* [PATCH 1/4] Input: psmouse - fix use-after-free during protocol disconnect
@ 2026-07-27 5:07 Dmitry Torokhov
2026-07-27 5:07 ` [PATCH 2/4] Input: psmouse - clean up locking around disable_work_sync() Dmitry Torokhov
` (3 more replies)
0 siblings, 4 replies; 9+ messages in thread
From: Dmitry Torokhov @ 2026-07-27 5:07 UTC (permalink / raw)
To: linux-input; +Cc: Hans de Goede
When a PS/2 mouse is disconnected or unbound, psmouse_disconnect() calls
the protocol disconnect handler (psmouse->disconnect()). During this time,
stray bytes arriving from the physical controller can still be passed to
psmouse_handle_byte(), which will invoke psmouse->protocol_handler().
This creates an asynchronous race condition with vendor disconnect handlers
(such as synaptics_disconnect()), which free vendor-specific private
structures (psmouse->private). If a byte arrives while the structures
are being freed, it leads to a use-after-free or NULL pointer
dereference in the protocol handler.
Fix this by explicitly setting psmouse->protocol_handler to NULL
safely wrapped in scoped_guard(serio_pause_rx, serio) immediately before
calling the vendor disconnect handler. We also add an unlikely check
in psmouse_handle_byte() to safely drop incoming bytes if the protocol
handler is NULL.
Assisted-by: Antigravity:gemini-3.5-flash
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
---
drivers/input/mouse/psmouse-base.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
diff --git a/drivers/input/mouse/psmouse-base.c b/drivers/input/mouse/psmouse-base.c
index 6ab5f1d96eae..916a14b9b6a7 100644
--- a/drivers/input/mouse/psmouse-base.c
+++ b/drivers/input/mouse/psmouse-base.c
@@ -267,7 +267,13 @@ void psmouse_set_state(struct psmouse *psmouse, enum psmouse_state new_state)
*/
static int psmouse_handle_byte(struct psmouse *psmouse)
{
- psmouse_ret_t rc = psmouse->protocol_handler(psmouse);
+ psmouse_ret_t rc;
+
+ /* protocol_handler is NULL when device is being disconnected */
+ if (unlikely(!psmouse->protocol_handler))
+ return 0;
+
+ rc = psmouse->protocol_handler(psmouse);
switch (rc) {
case PSMOUSE_BAD_DATA:
@@ -1466,6 +1472,9 @@ static void psmouse_disconnect(struct serio *serio)
psmouse_deactivate(parent);
}
+ scoped_guard(serio_pause_rx, serio)
+ psmouse->protocol_handler = NULL;
+
if (psmouse->disconnect)
psmouse->disconnect(psmouse);
--
2.55.0.229.g6434b31f56-goog
^ permalink raw reply related [flat|nested] 9+ messages in thread
* [PATCH 2/4] Input: psmouse - clean up locking around disable_work_sync()
2026-07-27 5:07 [PATCH 1/4] Input: psmouse - fix use-after-free during protocol disconnect Dmitry Torokhov
@ 2026-07-27 5:07 ` Dmitry Torokhov
2026-07-27 5:32 ` sashiko-bot
2026-07-27 5:08 ` [PATCH 3/4] Input: psmouse - modernize PNP ID parsing Dmitry Torokhov
` (2 subsequent siblings)
3 siblings, 1 reply; 9+ messages in thread
From: Dmitry Torokhov @ 2026-07-27 5:07 UTC (permalink / raw)
To: linux-input; +Cc: Hans de Goede
In the past, psmouse_disconnect() used cancel_work_sync(). Because
cancel_work_sync() must be called with the psmouse_mutex dropped, and we
needed to prevent psmouse_receive_byte() from re-queueing the work
behind our back, the code transitioned the device to PSMOUSE_CMD_MODE
while holding the mutex, then dropped the mutex and cancelled the work.
