Re: [PATCH] spi: ch341: handle transfers without a TX or RX buffer

From: Mark Brown

Date: Tue Sep 29 2026 - 10:44:43 EST


On Tue, Sep 29, 2026 at 04:11:52PM +0800, Weibin Liu wrote:
> ch341_transfer_one() unconditionally copies from trans->tx_buf into the
> TX packet and hands trans->rx_buf to usb_bulk_msg() for the readback.
>
> The SPI core allows half-duplex transfers where either of the buffers
> is NULL, so a transfer without TX data crashes the kernel on the memcpy
> and a transfer without RX data makes usb_bulk_msg() store the received
> data at address 0.

...

> Functionally verified in QEMU on x86_64: a CH341a adapter was emulated
> with gadgetfs + dummy_hcd (the emulated device echoes every SPI stream
> packet's payload back on the bulk IN endpoint). With this patch
> applied the probe completes, and tx-only, rx-only and full-duplex
> transfers issued through spidev succeed, with the full-duplex readback
> matching the sent payload, and without a splat. The emulator and the
> test program are local test tooling and are not part of this
> submission.

Are you sure the actual hardware supports half duplex and the fix isn't
to set _MUST_RX and _MUST_TX?

Attachment: signature.asc
Description: PGP signature