* [REGRESSION] 6.18.y: HID: asus: ROG keyboard 0b05:19b6 stops working after 56d1b33e644c backport; missing buffer size fix e82ae34af29e
@ 2026-09-30 4:24 André Pinheiro
2026-09-30 12:13 ` Greg Kroah-Hartman
0 siblings, 1 reply; 3+ messages in thread
From: André Pinheiro @ 2026-09-30 4:24 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, Sasha Levin, Jiri Kosina, Benjamin Tissoires,
Antheas Kapenekakis, Ilpo Järvinen, linux-input, regressions
Hi,
Since 6.18.49, the internal keyboard of ASUS ROG Zephyrus G16 GU605MV
(USB 0b05:19b6, ITE Device(8910), bcdDevice 0.03) can stop sending input
events. 6.18.42 works. 6.18.51 is broken. I did not test 6.18.49/6.18.50.
Cause: the backport of 56d1b33e644c ("HID: asus: simplify RGB init
sequence") made asus_kbd_get_functions() run for QUIRK_ROG_NKEY_KEYBOARD
devices too. That function reads feature report 0x5A into a buffer of
FEATURE_KBD_REPORT_SIZE = 16 bytes. This device answers with 63 bytes, so
the transfer fails with EOVERFLOW. The buffer size fix is in mainline as
e82ae34af29e ("HID: asus: fortify keyboard handshake",
FEATURE_KBD_REPORT_SIZE
16 -> 64; its message says "Since the response is more than 16 bytes,
increase the buffer size to 64 as well to avoid overflow errors"). It is in
the same series as 56d1b33e644c but was not backported. v7.0 has the value
64 (checked in the source, not booted on this machine).
Symptom (6.18.51):
asus 0003:0B05:19B6.0001: Asus failed to request functions: -75
asus 0003:0B05:19B6.0001: Failed to initialize backlight.
usbmon:
S Ci:1:002:0 s a1 01 035a 0000 0010 16 <
C Ci:1:002:0 -75 0
The HID report descriptor (1102 bytes, from sysfs) declares Feature report
0x5A as 62 data bytes plus the report ID (63). The device matches its own
descriptor; the driver buffer is too small.
Evidence. Same physical device and USB host controller (xhci on 6.18.42) in
both runs, only the guest kernel driving the HID device changes; bytes read
from the evdev node while typing:
guest 6.18.42: 16776 bytes in 12 s
guest 6.18.51: -75 as above, 0 bytes in 12 s
Requests sent by hand on 6.18.42 through hidraw (HIDIOCGFEATURE on report
0x5A), device re-enumerated before each case, bytes in 5 s windows:
GET 16, no SET before: 7488 -> EOVERFLOW -> 0
GET 32, no SET before: 7776 -> EOVERFLOW -> 0
GET 64, no SET before: 8208 -> ok, 63 bytes returned -> 8568
SET 5a 05 20 31 00 08, then GET 64: 8496 -> ok, 63 bytes -> 7920
SET, then GET 16: 7848 -> EOVERFLOW -> 7056 (did not silence
this run)
(an earlier run of SET, GET 16: 2736 -> 6984 after SET -> 0 after GET)
With a 64-byte buffer byte 6 of the reply is 0x83, i.e.
SUPPORT_KBD_BACKLIGHT
is set. So with the fix the driver would register the backlight instead of
failing. One or two runs per case, only this device tested.
Request: please backport e82ae34af29e (or at least the
FEATURE_KBD_REPORT_SIZE
16 -> 64 change) to 6.18.y, and to any other stable branch that received
56d1b33e644c. Alternatively drop 56d1b33e644c there.
Thanks,
André
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [REGRESSION] 6.18.y: HID: asus: ROG keyboard 0b05:19b6 stops working after 56d1b33e644c backport; missing buffer size fix e82ae34af29e
2026-09-30 4:24 [REGRESSION] 6.18.y: HID: asus: ROG keyboard 0b05:19b6 stops working after 56d1b33e644c backport; missing buffer size fix e82ae34af29e André Pinheiro
@ 2026-09-30 12:13 ` Greg Kroah-Hartman
2026-09-30 14:53 ` Salvatore Bonaccorso
0 siblings, 1 reply; 3+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 12:13 UTC (permalink / raw)
To: André Pinheiro
Cc: stable, Sasha Levin, Jiri Kosina, Benjamin Tissoires,
Antheas Kapenekakis, Ilpo Järvinen, linux-input, regressions
On Wed, Sep 30, 2026 at 05:24:59AM +0100, André Pinheiro wrote:
> Hi,
>
> Since 6.18.49, the internal keyboard of ASUS ROG Zephyrus G16 GU605MV
> (USB 0b05:19b6, ITE Device(8910), bcdDevice 0.03) can stop sending input
> events. 6.18.42 works. 6.18.51 is broken. I did not test 6.18.49/6.18.50.
