struct can_skb_ext {
 	int	can_iif;
 	u16	can_framelen;
 	u8	can_gw_hops;
 	u8	can_ext_flags;
+	u32	can_skb_uid;
 };
 
 #endif /* _NET_CAN_H */
diff --git a/net/can/af_can.c b/net/can/af_can.c
index ef435f22ac93..dc27ace43719 100644
--- a/net/can/af_can.c
+++ b/net/can/af_can.c
@@ -641,13 +641,10 @@ static int can_rcv_filter(struct can_dev_rcv_lists *dev_rcv_lists, struct sk_buf
 	return matches;
 }
 
-void can_set_skb_uid(struct sk_buff *skb)
+void can_set_skb_uid(struct can_skb_ext *csx)
 {
-	/* create non-zero unique skb identifier together with *skb */
-	while (!(skb->hash))
-		skb->hash = atomic_inc_return(&skbcounter);
-
-	skb->sw_hash = 1;
+	while (!(csx->can_skb_uid))
+		csx->can_skb_uid = atomic_inc_return(&skbcounter);
 }
 EXPORT_SYMBOL(can_set_skb_uid);
 
@@ -662,8 +659,6 @@ static void can_receive(struct sk_buff *skb, struct net_device *dev)
 	atomic_long_inc(&pkg_stats->rx_frames);
 	atomic_long_inc(&pkg_stats->rx_frames_delta);
 
-	can_set_skb_uid(skb);
-
 	rcu_read_lock();
 
 	/* deliver the packet to sockets listening on all devices */
@@ -687,8 +682,9 @@ static void can_receive(struct sk_buff *skb, struct net_device *dev)
 static int can_rcv(struct sk_buff *skb, struct net_device *dev,
 		   struct packet_type *pt, struct net_device *orig_dev)
 {
-	if (unlikely(!can_get_ml_priv(dev) ||
-		     !can_skb_ext_find(skb) || !can_is_can_skb(skb))) {
+	struct can_skb_ext *csx = can_skb_ext_find(skb);
+
+	if (unlikely(!can_get_ml_priv(dev) || !csx || !can_is_can_skb(skb))) {
 		pr_warn_once("PF_CAN: dropped non conform CAN skbuff: dev type %d, len %d\n",
 			     dev->type, skb->len);
 
@@ -696,6 +692,14 @@ static int can_rcv(struct sk_buff *skb, struct net_device *dev,
 		return NET_RX_DROP;
 	}
 
+	/* create unshared CAN skb_extension for netem/mirred skb clones */
+	csx = skb_ext_add(skb, SKB_EXT_CAN);
+	if (unlikely(!csx)) {
+		kfree_skb_reason(skb, SKB_DROP_REASON_NOMEM);
+		return NET_RX_DROP;
+	}
+
+	can_set_skb_uid(csx);
 	can_receive(skb, dev);
 	return NET_RX_SUCCESS;
 }
@@ -703,8 +707,9 @@ static int can_rcv(struct sk_buff *skb, struct net_device *dev,
 static int canfd_rcv(struct sk_buff *skb, struct net_device *dev,
 		     struct packet_type *pt, struct net_device *orig_dev)
 {
-	if (unlikely(!can_get_ml_priv(dev) ||
-		     !can_skb_ext_find(skb) || !can_is_canfd_skb(skb))) {
+	struct can_skb_ext *csx = can_skb_ext_find(skb);
+
+	if (unlikely(!can_get_ml_priv(dev) || !csx || !can_is_canfd_skb(skb))) {
 		pr_warn_once("PF_CAN: dropped non conform CAN FD skbuff: dev type %d, len %d\n",
 			     dev->type, skb->len);
 
@@ -712,6 +717,14 @@ static int canfd_rcv(struct sk_buff *skb, struct net_device *dev,
 		return NET_RX_DROP;
 	}
 
+	/* create unshared CAN skb_extension for netem/mirred skb clones */
+	csx = skb_ext_add(skb, SKB_EXT_CAN);
+	if (unlikely(!csx)) {
+		kfree_skb_reason(skb, SKB_DROP_REASON_NOMEM);
+		return NET_RX_DROP;
+	}
+
+	can_set_skb_uid(csx);
 	can_receive(skb, dev);
 	return NET_RX_SUCCESS;
 }
@@ -719,8 +732,9 @@ static int canfd_rcv(struct sk_buff *skb, struct net_device *dev,
 static int canxl_rcv(struct sk_buff *skb, struct net_device *dev,
 		     struct packet_type *pt, struct net_device *orig_dev)
 {
-	if (unlikely(!can_get_ml_priv(dev) ||
-		     !can_skb_ext_find(skb) || !can_is_canxl_skb(skb))) {
+	struct can_skb_ext *csx = can_skb_ext_find(skb);
+
+	if (unlikely(!can_get_ml_priv(dev) || !csx || !can_is_canxl_skb(skb))) {
 		pr_warn_once("PF_CAN: dropped non conform CAN XL skbuff: dev type %d, len %d\n",
 			     dev->type, skb->len);
 
@@ -728,6 +742,14 @@ static int canxl_rcv(struct sk_buff *skb, struct net_device *dev,
 		return NET_RX_DROP;
 	}
 
+	/* create unshared CAN skb_extension for netem/mirred skb clones */
+	csx = skb_ext_add(skb, SKB_EXT_CAN);
+	if (unlikely(!csx)) {
+		kfree_skb_reason(skb, SKB_DROP_REASON_NOMEM);
+		return NET_RX_DROP;
+	}
+
+	can_set_skb_uid(csx);
 	can_receive(skb, dev);
 	return NET_RX_SUCCESS;
 }
diff --git a/net/can/gw.c b/net/can/gw.c
index d9912dea738b..54bb5bd3242a 100644
--- a/net/can/gw.c
+++ b/net/can/gw.c
@@ -528,6 +528,9 @@ static void can_can_gw_rcv(struct sk_buff *skb, void *data)
 	/* put the incremented hop counter in the cloned skb */
 	ncsx->can_gw_hops = csx->can_gw_hops + 1;
 
+	/* force a new CAN UID generation for the routed frame */
+	ncsx->can_skb_uid = 0;
+
 	/* first processing of this CAN frame -> adjust to private hop limit */
 	if (gwj->limit_hops && ncsx->can_gw_hops == 1)
 		ncsx->can_gw_hops = max_hops - gwj->limit_hops + 1;
diff --git a/net/can/isotp.c b/net/can/isotp.c
index d3f79efc9c1e..860c5221e299 100644
--- a/net/can/isotp.c
+++ b/net/can/isotp.c
@@ -892,7 +892,7 @@ static void isotp_send_cframe(struct isotp_sock *so)
 	csx->can_iif = dev->ifindex;
 
 	/* set uid in tx skb to identify CF echo frames */
-	can_set_skb_uid(skb);
+	can_set_skb_uid(csx);
 
 	cf = (struct canfd_frame *)skb->data;
 	skb_put_zero(skb, so->ll.mtu);
@@ -918,7 +918,7 @@ static void isotp_send_cframe(struct isotp_sock *so)
 		pr_notice_once("can-isotp: cfecho is %08X != 0\n", old_cfecho);
 
 	/* set consecutive frame echo tag */
-	WRITE_ONCE(so->cfecho, skb->hash);
+	WRITE_ONCE(so->cfecho, csx->can_skb_uid);
 
 	/* send frame with local echo enabled */
 	can_send_ret = can_send(skb, 1);
@@ -970,18 +970,22 @@ static void isotp_rcv_echo(struct sk_buff *skb, void *data)
 {
 	struct sock *sk = (struct sock *)data;
 	struct isotp_sock *so = isotp_sk(sk);
+	struct can_skb_ext *csx = can_skb_ext_find(skb);
 
 	/* only handle my own local echo CF/SF skb's (no FF!) */
 	if (skb->sk != sk)
 		return;
 
+	if (WARN_ON_ONCE(!csx))
+		return;
+
 	/* unlike isotp_rcv_fc()/isotp_rcv_cf(), not already under so->rx_lock
 	 * (no isotp_rcv() caller here), so take it ourselves
 	 */
 	spin_lock(&so->rx_lock);
 
 	/* so->cfecho may since belong to a new transfer; recheck under lock */
-	if (READ_ONCE(so->cfecho) != skb->hash)
+	if (READ_ONCE(so->cfecho) != csx->can_skb_uid)
 		goto out_unlock;
 
 	/* cancel local echo timeout */
@@ -1223,7 +1227,7 @@ static int isotp_sendmsg(struct socket *sock, struct msghdr *msg, size_t size)
 	csx->can_iif = dev->ifindex;
 
 	/* set uid in tx skb to identify CF echo frames */
-	can_set_skb_uid(skb);
+	can_set_skb_uid(csx);
 
 	so->tx.len = size;
 	so->tx.idx = 0;
@@ -1262,7 +1266,7 @@ static int isotp_sendmsg(struct socket *sock, struct msghdr *msg, size_t size)
 			cf->data[ae] |= size;
 
 		/* set CF echo tag for isotp_rcv_echo() (SF-mode) */
-		WRITE_ONCE(so->cfecho, skb->hash);
+		WRITE_ONCE(so->cfecho, csx->can_skb_uid);
 	} else {
 		/* send first frame */
 
@@ -1279,7 +1283,7 @@ static int isotp_sendmsg(struct socket *sock, struct msghdr *msg, size_t size)
 			so->txfc.bs = 0;
 
 			/* set CF echo tag for isotp_rcv_echo() (CF-mode) */
-			WRITE_ONCE(so->cfecho, skb->hash);
+			WRITE_ONCE(so->cfecho, csx->can_skb_uid);
 		} else {
 			/* standard flow control check */
 			new_state = ISOTP_WAIT_FIRST_FC;
diff --git a/net/can/raw.c b/net/can/raw.c
index 7c48ff36e6cd..7873bfc584ef 100644
--- a/net/can/raw.c
+++ b/net/can/raw.c
@@ -77,7 +77,7 @@ MODULE_ALIAS("can-proto-1");
 
 struct uniqframe {
 	const struct sk_buff *skb;
-	u32 hash;
+	u32 can_skb_uid;
 	unsigned int join_rx_count;
 };
 
@@ -133,12 +133,16 @@ static void raw_rcv(struct sk_buff *oskb, void *data)
 	enum skb_drop_reason reason;
 	struct sockaddr_can *addr;
 	struct sk_buff *skb;
+	struct can_skb_ext *csx = can_skb_ext_find(oskb);
 	unsigned int *pflags;
 
 	/* check the received tx sock reference */
 	if (!ro->recv_own_msgs && oskb->sk == sk)
 		return;
 
+	if (WARN_ON_ONCE(!csx))
+		return;
+
 	/* make sure to not pass oversized frames to the socket */
 	if (!ro->fd_frames && can_is_canfd_skb(oskb))
 		return;
@@ -165,7 +169,7 @@ static void raw_rcv(struct sk_buff *oskb, void *data)
 
 	/* eliminate multiple filter matches for the same skb */
 	if (this_cpu_ptr(ro->uniq)->skb == oskb &&
-	    this_cpu_ptr(ro->uniq)->hash == oskb->hash) {
+	    this_cpu_ptr(ro->uniq)->can_skb_uid == csx->can_skb_uid) {
 		if (!ro->join_filters)
 			return;
 
@@ -175,7 +179,7 @@ static void raw_rcv(struct sk_buff *oskb, void *data)
 			return;
 	} else {
 		this_cpu_ptr(ro->uniq)->skb = oskb;
-		this_cpu_ptr(ro->uniq)->hash = oskb->hash;
+		this_cpu_ptr(ro->uniq)->can_skb_uid = csx->can_skb_uid;
 		this_cpu_ptr(ro->uniq)->join_rx_count = 1;
 		/* drop first frame to check all enabled filters? */
 		if (ro->join_filters && ro->count > 1)
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [PATCH net 06/16] can: isotp: check the frame type, not just the length
  2026-09-29 20:43 [PATCH net 0/16] pull-request: can 2026-09-29 Marc Kleine-Budde
                   ` (4 preceding siblings ...)
  2026-09-29 20:43 ` [PATCH net 05/16] can: fix unique skb identifier regression under RPS Marc Kleine-Budde
@ 2026-09-29 20:43 ` Marc Kleine-Budde
  2026-09-29 20:43 ` [PATCH net 07/16] can: m_can: pci: add missing pm_runtime_dont_use_autosuspend() call Marc Kleine-Budde
                   ` (11 subsequent siblings)
  17 siblings, 0 replies; 32+ messages in thread
From: Marc Kleine-Budde @ 2026-09-29 20:43 UTC (permalink / raw)
  To: netdev
  Cc: davem, kuba, linux-can, kernel, Kaixuan Li, Oliver Hartkopp,
	Quchaosheng, stable, Marc Kleine-Budde

From: Kaixuan Li <kaixuanli0131@gmail.com>

isotp_rcv() separates Classic CAN from CAN FD by skb->len alone:

	if (skb->len != so->ll.mtu)
		return;

	cf = (struct canfd_frame *)skb->data;

A CAN XL frame with cxl->len 4 is CAN_MTU bytes, so it passes, and is then
read as a canfd_frame whose len comes out of canxl_frame.flags: at least
0x80.

Of the paths that follow, only the flow control one uses that length
without bounding it first, so check_pad() walks to 255 over a 16-byte
frame and the caller reports EBADMSG on an unrelated socket.

bcm_rx_handler(), j1939_can_recv(), can_can_gw_rcv() and raw_rcv() check
the frame type here, and can_dropped_invalid_skb() switches on
skb->protocol on the transmit side. isotp_rcv() is the gap.

Fixes: fb08cba12b52 ("can: canxl: update CAN infrastructure for CAN XL frames")
Signed-off-by: Kaixuan Li <kaixuanli0131@gmail.com>
Reviewed-by: Oliver Hartkopp <socketcan@hartkopp.net>
Acked-by: Oliver Hartkopp <socketcan@hartkopp.net>
Reviewed-by: Quchaosheng <quchaosheng000406@163.com>
Link: https://patch.msgid.link/20260920035626.2581040-1-kaixuanli0131@gmail.com
Cc: stable@vger.kernel.org
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
---
 net/can/isotp.c | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/net/can/isotp.c b/net/can/isotp.c
index 860c5221e299..e2dc10c5d11e 100644
--- a/net/can/isotp.c
+++ b/net/can/isotp.c
@@ -756,6 +756,14 @@ static void isotp_rcv(struct sk_buff *skb, void *data)
 	if (skb->len != so->ll.mtu)
 		return;
 
+	/* check for correct CAN CC/FD frame content */
+	if (so->ll.mtu == CAN_MTU) {
+		if (!can_is_can_skb(skb))
+			return;
+	} else if (!can_is_canfd_skb(skb)) {
+		return;
+	}
+
 	cf = (struct canfd_frame *)skb->data;
 
 	/* if enabled: check reception of my configured extended address */
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [PATCH net 07/16] can: m_can: pci: add missing pm_runtime_dont_use_autosuspend() call
  2026-09-29 20:43 [PATCH net 0/16] pull-request: can 2026-09-29 Marc Kleine-Budde
                   ` (5 preceding siblings ...)
  2026-09-29 20:43 ` [PATCH net 06/16] can: isotp: check the frame type, not just the length Marc Kleine-Budde
@ 2026-09-29 20:43 ` Marc Kleine-Budde
  2026-09-29 20:43 ` [PATCH net 08/16] can: xilinx_can: set CAN FD flags on received frames Marc Kleine-Budde
                   ` (10 subsequent siblings)
  17 siblings, 0 replies; 32+ messages in thread
From: Marc Kleine-Budde @ 2026-09-29 20:43 UTC (permalink / raw)
  To: netdev
  Cc: davem, kuba, linux-can, kernel, Joshua Crofts,
	Markus Schneider-Pargmann, stable, Marc Kleine-Budde

From: Joshua Crofts <joshua.crofts1@gmail.com>

m_can_pci_remove() forgets to call pm_runtime_dont_use_autosuspend() on
teardown, even though autosuspend is enabled in m_can_pci_probe().

Add the missing function call.

Signed-off-by: Joshua Crofts <joshua.crofts1@gmail.com>
Acked-by: Markus Schneider-Pargmann <msp@baylibre.com>
Fixes: cab7ffc0324f ("can: m_can: add PCI glue driver for Intel Elkhart Lake")
Link: https://patch.msgid.link/20260916124236.1389-1-joshua.crofts1@gmail.com
Cc: stable@vger.kernel.org
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
---
 drivers/net/can/m_can/m_can_pci.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/net/can/m_can/m_can_pci.c b/drivers/net/can/m_can/m_can_pci.c
index d11a7c88fc32..3c595749b5c7 100644
--- a/drivers/net/can/m_can/m_can_pci.c
+++ b/drivers/net/can/m_can/m_can_pci.c
@@ -159,6 +159,7 @@ static void m_can_pci_remove(struct pci_dev *pci)
 	struct m_can_pci_priv *priv = cdev_to_priv(mcan_class);
 
 	pm_runtime_forbid(&pci->dev);
+	pm_runtime_dont_use_autosuspend(&pci->dev);
 	pm_runtime_get_noresume(&pci->dev);
 
 	/* Disable interrupt control at CAN wrapper IP */
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [PATCH net 08/16] can: xilinx_can: set CAN FD flags on received frames
  2026-09-29 20:43 [PATCH net 0/16] pull-request: can 2026-09-29 Marc Kleine-Budde
                   ` (6 preceding siblings ...)
  2026-09-29 20:43 ` [PATCH net 07/16] can: m_can: pci: add missing pm_runtime_dont_use_autosuspend() call Marc Kleine-Budde
@ 2026-09-29 20:43 ` Marc Kleine-Budde
  2026-09-29 20:43 ` [PATCH net 09/16] can: mcp251xfd: mcp251xfd_probe(): reject devices without match data Marc Kleine-Budde
                   ` (9 subsequent siblings)
  17 siblings, 0 replies; 32+ messages in thread
From: Marc Kleine-Budde @ 2026-09-29 20:43 UTC (permalink / raw)
  To: netdev
  Cc: davem, kuba, linux-can, kernel, Maximilian Zimmermann, stable,
	Marc Kleine-Budde

From: Maximilian Zimmermann <maxz@spacecubics.com>

The Xilinx CAN FD controller reports the bit rate switch (BRS) and error
state indicator (ESI) in the receive buffer DLC register. The receive
path currently uses this register to determine frame format and payload
length, but does not set BRS and ESI in struct canfd_frame::flags.

This results in applications being unable to receive the BRS and ESI
flags, even when the controller correctly received them.

Add the ESI register mask and copy the controller flags to the
corresponding SocketCAN canfd_frame struct.

Fixes: c223da689324 ("can: xilinx_can: Add support for CANFD FD frames")
Cc: stable@vger.kernel.org
Signed-off-by: Maximilian Zimmermann <maxz@spacecubics.com>
Link: https://patch.msgid.link/20260921-fix-xilinx-canfd-flags-v1-1-a371c90b4e7c@spacecubics.com
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
---
 drivers/net/can/xilinx_can.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/drivers/net/can/xilinx_can.c b/drivers/net/can/xilinx_can.c
index 43d7f22820b8..52661e088205 100644
--- a/drivers/net/can/xilinx_can.c
+++ b/drivers/net/can/xilinx_can.c
@@ -157,6 +157,7 @@ enum xcan_reg {
 #define XCAN_2_FSR_RI_MASK		0x0000003F /* RX Read Index */
 #define XCAN_DLCR_EDL_MASK		0x08000000 /* EDL Mask in DLC */
 #define XCAN_DLCR_BRS_MASK		0x04000000 /* BRS Mask in DLC */
+#define XCAN_DLCR_ESI_MASK		0x02000000 /* ESI Mask in DLC */
 #define XCAN_ECC_CFG_REECRX_MASK	BIT(2) /* Reset RX FIFO ECC error counters */
 #define XCAN_ECC_CFG_REECTXOL_MASK	BIT(1) /* Reset TXOL FIFO ECC error counters */
 #define XCAN_ECC_CFG_REECTXTL_MASK	BIT(0) /* Reset TXTL FIFO ECC error counters */
@@ -959,6 +960,11 @@ static int xcanfd_rx(struct net_device *ndev, int frame_base)
 
 	/* Check the frame received is FD or not*/
 	if (dlc & XCAN_DLCR_EDL_MASK) {
+		if (dlc & XCAN_DLCR_BRS_MASK)
+			cf->flags |= CANFD_BRS;
+		if (dlc & XCAN_DLCR_ESI_MASK)
+			cf->flags |= CANFD_ESI;
+
 		for (i = 0; i < cf->len; i += 4) {
 			dw_offset = XCANFD_FRAME_DW_OFFSET(frame_base) +
 					(dwindex * XCANFD_DW_BYTES);
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [PATCH net 09/16] can: mcp251xfd: mcp251xfd_probe(): reject devices without match data
  2026-09-29 20:43 [PATCH net 0/16] pull-request: can 2026-09-29 Marc Kleine-Budde
                   ` (7 preceding siblings ...)
  2026-09-29 20:43 ` [PATCH net 08/16] can: xilinx_can: set CAN FD flags on received frames Marc Kleine-Budde
@ 2026-09-29 20:43 ` Marc Kleine-Budde
  2026-09-29 20:44 ` [PATCH net 10/16] usb: f81604: fix struct f81604_int_data size mismatch Marc Kleine-Budde
                   ` (8 subsequent siblings)
  17 siblings, 0 replies; 32+ messages in thread
From: Marc Kleine-Budde @ 2026-09-29 20:43 UTC (permalink / raw)
  To: netdev; +Cc: davem, kuba, linux-can, kernel, Jiale Yao, Marc Kleine-Budde

From: Jiale Yao <yaojiale02@163.com>

A device bound through driver_override need not match an entry in the
driver tables. In that case spi_get_device_match_data() returns NULL, but
mcp251xfd_probe() dereferences the result while copying the device type
data.

Reject devices without match data before continuing probe.

Fixes: 9cdae370c4ec ("can: mcp251xfd: simplify with spi_get_device_match_data()")
Signed-off-by: Jiale Yao <yaojiale02@163.com>
Link: https://patch.msgid.link/20260925133716.2230252-1-yaojiale02@163.com
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
---
 drivers/net/can/spi/mcp251xfd/mcp251xfd-core.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/drivers/net/can/spi/mcp251xfd/mcp251xfd-core.c b/drivers/net/can/spi/mcp251xfd/mcp251xfd-core.c
index f441f2265299..8759bc05bd8f 100644
--- a/drivers/net/can/spi/mcp251xfd/mcp251xfd-core.c
+++ b/drivers/net/can/spi/mcp251xfd/mcp251xfd-core.c
@@ -2213,6 +2213,7 @@ MODULE_DEVICE_TABLE(spi, mcp251xfd_id_table);
 
 static int mcp251xfd_probe(struct spi_device *spi)
 {
+	const struct mcp251xfd_devtype_data *devtype_data;
 	struct net_device *ndev;
 	struct mcp251xfd_priv *priv;
 	struct gpio_desc *rx_int;
@@ -2222,6 +2223,10 @@ static int mcp251xfd_probe(struct spi_device *spi)
 	u32 freq = 0;
 	int err;
 
+	devtype_data = spi_get_device_match_data(spi);
+	if (!devtype_data)
+		return -ENODATA;
+
 	if (!spi->irq)
 		return dev_err_probe(&spi->dev, -ENXIO,
 				     "No IRQ specified (maybe node \"interrupts-extended\" in DT missing)!\n");
@@ -2307,7 +2312,7 @@ static int mcp251xfd_probe(struct spi_device *spi)
 	priv->reg_vdd = reg_vdd;
 	priv->reg_xceiver = reg_xceiver;
 	priv->xstbyen = device_property_present(&spi->dev, "microchip,xstbyen");
-	priv->devtype_data = *(struct mcp251xfd_devtype_data *)spi_get_device_match_data(spi);
+	priv->devtype_data = *devtype_data;
 
 	/* Errata Reference:
 	 * mcp2517fd: DS80000792C 5., mcp2518fd: DS80000789E 4.,
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [PATCH net 10/16] usb: f81604: fix struct f81604_int_data size mismatch
  2026-09-29 20:43 [PATCH net 0/16] pull-request: can 2026-09-29 Marc Kleine-Budde
                   ` (8 preceding siblings ...)
  2026-09-29 20:43 ` [PATCH net 09/16] can: mcp251xfd: mcp251xfd_probe(): reject devices without match data Marc Kleine-Budde
@ 2026-09-29 20:44 ` Marc Kleine-Budde
  2026-09-29 20:44 ` [PATCH net 11/16] can: gs_usb: kill RX URBs before destroying the netdevs Marc Kleine-Budde
                   ` (7 subsequent siblings)
  17 siblings, 0 replies; 32+ messages in thread
From: Marc Kleine-Budde @ 2026-09-29 20:44 UTC (permalink / raw)
  To: netdev
  Cc: davem, kuba, linux-can, kernel, Ji-Ze Hong (Peter Hong), stable,
	Dynetrex, Admin, Greg Kroah-Hartman, Drew Willey,
	Marc Kleine-Budde

From: "Ji-Ze Hong (Peter Hong)" <peter_hong@fintek.com.tw>

The struct f81604_int_data defines 9 bytes of interrupt data:
- Byte 0: Status register (sr)
- Byte 1: Interrupt register (isrc)
- Byte 2: Interrupt enable register (ier)
- Byte 3: Arbitration lost capture (alc)
- Byte 4: Error code capture (ecc)
- Byte 5: Error warning limit register (ewlr)
- Byte 6: RX error counter (rxerr)
- Byte 7: TX error counter (txerr)
- Byte 8: Reserved (val)

The hardware sends exactly 9 bytes for the interrupt endpoint.
However, the struct was defined with __aligned(4) attribute which
caused the compiler to pad the struct to 12 bytes.