When cancel_work_sync() was replaced with disable_work_sync() in this
path, the mutex juggling remained. However, disable_work_sync()
inherently prevents the work from being executed or re-queued, making
the mutex juggling unnecessary.
Clean this up by moving disable_work_sync() to the very top of
psmouse_disconnect(), before we acquire psmouse_mutex.
Assisted-by: Antigravity:gemini-3.5-flash
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
---
drivers/input/mouse/psmouse-base.c | 7 ++-----
1 file changed, 2 insertions(+), 5 deletions(-)
diff --git a/drivers/input/mouse/psmouse-base.c b/drivers/input/mouse/psmouse-base.c
index 916a14b9b6a7..3fcc1d293c31 100644
--- a/drivers/input/mouse/psmouse-base.c
+++ b/drivers/input/mouse/psmouse-base.c
@@ -1458,15 +1458,12 @@ static void psmouse_disconnect(struct serio *serio)
struct psmouse *psmouse = psmouse_from_serio(serio);
struct psmouse *parent = NULL;
+ disable_work_sync(&psmouse->resync_work);
+
mutex_lock(&psmouse_mutex);
psmouse_set_state(psmouse, PSMOUSE_CMD_MODE);
- /* make sure we don't have a resync in progress */
- mutex_unlock(&psmouse_mutex);
- disable_work_sync(&psmouse->resync_work);
- mutex_lock(&psmouse_mutex);
-
if (serio->parent && serio->id.type == SERIO_PS_PSTHRU) {
parent = psmouse_from_serio(serio->parent);
psmouse_deactivate(parent);
--
2.55.0.229.g6434b31f56-goog
^ permalink raw reply related [flat|nested] 9+ messages in thread
* [PATCH 3/4] Input: psmouse - modernize PNP ID parsing
2026-07-27 5:07 [PATCH 1/4] Input: psmouse - fix use-after-free during protocol disconnect Dmitry Torokhov
2026-07-27 5:07 ` [PATCH 2/4] Input: psmouse - clean up locking around disable_work_sync() Dmitry Torokhov
@ 2026-07-27 5:08 ` Dmitry Torokhov
2026-07-27 5:08 ` [PATCH 4/4] Input: psmouse - use guard() for resource management Dmitry Torokhov
2026-07-27 5:38 ` [PATCH 1/4] Input: psmouse - fix use-after-free during protocol disconnect sashiko-bot
3 siblings, 0 replies; 9+ messages in thread
From: Dmitry Torokhov @ 2026-07-27 5:08 UTC (permalink / raw)
To: linux-input; +Cc: Hans de Goede
Rewrite psmouse_matches_pnp_id() to parse and match the space-separated
PNP ID string directly in place without dynamic memory allocation.
Assisted-by: Antigravity:gemini-3.5-flash
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
---
drivers/input/mouse/psmouse-base.c | 39 +++++++++++++++---------------
1 file changed, 20 insertions(+), 19 deletions(-)
diff --git a/drivers/input/mouse/psmouse-base.c b/drivers/input/mouse/psmouse-base.c
index 3fcc1d293c31..a9a110f2c860 100644
--- a/drivers/input/mouse/psmouse-base.c
+++ b/drivers/input/mouse/psmouse-base.c
@@ -490,13 +490,16 @@ static int psmouse_poll(struct psmouse *psmouse)
PSMOUSE_CMD_POLL | (psmouse->pktsize << 8));
}
-static bool psmouse_check_pnp_id(const char *id, const char * const ids[])
+static bool psmouse_check_pnp_id(const char *p, const char * const ids[])
{
- int i;
+ const char * const *id;
+ size_t len;
- for (i = 0; ids[i]; i++)
- if (!strcasecmp(id, ids[i]))
+ for (id = ids; *id; id++) {
+ len = strlen(*id);
+ if (!strncasecmp(p, *id, len) && (p[len] == ' ' || p[len] == '\0'))
