All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Andrei Aldea" <andrei1998@gmail.com>
Cc: linux-input@vger.kernel.org, dmitry.torokhov@gmail.com
Subject: Re: [PATCH 12/15] HID: hid-oxp: support three-page button maps on X2 controllers
Date: Thu, 10 Sep 2026 03:40:33 +0000	[thread overview]
Message-ID: <20260910034033.A2BD81F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260910032115.28669-13-andrei1998@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Invalid cast of HID parent device to `usb_interface` without verifying the transport layer.
--

commit 435c693ab184a92fb526c35572b01cbea8f10f4a
Author: Andrei Aldea <andrei1998@gmail.com>

HID: hid-oxp: support three-page button maps on X2 controllers

This commit adds support for a three-page button map format on the ONEXPLAYER
3 and X2 Mini Pro using exact DMI matches. It initializes the pages and limits
duplicate LED registration by restricting initialization to configuration
interface 2.

> diff --git a/drivers/hid/hid-oxp.c b/drivers/hid/hid-oxp.c
> index 8c44f576f3956..48fa9169b84c7 100644
> --- a/drivers/hid/hid-oxp.c
> +++ b/drivers/hid/hid-oxp.c

[ ... ]

> @@ -1613,6 +1653,21 @@ static void oxp_quiesce_work(struct oxp_hid_cfg *cfg)
>  	oxp_drain_output(cfg);
>  }
>  
> +static bool oxp_is_cfg_interface(struct hid_device *hdev,
> +				 const struct quirk_entry *quirks)
> +{
> +	struct usb_interface *intf;
> +
> +	if (!quirks || !quirks->cfg_interface_num)
> +		return true;
> +	if (hdev->bus != BUS_USB)
> +		return false;
> +
> +	intf = to_usb_interface(hdev->dev.parent);

[Severity: High]
Can this cast to a usb_interface lead to an out-of-bounds read or kernel
crash?

Checking that hdev->bus equals BUS_USB is not sufficient to guarantee that
the parent device is actually a USB interface. A user with access to
/dev/uhid can inject a virtual HID device with the bus field spoofed to
BUS_USB.

If that happens, the parent device will be a UHID character device, not a
USB interface. Dereferencing intf->cur_altsetting will then access invalid
memory.

Should this code use the hid_is_usb(hdev) helper to safely validate the USB
transport layer before casting the parent device?

> +	return intf->cur_altsetting->desc.bInterfaceNumber ==
> +	       quirks->cfg_interface_num;
> +}
> +

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260910032115.28669-1-andrei1998@gmail.com?part=12

  reply	other threads:[~2026-09-10  3:40 UTC|newest]

Thread overview: 30+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-10  3:21 [PATCH 00/15] HID: hid-oxp: fix and extend X2-family controller support Andrei Aldea
2026-09-10  3:21 ` [PATCH 01/15] HID: hid-oxp: fix default M1 and M2 key mappings Andrei Aldea
2026-09-10  3:21 ` [PATCH 02/15] HID: hid-oxp: validate input report lengths before decoding Andrei Aldea
2026-09-10  3:34   ` sashiko-bot
2026-09-10  3:21 ` [PATCH 03/15] HID: hid-oxp: retain fractional brightness when reading RGB status Andrei Aldea
2026-09-10  3:29   ` sashiko-bot
2026-09-10  3:21 ` [PATCH 04/15] HID: hid-oxp: reject invalid Gen2 RGB status values Andrei Aldea
2026-09-10  3:32   ` sashiko-bot
2026-09-10  3:21 ` [PATCH 05/15] HID: hid-oxp: fix multicolor LED intensity scaling Andrei Aldea
2026-09-10  3:33   ` sashiko-bot
2026-09-10  3:21 ` [PATCH 06/15] HID: hid-oxp: serialize complete RGB updates Andrei Aldea
2026-09-10  3:32   ` sashiko-bot
2026-09-10  3:21 ` [PATCH 07/15] HID: hid-oxp: select brightness policy for the new RGB effect Andrei Aldea
2026-09-10  3:33   ` sashiko-bot
2026-09-10  3:21 ` [PATCH 08/15] HID: hid-oxp: stop configuration work during teardown Andrei Aldea
2026-09-10  3:32   ` sashiko-bot
2026-09-10  3:21 ` [PATCH 09/15] HID: hid-oxp: keep configuration state per HID interface Andrei Aldea
2026-09-10  3:35   ` sashiko-bot
2026-09-10  3:21 ` [PATCH 10/15] HID: hid-oxp: handle controller reinitialization across suspend Andrei Aldea
2026-09-10  3:34   ` sashiko-bot
2026-09-10  3:21 ` [PATCH 11/15] HID: hid-oxp: group declarations and protocol definitions Andrei Aldea
2026-09-10  3:40   ` sashiko-bot
2026-09-10  3:21 ` [PATCH 12/15] HID: hid-oxp: support three-page button maps on X2 controllers Andrei Aldea
2026-09-10  3:40   ` sashiko-bot [this message]
2026-09-10  3:21 ` [PATCH 13/15] HID: hid-oxp: represent RGB LEDs with a common array Andrei Aldea
2026-09-10  3:44   ` sashiko-bot
2026-09-10  3:21 ` [PATCH 14/15] HID: hid-oxp: add Gen3 joystick ring RGB support Andrei Aldea
2026-09-10  3:43   ` sashiko-bot
2026-09-10  3:21 ` [PATCH 15/15] HID: hid-oxp: add X2 auxiliary RGB zones Andrei Aldea
2026-09-10  3:44   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260910034033.A2BD81F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=andrei1998@gmail.com \
    --cc=dmitry.torokhov@gmail.com \
    --cc=linux-input@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.