Re: [PATCH can-next 6/7] can: peak_usb: Add bus error reporting for the PCAN-USB FD family
From: Stéphane Grosjean
Date: Tue Oct 06 2026 - 11:12:41 EST
Hi Marc,
I think I've pulled on a loose thread and ended up uncovering a much larger issue.
My original goal was to work on some improvements and cleanup for the PEAK USB drivers. However, while reviewing the series, Sashiko started pointing out places where the new code was still trusting data received from the USB device without sufficient validation.
After fixing those issues and respinning the series, the next round of comments raised a different question: if these checks are necessary in the newly added code, why are similar assumptions still present elsewhere in the driver?
The more I look at it, the more it seems that I'm mixing two different objectives in the same series:
- functional improvements and cleanups intended for linux-can-next,
- hardening changes required because USB devices can no longer be considered inherently trustworthy.
Given that every new fix tends to reveal additional places where the driver relies on the same trust assumptions, I wonder whether it would be better to pause the planned enhancements for now and first perform a dedicated pass over the entire driver focused on robustness and security.
My idea would be to start with a separate series whose sole purpose is to audit and harden the driver against malformed or unexpected data coming from the USB device, and only resume the functional improvements once that baseline is in place.
What do you think?
Best regards,
Stéphane
----- Mail original -----
> On 05.10.2026 16:22:12, Stéphane Grosjean wrote:
> > Can you let me know if I need to make changes myself to these
> > patches
> > you sent,
>
> Sure!
>
> > and if so, how? (Should the new requested changes—which are
> > unrelated to the original patch—be included in a new version? Or in
> > a
> > different series?...)
>
> As I'm not planing to work on this series, feel free to take it
> (including my patches), add your changes and send a v2.
>
> FYI: you can import the series to your b4 with:
>
> | b4 prep -n peak_usb_enhancements -f net-next/main -F
> | 20261002-peak_usb_enhancements-v1-0-50e965755c06@xxxxxxxxxxxxxx
>
> regards,
> Marc
>
> --
> Pengutronix e.K. | Marc Kleine-Budde |
> Embedded Linux | https://www.pengutronix.de |
> Vertretung Nürnberg | Phone: +49-5121-206917-129 |
> Amtsgericht Hildesheim, HRA 2686 | Fax: +49-5121-206917-9 |
>