This causes a problem in f81604_read_int_callback() where the short
URB check compares urb->actual_length against sizeof(*data). When
sizeof(struct f81604_int_data) is 12 but the hardware only sends 9
bytes, the check fails and valid interrupt messages are discarded.

This results in the driver only being able to transmit once because
the TX complete interrupt is never processed.

Fix this by removing the __aligned(4) attribute so the struct size
matches the actual hardware data size of 9 bytes.

Fixes: 7299b1b39a25 ("can: usb: f81604: handle short interrupt urb messages properly")
Cc: stable@vger.kernel.org
Reported-by: Dynetrex, Admin <admin@dynetrex.com>
Closes: https://lore.kernel.org/all/A3834A07-5639-4779-844F-C5843DFC3928@dynetrex.com/
Signed-off-by: Ji-Ze Hong (Peter Hong) <peter_hong@fintek.com.tw>
Acked-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Tested-by: Drew Willey <dwilley@google.com>
Link: https://patch.msgid.link/20260824-f81604-fix-v2-1-fc9be5581394@fintek.com.tw
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
---
 drivers/net/can/usb/f81604.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/can/usb/f81604.c b/drivers/net/can/usb/f81604.c
index f12318268e46..4c147b9d6d69 100644
--- a/drivers/net/can/usb/f81604.c
+++ b/drivers/net/can/usb/f81604.c
@@ -169,7 +169,7 @@ struct f81604_int_data {
 	u8 rxerr;
 	u8 txerr;
 	u8 val;
-} __packed __aligned(4);
+} __packed;
 
 struct f81604_sff {
 	__be16 id;
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [PATCH net 11/16] can: gs_usb: kill RX URBs before destroying the netdevs
  2026-09-29 20:43 [PATCH net 0/16] pull-request: can 2026-09-29 Marc Kleine-Budde
                   ` (9 preceding siblings ...)
  2026-09-29 20:44 ` [PATCH net 10/16] usb: f81604: fix struct f81604_int_data size mismatch Marc Kleine-Budde
@ 2026-09-29 20:44 ` Marc Kleine-Budde
  2026-09-29 20:44 ` [PATCH net 12/16] can: gs_usb: add workarounds for HScanT USB to CAN adapter Marc Kleine-Budde
                   ` (6 subsequent siblings)
  17 siblings, 0 replies; 32+ messages in thread
From: Marc Kleine-Budde @ 2026-09-29 20:44 UTC (permalink / raw)
  To: netdev
  Cc: davem, kuba, linux-can, kernel, Fan Wu, stable, Song Li,
	Marc Kleine-Budde

From: Fan Wu <fanwu01@zju.edu.cn>

gs_usb_disconnect() destroys the channels one by one via
gs_destroy_candev()/free_candev(). gs_can_close() disposes the RX bulk URBs
on the shared parent->rx_submitted anchor only when the last active channel
is closed. With two or more channels up, the earlier channels are freed
while their RX URBs are still submitted, and a completion in
gs_usb_receive_bulk_callback() accesses the freed struct gs_can and struct
net_device.

Fix this by killing the anchored RX URBs in gs_usb_disconnect() before the
first netdev is destroyed, and in the error path of gs_usb_probe() before
the previously created netdevs are destroyed.

usb_kill_anchored_urbs() waits for running completions and a killed URB
completes with -ENOENT, so the completion handler returns without
resubmitting the URB. The kill in gs_can_close() of the last active channel
then operates on an already empty anchor.

This issue was found by an in-house static analysis tool.

Fixes: d08e973a77d1 ("can: gs_usb: Added support for the GS_USB CAN devices")
Cc: stable@vger.kernel.org
Co-developed-by: Song Li <songl@zju.edu.cn>
Signed-off-by: Song Li <songl@zju.edu.cn>
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Link: https://patch.msgid.link/20260923070352.487595-1-fanwu01@zju.edu.cn
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
---
 drivers/net/can/usb/gs_usb.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/net/can/usb/gs_usb.c b/drivers/net/can/usb/gs_usb.c
index 3b9b2f104d86..f604358c8259 100644
--- a/drivers/net/can/usb/gs_usb.c
+++ b/drivers/net/can/usb/gs_usb.c
@@ -1595,10 +1595,10 @@ static int gs_usb_probe(struct usb_interface *intf,
 
 			/* on failure destroy previously created candevs */
 			icount = i;
+			usb_kill_anchored_urbs(&parent->rx_submitted);
 			for (i = 0; i < icount; i++)
 				gs_destroy_candev(parent->canch[i]);
 
-			usb_kill_anchored_urbs(&parent->rx_submitted);
 			kfree(parent);
 			return rc;
 		}
@@ -1636,6 +1636,8 @@ static void gs_usb_disconnect(struct usb_interface *intf)
 		return;
 	}
 
+	usb_kill_anchored_urbs(&parent->rx_submitted);
+
 	for (i = 0; i < parent->channel_cnt; i++)
 		if (parent->canch[i])
 			gs_destroy_candev(parent->canch[i]);
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [PATCH net 12/16] can: gs_usb: add workarounds for HScanT USB to CAN adapter
  2026-09-29 20:43 [PATCH net 0/16] pull-request: can 2026-09-29 Marc Kleine-Budde
                   ` (10 preceding siblings ...)
  2026-09-29 20:44 ` [PATCH net 11/16] can: gs_usb: kill RX URBs before destroying the netdevs Marc Kleine-Budde
@ 2026-09-29 20:44 ` Marc Kleine-Budde
  2026-09-29 20:44 ` [PATCH net 13/16] can: kvaser_usb: validate command format before parsing in hydra receive path Marc Kleine-Budde
                   ` (5 subsequent siblings)
  17 siblings, 0 replies; 32+ messages in thread
From: Marc Kleine-Budde @ 2026-09-29 20:44 UTC (permalink / raw)
  To: netdev; +Cc: davem, kuba, linux-can, kernel, Marc Kleine-Budde, stable

The HScanT [1] is a RISC-V based USB to 4 channels CAN-FD adapter, which is
compatible with the gs_usb protocol.

The device is shipped with firmware version 0x00010007 and needs several
quirks to work properly.

The HScanT FW announces 5 channels, but the hardware has only 4. Workaround
the problem by changing the struct gs_device_config::icount to 3, which
corresponds to 4 channels.

The HScanT FW requires a USB High Speed Hub, bail out if device is
connected to slower USB Hub.

The HScanT FW always sends USB In URB with length 512 bytes and seems to
have broken Zero Packet Length handling. Add quirk
GS_CAN_FEATURE_QUIRK_HSCANT_URB_SIZE to allocate URBs of 513 bytes to work
around these issues.

This driver supports up to 256 channels per USB Interface. The HScanT
device has 4 channels, but the FW requires each channels to be bound to a
USB interface using the GS_USB_BREQ_HSCANT_SET_INTERFACENUMBER_ENDPOINT USB
request. Add quirk to GS_CAN_FEATURE_QUIRK_HSCANT_BIND_CHANNEL to bind the
CAN channel to the USB Interface 0 during gs_can_open()

Link: https://github.com/cherry-embedded/HSCanT-hardware
Link: https://patch.msgid.link/20260928-gs_usb-hscant-v2-1-a7c1c02460e9@pengutronix.de
Cc: stable@vger.kernel.org
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
---
 drivers/net/can/usb/gs_usb.c | 125 +++++++++++++++++++++++++++++++++--
 1 file changed, 121 insertions(+), 4 deletions(-)

diff --git a/drivers/net/can/usb/gs_usb.c b/drivers/net/can/usb/gs_usb.c
index f604358c8259..f7a349902c42 100644
--- a/drivers/net/can/usb/gs_usb.c
+++ b/drivers/net/can/usb/gs_usb.c
@@ -72,6 +72,7 @@ enum gs_usb_breq {
 	GS_USB_BREQ_SET_TERMINATION,
 	GS_USB_BREQ_GET_TERMINATION,
 	GS_USB_BREQ_GET_STATE,
+	GS_USB_BREQ_HSCANT_SET_INTERFACENUMBER_ENDPOINT = 17,
 };
 
 enum gs_can_mode {
@@ -188,6 +189,21 @@ struct gs_device_termination_state {
 
 /* internal quirks - keep in GS_CAN_FEATURE space for now */
 
+/* HScanT firmware version 0x00010007:
+ * - FW requires the binding of CAN channels to USB Interfaces.
+ * - Route all CAN channels to USB Interface 0.
+ */
+#define GS_CAN_FEATURE_QUIRK_HSCANT_BIND_CHANNEL BIT(29)
+
+/* HScanT firmware version 0x00010007:
+ * - FW sends bulk In URBs with length of 512 bytes.
+ * - When using In URBs with 512 bytes it will send a second in URB with length 0
+ *   It seems the ZLP handling is broken.
+ * - Use In URBs of length GS_USB_QUIRK_HSCANT_IN_URB_SIZE as a workaround.
+ */
+#define GS_CAN_FEATURE_QUIRK_HSCANT_URB_SIZE BIT(30)
+#define GS_USB_QUIRK_HSCANT_IN_URB_SIZE (513)
+
 /* CANtact Pro original firmware:
  * BREQ DATA_BITTIMING overlaps with GET_USER_ID
  */
@@ -812,6 +828,18 @@ static int gs_usb_set_data_bittiming(struct gs_can *dev)
 				    GFP_KERNEL);
 }
 
+static int gs_usb_hscant_bind_channel_to_interface(const struct gs_can *dev)
+{
+	const u16 interface_number = 0;
+
+	/* Bind dev->channel to interface_number */
+	return usb_control_msg_send(dev->udev, 0, GS_USB_BREQ_HSCANT_SET_INTERFACENUMBER_ENDPOINT,
+				    USB_DIR_OUT | USB_TYPE_VENDOR | USB_RECIP_INTERFACE,
+				    dev->channel, interface_number,
+				    NULL, 0, 1000,
+				    GFP_KERNEL);
+}
+
 static void gs_usb_xmit_callback(struct urb *urb)
 {
 	struct gs_tx_context *txc = urb->context;
@@ -1069,6 +1097,16 @@ static int gs_can_open(struct net_device *netdev)
 		}
 	}
 
+	if (dev->feature & GS_CAN_FEATURE_QUIRK_HSCANT_BIND_CHANNEL) {
+		rc = gs_usb_hscant_bind_channel_to_interface(dev);
+		if (rc) {
+			netdev_err(netdev,
+				   "failed to bind Channel to Interface: %pe\n",
+				   ERR_PTR(rc));
+			goto out_usb_kill_anchored_urbs;
+		}
+	}
+
 	/* finally start device */
 	dev->can.state = CAN_STATE_ERROR_ACTIVE;
 	dm.flags = cpu_to_le32(flags);
@@ -1314,6 +1352,49 @@ static const u16 gs_usb_termination_const[] = {
 	GS_USB_TERMINATION_ENABLED
 };
 
