Linux Input/HID development
 help / color / mirror / Atom feed
From: "André Pinheiro" <andre@pepdata.pt>
To: stable@vger.kernel.org
Cc: "Greg Kroah-Hartman" <gregkh@linuxfoundation.org>,
	"Sasha Levin" <sashal@kernel.org>,
	"Jiri Kosina" <jikos@kernel.org>,
	"Benjamin Tissoires" <bentiss@kernel.org>,
	"Antheas Kapenekakis" <lkml@antheas.dev>,
	"Ilpo Järvinen" <ilpo.jarvinen@linux.intel.com>,
	linux-input@vger.kernel.org, regressions@lists.linux.dev
Subject: [REGRESSION] 6.18.y: HID: asus: ROG keyboard 0b05:19b6 stops working after 56d1b33e644c backport; missing buffer size fix e82ae34af29e
Date: Wed, 30 Sep 2026 05:24:59 +0100	[thread overview]
Message-ID: <14ed23dd-b171-4ffb-b368-5c717f56188c@pepdata.pt> (raw)

Hi,

Since 6.18.49, the internal keyboard of ASUS ROG Zephyrus G16 GU605MV
(USB 0b05:19b6, ITE Device(8910), bcdDevice 0.03) can stop sending input
events. 6.18.42 works. 6.18.51 is broken. I did not test 6.18.49/6.18.50.

Cause: the backport of 56d1b33e644c ("HID: asus: simplify RGB init
sequence") made asus_kbd_get_functions() run for QUIRK_ROG_NKEY_KEYBOARD
devices too. That function reads feature report 0x5A into a buffer of
FEATURE_KBD_REPORT_SIZE = 16 bytes. This device answers with 63 bytes, so
the transfer fails with EOVERFLOW. The buffer size fix is in mainline as
e82ae34af29e ("HID: asus: fortify keyboard handshake", 
FEATURE_KBD_REPORT_SIZE
16 -> 64; its message says "Since the response is more than 16 bytes,
increase the buffer size to 64 as well to avoid overflow errors"). It is in
the same series as 56d1b33e644c but was not backported. v7.0 has the value
64 (checked in the source, not booted on this machine).

Symptom (6.18.51):
   asus 0003:0B05:19B6.0001: Asus failed to request functions: -75
   asus 0003:0B05:19B6.0001: Failed to initialize backlight.
usbmon:
   S Ci:1:002:0 s a1 01 035a 0000 0010 16 <
   C Ci:1:002:0 -75 0

The HID report descriptor (1102 bytes, from sysfs) declares Feature report
0x5A as 62 data bytes plus the report ID (63). The device matches its own
descriptor; the driver buffer is too small.

Evidence. Same physical device and USB host controller (xhci on 6.18.42) in
both runs, only the guest kernel driving the HID device changes; bytes read
from the evdev node while typing:
   guest 6.18.42: 16776 bytes in 12 s
   guest 6.18.51: -75 as above, 0 bytes in 12 s

Requests sent by hand on 6.18.42 through hidraw (HIDIOCGFEATURE on report
0x5A), device re-enumerated before each case, bytes in 5 s windows:
   GET 16, no SET before:  7488 -> EOVERFLOW -> 0
   GET 32, no SET before:  7776 -> EOVERFLOW -> 0
   GET 64, no SET before:  8208 -> ok, 63 bytes returned -> 8568
   SET 5a 05 20 31 00 08, then GET 64: 8496 -> ok, 63 bytes -> 7920
   SET, then GET 16:       7848 -> EOVERFLOW -> 7056 (did not silence 
this run)
   (an earlier run of SET, GET 16: 2736 -> 6984 after SET -> 0 after GET)
With a 64-byte buffer byte 6 of the reply is 0x83, i.e. 
SUPPORT_KBD_BACKLIGHT
is set. So with the fix the driver would register the backlight instead of
failing. One or two runs per case, only this device tested.

Request: please backport e82ae34af29e (or at least the 
FEATURE_KBD_REPORT_SIZE
16 -> 64 change) to 6.18.y, and to any other stable branch that received
56d1b33e644c. Alternatively drop 56d1b33e644c there.

Thanks,
André


             reply	other threads:[~2026-09-30  4:30 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-30  4:24 André Pinheiro [this message]
2026-09-30 12:13 ` [REGRESSION] 6.18.y: HID: asus: ROG keyboard 0b05:19b6 stops working after 56d1b33e644c backport; missing buffer size fix e82ae34af29e Greg Kroah-Hartman
2026-09-30 14:53   ` Salvatore Bonaccorso

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=14ed23dd-b171-4ffb-b368-5c717f56188c@pepdata.pt \
    --to=andre@pepdata.pt \
    --cc=bentiss@kernel.org \
    --cc=gregkh@linuxfoundation.org \
    --cc=ilpo.jarvinen@linux.intel.com \
    --cc=jikos@kernel.org \
    --cc=linux-input@vger.kernel.org \
    --cc=lkml@antheas.dev \
    --cc=regressions@lists.linux.dev \
    --cc=sashal@kernel.org \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox