All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Youth Cao" <cocoh2os08@gmail.com>
Cc: dmitry.torokhov@gmail.com, linux-input@vger.kernel.org
Subject: Re: [PATCH] HID: i2c-hid: Add i2c-hid-quirk-bad-input-size quirk for 0911:5288 device
Date: Thu, 03 Sep 2026 16:25:46 +0000	[thread overview]
Message-ID: <20260903162547.462241F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260903161444.786-1-cocoh2os08@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] An embedded struct member (which is not cacheline-aligned) is passed to an I2C transfer explicitly marked with I2C_M_DMA_SAFE, causing memory corruption if the adapter attempts direct DMA mapping.
--

commit 4324d522e00df3b4f32a9d44f12c88ed0a6abf38
Author: Youth Cao <cocoh2os08@gmail.com>

HID: i2c-hid: Add i2c-hid-quirk-bad-input-size quirk for 0911:5288 device

This commit adds the I2C_HID_QUIRK_BAD_INPUT_SIZE quirk option to the
existing Hantick 5288 quirk entry. This suppresses a kernel log flood
caused by incomplete reports from the Hynitron CST128-A touchpad controller.

> diff --git a/drivers/hid/i2c-hid/i2c-hid-core.c b/drivers/hid/i2c-hid/i2c-hid-core.c
> index 0e725a0f0abee..776dd14feba79 100644
> --- a/drivers/hid/i2c-hid/i2c-hid-core.c
> +++ b/drivers/hid/i2c-hid/i2c-hid-core.c
> @@ -123,7 +123,7 @@ static const struct i2c_hid_quirks {
>  	__u32 quirks;
>  } i2c_hid_quirks[] = {
>  	{ I2C_VENDOR_ID_HANTICK, I2C_PRODUCT_ID_HANTICK_5288,
> -		I2C_HID_QUIRK_NO_IRQ_AFTER_RESET },
> +		I2C_HID_QUIRK_NO_IRQ_AFTER_RESET | I2C_HID_QUIRK_BAD_INPUT_SIZE },
>  	{ I2C_VENDOR_ID_ITE, I2C_DEVICE_ID_ITE_VOYO_WINPAD_A15,
>  		I2C_HID_QUIRK_NO_IRQ_AFTER_RESET },
>  	{ I2C_VENDOR_ID_RAYDIUM, I2C_PRODUCT_ID_RAYDIUM_3118,

[Severity: High]
This is a pre-existing issue, but I noticed a potential memory corruption
in how I2C HID devices are probed.

During device probe, i2c_hid_fetch_hid_descriptor() calls
i2c_hid_read_register() and passes the embedded struct member &ihid->hdesc
as the receive buffer:

drivers/hid/i2c-hid/i2c-hid-core.c:i2c_hid_fetch_hid_descriptor() {
	...
		error = i2c_hid_read_register(ihid,
					      ihid->wHIDDescRegister,
					      &ihid->hdesc,
					      sizeof(ihid->hdesc));
	...
}

This buffer is eventually passed to i2c_hid_xfer(), which explicitly sets the
I2C_M_DMA_SAFE flag on the message:

drivers/hid/i2c-hid/i2c-hid-core.c:i2c_hid_xfer() {
	...
	if (recv_len) {
		msgs[n].addr = client->addr;
		msgs[n].flags = (client->flags & I2C_M_TEN) |
				I2C_M_RD | I2C_M_DMA_SAFE;
		msgs[n].len = recv_len;
		msgs[n].buf = recv_buf;
		n++;
	}
	...
}

Since &ihid->hdesc is an embedded struct member and not cacheline-aligned,
explicitly marking it as I2C_M_DMA_SAFE bypasses the I2C core's bounce
buffering.

Could this cause memory corruption if the adapter attempts direct DMA mapping,
flushing or invalidating the shared cacheline and corrupting adjacent members
(like the client and hid pointers in struct i2c_hid)?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260903161444.786-1-cocoh2os08@gmail.com?part=1

  reply	other threads:[~2026-09-03 16:25 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-03 16:14 [PATCH] HID: i2c-hid: Add i2c-hid-quirk-bad-input-size quirk for 0911:5288 device Youth Cao
2026-09-03 16:25 ` sashiko-bot [this message]
2026-09-11 16:04 ` Jiri Kosina

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260903162547.462241F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=cocoh2os08@gmail.com \
    --cc=dmitry.torokhov@gmail.com \
    --cc=linux-input@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.