+static bool gs_usb_is_hscant(const struct usb_device *udev,
+			     const struct gs_device_config *dconf,
+			     const u32 sw_version)
+{
+	if (udev->descriptor.idVendor != cpu_to_le16(USB_GS_USB_1_VENDOR_ID) ||
+	    udev->descriptor.idProduct != cpu_to_le16(USB_GS_USB_1_PRODUCT_ID))
+		return false;
+
+	if (strcmp(udev->manufacturer, "HScanT") ||
+	    strcmp(udev->product, "HScanT USB to CAN adapter"))
+		return false;
+
+	if (dconf->sw_version != cpu_to_le32(sw_version))
+		return false;
+
+	return true;
+}
+
+static void
+gs_usb_make_candev_get_feature(struct gs_can *dev, const struct gs_device_config *dconf,
+			       const struct gs_device_bt_const *bt_const)
+{
+	const struct usb_device *udev = dev->udev;
+	const u32 feature = le32_to_cpu(bt_const->feature);
+
+	dev->feature = FIELD_GET(GS_CAN_FEATURE_MASK, feature);
+
+	if (!udev->manufacturer || !udev->product)
+		return;
+
+	/* HScanT firmware version 0x00010007:
+	 * - FW doesn't advertise GS_CAN_FEATURE_BT_CONST_EXT,
+	 *   but implements GS_USB_BREQ_BT_CONST_EXT, fixup.
+	 * - FW requires binding of CAN channel to USB Interface, add quirk.
+	 * - FW requires bulk In URBs with >= 512 bytes, add quirk.
+	 */
+	if (gs_usb_is_hscant(udev, dconf, 0x00010007)) {
+		dev->feature |= GS_CAN_FEATURE_BT_CONST_EXT |
+			GS_CAN_FEATURE_QUIRK_HSCANT_BIND_CHANNEL |
+			GS_CAN_FEATURE_QUIRK_HSCANT_URB_SIZE;
+	}
+}
+
 static struct gs_can *gs_make_candev(unsigned int channel,
 				     struct usb_interface *intf,
 				     struct gs_device_config *dconf)
@@ -1385,8 +1466,9 @@ static struct gs_can *gs_make_candev(unsigned int channel,
 
 	dev->can.ctrlmode_supported = CAN_CTRLMODE_CC_LEN8_DLC;
 
-	feature = le32_to_cpu(bt_const.feature);
-	dev->feature = FIELD_GET(GS_CAN_FEATURE_MASK, feature);
+	gs_usb_make_candev_get_feature(dev, dconf, &bt_const);
+	feature = dev->feature;
+
 	if (feature & GS_CAN_FEATURE_LISTEN_ONLY)
 		dev->can.ctrlmode_supported |= CAN_CTRLMODE_LISTENONLY;
 
@@ -1514,6 +1596,34 @@ static void gs_destroy_candev(struct gs_can *dev)
 	free_candev(dev->netdev);
 }
 
+static int gs_usb_probe_quirks(const struct usb_interface *intf, struct gs_device_config *dconf)
+{
+	const struct usb_device *udev = interface_to_usbdev(intf);
+
+	if (!udev->manufacturer || !udev->product)
+		return 0;
+
+	/* HScanT firmware version 0x00010007:
+	 * - FW has an icount of 4, which corresponds to 5 CAN interfaces.
+	 *   The hardware has only 4 interfaces, fixup.
+	 * - FW provides broken Endpoint Descriptors on USB Full Speed Hubs:
+	 *   config 1 interface 0 altsetting 0 endpoint 0x4 has invalid maxpacket 512, setting to 64
+	 *   Probably related to GS_CAN_FEATURE_QUIRK_HSCANT_URB_SIZE,
+	 *   FW only works on USB High Speed Hubs, detect and bail out.
+	 */
+	if (gs_usb_is_hscant(udev, dconf, 0x00010007)) {
+		if (dconf->icount == 4)
+			dconf->icount = 3;
+
+		if (udev->speed < USB_SPEED_HIGH) {
+			dev_err(&intf->dev, "Device only works with USB High Speed Hubs\n");
+			return -ENODEV;
+		}
+	}
+
+	return 0;
+}
+
 static int gs_usb_probe(struct usb_interface *intf,
 			const struct usb_device_id *id)
 {
@@ -1560,6 +1670,10 @@ static int gs_usb_probe(struct usb_interface *intf,
 		return rc;
 	}
 
+	rc = gs_usb_probe_quirks(intf, &dconf);
+	if (rc)
+		return rc;
+
 	icount = dconf.icount + 1;
 	dev_info(&intf->dev, "Configuring for %u interfaces\n", icount);
 
@@ -1604,10 +1718,13 @@ static int gs_usb_probe(struct usb_interface *intf,
 		}
 		parent->canch[i]->parent = parent;
 
-		/* set RX packet size based on FD and if hardware
+		/* set RX packet size based on quirks, FD and if hardware
 		 * timestamps are supported.
 		 */
-		if (parent->canch[i]->can.ctrlmode_supported & CAN_CTRLMODE_FD) {
+		if (parent->canch[i]->feature & GS_CAN_FEATURE_QUIRK_HSCANT_URB_SIZE) {
+			hf_size_rx = GS_USB_QUIRK_HSCANT_IN_URB_SIZE;
+			BUILD_BUG_ON(struct_size(hf, canfd, 1) > GS_USB_QUIRK_HSCANT_IN_URB_SIZE);
+		} else if (parent->canch[i]->can.ctrlmode_supported & CAN_CTRLMODE_FD) {
 			if (parent->canch[i]->feature & GS_CAN_FEATURE_HW_TIMESTAMP)
 				hf_size_rx = struct_size(hf, canfd_ts, 1);
 			else
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [PATCH net 13/16] can: kvaser_usb: validate command format before parsing in hydra receive path
  2026-09-29 20:43 [PATCH net 0/16] pull-request: can 2026-09-29 Marc Kleine-Budde
                   ` (11 preceding siblings ...)
  2026-09-29 20:44 ` [PATCH net 12/16] can: gs_usb: add workarounds for HScanT USB to CAN adapter Marc Kleine-Budde
@ 2026-09-29 20:44 ` Marc Kleine-Budde
  2026-09-29 20:44 ` [PATCH net 14/16] can: peak_usb: fix missing CAN_ERR_FLAG when reporting error counters Marc Kleine-Budde
                   ` (4 subsequent siblings)
  17 siblings, 0 replies; 32+ messages in thread
From: Marc Kleine-Budde @ 2026-09-29 20:44 UTC (permalink / raw)
  To: netdev
  Cc: davem, kuba, linux-can, kernel,
	Cen Zhang (Microsoft Security FORGE Labs), AutonomousCodeSecurity,
	Xiang Mei (Microsoft), stable, Marc Kleine-Budde

From: "Cen Zhang (Microsoft Security FORGE Labs)" <cenzhang@linux.microsoft.com>

The receive-path command parsers (kvaser_usb_hydra_wait_cmd and
kvaser_usb_hydra_read_bulk_callback) call kvaser_usb_hydra_cmd_size()
without verifying that enough buffer remains. For CMD_EXTENDED,
kvaser_usb_hydra_cmd_size() unconditionally reads a 2-byte len field
at offset 4. A malicious USB device can place a CMD_EXTENDED header at
the end of a 3072-byte bulk transfer such that only 4 bytes remain,
causing a 2-byte slab-out-of-bounds read.

  BUG: KASAN: slab-out-of-bounds in kvaser_usb_hydra_wait_cmd+0x3f1/0x480
    [kvaser_usb_hydra.c:678]
  Read of size 2 at addr ffff888013f7ec00 by task kworker/0:0/9
   kvaser_usb_hydra_wait_cmd+0x3f1/0x480
   kvaser_usb_hydra_get_software_details+0x1c7/0x5d0
   kvaser_usb_probe+0x36a/0x1240

Additionally, if the device sends CMD_EXTENDED with len=0,
kvaser_usb_hydra_cmd_size() returns 0 and the parser loops forever
(pos += 0), permanently burning one CPU core.

A positive but undersized extended length can also pass the buffer extent
check and reach a handler. For example, an 8-byte CMD_RX_MESSAGE_FD at
the end of an RX URB causes kvaser_usb_hydra_rx_msg_ext() to read fixed
fields and payload past the buffer.

Add receive-side length validation which preserves incomplete headers for
reassembly, rejects extended lengths outside 8..128 bytes, and checks each
known extended command against the minimum length its handler consumes.
For CMD_RX_MESSAGE_FD, derive the required length from its flags and DLC
so valid variable-length commands remain accepted. Apply the checks to
both receive paths and clear malformed leftover state before returning.

Fixes: aec5fb2268b7 ("can: kvaser_usb: Add support for Kvaser USB hydra family")
Reported-by: AutonomousCodeSecurity@microsoft.com
Reported-by: Xiang Mei (Microsoft) <xmei5@asu.edu>
Suggested-by: Jakub Kicinski <kuba@kernel.org>
Closes: https://lore.kernel.org/all/20260819145658.29872-1-blbllhy@gmail.com
Cc: stable@vger.kernel.org
Signed-off-by: Cen Zhang (Microsoft Security FORGE Labs) <cenzhang@linux.microsoft.com>
Link: https://patch.msgid.link/20260910135000.34796-1-cenzhang@linux.microsoft.com
[mkl: reduce scope of err in kvaser_usb_hydra_read_bulk_callback()]
[mkl: increase readability, reformat to make use of ~100 columns]
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
---
 .../net/can/usb/kvaser_usb/kvaser_usb_hydra.c | 135 +++++++++++++++++-
 1 file changed, 128 insertions(+), 7 deletions(-)

diff --git a/drivers/net/can/usb/kvaser_usb/kvaser_usb_hydra.c b/drivers/net/can/usb/kvaser_usb/kvaser_usb_hydra.c
index efbb7bed34c9..43405b1b6a3c 100644
--- a/drivers/net/can/usb/kvaser_usb/kvaser_usb_hydra.c
+++ b/drivers/net/can/usb/kvaser_usb/kvaser_usb_hydra.c
@@ -536,6 +536,82 @@ static size_t kvaser_usb_hydra_cmd_size(struct kvaser_cmd *cmd)
 	return ret;
 }
 
+/* -EAGAIN means incomplete; -EINVAL rejects an invalid command length. */
+static int kvaser_usb_hydra_cmd_size_rx(struct kvaser_cmd *cmd,
+					size_t remaining, size_t *cmd_len)
+{
+	if (remaining < sizeof(cmd->header.cmd_no))
+		return -EAGAIN;
+
+	if (cmd->header.cmd_no == CMD_EXTENDED &&
+	    remaining < offsetof(struct kvaser_cmd_ext, cmd_no_ext))
+		return -EAGAIN;
+
+	*cmd_len = kvaser_usb_hydra_cmd_size(cmd);
+	if (cmd->header.cmd_no != CMD_EXTENDED)
+		return 0;
+
+	if (*cmd_len < offsetof(struct kvaser_cmd_ext, rx_can) ||
+	    *cmd_len > KVASER_USB_HYDRA_MAX_CMD_LEN)
+		return -EINVAL;
+
+	return 0;
+}
+
+static int kvaser_usb_hydra_verify_cmd_size(const struct kvaser_cmd *cmd,
+					    size_t cmd_len)
+{
+	const struct kvaser_cmd_ext *cmd_ext;
+	size_t min_len;
+
+	if (cmd->header.cmd_no != CMD_EXTENDED)
+		return 0;
+
+	cmd_ext = (const struct kvaser_cmd_ext *)cmd;
+
+	/* Keep this switch in sync with kvaser_usb_hydra_handle_cmd_ext(). */
+	switch (cmd_ext->cmd_no_ext) {
+	case CMD_TX_ACKNOWLEDGE_FD:
+		min_len = offsetof(struct kvaser_cmd_ext, tx_ack.timestamp) +
+			  sizeof(cmd_ext->tx_ack.timestamp);
+		break;
+
+	case CMD_RX_MESSAGE_FD: {
+		u32 flags;
+
+		min_len = offsetof(struct kvaser_cmd_ext, rx_can.kcan_payload);
+		if (cmd_len < min_len)
+			return -EINVAL;
+
+		flags = le32_to_cpu(cmd_ext->rx_can.flags);
+		if (flags & KVASER_USB_HYDRA_CF_FLAG_ERROR_FRAME) {
+			min_len += sizeof(cmd_ext->rx_can.err_frame_data);
+		} else if (!(flags & KVASER_USB_HYDRA_CF_FLAG_REMOTE_FRAME)) {
+			u32 kcan_header;
+			u8 dlc;
+
+			kcan_header = le32_to_cpu(cmd_ext->rx_can.kcan_header);
+			dlc = (kcan_header & KVASER_USB_KCAN_DATA_DLC_MASK) >>
+				KVASER_USB_KCAN_DATA_DLC_SHIFT;
+
+			if (flags & KVASER_USB_HYDRA_CF_FLAG_FDF)
+				min_len += can_fd_dlc2len(dlc);
+			else
+				min_len += can_cc_dlc2len(dlc);
+		}
+		break;
+	}
+
+	default:
+		return 0;
+	}
+
+	if (cmd_len < min_len)
+		return -EINVAL;
+
+	return 0;
+}
+
 static struct kvaser_usb_net_priv *
 kvaser_usb_hydra_net_priv_from_cmd(const struct kvaser_usb *dev,
 				   const struct kvaser_cmd *cmd)
@@ -675,8 +751,9 @@ static int kvaser_usb_hydra_wait_cmd(const struct kvaser_usb *dev, u8 cmd_no,
 			size_t cmd_len;
 
 			tmp_cmd = buf + pos;
-			cmd_len = kvaser_usb_hydra_cmd_size(tmp_cmd);
-			if (pos + cmd_len > actual_len) {
+			err = kvaser_usb_hydra_cmd_size_rx(tmp_cmd, actual_len - pos,&cmd_len);
+			if (err || pos + cmd_len > actual_len ||
+			    kvaser_usb_hydra_verify_cmd_size(tmp_cmd, cmd_len)) {
 				dev_err_ratelimited(&dev->intf->dev,
 						    "Format error\n");
 				break;
@@ -2120,27 +2197,60 @@ static void kvaser_usb_hydra_read_bulk_callback(struct kvaser_usb *dev,
 	spin_lock_irqsave(usb_rx_leftover_lock, irq_flags);
 	usb_rx_leftover_len = card_data->usb_rx_leftover_len;
 	if (usb_rx_leftover_len) {
+		const size_t cmd_size_field_end = offsetof(struct kvaser_cmd_ext, cmd_no_ext);
 		int remaining_bytes;
+		int err;
 
 		cmd = (struct kvaser_cmd *)card_data->usb_rx_leftover;
 