return true;
+ }
return false;
}
@@ -507,28 +510,26 @@ static bool psmouse_check_pnp_id(const char *id, const char * const ids[])
bool psmouse_matches_pnp_id(struct psmouse *psmouse, const char * const ids[])
{
struct serio *serio = psmouse->ps2dev.serio;
- char *p, *fw_id_copy, *save_ptr;
- bool found = false;
+ const char *p = serio->firmware_id;
- if (strncmp(serio->firmware_id, "PNP: ", 5))
+ if (!strstarts(p, "PNP: "))
return false;
- fw_id_copy = kstrndup(&serio->firmware_id[5],
- sizeof(serio->firmware_id) - 5,
- GFP_KERNEL);
- if (!fw_id_copy)
- return false;
+ p += 5;
+ while (*p) {
+ p = skip_spaces(p);
+ if (!*p)
+ break;
- save_ptr = fw_id_copy;
- while ((p = strsep(&fw_id_copy, " ")) != NULL) {
- if (psmouse_check_pnp_id(p, ids)) {
- found = true;
+ if (psmouse_check_pnp_id(p, ids))
+ return true;
+
+ p = strchr(p, ' ');
+ if (!p)
break;
- }
}
- kfree(save_ptr);
- return found;
+ return false;
}
/*
--
2.55.0.229.g6434b31f56-goog
^ permalink raw reply related [flat|nested] 9+ messages in thread
* [PATCH 4/4] Input: psmouse - use guard() for resource management
2026-07-27 5:07 [PATCH 1/4] Input: psmouse - fix use-after-free during protocol disconnect Dmitry Torokhov
2026-07-27 5:07 ` [PATCH 2/4] Input: psmouse - clean up locking around disable_work_sync() Dmitry Torokhov
2026-07-27 5:08 ` [PATCH 3/4] Input: psmouse - modernize PNP ID parsing Dmitry Torokhov
@ 2026-07-27 5:08 ` Dmitry Torokhov
2026-07-27 5:35 ` sashiko-bot
2026-07-27 5:38 ` [PATCH 1/4] Input: psmouse - fix use-after-free during protocol disconnect sashiko-bot
3 siblings, 1 reply; 9+ messages in thread
From: Dmitry Torokhov @ 2026-07-27 5:08 UTC (permalink / raw)
To: linux-input; +Cc: Hans de Goede
Replace manual serialization with guard(mutex) and guard(serio_pause_rx)
where appropriate. This eliminates the need for explicit goto-based error
paths.
Assisted-by: Antigravity:gemini-3.5-flash
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
---
drivers/input/mouse/psmouse-base.c | 31 ++++++++++++------------------
1 file changed, 12 insertions(+), 19 deletions(-)
diff --git a/drivers/input/mouse/psmouse-base.c b/drivers/input/mouse/psmouse-base.c
index a9a110f2c860..58b9b5dd7f08 100644
--- a/drivers/input/mouse/psmouse-base.c
+++ b/drivers/input/mouse/psmouse-base.c
@@ -256,9 +256,8 @@ static inline void __psmouse_set_state(struct psmouse *psmouse, enum psmouse_sta
*/
void psmouse_set_state(struct psmouse *psmouse, enum psmouse_state new_state)
{
- serio_pause_rx(psmouse->ps2dev.serio);
+ guard(serio_pause_rx)(psmouse->ps2dev.serio);
__psmouse_set_state(psmouse, new_state);
- serio_continue_rx(psmouse->ps2dev.serio);
}
/*
@@ -1318,10 +1317,10 @@ static void psmouse_resync(struct work_struct *work)
bool failed = false, enabled = false;
int i;
- mutex_lock(&psmouse_mutex);
+ guard(mutex)(&psmouse_mutex);
if (psmouse->state != PSMOUSE_RESYNCING)
- goto out;
+ return;
if (serio->parent && serio->id.type == SERIO_PS_PSTHRU) {
parent = psmouse_from_serio(serio->parent);
@@ -1399,8 +1398,6 @@ static void psmouse_resync(struct work_struct *work)
if (parent)
psmouse_activate(parent);
- out:
- mutex_unlock(&psmouse_mutex);
