Re: [PATCH can-next 6/7] can: peak_usb: Add bus error reporting for the PCAN-USB FD family
From: Marc Kleine-Budde
Date: Wed Oct 07 2026 - 09:18:45 EST
On 06.10.2026 17:11:08, Stéphane Grosjean wrote:
> I think I've pulled on a loose thread and ended up uncovering a much
> larger issue.
>
> My original goal was to work on some improvements and cleanup for the
> PEAK USB drivers. However, while reviewing the series, Sashiko started
> pointing out places where the new code was still trusting data
> received from the USB device without sufficient validation.
>
> After fixing those issues and respinning the series, the next round of
> comments raised a different question: if these checks are necessary in
> the newly added code, why are similar assumptions still present
> elsewhere in the driver?
>
> The more I look at it, the more it seems that I'm mixing two different
> objectives in the same series:
>
> - functional improvements and cleanups intended for linux-can-next,
> - hardening changes required because USB devices can no longer be
> considered inherently trustworthy.
As far as I know, the Linux thread model is to trust USB devices. If you
don't there's infrastructure that USB devices are mistrusted, i.e.
disabled, by default.
On the other hand I really appreciate that you take time to fix these
issues.
> Given that every new fix tends to reveal additional places where the
> driver relies on the same trust assumptions, I wonder whether it would
> be better to pause the planned enhancements for now and first perform
> a dedicated pass over the entire driver focused on robustness and
> security.
Yes. That's a good idea!
> My idea would be to start with a separate series whose sole purpose is
> to audit and harden the driver against malformed or unexpected data
> coming from the USB device, and only resume the functional
> improvements once that baseline is in place.
I think this is the best way to move forward! As these issues are found
by bots, the current consensus is to mainline them via net-next. I think
you should add a Fixes tag. I'm not sure if we should add stable on Cc.
For now try without and let's see what the humans and the bots say to
this approach. :)
regards,
Marc
P.S.: I'm not quite sure myself yet how we should handle the details;
we'll have to wait and see what feedback we get. We'll just learn as we
go.
--
Pengutronix e.K. | Marc Kleine-Budde |
Embedded Linux | https://www.pengutronix.de |
Vertretung Nürnberg | Phone: +49-5121-206917-129 |
Amtsgericht Hildesheim, HRA 2686 | Fax: +49-5121-206917-9 |
Attachment:
signature.asc
Description: PGP signature