-		cmd_len = kvaser_usb_hydra_cmd_size(cmd);
+		if (cmd->header.cmd_no == CMD_EXTENDED &&
+		    usb_rx_leftover_len < cmd_size_field_end) {
+			remaining_bytes = min_t(int, len, cmd_size_field_end - usb_rx_leftover_len);
 
-		remaining_bytes = min_t(unsigned int, len,
+			memcpy(card_data->usb_rx_leftover + usb_rx_leftover_len, buf, remaining_bytes);
+			usb_rx_leftover_len += remaining_bytes;
+			card_data->usb_rx_leftover_len = usb_rx_leftover_len;
+			pos += remaining_bytes;
+
+			if (usb_rx_leftover_len < cmd_size_field_end) {
+				spin_unlock_irqrestore(usb_rx_leftover_lock,
+						       irq_flags);
+				return;
+			}
+		}
+
+		err = kvaser_usb_hydra_cmd_size_rx(cmd, usb_rx_leftover_len,
+						   &cmd_len);
+		if (err || cmd_len < usb_rx_leftover_len) {
+			dev_err(&dev->intf->dev, "Format error\n");
+			card_data->usb_rx_leftover_len = 0;
+			spin_unlock_irqrestore(usb_rx_leftover_lock, irq_flags);
+			return;
+		}
+
+		remaining_bytes = min_t(unsigned int, len - pos,
 					cmd_len - usb_rx_leftover_len);
 		/* Make sure we do not overflow usb_rx_leftover */
 		if (remaining_bytes + usb_rx_leftover_len >
 						KVASER_USB_HYDRA_MAX_CMD_LEN) {
 			dev_err(&dev->intf->dev, "Format error\n");
+			card_data->usb_rx_leftover_len = 0;
 			spin_unlock_irqrestore(usb_rx_leftover_lock, irq_flags);
 			return;
 		}
 
-		memcpy(card_data->usb_rx_leftover + usb_rx_leftover_len, buf,
+		memcpy(card_data->usb_rx_leftover + usb_rx_leftover_len, buf + pos,
 		       remaining_bytes);
 		pos += remaining_bytes;
 
 		if (remaining_bytes + usb_rx_leftover_len == cmd_len) {
+			if (kvaser_usb_hydra_verify_cmd_size(cmd, cmd_len)) {
+				dev_err(&dev->intf->dev, "Format error\n");
+				card_data->usb_rx_leftover_len = 0;
+				spin_unlock_irqrestore(usb_rx_leftover_lock, irq_flags);
+				return;
+			}
+
 			kvaser_usb_hydra_handle_cmd(dev, cmd);
 			usb_rx_leftover_len = 0;
 		} else {
@@ -2152,11 +2262,17 @@ static void kvaser_usb_hydra_read_bulk_callback(struct kvaser_usb *dev,
 	spin_unlock_irqrestore(usb_rx_leftover_lock, irq_flags);
 
 	while (pos < len) {
+		int err;
+
 		cmd = buf + pos;
 
-		cmd_len = kvaser_usb_hydra_cmd_size(cmd);
+		err = kvaser_usb_hydra_cmd_size_rx(cmd, len - pos, &cmd_len);
+		if (err && err != -EAGAIN) {
+			dev_err(&dev->intf->dev, "Format error\n");
+			return;
+		}
 
-		if (pos + cmd_len > len) {
+		if (err == -EAGAIN || pos + cmd_len > len) {
 			/* We got first part of a command */
 			int leftover_bytes;
 
@@ -2174,6 +2290,11 @@ static void kvaser_usb_hydra_read_bulk_callback(struct kvaser_usb *dev,
 			break;
 		}
 
+		if (kvaser_usb_hydra_verify_cmd_size(cmd, cmd_len)) {
+			dev_err(&dev->intf->dev, "Format error\n");
+			return;
+		}
+
 		kvaser_usb_hydra_handle_cmd(dev, cmd);
 		pos += cmd_len;
 	}
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [PATCH net 14/16] can: peak_usb: fix missing CAN_ERR_FLAG when reporting error counters
  2026-09-29 20:43 [PATCH net 0/16] pull-request: can 2026-09-29 Marc Kleine-Budde
                   ` (12 preceding siblings ...)
  2026-09-29 20:44 ` [PATCH net 13/16] can: kvaser_usb: validate command format before parsing in hydra receive path Marc Kleine-Budde
@ 2026-09-29 20:44 ` Marc Kleine-Budde
  2026-09-29 20:44 ` [PATCH net 15/16] can: rx-offload: add IRQ queue flush predicate Marc Kleine-Budde
                   ` (3 subsequent siblings)
  17 siblings, 0 replies; 32+ messages in thread
From: Marc Kleine-Budde @ 2026-09-29 20:44 UTC (permalink / raw)
  To: netdev
  Cc: davem, kuba, linux-can, kernel, Stefan Günther, stable,
	Marc Kleine-Budde

From: Stefan Günther <stefangun@pm.me>

When the device reports error counters, the driver incorrectly uses an
assignment (=) instead of a bitwise OR (|=) for CAN_ERR_CNT. This wipes
out the CAN_ERR_FLAG and CAN_ERR_CRTL flags, causing the error frame to
be sent to userspace as a regular CAN frame with ID 0x200.

Fix this by using a bitwise OR to preserve the flags.

Signed-off-by: Stefan Günther <stefangun@pm.me>
Link: https://patch.msgid.link/20260915134551.54038-1-stefangun@pm.me
Cc: stable@vger.kernel.org
Fixes: 3e5c291c7942 ("can: add CAN_ERR_CNT flag to notify availability of error counter")
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
---
 drivers/net/can/usb/peak_usb/pcan_usb.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/can/usb/peak_usb/pcan_usb.c b/drivers/net/can/usb/peak_usb/pcan_usb.c
index 8fd058c32856..785224e00c4e 100644
--- a/drivers/net/can/usb/peak_usb/pcan_usb.c
+++ b/drivers/net/can/usb/peak_usb/pcan_usb.c
@@ -526,7 +526,7 @@ static int pcan_usb_decode_error(struct pcan_usb_msg_context *mc, u8 n,
 			/* Supply TX/RX error counters in case of
 			 * controller error.
 			 */
-			cf->can_id = CAN_ERR_CNT;
+			cf->can_id |= CAN_ERR_CNT;
 			cf->data[6] = mc->pdev->bec.txerr;
 			cf->data[7] = mc->pdev->bec.rxerr;
 		}
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [PATCH net 15/16] can: rx-offload: add IRQ queue flush predicate
  2026-09-29 20:43 [PATCH net 0/16] pull-request: can 2026-09-29 Marc Kleine-Budde
                   ` (13 preceding siblings ...)
  2026-09-29 20:44 ` [PATCH net 14/16] can: peak_usb: fix missing CAN_ERR_FLAG when reporting error counters Marc Kleine-Budde
@ 2026-09-29 20:44 ` Marc Kleine-Budde
  2026-09-29 20:44 ` [PATCH net 16/16] can: mcp251xfd: flush RX offload queue during long IRQs Marc Kleine-Budde
                   ` (2 subsequent siblings)
  17 siblings, 0 replies; 32+ messages in thread
From: Marc Kleine-Budde @ 2026-09-29 20:44 UTC (permalink / raw)
  To: netdev; +Cc: davem, kuba, linux-can, kernel, Chris Strong, Marc Kleine-Budde

From: Chris Strong <chris.strong@flocksafety.com>

Drivers that queue received SKBs from a threaded interrupt may need to
publish a partial batch before the handler returns. The existing overflow
check covers only the NAPI-visible queue after the IRQ-local queue has been
spliced, so it cannot guide that decision.

Add can_rx_offload_irq_queue_needs_flush() to report when the IRQ-local
queue reaches the NAPI poll weight. Keep the query separate from the flush
operation so callers can finish processing related interrupt sources before
publishing the batch.

Assisted-by: LLM
Signed-off-by: Chris Strong <chris.strong@flocksafety.com>
Link: https://patch.msgid.link/20260929-upstream-can-rx-offload-batching-v2-1-3b587c519f5d@flocksafety.com
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
---
 include/linux/can/rx-offload.h | 7 +++++++
 1 file changed, 7 insertions(+)

diff --git a/include/linux/can/rx-offload.h b/include/linux/can/rx-offload.h
index d29bb4521947..f9b9474f7190 100644
--- a/include/linux/can/rx-offload.h
+++ b/include/linux/can/rx-offload.h
@@ -62,4 +62,11 @@ static inline void can_rx_offload_disable(struct can_rx_offload *offload)
 	napi_disable(&offload->napi);
 }
 
+static inline bool
+can_rx_offload_irq_queue_needs_flush(const struct can_rx_offload *offload)
+{
+	/* skb_irq_queue is owned by the interrupt context queuing the SKBs. */
+	return skb_queue_len(&offload->skb_irq_queue) >= offload->napi.weight;
+}
+
 #endif /* !_CAN_RX_OFFLOAD_H */
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* [PATCH net 16/16] can: mcp251xfd: flush RX offload queue during long IRQs
  2026-09-29 20:43 [PATCH net 0/16] pull-request: can 2026-09-29 Marc Kleine-Budde
                   ` (14 preceding siblings ...)
  2026-09-29 20:44 ` [PATCH net 15/16] can: rx-offload: add IRQ queue flush predicate Marc Kleine-Budde
@ 2026-09-29 20:44 ` Marc Kleine-Budde
  2026-10-01  8:40 ` [PATCH net 0/16] pull-request: can 2026-09-29 Paolo Abeni
  2026-10-01 15:28 ` Jakub Kicinski
  17 siblings, 0 replies; 32+ messages in thread
From: Marc Kleine-Budde @ 2026-09-29 20:44 UTC (permalink / raw)
  To: netdev; +Cc: davem, kuba, linux-can, kernel, Chris Strong, Marc Kleine-Budde

From: Chris Strong <chris.strong@flocksafety.com>

Under sustained receive traffic, the threaded interrupt handler can
continue draining the controller indefinitely. Received SKBs remain in
skb_irq_queue until the handler returns, but the overflow checks inspect
the NAPI-visible skb_queue instead. The IRQ-local queue can therefore grow
without bound while NAPI remains unscheduled, potentially exhausting
memory.

Stop the dedicated RX loop when the IRQ-local queue reaches the NAPI weight
so TEF and other pending interrupts are processed before publishing the
batch. Publish further batches from the main interrupt loop while the
controller remains busy. This bounds IRQ-local accumulation and keeps RX
and TEF timestamps from each controller-status pass in the same sort
window.