>
> Cause: the backport of 56d1b33e644c ("HID: asus: simplify RGB init
> sequence") made asus_kbd_get_functions() run for QUIRK_ROG_NKEY_KEYBOARD
> devices too. That function reads feature report 0x5A into a buffer of
> FEATURE_KBD_REPORT_SIZE = 16 bytes. This device answers with 63 bytes, so
> the transfer fails with EOVERFLOW. The buffer size fix is in mainline as
> e82ae34af29e ("HID: asus: fortify keyboard handshake",
> FEATURE_KBD_REPORT_SIZE
> 16 -> 64; its message says "Since the response is more than 16 bytes,
> increase the buffer size to 64 as well to avoid overflow errors"). It is in
> the same series as 56d1b33e644c but was not backported. v7.0 has the value
> 64 (checked in the source, not booted on this machine).
>
> Symptom (6.18.51):
> asus 0003:0B05:19B6.0001: Asus failed to request functions: -75
> asus 0003:0B05:19B6.0001: Failed to initialize backlight.
> usbmon:
> S Ci:1:002:0 s a1 01 035a 0000 0010 16 <
> C Ci:1:002:0 -75 0
>
> The HID report descriptor (1102 bytes, from sysfs) declares Feature report
> 0x5A as 62 data bytes plus the report ID (63). The device matches its own
> descriptor; the driver buffer is too small.
>
> Evidence. Same physical device and USB host controller (xhci on 6.18.42) in
> both runs, only the guest kernel driving the HID device changes; bytes read
> from the evdev node while typing:
> guest 6.18.42: 16776 bytes in 12 s
> guest 6.18.51: -75 as above, 0 bytes in 12 s
>
> Requests sent by hand on 6.18.42 through hidraw (HIDIOCGFEATURE on report
> 0x5A), device re-enumerated before each case, bytes in 5 s windows:
> GET 16, no SET before: 7488 -> EOVERFLOW -> 0
> GET 32, no SET before: 7776 -> EOVERFLOW -> 0
> GET 64, no SET before: 8208 -> ok, 63 bytes returned -> 8568
> SET 5a 05 20 31 00 08, then GET 64: 8496 -> ok, 63 bytes -> 7920
> SET, then GET 16: 7848 -> EOVERFLOW -> 7056 (did not silence this
> run)
> (an earlier run of SET, GET 16: 2736 -> 6984 after SET -> 0 after GET)
> With a 64-byte buffer byte 6 of the reply is 0x83, i.e.
> SUPPORT_KBD_BACKLIGHT
> is set. So with the fix the driver would register the backlight instead of
> failing. One or two runs per case, only this device tested.
>
> Request: please backport e82ae34af29e (or at least the
> FEATURE_KBD_REPORT_SIZE
> 16 -> 64 change) to 6.18.y, and to any other stable branch that received
> 56d1b33e644c. Alternatively drop 56d1b33e644c there.
That commit is already in the 6.18.54 kernel release, can you test the
latest one to verify it is now working? 6.18.51 is a few weeks old now.
thanks,
greg k-h
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [REGRESSION] 6.18.y: HID: asus: ROG keyboard 0b05:19b6 stops working after 56d1b33e644c backport; missing buffer size fix e82ae34af29e
2026-09-30 12:13 ` Greg Kroah-Hartman
@ 2026-09-30 14:53 ` Salvatore Bonaccorso
0 siblings, 0 replies; 3+ messages in thread
From: Salvatore Bonaccorso @ 2026-09-30 14:53 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: André Pinheiro, stable, Sasha Levin, Jiri Kosina,
Benjamin Tissoires, Antheas Kapenekakis, Ilpo Järvinen,
linux-input, regressions
Hi,
On Wed, Sep 30, 2026 at 02:13:03PM +0200, Greg Kroah-Hartman wrote:
> On Wed, Sep 30, 2026 at 05:24:59AM +0100, André Pinheiro wrote:
> > Hi,
> >
> > Since 6.18.49, the internal keyboard of ASUS ROG Zephyrus G16 GU605MV
> > (USB 0b05:19b6, ITE Device(8910), bcdDevice 0.03) can stop sending input
> > events. 6.18.42 works. 6.18.51 is broken. I did not test 6.18.49/6.18.50.
