* [PATCH] HID: i2c-hid: Add i2c-hid-quirk-bad-input-size quirk for 0911:5288 device
@ 2026-09-03 16:14 Youth Cao
2026-09-03 16:25 ` sashiko-bot
2026-09-11 16:04 ` Jiri Kosina
0 siblings, 2 replies; 3+ messages in thread
From: Youth Cao @ 2026-09-03 16:14 UTC (permalink / raw)
To: Jiri Kosina, Benjamin Tissoires
Cc: Xu Rao, Ai Chao, Kwok Kin Ming, Youth Cao, linux-input,
linux-kernel
I have recently acquired a cheap Apollo Lake-based laptop that uses a
Hynitron CST128-A touchpad controller. While booting from a Debian LiveCD,
the kernel log is flooded with the following error (though the touchpad
works well):
i2c_hid_acpi i2c-ALPS0001:00: i2c_hid_get_input: incomplete report (27/42405)
The CST128-A was identified via ACPI as ALPS0001:00, and the I2C HID
device ID (0911:5288) was shared with the Hantick 5288.
Add the I2C_HID_QUIRK_BAD_INPUT_SIZE quirk option to the existing Hantick
5288 quirk entry to suppress the kernel log flood.
Signed-off-by: Youth Cao <cocoh2os08@gmail.com>
---
drivers/hid/i2c-hid/i2c-hid-core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/hid/i2c-hid/i2c-hid-core.c b/drivers/hid/i2c-hid/i2c-hid-core.c
index 0e725a0f0abe..776dd14feba7 100644
--- a/drivers/hid/i2c-hid/i2c-hid-core.c
+++ b/drivers/hid/i2c-hid/i2c-hid-core.c
@@ -123,7 +123,7 @@ static const struct i2c_hid_quirks {
__u32 quirks;
} i2c_hid_quirks[] = {
{ I2C_VENDOR_ID_HANTICK, I2C_PRODUCT_ID_HANTICK_5288,
- I2C_HID_QUIRK_NO_IRQ_AFTER_RESET },
+ I2C_HID_QUIRK_NO_IRQ_AFTER_RESET | I2C_HID_QUIRK_BAD_INPUT_SIZE },
{ I2C_VENDOR_ID_ITE, I2C_DEVICE_ID_ITE_VOYO_WINPAD_A15,
I2C_HID_QUIRK_NO_IRQ_AFTER_RESET },
{ I2C_VENDOR_ID_RAYDIUM, I2C_PRODUCT_ID_RAYDIUM_3118,
--
2.47.3
^ permalink raw reply related [flat|nested] 3+ messages in thread* Re: [PATCH] HID: i2c-hid: Add i2c-hid-quirk-bad-input-size quirk for 0911:5288 device
2026-09-03 16:14 [PATCH] HID: i2c-hid: Add i2c-hid-quirk-bad-input-size quirk for 0911:5288 device Youth Cao
@ 2026-09-03 16:25 ` sashiko-bot
2026-09-11 16:04 ` Jiri Kosina
1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-09-03 16:25 UTC (permalink / raw)
To: Youth Cao; +Cc: dmitry.torokhov, linux-input
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] An embedded struct member (which is not cacheline-aligned) is passed to an I2C transfer explicitly marked with I2C_M_DMA_SAFE, causing memory corruption if the adapter attempts direct DMA mapping.
--
commit 4324d522e00df3b4f32a9d44f12c88ed0a6abf38
Author: Youth Cao <cocoh2os08@gmail.com>
HID: i2c-hid: Add i2c-hid-quirk-bad-input-size quirk for 0911:5288 device
This commit adds the I2C_HID_QUIRK_BAD_INPUT_SIZE quirk option to the
existing Hantick 5288 quirk entry. This suppresses a kernel log flood
caused by incomplete reports from the Hynitron CST128-A touchpad controller.
> diff --git a/drivers/hid/i2c-hid/i2c-hid-core.c b/drivers/hid/i2c-hid/i2c-hid-core.c
> index 0e725a0f0abee..776dd14feba79 100644
> --- a/drivers/hid/i2c-hid/i2c-hid-core.c
> +++ b/drivers/hid/i2c-hid/i2c-hid-core.c
> @@ -123,7 +123,7 @@ static const struct i2c_hid_quirks {
> __u32 quirks;
> } i2c_hid_quirks[] = {
> { I2C_VENDOR_ID_HANTICK, I2C_PRODUCT_ID_HANTICK_5288,
> - I2C_HID_QUIRK_NO_IRQ_AFTER_RESET },
> + I2C_HID_QUIRK_NO_IRQ_AFTER_RESET | I2C_HID_QUIRK_BAD_INPUT_SIZE },
> { I2C_VENDOR_ID_ITE, I2C_DEVICE_ID_ITE_VOYO_WINPAD_A15,
> I2C_HID_QUIRK_NO_IRQ_AFTER_RESET },
> { I2C_VENDOR_ID_RAYDIUM, I2C_PRODUCT_ID_RAYDIUM_3118,
[Severity: High]
This is a pre-existing issue, but I noticed a potential memory corruption
in how I2C HID devices are probed.
