From: Dmitry Torokhov <dmitry.torokhov@gmail.com>
To: Pooyan Azad <pooyan.azadparvar@gmail.com>
Cc: "Uwe Kleine-König" <u.kleine-koenig@baylibre.com>,
"Muhammad Bilal" <meatuni001@gmail.com>,
"Herlangga Maulani" <w1zardsec@proton.me>,
linux-input@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH] Input: raydium_i2c_ts - validate report parameters
Date: Sun, 27 Sep 2026 19:38:54 -0700 [thread overview]
Message-ID: <arnRiZyWe6zmd68S@google.com> (raw)
In-Reply-To: <20260927114425.442803-1-pooyan.azadparvar@gmail.com>
Hi Pooyan,
On Sun, Sep 27, 2026 at 01:44:25PM +0200, Pooyan Azad wrote:
> The controller supplies packet and per-contact sizes used to allocate and
> parse touch reports. The driver trusts these values without validation.
>
> A packet size smaller than the two-byte checksum makes report_size wrap,
> allowing the IRQ handler to read beyond the report buffer. A zero or
> undersized contact size can cause a divide by zero or make the contact
> parser read beyond a record.
>
> Validate both sizes before publishing them, and reject reports that
> describe more contacts than the input device has slots.
>
> Allocate the report buffer once valid main firmware information is
> available, and resize it if a firmware update changes the packet size.
> This also handles devices that probe in bootloader mode, where the packet
> size is not known yet.
>
> Finally, return main firmware query failures from initialization so probe
> and firmware update do not continue with invalid report parameters. Keep
> bootloader HWID query failures non-fatal so the recovery interface remains
> available.
It looks like there ate 3 somewhat independent changes. Please split the
incoming data validation from the buffer management and handling
bootloader query failures. I think only the data validation needs to go
into stable, the rest are regular behavior improvements.
Thanks.
--
Dmitry
next prev parent reply other threads:[~2026-09-28 2:39 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-27 11:44 [PATCH] Input: raydium_i2c_ts - validate report parameters Pooyan Azad
2026-09-27 17:30 ` Muhammad Bilal
2026-09-27 17:58 ` Pooyan Azadparvar
2026-09-28 2:38 ` Dmitry Torokhov [this message]
2026-09-28 6:04 ` Pooyan Azadparvar
2026-09-28 16:26 ` [PATCH v2 0/3] Input: raydium_i2c_ts report handling fixes Pooyan Azad
2026-09-28 16:26 ` [PATCH v2 1/3] Input: raydium_i2c_ts - validate report parameters Pooyan Azad
2026-09-28 16:26 ` [PATCH v2 2/3] Input: raydium_i2c_ts - resize report buffer after firmware update Pooyan Azad
2026-09-28 16:26 ` [PATCH v2 3/3] Input: raydium_i2c_ts - defer report buffer allocation Pooyan Azad
2026-10-07 9:04 ` [PATCH v2 0/3] Input: raydium_i2c_ts report handling fixes Pooyan Azadparvar
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=arnRiZyWe6zmd68S@google.com \
--to=dmitry.torokhov@gmail.com \
--cc=linux-input@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=meatuni001@gmail.com \
--cc=pooyan.azadparvar@gmail.com \
--cc=u.kleine-koenig@baylibre.com \
--cc=w1zardsec@proton.me \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.