mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] ieee802154: atusb: Fix URB reference leak in atusb_work_urbs()
@ 2026-09-17 11:48 Wentao Liang
  2026-09-19  7:46 ` Miquel Raynal
  2026-09-21 15:14 ` krzk
  0 siblings, 2 replies; 3+ messages in thread
From: Wentao Liang @ 2026-09-17 11:48 UTC (permalink / raw)
  To: alex.aring
  Cc: andrew+netdev, davem, edumazet, kuba, linux-kernel, linux-wpan,
	marcel, miquel.raynal, netdev, pabeni, stefan, Wentao Liang,
	stable

usb_get_from_anchor() hands over a reference to the URB, which the caller
has to release. atusb_work_urbs() never does, so every URB collected from
the idle anchor keeps an extra reference: the reference count grows on
each retry cycle and the URBs are never freed on disconnect. Drop the
reference after a successful submission, and after the URB has been put
back on the idle anchor when submission failed, as the HCD holds its own
reference while the URB is in flight.

Fixes: 7490b008d123 ("ieee802154: add support for atusb transceiver")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
---
 drivers/net/ieee802154/atusb.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/drivers/net/ieee802154/atusb.c b/drivers/net/ieee802154/atusb.c
index 5f7fc4ee7a07..3dbb142eccb2 100644
--- a/drivers/net/ieee802154/atusb.c
+++ b/drivers/net/ieee802154/atusb.c
@@ -180,9 +180,15 @@ static void atusb_work_urbs(struct work_struct *work)
 		if (!urb)
 			return;
 		ret = atusb_submit_rx_urb(atusb, urb);
+		if (!ret)
+			usb_put_urb(urb);
 	} while (!ret);
 
+	/* The reference obtained above is dropped once the URB is back
+	 * on the idle anchor.
+	 */
 	usb_anchor_urb(urb, &atusb->idle_urbs);
+	usb_put_urb(urb);
 	dev_warn_ratelimited(&usb_dev->dev,
 			     "atusb_in: can't allocate/submit URB (%d)\n", ret);
 	schedule_delayed_work(&atusb->work,
-- 
2.34.1


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] ieee802154: atusb: Fix URB reference leak in atusb_work_urbs()
  2026-09-17 11:48 [PATCH] ieee802154: atusb: Fix URB reference leak in atusb_work_urbs() Wentao Liang
@ 2026-09-19  7:46 ` Miquel Raynal
  2026-09-21 15:14 ` krzk
  1 sibling, 0 replies; 3+ messages in thread
From: Miquel Raynal @ 2026-09-19  7:46 UTC (permalink / raw)
  To: Wentao Liang
  Cc: alex.aring, andrew+netdev, davem, edumazet, kuba, linux-kernel,
	linux-wpan, marcel, netdev, pabeni, stefan, stable


> usb_get_from_anchor() hands over a reference to the URB, which the caller
> has to release. atusb_work_urbs() never does, so every URB collected from
> the idle anchor keeps an extra reference: the reference count grows on
> each retry cycle and the URBs are never freed on disconnect. Drop the
> reference after a successful submission, and after the URB has been put
> back on the idle anchor when submission failed, as the HCD holds its own
> reference while the URB is in flight.
>
> Fixes: 7490b008d123 ("ieee802154: add support for atusb transceiver")
> Cc: stable@vger.kernel.org
> Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>

Reviewed-by: Miquel Raynal <miquel.raynal@bootlin.com>

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] ieee802154: atusb: Fix URB reference leak in atusb_work_urbs()
  2026-09-17 11:48 [PATCH] ieee802154: atusb: Fix URB reference leak in atusb_work_urbs() Wentao Liang
  2026-09-19  7:46 ` Miquel Raynal
@ 2026-09-21 15:14 ` krzk
  1 sibling, 0 replies; 3+ messages in thread
From: krzk @ 2026-09-21 15:14 UTC (permalink / raw)
  To: Wentao Liang
  Cc: linux-wpan, davem, andrew+netdev, edumazet, netdev, pabeni,
	linux-kernel, stefan, kuba, miquel.raynal, alex.aring, marcel,
	stable


On Thu, 17 Sep 2026 11:48:21 +0000, Wentao Liang wrote:
> usb_get_from_anchor() hands over a reference to the URB, which the caller
> has to release. atusb_work_urbs() never does, so every URB collected from
> the idle anchor keeps an extra reference: the reference count grows on
> each retry cycle and the URBs are never freed on disconnect. Drop the
> reference after a successful submission, and after the URB has been put
> back on the idle anchor when submission failed, as the HCD holds its own
> reference while the URB is in flight.
> 
> Fixes: 7490b008d123 ("ieee802154: add support for atusb transceiver")
> Cc: stable@vger.kernel.org
> Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
> ---
>  drivers/net/ieee802154/atusb.c | 6 ++++++
>  1 file changed, 6 insertions(+)
> 


You sent multiple independent patches, to multiple independent
subsystems. The amount of these patches clearly suggest this was
AI generated and most likely not tested.

More importantly, you sent all this work without properly organizing
relevant patches into patchsets. This makes reviewing difficult
and might cause multiple reviewers to address the same issue.
Replying to the entire set is impossible and requires handling each
patch independently, instead of applying or discarding the set.
Maintainers also won't see the bigger picture of your work. Quite
worrying.

This is on the verge of hostile patch: bomb us with so many
contributions, we won't be able to handle them in efficient manner,
like responding ONCE to ask you to slow down.  Considering all this
is untested and LLM generated, I have even more doubts whether this
should be considered for review.

Please read kernel documentation BEFORE posting more work. It will
explain you how to identify subsystems, how to organize your work per
subsystem, how to document usage of LLM and how what you should not
do if this was posted in a good faith.

Best regards,
Krzysztof




^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-21 15:14 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-17 11:48 [PATCH] ieee802154: atusb: Fix URB reference leak in atusb_work_urbs() Wentao Liang
2026-09-19  7:46 ` Miquel Raynal
2026-09-21 15:14 ` krzk

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®