During device probe, i2c_hid_fetch_hid_descriptor() calls
i2c_hid_read_register() and passes the embedded struct member &ihid->hdesc
as the receive buffer:
drivers/hid/i2c-hid/i2c-hid-core.c:i2c_hid_fetch_hid_descriptor() {
...
error = i2c_hid_read_register(ihid,
ihid->wHIDDescRegister,
&ihid->hdesc,
sizeof(ihid->hdesc));
...
}
This buffer is eventually passed to i2c_hid_xfer(), which explicitly sets the
I2C_M_DMA_SAFE flag on the message:
drivers/hid/i2c-hid/i2c-hid-core.c:i2c_hid_xfer() {
...
if (recv_len) {
msgs[n].addr = client->addr;
msgs[n].flags = (client->flags & I2C_M_TEN) |
I2C_M_RD | I2C_M_DMA_SAFE;
msgs[n].len = recv_len;
msgs[n].buf = recv_buf;
n++;
}
...
}
Since &ihid->hdesc is an embedded struct member and not cacheline-aligned,
explicitly marking it as I2C_M_DMA_SAFE bypasses the I2C core's bounce
buffering.
Could this cause memory corruption if the adapter attempts direct DMA mapping,
flushing or invalidating the shared cacheline and corrupting adjacent members
(like the client and hid pointers in struct i2c_hid)?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260903161444.786-1-cocoh2os08@gmail.com?part=1
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [PATCH] HID: i2c-hid: Add i2c-hid-quirk-bad-input-size quirk for 0911:5288 device
2026-09-03 16:14 [PATCH] HID: i2c-hid: Add i2c-hid-quirk-bad-input-size quirk for 0911:5288 device Youth Cao
2026-09-03 16:25 ` sashiko-bot
@ 2026-09-11 16:04 ` Jiri Kosina
1 sibling, 0 replies; 3+ messages in thread
From: Jiri Kosina @ 2026-09-11 16:04 UTC (permalink / raw)
To: Youth Cao
Cc: Benjamin Tissoires, Xu Rao, Ai Chao, Kwok Kin Ming, linux-input,
linux-kernel
On Fri, 4 Sep 2026, Youth Cao wrote:
> I have recently acquired a cheap Apollo Lake-based laptop that uses a
> Hynitron CST128-A touchpad controller. While booting from a Debian LiveCD,
> the kernel log is flooded with the following error (though the touchpad
> works well):
>
> i2c_hid_acpi i2c-ALPS0001:00: i2c_hid_get_input: incomplete report (27/42405)
>
> The CST128-A was identified via ACPI as ALPS0001:00, and the I2C HID
> device ID (0911:5288) was shared with the Hantick 5288.
>
> Add the I2C_HID_QUIRK_BAD_INPUT_SIZE quirk option to the existing Hantick
> 5288 quirk entry to suppress the kernel log flood.
>
> Signed-off-by: Youth Cao <cocoh2os08@gmail.com>
> ---
> drivers/hid/i2c-hid/i2c-hid-core.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/hid/i2c-hid/i2c-hid-core.c b/drivers/hid/i2c-hid/i2c-hid-core.c
> index 0e725a0f0abe..776dd14feba7 100644
> --- a/drivers/hid/i2c-hid/i2c-hid-core.c
> +++ b/drivers/hid/i2c-hid/i2c-hid-core.c
> @@ -123,7 +123,7 @@ static const struct i2c_hid_quirks {
> __u32 quirks;
> } i2c_hid_quirks[] = {
> { I2C_VENDOR_ID_HANTICK, I2C_PRODUCT_ID_HANTICK_5288,
> - I2C_HID_QUIRK_NO_IRQ_AFTER_RESET },
> + I2C_HID_QUIRK_NO_IRQ_AFTER_RESET | I2C_HID_QUIRK_BAD_INPUT_SIZE },
> { I2C_VENDOR_ID_ITE, I2C_DEVICE_ID_ITE_VOYO_WINPAD_A15,
> I2C_HID_QUIRK_NO_IRQ_AFTER_RESET },
> { I2C_VENDOR_ID_RAYDIUM, I2C_PRODUCT_ID_RAYDIUM_3118,
Applied, thanks.
--
Jiri Kosina
SUSE Labs
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-11 16:04 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-03 16:14 [PATCH] HID: i2c-hid: Add i2c-hid-quirk-bad-input-size quirk for 0911:5288 device Youth Cao
2026-09-03 16:25 ` sashiko-bot
2026-09-11 16:04 ` Jiri Kosina
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.