> >
> > Cause: the backport of 56d1b33e644c ("HID: asus: simplify RGB init
> > sequence") made asus_kbd_get_functions() run for QUIRK_ROG_NKEY_KEYBOARD
> > devices too. That function reads feature report 0x5A into a buffer of
> > FEATURE_KBD_REPORT_SIZE = 16 bytes. This device answers with 63 bytes, so
> > the transfer fails with EOVERFLOW. The buffer size fix is in mainline as
> > e82ae34af29e ("HID: asus: fortify keyboard handshake",
> > FEATURE_KBD_REPORT_SIZE
> > 16 -> 64; its message says "Since the response is more than 16 bytes,
> > increase the buffer size to 64 as well to avoid overflow errors"). It is in
> > the same series as 56d1b33e644c but was not backported. v7.0 has the value
> > 64 (checked in the source, not booted on this machine).
> >
> > Symptom (6.18.51):
> > asus 0003:0B05:19B6.0001: Asus failed to request functions: -75
> > asus 0003:0B05:19B6.0001: Failed to initialize backlight.
> > usbmon:
> > S Ci:1:002:0 s a1 01 035a 0000 0010 16 <
> > C Ci:1:002:0 -75 0
> >
> > The HID report descriptor (1102 bytes, from sysfs) declares Feature report
> > 0x5A as 62 data bytes plus the report ID (63). The device matches its own
> > descriptor; the driver buffer is too small.
> >
> > Evidence. Same physical device and USB host controller (xhci on 6.18.42) in
> > both runs, only the guest kernel driving the HID device changes; bytes read
> > from the evdev node while typing:
> > guest 6.18.42: 16776 bytes in 12 s
> > guest 6.18.51: -75 as above, 0 bytes in 12 s
> >
> > Requests sent by hand on 6.18.42 through hidraw (HIDIOCGFEATURE on report
> > 0x5A), device re-enumerated before each case, bytes in 5 s windows:
> > GET 16, no SET before: 7488 -> EOVERFLOW -> 0
> > GET 32, no SET before: 7776 -> EOVERFLOW -> 0
> > GET 64, no SET before: 8208 -> ok, 63 bytes returned -> 8568
> > SET 5a 05 20 31 00 08, then GET 64: 8496 -> ok, 63 bytes -> 7920
> > SET, then GET 16: 7848 -> EOVERFLOW -> 7056 (did not silence this
> > run)
> > (an earlier run of SET, GET 16: 2736 -> 6984 after SET -> 0 after GET)
> > With a 64-byte buffer byte 6 of the reply is 0x83, i.e.
> > SUPPORT_KBD_BACKLIGHT
> > is set. So with the fix the driver would register the backlight instead of
> > failing. One or two runs per case, only this device tested.
> >
> > Request: please backport e82ae34af29e (or at least the
> > FEATURE_KBD_REPORT_SIZE
> > 16 -> 64 change) to 6.18.y, and to any other stable branch that received
> > 56d1b33e644c. Alternatively drop 56d1b33e644c there.
>
> That commit is already in the 6.18.54 kernel release, can you test the
> latest one to verify it is now working? 6.18.51 is a few weeks old now.
FWIW, the commit is missing in the 6.12.y series yet (but I see it has
been already queued for the next review round, thanks!).
We got in Debian a related report at:
https://bugs.debian.org/1149499
Regards,
Salvatore
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-30 14:53 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-30 4:24 [REGRESSION] 6.18.y: HID: asus: ROG keyboard 0b05:19b6 stops working after 56d1b33e644c backport; missing buffer size fix e82ae34af29e André Pinheiro
2026-09-30 12:13 ` Greg Kroah-Hartman
2026-09-30 14:53 ` Salvatore Bonaccorso
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).