}
/*
@@ -1411,7 +1408,7 @@ static void psmouse_cleanup(struct serio *serio)
struct psmouse *psmouse = psmouse_from_serio(serio);
struct psmouse *parent = NULL;
- mutex_lock(&psmouse_mutex);
+ guard(mutex)(&psmouse_mutex);
if (serio->parent && serio->id.type == SERIO_PS_PSTHRU) {
parent = psmouse_from_serio(serio->parent);
@@ -1447,8 +1444,6 @@ static void psmouse_cleanup(struct serio *serio)
psmouse_activate(parent);
}
-
- mutex_unlock(&psmouse_mutex);
}
/*
@@ -1461,7 +1456,7 @@ static void psmouse_disconnect(struct serio *serio)
disable_work_sync(&psmouse->resync_work);
- mutex_lock(&psmouse_mutex);
+ guard(mutex)(&psmouse_mutex);
psmouse_set_state(psmouse, PSMOUSE_CMD_MODE);
@@ -1491,8 +1486,6 @@ static void psmouse_disconnect(struct serio *serio)
if (parent)
psmouse_activate(parent);
-
- mutex_unlock(&psmouse_mutex);
}
static int psmouse_switch_protocol(struct psmouse *psmouse,
@@ -1661,14 +1654,12 @@ static int __psmouse_reconnect(struct serio *serio, bool fast_reconnect)
enum psmouse_type type;
int rc = -1;
- mutex_lock(&psmouse_mutex);
+ lockdep_assert_held(&psmouse_mutex);
if (fast_reconnect) {
reconnect_handler = psmouse->fast_reconnect;
- if (!reconnect_handler) {
- rc = -ENOENT;
- goto out_unlock;
- }
+ if (!reconnect_handler)
+ return -ENOENT;
} else {
reconnect_handler = psmouse->reconnect;
}
@@ -1720,18 +1711,20 @@ static int __psmouse_reconnect(struct serio *serio, bool fast_reconnect)
if (parent)
psmouse_activate(parent);
-out_unlock:
- mutex_unlock(&psmouse_mutex);
return rc;
}
static int psmouse_reconnect(struct serio *serio)
{
+ guard(mutex)(&psmouse_mutex);
+
return __psmouse_reconnect(serio, false);
}
static int psmouse_fast_reconnect(struct serio *serio)
{
+ guard(mutex)(&psmouse_mutex);
+
return __psmouse_reconnect(serio, true);
}
--
2.55.0.229.g6434b31f56-goog
^ permalink raw reply related [flat|nested] 9+ messages in thread
* Re: [PATCH 2/4] Input: psmouse - clean up locking around disable_work_sync()
2026-07-27 5:07 ` [PATCH 2/4] Input: psmouse - clean up locking around disable_work_sync() Dmitry Torokhov
@ 2026-07-27 5:32 ` sashiko-bot
2026-07-27 5:52 ` Dmitry Torokhov
0 siblings, 1 reply; 9+ messages in thread
From: sashiko-bot @ 2026-07-27 5:32 UTC (permalink / raw)
To: Dmitry Torokhov; +Cc: linux-input, dmitry.torokhov
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Moving disable_work_sync() to the top of psmouse_disconnect() breaks the early-abort synchronization in psmouse_resync(), causing delays and queuing stray reconnect events.
--
--- Patch [2]: [PATCH 2/4] Input: psmouse - clean up locking around disable_work_sync() ---
commit f2e43a3d4ae9250b89f797899728eb8d61c0ef21
Author: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Input: psmouse - clean up locking around disable_work_sync()
In the past, psmouse_disconnect() used cancel_work_sync(). Because
cancel_work_sync() must be called with the psmouse_mutex dropped, and we
needed to prevent psmouse_receive_byte() from re-queueing the work
behind our back, the code transitioned the device to PSMOUSE_CMD_MODE
while holding the mutex, then dropped the mutex and cancelled the work.