Fixes: c757096ea103 ("can: rx-offload: add skb queue for use during ISR")
Assisted-by: LLM
Signed-off-by: Chris Strong <chris.strong@flocksafety.com>
Link: https://patch.msgid.link/20260929-upstream-can-rx-offload-batching-v2-2-3b587c519f5d@flocksafety.com
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
---
 drivers/net/can/spi/mcp251xfd/mcp251xfd-core.c | 14 +++++++++++++-
 1 file changed, 13 insertions(+), 1 deletion(-)

diff --git a/drivers/net/can/spi/mcp251xfd/mcp251xfd-core.c b/drivers/net/can/spi/mcp251xfd/mcp251xfd-core.c
index 8759bc05bd8f..26d6a0d4b34b 100644
--- a/drivers/net/can/spi/mcp251xfd/mcp251xfd-core.c
+++ b/drivers/net/can/spi/mcp251xfd/mcp251xfd-core.c
@@ -1498,8 +1498,14 @@ static irqreturn_t mcp251xfd_irq(int irq, void *dev_id)
 			/* We don't know which RX-FIFO is pending, but only
 			 * handle the 1st RX-FIFO. Leave loop here if we have
 			 * more than 1 RX-FIFO to avoid starvation.
+			 *
+			 * Once the IRQ queue reaches the NAPI weight, process
+			 * TEF and other pending interrupts before publishing
+			 * the batch, keeping RX and TEF timestamps in the same
+			 * sort window.
 			 */
-		} while (priv->rx_ring_num == 1);
+		} while (priv->rx_ring_num == 1 &&
+			 !can_rx_offload_irq_queue_needs_flush(&priv->offload));
 
 	do {
 		u32 intf_pending, intf_pending_clearable;
@@ -1615,6 +1621,12 @@ static irqreturn_t mcp251xfd_irq(int irq, void *dev_id)
 			}
 		}
 
+		/* Keep each splice into the offload queue near one NAPI poll
+		 * budget when a busy controller keeps this handler running.
+		 */
+		if (can_rx_offload_irq_queue_needs_flush(&priv->offload))
+			can_rx_offload_threaded_irq_finish(&priv->offload);
+
 		handled = IRQ_HANDLED;
 	} while (1);
 
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 32+ messages in thread

* Re: [PATCH net 01/16] can: dev: can_dropped_invalid_skb: drop CAN XL frames on non-CAN XL devices
  2026-09-29 20:43 ` [PATCH net 01/16] can: dev: can_dropped_invalid_skb: drop CAN XL frames on non-CAN XL devices Marc Kleine-Budde
@ 2026-09-29 21:13   ` netdev-bot+sinfo
  0 siblings, 0 replies; 32+ messages in thread
From: netdev-bot+sinfo @ 2026-09-29 21:13 UTC (permalink / raw)
  To: Marc Kleine-Budde
  Cc: netdev, davem, kuba, linux-can, kernel, Vincent Mailhol, stable

Hi!

This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:

 - How the issue was discovered, e.g. hit in production, hit during
   development, syzbot report, manual code inspection, LLM or static
   analysis tool scan.

 - Whether the issue was actually triggered, or is only theoretical
   (e.g. found by code inspection). If it was triggered please include
   the symptoms, like the stack trace or error messages.

Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.

The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.

^ permalink raw reply	[flat|nested] 32+ messages in thread

* Re: [PATCH net 0/16] pull-request: can 2026-09-29
  2026-09-29 20:43 [PATCH net 0/16] pull-request: can 2026-09-29 Marc Kleine-Budde
                   ` (15 preceding siblings ...)
  2026-09-29 20:44 ` [PATCH net 16/16] can: mcp251xfd: flush RX offload queue during long IRQs Marc Kleine-Budde
@ 2026-10-01  8:40 ` Paolo Abeni
  2026-10-01  9:23   ` Oliver Hartkopp
  2026-10-01 15:28 ` Jakub Kicinski
  17 siblings, 1 reply; 32+ messages in thread
From: Paolo Abeni @ 2026-10-01  8:40 UTC (permalink / raw)
  To: Marc Kleine-Budde, netdev; +Cc: davem, kuba, linux-can, kernel

Hi,

On 9/29/26 22:43, Marc Kleine-Budde wrote:
> this is a pull request of 16 patches for net/main.
> 
> The first patch is by Vincent Mailhol and drops CAN-XL frames on non
> CAN-XL devices.
> 
> A patch by zjamg restores the skb header initialization lost during
> the v7.0 release cycle.
> 
> Oliver Hartkopp contributes 3 patches for the CAN net layer, the first
> one fixes the net namespace integration for BCM, ISOTP and the CAN RAW
> protocols. The second one converts the unreliable ARPHRD_CAN type
> check to the robust can_get_ml_priv(). The third one fixes the unique
> skb identifier regression under RPS, introduced in the v7.0 release
> cycle, which causes lost packets.
> 
> A patch by Joshua Crofts adds a missing
> pm_runtime_dont_use_autosuspend() to the m_can_pci driver.
> 
> Maximilian Zimmermann's patch for the xilinx CAN driver adds the
> setting the ESI and BSR flags in the receive path if they are active.
> 
> Jiale Yao's patch for the mcp251xfd driver rejects devices without
> match data.
> 
> Ji-Ze Hong fixes a struct size mismatch in the f81604 CAN driver.
> 
> The next patch is by me, targets the gs_usb driver and adds
> workarounds for the HScanT USB to CAN adapter.
> 
> Cen Zhang fixes a slab-out-of-bounds read access in the kvaser_usb
> driver.
> 
> A patch by Stefan Günther targets the peak_usb driver and fixes the
> CAN-ID when reporting CAN errors.
> 
> Chris Strong contributes 2 patches, to fix an out of memory and packet
> loss problem in the mcp251xfd CAN driver under sustained receive
> traffic.
Linus has started pushing back on the ever-increasing net RC PRs:

https://lore.kernel.org/netdev/CAHk-=wiSnTE9vBZ=5_v+3EEkdazCCbBM5YABRzRHUAeRdyd4Xw@mail.gmail.com/

We are trying to defer things to 'next', especially this late
in the cycle.

I think there are a few patches here eligible for that. i.e.

can: gs_usb: add workarounds for HScanT USB to CAN adapter
can: remove CAN filters independent from namespace
can: convert unreliable ARPHRD_CAN type checks to robust can_get_ml_priv()

WDYT? How much a pain would be shrinking this PR?

Thanks,

Paolo


^ permalink raw reply	[flat|nested] 32+ messages in thread

* Re: [PATCH net 0/16] pull-request: can 2026-09-29
  2026-10-01  8:40 ` [PATCH net 0/16] pull-request: can 2026-09-29 Paolo Abeni
@ 2026-10-01  9:23   ` Oliver Hartkopp
  2026-10-01 10:13     ` Paolo Abeni
  0 siblings, 1 reply; 32+ messages in thread
From: Oliver Hartkopp @ 2026-10-01  9:23 UTC (permalink / raw)
  To: Paolo Abeni, Marc Kleine-Budde, netdev; +Cc: davem, kuba, linux-can, kernel



On 01.10.26 10:40, Paolo Abeni wrote:
> Hi,
> 
> On 9/29/26 22:43, Marc Kleine-Budde wrote:
>> this is a pull request of 16 patches for net/main.
>>
>> The first patch is by Vincent Mailhol and drops CAN-XL frames on non
>> CAN-XL devices.
>>
>> A patch by zjamg restores the skb header initialization lost during
>> the v7.0 release cycle.
>>
>> Oliver Hartkopp contributes 3 patches for the CAN net layer, the first
>> one fixes the net namespace integration for BCM, ISOTP and the CAN RAW
>> protocols. The second one converts the unreliable ARPHRD_CAN type
>> check to the robust can_get_ml_priv(). The third one fixes the unique
>> skb identifier regression under RPS, introduced in the v7.0 release
>> cycle, which causes lost packets.
>>
>> A patch by Joshua Crofts adds a missing
>> pm_runtime_dont_use_autosuspend() to the m_can_pci driver.
>>
>> Maximilian Zimmermann's patch for the xilinx CAN driver adds the
>> setting the ESI and BSR flags in the receive path if they are active.
>>
>> Jiale Yao's patch for the mcp251xfd driver rejects devices without
>> match data.
>>
>> Ji-Ze Hong fixes a struct size mismatch in the f81604 CAN driver.
>>
>> The next patch is by me, targets the gs_usb driver and adds
>> workarounds for the HScanT USB to CAN adapter.
>>
>> Cen Zhang fixes a slab-out-of-bounds read access in the kvaser_usb
>> driver.
>>
>> A patch by Stefan Günther targets the peak_usb driver and fixes the
>> CAN-ID when reporting CAN errors.
>>
>> Chris Strong contributes 2 patches, to fix an out of memory and packet
>> loss problem in the mcp251xfd CAN driver under sustained receive
>> traffic.
> Linus has started pushing back on the ever-increasing net RC PRs:
> 
> https://lore.kernel.org/netdev/CAHk- 
> =wiSnTE9vBZ=5_v+3EEkdazCCbBM5YABRzRHUAeRdyd4Xw@mail.gmail.com/
> 
> We are trying to defer things to 'next', especially this late
> in the cycle.
> 
> I think there are a few patches here eligible for that. i.e.
> 
> can: gs_usb: add workarounds for HScanT USB to CAN adapter


> can: remove CAN filters independent from namespace
> can: convert unreliable ARPHRD_CAN type checks to robust can_get_ml_priv()

I would be fine with those two patches.
There was unfortunately some new(!) feedback by sashiko-bot on the 
namespace patch and the ml_priv patch is not that urgent.

> 
> WDYT? How much a pain would be shrinking this PR?
> 
> Thanks,
> 
> Paolo
> 
> 

Best regards,
Oliver


^ permalink raw reply	[flat|nested] 32+ messages in thread

* Re: [PATCH net 0/16] pull-request: can 2026-09-29
  2026-10-01  9:23   ` Oliver Hartkopp
@ 2026-10-01 10:13     ` Paolo Abeni
  2026-10-01 10:28       ` Oliver Hartkopp
  0 siblings, 1 reply; 32+ messages in thread
From: Paolo Abeni @ 2026-10-01 10:13 UTC (permalink / raw)
  To: Oliver Hartkopp, Marc Kleine-Budde, netdev; +Cc: davem, kuba, linux-can, kernel

On 10/1/26 11:23, Oliver Hartkopp wrote:
> On 01.10.26 10:40, Paolo Abeni wrote:
>> On 9/29/26 22:43, Marc Kleine-Budde wrote:
>>> this is a pull request of 16 patches for net/main.
>>>
>>> The first patch is by Vincent Mailhol and drops CAN-XL frames on non
>>> CAN-XL devices.
>>>
>>> A patch by zjamg restores the skb header initialization lost during
>>> the v7.0 release cycle.
>>>
>>> Oliver Hartkopp contributes 3 patches for the CAN net layer, the first
>>> one fixes the net namespace integration for BCM, ISOTP and the CAN RAW
>>> protocols. The second one converts the unreliable ARPHRD_CAN type
>>> check to the robust can_get_ml_priv(). The third one fixes the unique
>>> skb identifier regression under RPS, introduced in the v7.0 release
>>> cycle, which causes lost packets.
>>>
>>> A patch by Joshua Crofts adds a missing
>>> pm_runtime_dont_use_autosuspend() to the m_can_pci driver.
>>>
>>> Maximilian Zimmermann's patch for the xilinx CAN driver adds the
>>> setting the ESI and BSR flags in the receive path if they are active.
>>>
>>> Jiale Yao's patch for the mcp251xfd driver rejects devices without
>>> match data.
>>>
>>> Ji-Ze Hong fixes a struct size mismatch in the f81604 CAN driver.
>>>
>>> The next patch is by me, targets the gs_usb driver and adds
>>> workarounds for the HScanT USB to CAN adapter.
>>>
>>> Cen Zhang fixes a slab-out-of-bounds read access in the kvaser_usb
>>> driver.
>>>
>>> A patch by Stefan Günther targets the peak_usb driver and fixes the
>>> CAN-ID when reporting CAN errors.
>>>
>>> Chris Strong contributes 2 patches, to fix an out of memory and packet
>>> loss problem in the mcp251xfd CAN driver under sustained receive
>>> traffic.
>> Linus has started pushing back on the ever-increasing net RC PRs:
>>
>> https://lore.kernel.org/netdev/CAHk- =wiSnTE9vBZ=5_v+3EEkdazCCbBM5YABRzRHUAeRdyd4Xw@mail.gmail.com/
>>
>> We are trying to defer things to 'next', especially this late
>> in the cycle.
>>
>> I think there are a few patches here eligible for that. i.e.
>>
>> can: gs_usb: add workarounds for HScanT USB to CAN adapter
> 
> 
>> can: remove CAN filters independent from namespace
>> can: convert unreliable ARPHRD_CAN type checks to robust can_get_ml_priv()
> 
> I would be fine with those two patches.
> There was unfortunately some new(!) feedback by sashiko-bot on the 
 > namespace patch and the ml_priv patch is not that urgent.
FTR I mentioned the HScanT patch because if feels more additional H/W
enablement than a fix and is also quite largish/invasive. Feel free to
disagree!

Also, not sure if it's already clear, but the main/more relevant sashiko
instance for netdev is the nipa one:

https://netdev-ai.bots.linux.dev/sashiko/#

It uses more models, and cross-correlates among them and sashiko.dev
feedback.

/P
for


^ permalink raw reply	[flat|nested] 32+ messages in thread

* Re: [PATCH net 0/16] pull-request: can 2026-09-29
  2026-10-01 10:13     ` Paolo Abeni
@ 2026-10-01 10:28       ` Oliver Hartkopp
  2026-10-01 10:55         ` Marc Kleine-Budde
  0 siblings, 1 reply; 32+ messages in thread
From: Oliver Hartkopp @ 2026-10-01 10:28 UTC (permalink / raw)
  To: Paolo Abeni, Marc Kleine-Budde, netdev; +Cc: davem, kuba, linux-can, kernel



On 01.10.26 12:13, Paolo Abeni wrote:
> On 10/1/26 11:23, Oliver Hartkopp wrote:
>> On 01.10.26 10:40, Paolo Abeni wrote:
>>> On 9/29/26 22:43, Marc Kleine-Budde wrote:
>>>> this is a pull request of 16 patches for net/main.
>>>>
>>>> The first patch is by Vincent Mailhol and drops CAN-XL frames on non
>>>> CAN-XL devices.
>>>>
>>>> A patch by zjamg restores the skb header initialization lost during
>>>> the v7.0 release cycle.
>>>>
>>>> Oliver Hartkopp contributes 3 patches for the CAN net layer, the first
>>>> one fixes the net namespace integration for BCM, ISOTP and the CAN RAW
>>>> protocols. The second one converts the unreliable ARPHRD_CAN type
>>>> check to the robust can_get_ml_priv(). The third one fixes the unique
>>>> skb identifier regression under RPS, introduced in the v7.0 release
>>>> cycle, which causes lost packets.
>>>>
>>>> A patch by Joshua Crofts adds a missing
>>>> pm_runtime_dont_use_autosuspend() to the m_can_pci driver.
>>>>
>>>> Maximilian Zimmermann's patch for the xilinx CAN driver adds the
>>>> setting the ESI and BSR flags in the receive path if they are active.
>>>>
>>>> Jiale Yao's patch for the mcp251xfd driver rejects devices without
>>>> match data.
>>>>
>>>> Ji-Ze Hong fixes a struct size mismatch in the f81604 CAN driver.
>>>>
>>>> The next patch is by me, targets the gs_usb driver and adds
>>>> workarounds for the HScanT USB to CAN adapter.
>>>>
>>>> Cen Zhang fixes a slab-out-of-bounds read access in the kvaser_usb
>>>> driver.
>>>>
>>>> A patch by Stefan Günther targets the peak_usb driver and fixes the
>>>> CAN-ID when reporting CAN errors.
>>>>
>>>> Chris Strong contributes 2 patches, to fix an out of memory and packet
>>>> loss problem in the mcp251xfd CAN driver under sustained receive
>>>> traffic.
>>> Linus has started pushing back on the ever-increasing net RC PRs:
>>>
>>> https://lore.kernel.org/netdev/CAHk- 
>>> =wiSnTE9vBZ=5_v+3EEkdazCCbBM5YABRzRHUAeRdyd4Xw@mail.gmail.com/
>>>
>>> We are trying to defer things to 'next', especially this late
>>> in the cycle.
>>>
>>> I think there are a few patches here eligible for that. i.e.
>>>
>>> can: gs_usb: add workarounds for HScanT USB to CAN adapter
>>
>>
>>> can: remove CAN filters independent from namespace
>>> can: convert unreliable ARPHRD_CAN type checks to robust 
>>> can_get_ml_priv()
>>
>> I would be fine with those two patches.
>> There was unfortunately some new(!) feedback by sashiko-bot on the 
>  > namespace patch and the ml_priv patch is not that urgent.
> FTR I mentioned the HScanT patch because if feels more additional H/W
> enablement than a fix and is also quite largish/invasive. Feel free to
> disagree!

Btw. we need the

can: convert unreliable ARPHRD_CAN type checks to robust can_get_ml_priv()

patch as it is a prerequisite for the urgent

can: fix unique skb identifier regression under RPS

The ml_priv patch is not a big thing and intended for stable too.

> Also, not sure if it's already clear, but the main/more relevant sashiko
> instance for netdev is the nipa one:
> 
> https://netdev-ai.bots.linux.dev/sashiko/#
> 
> It uses more models, and cross-correlates among them and sashiko.dev
> feedback.

Ok. The review on Linux-CAN ML was done with

gemini/gemini-3.1-pro-preview

https://sashiko.dev/#/patchset/20260929163424.16382-1-socketcan%40hartkopp.net

While the PR netdev review was done by

bedrock/us.anthropic.claude-opus-5-5

https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260929210700.1183036-1-mkl%40pengutronix.de

@Marc: Can we switch on Linux-CAN Patchwork to Claude Opus too?

Best regards,
Oliver


^ permalink raw reply	[flat|nested] 32+ messages in thread

* Re: [PATCH net 0/16] pull-request: can 2026-09-29
  2026-10-01 10:28       ` Oliver Hartkopp
@ 2026-10-01 10:55         ` Marc Kleine-Budde
  2026-10-01 15:25           ` Jakub Kicinski
  0 siblings, 1 reply; 32+ messages in thread
From: Marc Kleine-Budde @ 2026-10-01 10:55 UTC (permalink / raw)
  To: Oliver Hartkopp, ore; +Cc: Paolo Abeni, netdev, davem, kuba, linux-can, kernel

[-- Attachment #1: Type: text/plain, Size: 814 bytes --]

On 01.10.2026 12:28:48, Oliver Hartkopp wrote:
> Ok. The review on Linux-CAN ML was done with
>
> gemini/gemini-3.1-pro-preview
>
> https://sashiko.dev/#/patchset/20260929163424.16382-1-socketcan%40hartkopp.net
>
> While the PR netdev review was done by
>
> bedrock/us.anthropic.claude-opus-5-5
>
> https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260929210700.1183036-1-mkl%40pengutronix.de
>
> @Marc: Can we switch on Linux-CAN Patchwork to Claude Opus too?

Don't know Oleksij has done the sashiko.dev integraton.

Marc

-- 
Pengutronix e.K.                 | Marc Kleine-Budde          |
Embedded Linux                   | https://www.pengutronix.de |
Vertretung Nürnberg              | Phone: +49-5121-206917-129 |
Amtsgericht Hildesheim, HRA 2686 | Fax:   +49-5121-206917-9   |

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 228 bytes --]

^ permalink raw reply	[flat|nested] 32+ messages in thread

* Re: [PATCH net 0/16] pull-request: can 2026-09-29
  2026-10-01 10:55         ` Marc Kleine-Budde
@ 2026-10-01 15:25           ` Jakub Kicinski
  2026-10-01 15:38             ` Marc Kleine-Budde
  0 siblings, 1 reply; 32+ messages in thread
From: Jakub Kicinski @ 2026-10-01 15:25 UTC (permalink / raw)
  To: Marc Kleine-Budde
  Cc: Oliver Hartkopp, ore, Paolo Abeni, netdev, davem, linux-can,
	kernel

On Thu, 1 Oct 2026 12:55:59 +0200 Marc Kleine-Budde wrote:
> On 01.10.2026 12:28:48, Oliver Hartkopp wrote:
> > Ok. The review on Linux-CAN ML was done with
> >
> > gemini/gemini-3.1-pro-preview
> >
> > https://sashiko.dev/#/patchset/20260929163424.16382-1-socketcan%40hartkopp.net
> >
> > While the PR netdev review was done by
> >
> > bedrock/us.anthropic.claude-opus-5-5
> >
> > https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260929210700.1183036-1-mkl%40pengutronix.de
> >
> > @Marc: Can we switch on Linux-CAN Patchwork to Claude Opus too?  
> 
> Don't know Oleksij has done the sashiko.dev integraton.

Let me try to plug you into netdev-ai one for now.

^ permalink raw reply	[flat|nested] 32+ messages in thread

* Re: [PATCH net 0/16] pull-request: can 2026-09-29
  2026-09-29 20:43 [PATCH net 0/16] pull-request: can 2026-09-29 Marc Kleine-Budde
                   ` (16 preceding siblings ...)
  2026-10-01  8:40 ` [PATCH net 0/16] pull-request: can 2026-09-29 Paolo Abeni
@ 2026-10-01 15:28 ` Jakub Kicinski
  2026-10-01 15:37   ` Marc Kleine-Budde
  17 siblings, 1 reply; 32+ messages in thread
From: Jakub Kicinski @ 2026-10-01 15:28 UTC (permalink / raw)
  To: Marc Kleine-Budde; +Cc: netdev, davem, linux-can, kernel

On Tue, 29 Sep 2026 22:43:50 +0200 Marc Kleine-Budde wrote:
> Hello netdev-team,
> 
> this is a pull request of 16 patches for net/main.

AFAIU there will be a respin here, and it's hitting:

net/can/bcm.c:944:2-12: WARNING: NULL check before (net)dev_{put, hold} functions is not needed.
net/can/bcm.c:1312:2-12: WARNING: NULL check before (net)dev_{put, hold} functions is not needed.

so dropping from PW.

^ permalink raw reply	[flat|nested] 32+ messages in thread

* Re: [PATCH net 0/16] pull-request: can 2026-09-29
  2026-10-01 15:28 ` Jakub Kicinski
@ 2026-10-01 15:37   ` Marc Kleine-Budde
  0 siblings, 0 replies; 32+ messages in thread
From: Marc Kleine-Budde @ 2026-10-01 15:37 UTC (permalink / raw)
  To: Jakub Kicinski; +Cc: netdev, davem, linux-can, kernel

[-- Attachment #1: Type: text/plain, Size: 881 bytes --]

On 01.10.2026 08:28:50, Jakub Kicinski wrote:
> On Tue, 29 Sep 2026 22:43:50 +0200 Marc Kleine-Budde wrote:
> > Hello netdev-team,
> >
> > this is a pull request of 16 patches for net/main.
>
> AFAIU there will be a respin here, and it's hitting:
>
> net/can/bcm.c:944:2-12: WARNING: NULL check before (net)dev_{put, hold} functions is not needed.
> net/can/bcm.c:1312:2-12: WARNING: NULL check before (net)dev_{put, hold} functions is not needed.
>
> so dropping from PW.

Thanks. Meanwhile I've send a new one:

https://lore.kernel.org/all/20261001151905.1556270-1-mkl@pengutronix.de/

Marc


-- 
Pengutronix e.K.                 | Marc Kleine-Budde          |
Embedded Linux                   | https://www.pengutronix.de |
Vertretung Nürnberg              | Phone: +49-5121-206917-129 |
Amtsgericht Hildesheim, HRA 2686 | Fax:   +49-5121-206917-9   |

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 228 bytes --]

^ permalink raw reply	[flat|nested] 32+ messages in thread

* Re: [PATCH net 0/16] pull-request: can 2026-09-29
  2026-10-01 15:25           ` Jakub Kicinski
@ 2026-10-01 15:38             ` Marc Kleine-Budde
  2026-10-01 18:19               ` Jakub Kicinski
  0 siblings, 1 reply; 32+ messages in thread
From: Marc Kleine-Budde @ 2026-10-01 15:38 UTC (permalink / raw)
  To: Jakub Kicinski
  Cc: Oliver Hartkopp, ore, Paolo Abeni, netdev, davem, linux-can,
	kernel

[-- Attachment #1: Type: text/plain, Size: 482 bytes --]

On 01.10.2026 08:25:52, Jakub Kicinski wrote:
> > Don't know Oleksij has done the sashiko.dev integraton.
>
> Let me try to plug you into netdev-ai one for now.

Thanks, do you need anything from us?

Marc

-- 
Pengutronix e.K.                 | Marc Kleine-Budde          |
Embedded Linux                   | https://www.pengutronix.de |
Vertretung Nürnberg              | Phone: +49-5121-206917-129 |
Amtsgericht Hildesheim, HRA 2686 | Fax:   +49-5121-206917-9   |

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 228 bytes --]

^ permalink raw reply	[flat|nested] 32+ messages in thread

* Re: [PATCH net 0/16] pull-request: can 2026-09-29
  2026-10-01 15:38             ` Marc Kleine-Budde
@ 2026-10-01 18:19               ` Jakub Kicinski
  2026-10-05  7:28                 ` Oliver Hartkopp
  0 siblings, 1 reply; 32+ messages in thread
From: Jakub Kicinski @ 2026-10-01 18:19 UTC (permalink / raw)
  To: Marc Kleine-Budde
  Cc: Oliver Hartkopp, ore, Paolo Abeni, netdev, davem, linux-can,
	kernel

On Thu, 1 Oct 2026 17:38:17 +0200 Marc Kleine-Budde wrote:
> On 01.10.2026 08:25:52, Jakub Kicinski wrote:
> > > Don't know Oleksij has done the sashiko.dev integraton.  
> >
> > Let me try to plug you into netdev-ai one for now.  
> 
> Thanks, do you need anything from us?