When cancel_work_sync() was replaced with disable_work_sync() in this
path, the mutex juggling remained. However, disable_work_sync()
inherently prevents the work from being executed or re-queued, making
the mutex juggling unnecessary.
Clean this up by moving disable_work_sync() to the very top of
psmouse_disconnect(), before we acquire psmouse_mutex.
> diff --git a/drivers/input/mouse/psmouse-base.c b/drivers/input/mouse/psmouse-base.c
> index 916a14b9b6a7d..3fcc1d293c313 100644
> --- a/drivers/input/mouse/psmouse-base.c
> +++ b/drivers/input/mouse/psmouse-base.c
> @@ -1458,15 +1458,12 @@ static void psmouse_disconnect(struct serio *serio)
> struct psmouse *psmouse = psmouse_from_serio(serio);
> struct psmouse *parent = NULL;
>
> + disable_work_sync(&psmouse->resync_work);
> +
> mutex_lock(&psmouse_mutex);
>
> psmouse_set_state(psmouse, PSMOUSE_CMD_MODE);
>
> - /* make sure we don't have a resync in progress */
> - mutex_unlock(&psmouse_mutex);
> - disable_work_sync(&psmouse->resync_work);
> - mutex_lock(&psmouse_mutex);
> -
[Severity: High]
By moving disable_work_sync() before psmouse_set_state(..., PSMOUSE_CMD_MODE),
does this break the early-abort synchronization in psmouse_resync()?
If a hardware resync event races with driver unbind, disable_work_sync() will
block waiting for the already-running psmouse_resync() worker:
drivers/input/mouse/psmouse-base.c:psmouse_resync() {
mutex_lock(&psmouse_mutex);
if (psmouse->state != PSMOUSE_RESYNCING)
goto out;
Since psmouse_disconnect() hasn't updated the state yet, psmouse_resync() will
observe PSMOUSE_RESYNCING, proceed to poll the disconnected hardware (causing
delays), and upon failure, call serio_reconnect():
if (failed) {
psmouse_set_state(psmouse, PSMOUSE_IGNORE);
psmouse_info(psmouse,
"resync failed, issuing reconnect request\n");
serio_reconnect(serio);
}
Could this queued reconnect event cause the driver to spontaneously re-bind
after the disconnect finishes?
> if (serio->parent && serio->id.type == SERIO_PS_PSTHRU) {
> parent = psmouse_from_serio(serio->parent);
> psmouse_deactivate(parent);
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260727050803.1269941-1-dmitry.torokhov@gmail.com?part=2
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH 4/4] Input: psmouse - use guard() for resource management
2026-07-27 5:08 ` [PATCH 4/4] Input: psmouse - use guard() for resource management Dmitry Torokhov
@ 2026-07-27 5:35 ` sashiko-bot
0 siblings, 0 replies; 9+ messages in thread
From: sashiko-bot @ 2026-07-27 5:35 UTC (permalink / raw)
To: Dmitry Torokhov; +Cc: dmitry.torokhov, linux-input
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] Unbounded array write (buffer overflow) in `psmouse_receive_byte` due to unhandled `protocol_handler = NULL`.
--
--- Patch [4]: [PATCH 4/4] Input: psmouse - use guard() for resource management ---
commit 7e27c0c560cf8dcd06bedf52a084dc88e9bf3ed9
Author: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Input: psmouse - use guard() for resource management
Replace manual serialization with guard(mutex) and guard(serio_pause_rx)
where appropriate. This eliminates the need for explicit goto-based error
paths.
> diff --git a/drivers/input/mouse/psmouse-base.c b/drivers/input/mouse/psmouse-base.c
> index a9a110f2c860a..58b9b5dd7f085 100644
> --- a/drivers/input/mouse/psmouse-base.c
> +++ b/drivers/input/mouse/psmouse-base.c
[ ... ]
> @@ -1461,7 +1456,7 @@ static void psmouse_disconnect(struct serio *serio)
>
> disable_work_sync(&psmouse->resync_work);
>
> - mutex_lock(&psmouse_mutex);
> + guard(mutex)(&psmouse_mutex);
>
> psmouse_set_state(psmouse, PSMOUSE_CMD_MODE);
>
[Severity: Critical]
With the changes in the first patch of this series, psmouse_disconnect() sets
psmouse->state = PSMOUSE_CMD_MODE and sets psmouse->protocol_handler = NULL
before calling the vendor disconnect handler.
If a noisy or malicious PS/2 device (e.g., emulated by a BMC or USB adapter)
spams bytes during this driver unbind window, psmouse_receive_byte() will
place them into psmouse->packet[psmouse->pktcnt++] and call
psmouse_handle_byte().
Because protocol_handler is NULL, psmouse_handle_byte() immediately returns 0:
drivers/input/mouse/psmouse-base.c:psmouse_handle_byte() {
...
/* protocol_handler is NULL when device is being disconnected */
if (unlikely(!psmouse->protocol_handler))
return 0;
...
}
Since pktcnt is never reset here, could this regression allow pktcnt to
continuously increment and overflow the 8-byte psmouse->packet[] array on
subsequent bytes, corrupting struct psmouse fields and adjacent memory?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260727050803.1269941-1-dmitry.torokhov@gmail.com?part=4
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH 1/4] Input: psmouse - fix use-after-free during protocol disconnect
2026-07-27 5:07 [PATCH 1/4] Input: psmouse - fix use-after-free during protocol disconnect Dmitry Torokhov
` (2 preceding siblings ...)
2026-07-27 5:08 ` [PATCH 4/4] Input: psmouse - use guard() for resource management Dmitry Torokhov
@ 2026-07-27 5:38 ` sashiko-bot
2026-07-27 5:53 ` Dmitry Torokhov
3 siblings, 1 reply; 9+ messages in thread
From: sashiko-bot @ 2026-07-27 5:38 UTC (permalink / raw)
To: Dmitry Torokhov; +Cc: linux-input, dmitry.torokhov
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] The patch introduces an unbounded increment of `psmouse->pktcnt` leading to a heap buffer overflow in the `psmouse->packet` array when stray bytes are received during protocol disconnect.
--
--- Patch [1]: [PATCH 1/4] Input: psmouse - fix use-after-free during protocol disconnect ---
commit 6906d0fc401466f9489746b3c6e47ede12a56c49
Author: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Input: psmouse - fix use-after-free during protocol disconnect
This commit attempts to fix a use-after-free by explicitly setting
psmouse->protocol_handler to NULL inside a serio_pause_rx scoped_guard.
It also updates psmouse_handle_byte() to drop incoming bytes when the
handler is NULL.
> diff --git a/drivers/input/mouse/psmouse-base.c b/drivers/input/mouse/psmouse-base.c
> index 6ab5f1d96eaea..916a14b9b6a7d 100644
> --- a/drivers/input/mouse/psmouse-base.c
> +++ b/drivers/input/mouse/psmouse-base.c
> @@ -267,7 +267,13 @@ void psmouse_set_state(struct psmouse *psmouse, enum psmouse_state new_state)
> */
> static int psmouse_handle_byte(struct psmouse *psmouse)
> {
> - psmouse_ret_t rc = psmouse->protocol_handler(psmouse);
> + psmouse_ret_t rc;
> +
> + /* protocol_handler is NULL when device is being disconnected */
> + if (unlikely(!psmouse->protocol_handler))
> + return 0;
> +
[Severity: High]
Does this early return cause an out-of-bounds write in psmouse_receive_byte()?
By returning 0 here, we completely bypass the switch block below which is
responsible for resetting psmouse->pktcnt.
When stray bytes arrive during the disconnect window, psmouse_receive_byte()
will append them to the packet buffer and increment the counter:
psmouse_receive_byte() {
...
psmouse->packet[psmouse->pktcnt++] = data;
...
psmouse_handle_byte(psmouse);
}
If psmouse_handle_byte() keeps returning 0 without resetting pktcnt, won't
pktcnt grow monotonically and eventually overflow the 8-byte packet array?
> + rc = psmouse->protocol_handler(psmouse);
>
> switch (rc) {
> case PSMOUSE_BAD_DATA:
[ ... ]
> @@ -1466,6 +1472,9 @@ static void psmouse_disconnect(struct serio *serio)
> psmouse_deactivate(parent);
> }
>
> + scoped_guard(serio_pause_rx, serio)
> + psmouse->protocol_handler = NULL;
> +
> if (psmouse->disconnect)
> psmouse->disconnect(psmouse);
>
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260727050803.1269941-1-dmitry.torokhov@gmail.com?part=1
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH 2/4] Input: psmouse - clean up locking around disable_work_sync()
2026-07-27 5:32 ` sashiko-bot
@ 2026-07-27 5:52 ` Dmitry Torokhov
0 siblings, 0 replies; 9+ messages in thread
From: Dmitry Torokhov @ 2026-07-27 5:52 UTC (permalink / raw)
To: sashiko-reviews; +Cc: linux-input
On Mon, Jul 27, 2026 at 05:32:54AM +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [High] Moving disable_work_sync() to the top of psmouse_disconnect() breaks the early-abort synchronization in psmouse_resync(), causing delays and queuing stray reconnect events.
> --
This is incorrect analysis. Disconnect may happen a millisecond earlier
or millisecond later, and setting PSMOUSE_CMD_MODE first would not
change anything. We just have to deal with such scenario.
Thanks.
--
Dmitry
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH 1/4] Input: psmouse - fix use-after-free during protocol disconnect
2026-07-27 5:38 ` [PATCH 1/4] Input: psmouse - fix use-after-free during protocol disconnect sashiko-bot
@ 2026-07-27 5:53 ` Dmitry Torokhov
0 siblings, 0 replies; 9+ messages in thread
From: Dmitry Torokhov @ 2026-07-27 5:53 UTC (permalink / raw)
To: sashiko-reviews; +Cc: linux-input
On Mon, Jul 27, 2026 at 05:38:08AM +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [High] The patch introduces an unbounded increment of `psmouse->pktcnt` leading to a heap buffer overflow in the `psmouse->packet` array when stray bytes are received during protocol disconnect.
> --
Fair, I'll fix this up.
Thanks.
--
Dmitry
^ permalink raw reply [flat|nested] 9+ messages in thread
end of thread, other threads:[~2026-07-27 5:53 UTC | newest]
Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-27 5:07 [PATCH 1/4] Input: psmouse - fix use-after-free during protocol disconnect Dmitry Torokhov
2026-07-27 5:07 ` [PATCH 2/4] Input: psmouse - clean up locking around disable_work_sync() Dmitry Torokhov
2026-07-27 5:32 ` sashiko-bot
2026-07-27 5:52 ` Dmitry Torokhov
2026-07-27 5:08 ` [PATCH 3/4] Input: psmouse - modernize PNP ID parsing Dmitry Torokhov
2026-07-27 5:08 ` [PATCH 4/4] Input: psmouse - use guard() for resource management Dmitry Torokhov
2026-07-27 5:35 ` sashiko-bot
2026-07-27 5:38 ` [PATCH 1/4] Input: psmouse - fix use-after-free during protocol disconnect sashiko-bot
2026-07-27 5:53 ` Dmitry Torokhov
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.