I don't think so, we already had the setup for the old AIR system.
The emails should start flowing in a day or two. Please let me know
if you don't see any review out by Monday!

^ permalink raw reply	[flat|nested] 32+ messages in thread

* Re: [PATCH net 0/16] pull-request: can 2026-09-29
  2026-10-01 18:19               ` Jakub Kicinski
@ 2026-10-05  7:28                 ` Oliver Hartkopp
  2026-10-05  9:20                   ` Marc Kleine-Budde
  0 siblings, 1 reply; 32+ messages in thread
From: Oliver Hartkopp @ 2026-10-05  7:28 UTC (permalink / raw)
  To: Jakub Kicinski, Marc Kleine-Budde
  Cc: ore, Paolo Abeni, netdev, davem, linux-can, kernel

Hello Jakub,

On 01.10.26 20:19, Jakub Kicinski wrote:
> On Thu, 1 Oct 2026 17:38:17 +0200 Marc Kleine-Budde wrote:
>> On 01.10.2026 08:25:52, Jakub Kicinski wrote:
>>>> Don't know Oleksij has done the sashiko.dev integraton.
>>>
>>> Let me try to plug you into netdev-ai one for now.
>>
>> Thanks, do you need anything from us?
> 
> I don't think so, we already had the setup for the old AIR system.
> The emails should start flowing in a day or two. Please let me know
> if you don't see any review out by Monday!
> 

The new netdev-ai picked some older can-ML patches for an additional 
review but not the important latest "[PATCH net 0/3] pull-request: can 
2026-10-01" which is still only reviewed by gemini-3.1-pro-preview :

https://sashiko.dev/#/patchset/20261001151905.1556270-1-mkl%40pengutronix.de

Should Marc resend the PR or can you trigger its review manually?

Best regards,
Oliver

^ permalink raw reply	[flat|nested] 32+ messages in thread

* Re: [PATCH net 0/16] pull-request: can 2026-09-29
  2026-10-05  7:28                 ` Oliver Hartkopp
@ 2026-10-05  9:20                   ` Marc Kleine-Budde
  2026-10-05  9:24                     ` Oliver Hartkopp
  0 siblings, 1 reply; 32+ messages in thread
From: Marc Kleine-Budde @ 2026-10-05  9:20 UTC (permalink / raw)
  To: Oliver Hartkopp
  Cc: Jakub Kicinski, ore, Paolo Abeni, netdev, davem, linux-can,
	kernel

[-- Attachment #1: Type: text/plain, Size: 1376 bytes --]

On 05.10.2026 09:28:13, Oliver Hartkopp wrote:
> Hello Jakub,
>
> On 01.10.26 20:19, Jakub Kicinski wrote:
> > On Thu, 1 Oct 2026 17:38:17 +0200 Marc Kleine-Budde wrote:
> > > On 01.10.2026 08:25:52, Jakub Kicinski wrote:
> > > > > Don't know Oleksij has done the sashiko.dev integraton.
> > > >
> > > > Let me try to plug you into netdev-ai one for now.
> > >
> > > Thanks, do you need anything from us?
> >
> > I don't think so, we already had the setup for the old AIR system.
> > The emails should start flowing in a day or two. Please let me know
> > if you don't see any review out by Monday!
> >
>
> The new netdev-ai picked some older can-ML patches for an additional review
> but not the important latest "[PATCH net 0/3] pull-request: can 2026-10-01"
> which is still only reviewed by gemini-3.1-pro-preview :
>
> https://sashiko.dev/#/patchset/20261001151905.1556270-1-mkl%40pengutronix.de
>
> Should Marc resend the PR or can you trigger its review manually?

👀
https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20261001151905.1556270-1-mkl@pengutronix.de

Marc

-- 
Pengutronix e.K.                 | Marc Kleine-Budde          |
Embedded Linux                   | https://www.pengutronix.de |
Vertretung Nürnberg              | Phone: +49-5121-206917-129 |
Amtsgericht Hildesheim, HRA 2686 | Fax:   +49-5121-206917-9   |

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 228 bytes --]

^ permalink raw reply	[flat|nested] 32+ messages in thread

* Re: [PATCH net 0/16] pull-request: can 2026-09-29
  2026-10-05  9:20                   ` Marc Kleine-Budde
@ 2026-10-05  9:24                     ` Oliver Hartkopp
  2026-10-05  9:32                       ` Marc Kleine-Budde
  0 siblings, 1 reply; 32+ messages in thread
From: Oliver Hartkopp @ 2026-10-05  9:24 UTC (permalink / raw)
  To: Marc Kleine-Budde
  Cc: Jakub Kicinski, ore, Paolo Abeni, netdev, davem, linux-can,
	kernel



On 05.10.26 11:20, Marc Kleine-Budde wrote:
> On 05.10.2026 09:28:13, Oliver Hartkopp wrote:
>> Hello Jakub,
>>
>> On 01.10.26 20:19, Jakub Kicinski wrote:
>>> On Thu, 1 Oct 2026 17:38:17 +0200 Marc Kleine-Budde wrote:
>>>> On 01.10.2026 08:25:52, Jakub Kicinski wrote:
>>>>>> Don't know Oleksij has done the sashiko.dev integraton.
>>>>>
>>>>> Let me try to plug you into netdev-ai one for now.
>>>>
>>>> Thanks, do you need anything from us?
>>>
>>> I don't think so, we already had the setup for the old AIR system.
>>> The emails should start flowing in a day or two. Please let me know
>>> if you don't see any review out by Monday!
>>>
>>
>> The new netdev-ai picked some older can-ML patches for an additional review
>> but not the important latest "[PATCH net 0/3] pull-request: can 2026-10-01"
>> which is still only reviewed by gemini-3.1-pro-preview :
>>
>> https://sashiko.dev/#/patchset/20261001151905.1556270-1-mkl%40pengutronix.de
>>
>> Should Marc resend the PR or can you trigger its review manually?
> 
> 👀
> https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20261001151905.1556270-1-mkl@pengutronix.de

Ah, thanks! Did not see that. Too many URL locations ;-)

So the can 2026-10-01 PR can get into upstream.

Thanks & sorry for the noise.
Oliver

^ permalink raw reply	[flat|nested] 32+ messages in thread

* Re: [PATCH net 0/16] pull-request: can 2026-09-29
  2026-10-05  9:24                     ` Oliver Hartkopp
@ 2026-10-05  9:32                       ` Marc Kleine-Budde
  0 siblings, 0 replies; 32+ messages in thread
From: Marc Kleine-Budde @ 2026-10-05  9:32 UTC (permalink / raw)
  To: Oliver Hartkopp
  Cc: Marc Kleine-Budde, Jakub Kicinski, ore, Paolo Abeni, netdev,
	davem, linux-can, kernel

[-- Attachment #1: Type: text/plain, Size: 1884 bytes --]

On 05.10.2026 11:24:48, Oliver Hartkopp wrote:
>
>
> On 05.10.26 11:20, Marc Kleine-Budde wrote:
> > On 05.10.2026 09:28:13, Oliver Hartkopp wrote:
> > > Hello Jakub,
> > >
> > > On 01.10.26 20:19, Jakub Kicinski wrote:
> > > > On Thu, 1 Oct 2026 17:38:17 +0200 Marc Kleine-Budde wrote:
> > > > > On 01.10.2026 08:25:52, Jakub Kicinski wrote:
> > > > > > > Don't know Oleksij has done the sashiko.dev integraton.
> > > > > >
> > > > > > Let me try to plug you into netdev-ai one for now.
> > > > >
> > > > > Thanks, do you need anything from us?
> > > >
> > > > I don't think so, we already had the setup for the old AIR system.
> > > > The emails should start flowing in a day or two. Please let me know
> > > > if you don't see any review out by Monday!
> > > >
> > >
> > > The new netdev-ai picked some older can-ML patches for an additional review
> > > but not the important latest "[PATCH net 0/3] pull-request: can 2026-10-01"
> > > which is still only reviewed by gemini-3.1-pro-preview :
> > >
> > > https://sashiko.dev/#/patchset/20261001151905.1556270-1-mkl%40pengutronix.de
> > >
> > > Should Marc resend the PR or can you trigger its review manually?
> >
> > 👀
> > https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20261001151905.1556270-1-mkl@pengutronix.de
>
> Ah, thanks! Did not see that. Too many URL locations ;-)
>
> So the can 2026-10-01 PR can get into upstream.

FYI: I've commented on the "high" severity issue (which is actually a
pre-existing one):

https://lore.kernel.org/all/20261005-weightless-fat-seriema-802f2e-mkl@pengutronix.de/

Marc

-- 
Pengutronix e.K.                 | Marc Kleine-Budde          |
Embedded Linux                   | https://www.pengutronix.de |
Vertretung Nürnberg              | Phone: +49-5121-206917-129 |
Amtsgericht Hildesheim, HRA 2686 | Fax:   +49-5121-206917-9   |

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 228 bytes --]

^ permalink raw reply	[flat|nested] 32+ messages in thread

end of thread, other threads:[~2026-10-05  9:32 UTC | newest]

Thread overview: 32+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-29 20:43 [PATCH net 0/16] pull-request: can 2026-09-29 Marc Kleine-Budde
2026-09-29 20:43 ` [PATCH net 01/16] can: dev: can_dropped_invalid_skb: drop CAN XL frames on non-CAN XL devices Marc Kleine-Budde
2026-09-29 21:13   ` netdev-bot+sinfo
2026-09-29 20:43 ` [PATCH net 02/16] can: dev: init_can_skb(): restore skb header initialization Marc Kleine-Budde
2026-09-29 20:43 ` [PATCH net 03/16] can: remove CAN filters independent from namespace Marc Kleine-Budde
2026-09-29 20:43 ` [PATCH net 04/16] can: convert unreliable ARPHRD_CAN type checks to robust can_get_ml_priv() Marc Kleine-Budde
2026-09-29 20:43 ` [PATCH net 05/16] can: fix unique skb identifier regression under RPS Marc Kleine-Budde
2026-09-29 20:43 ` [PATCH net 06/16] can: isotp: check the frame type, not just the length Marc Kleine-Budde
2026-09-29 20:43 ` [PATCH net 07/16] can: m_can: pci: add missing pm_runtime_dont_use_autosuspend() call Marc Kleine-Budde
2026-09-29 20:43 ` [PATCH net 08/16] can: xilinx_can: set CAN FD flags on received frames Marc Kleine-Budde
2026-09-29 20:43 ` [PATCH net 09/16] can: mcp251xfd: mcp251xfd_probe(): reject devices without match data Marc Kleine-Budde
2026-09-29 20:44 ` [PATCH net 10/16] usb: f81604: fix struct f81604_int_data size mismatch Marc Kleine-Budde
2026-09-29 20:44 ` [PATCH net 11/16] can: gs_usb: kill RX URBs before destroying the netdevs Marc Kleine-Budde
2026-09-29 20:44 ` [PATCH net 12/16] can: gs_usb: add workarounds for HScanT USB to CAN adapter Marc Kleine-Budde
2026-09-29 20:44 ` [PATCH net 13/16] can: kvaser_usb: validate command format before parsing in hydra receive path Marc Kleine-Budde
2026-09-29 20:44 ` [PATCH net 14/16] can: peak_usb: fix missing CAN_ERR_FLAG when reporting error counters Marc Kleine-Budde
2026-09-29 20:44 ` [PATCH net 15/16] can: rx-offload: add IRQ queue flush predicate Marc Kleine-Budde
2026-09-29 20:44 ` [PATCH net 16/16] can: mcp251xfd: flush RX offload queue during long IRQs Marc Kleine-Budde
2026-10-01  8:40 ` [PATCH net 0/16] pull-request: can 2026-09-29 Paolo Abeni
2026-10-01  9:23   ` Oliver Hartkopp
2026-10-01 10:13     ` Paolo Abeni
2026-10-01 10:28       ` Oliver Hartkopp
2026-10-01 10:55         ` Marc Kleine-Budde
2026-10-01 15:25           ` Jakub Kicinski
2026-10-01 15:38             ` Marc Kleine-Budde
2026-10-01 18:19               ` Jakub Kicinski
2026-10-05  7:28                 ` Oliver Hartkopp
2026-10-05  9:20                   ` Marc Kleine-Budde
2026-10-05  9:24                     ` Oliver Hartkopp
2026-10-05  9:32                       ` Marc Kleine-Budde
2026-10-01 15:28 ` Jakub Kicinski
2026-10-01 15:37   ` Marc Kleine-Budde

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox