* [PATCH v2] HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() [not found] <CGME20250813103051epcas1p39a9dacf48770020ca234e0c648bb01d2@epcas1p3.samsung.com> @ 2025-08-13 10:30 ` Minjong Kim 2025-08-13 11:53 ` Benjamin Tissoires 0 siblings, 1 reply; 4+ messages in thread From: Minjong Kim @ 2025-08-13 10:30 UTC (permalink / raw) To: Jiri Kosina, Benjamin Tissoires; +Cc: linux-input, linux-kernel, Minjong Kim in ntrig_report_version(), hdev parameter passed from hid_probe(). sending descriptor to /dev/uhid can make hdev->dev.parent->parent to null if hdev->dev.parent->parent is null, usb_dev has invalid address(0xffffffffffffff58) that hid_to_usb_dev(hdev) returned when usb_rcvctrlpipe() use usb_dev,it trigger page fault error for address(0xffffffffffffff58) add null check logic to ntrig_report_version() before calling hid_to_usb_dev() Signed-off-by: Minjong Kim <minbell.kim@samsung.com> --- drivers/hid/hid-ntrig.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/drivers/hid/hid-ntrig.c b/drivers/hid/hid-ntrig.c index 2738ce947434f904f32e9a1979b1681c66972ff9..0f76e241e0afb4adb38885a008a05edb24169ea9 100644 --- a/drivers/hid/hid-ntrig.c +++ b/drivers/hid/hid-ntrig.c @@ -144,6 +144,9 @@ static void ntrig_report_version(struct hid_device *hdev) struct usb_device *usb_dev = hid_to_usb_dev(hdev); unsigned char *data = kmalloc(8, GFP_KERNEL); + if (!hid_is_usb(hdev)) + return; + if (!data) goto err_free; --- base-commit: 347e9f5043c89695b01e66b3ed111755afcf1911 change-id: 20250717-hid-ntrig-page-fault-fix-d13c49c86473 Best regards, -- Minjong Kim <minbell.kim@samsung.com> ^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [PATCH v2] HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() 2025-08-13 10:30 ` [PATCH v2] HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() Minjong Kim @ 2025-08-13 11:53 ` Benjamin Tissoires 0 siblings, 0 replies; 4+ messages in thread From: Benjamin Tissoires @ 2025-08-13 11:53 UTC (permalink / raw) To: Jiri Kosina, Minjong Kim; +Cc: linux-input, linux-kernel On Wed, 13 Aug 2025 19:30:22 +0900, Minjong Kim wrote: > in ntrig_report_version(), hdev parameter passed from hid_probe(). > sending descriptor to /dev/uhid can make hdev->dev.parent->parent to null > if hdev->dev.parent->parent is null, usb_dev has > invalid address(0xffffffffffffff58) that hid_to_usb_dev(hdev) returned > when usb_rcvctrlpipe() use usb_dev,it trigger > page fault error for address(0xffffffffffffff58) > > [...] Applied to hid/hid.git (for-6.17/upstream-fixes), thanks! [1/1] HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() https://git.kernel.org/hid/hid/c/185c926283da Cheers, -- Benjamin Tissoires <bentiss@kernel.org> ^ permalink raw reply [flat|nested] 4+ messages in thread
[parent not found: <CGME20250717061154epcas1p329022ab54ed143d2a8d5b3f8b7554b38@epcas1p3.samsung.com>]
* [PATCH] HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() [not found] <CGME20250717061154epcas1p329022ab54ed143d2a8d5b3f8b7554b38@epcas1p3.samsung.com> @ 2025-07-17 6:11 ` Minjong Kim 2025-08-12 12:46 ` Jiri Kosina 0 siblings, 1 reply; 4+ messages in thread From: Minjong Kim @ 2025-07-17 6:11 UTC (permalink / raw) To: Jiri Kosina, Benjamin Tissoires; +Cc: linux-input, linux-kernel, Minjong Kim in ntrig_report_version(), hdev parameter passed from hid_probe(). sending descriptor to /dev/uhid can make hdev->dev.parent->parent to null if hdev->dev.parent->parent is null, usb_dev has invalid address(0xffffffffffffff58) that hid_to_usb_dev(hdev) returned when usb_rcvctrlpipe() use usb_dev,it trigger page fault error for address(0xffffffffffffff58) add null check logic to ntrig_report_version() before calling hid_to_usb_dev() Signed-off-by: Minjong Kim <minbell.kim@samsung.com> --- drivers/hid/hid-ntrig.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/hid/hid-ntrig.c b/drivers/hid/hid-ntrig.c index 2738ce947434f904f32e9a1979b1681c66972ff9..96d3300655b5aa1621015b8e1fb511e6f616a713 100644 --- a/drivers/hid/hid-ntrig.c +++ b/drivers/hid/hid-ntrig.c @@ -139,6 +139,10 @@ static inline void ntrig_set_mode(struct hid_device *hdev, const int mode) static void ntrig_report_version(struct hid_device *hdev) { + + if (!hdev->dev.parent->parent) + return; + int ret; char buf[20]; struct usb_device *usb_dev = hid_to_usb_dev(hdev); --- base-commit: 347e9f5043c89695b01e66b3ed111755afcf1911 change-id: 20250717-hid-ntrig-page-fault-fix-d13c49c86473 Best regards, -- Minjong Kim <minbell.kim@samsung.com> ^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [PATCH] HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() 2025-07-17 6:11 ` [PATCH] " Minjong Kim @ 2025-08-12 12:46 ` Jiri Kosina 2025-08-13 5:17 ` [PATCH v2] " Minjong Kim 0 siblings, 1 reply; 4+ messages in thread From: Jiri Kosina @ 2025-08-12 12:46 UTC (permalink / raw) To: Minjong Kim; +Cc: Benjamin Tissoires, linux-input, linux-kernel On Thu, 17 Jul 2025, Minjong Kim wrote: > in ntrig_report_version(), hdev parameter passed from hid_probe(). > sending descriptor to /dev/uhid can make hdev->dev.parent->parent to null > if hdev->dev.parent->parent is null, usb_dev has > invalid address(0xffffffffffffff58) that hid_to_usb_dev(hdev) returned > when usb_rcvctrlpipe() use usb_dev,it trigger > page fault error for address(0xffffffffffffff58) > > add null check logic to ntrig_report_version() > before calling hid_to_usb_dev() > > Signed-off-by: Minjong Kim <minbell.kim@samsung.com> > --- > drivers/hid/hid-ntrig.c | 4 ++++ > 1 file changed, 4 insertions(+) > > diff --git a/drivers/hid/hid-ntrig.c b/drivers/hid/hid-ntrig.c > index 2738ce947434f904f32e9a1979b1681c66972ff9..96d3300655b5aa1621015b8e1fb511e6f616a713 100644 > --- a/drivers/hid/hid-ntrig.c > +++ b/drivers/hid/hid-ntrig.c > @@ -139,6 +139,10 @@ static inline void ntrig_set_mode(struct hid_device *hdev, const int mode) > > static void ntrig_report_version(struct hid_device *hdev) > { > + > + if (!hdev->dev.parent->parent) > + return; > + > int ret; > char buf[20]; > struct usb_device *usb_dev = hid_to_usb_dev(hdev); I know that mixing declarations and code is fine these days, but we haven't been progressive enough to switch to that coding style in HID subsystem yet :) Would you be willing to move it below the declarations? Thanks, -- Jiri Kosina SUSE Labs ^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH v2] HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() 2025-08-12 12:46 ` Jiri Kosina @ 2025-08-13 5:17 ` Minjong Kim 2025-08-13 8:39 ` Benjamin Tissoires 0 siblings, 1 reply; 4+ messages in thread From: Minjong Kim @ 2025-08-13 5:17 UTC (permalink / raw) To: Jiri Kosina; +Cc: Benjamin Tissoires, linux-input, linux-kernel [-- Attachment #1: Type: text/plain, Size: 1580 bytes --] On Tue, Aug 12, 2025 at 02:46:24PM +0200, Jiri Kosina wrote: > > I know that mixing declarations and code is fine these days, but we > haven't been progressive enough to switch to that coding style in HID > subsystem yet :) Would you be willing to move it below the declarations? > From 75e52defd4b2fd138285c5ad953942e2e6cf2fbb Mon Sep 17 00:00:00 2001 From: Minjong Kim <minbell.kim@samsung.com> Date: Thu, 17 Jul 2025 14:37:47 +0900 Subject: [PATCH v2] HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() in ntrig_report_version(), hdev parameter passed from hid_probe(). sending descriptor to /dev/uhid can make hdev->dev.parent->parent to null if hdev->dev.parent->parent is null, usb_dev has invalid address(0xffffffffffffff58) that hid_to_usb_dev(hdev) returned when usb_rcvctrlpipe() use usb_dev,it trigger page fault error for address(0xffffffffffffff58) add null check logic to ntrig_report_version() before calling hid_to_usb_dev() Signed-off-by: Minjong Kim <minbell.kim@samsung.com> --- drivers/hid/hid-ntrig.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/drivers/hid/hid-ntrig.c b/drivers/hid/hid-ntrig.c index 2738ce947434..fa948d9e236c 100644 --- a/drivers/hid/hid-ntrig.c +++ b/drivers/hid/hid-ntrig.c @@ -144,6 +144,9 @@ static void ntrig_report_version(struct hid_device *hdev) struct usb_device *usb_dev = hid_to_usb_dev(hdev); unsigned char *data = kmalloc(8, GFP_KERNEL); + if (!hdev->dev.parent->parent) + return; + if (!data) goto err_free; -- 2.34.1 I move it below the declarations. Best regards, [-- Attachment #2: Type: text/plain, Size: 0 bytes --] ^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [PATCH v2] HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() 2025-08-13 5:17 ` [PATCH v2] " Minjong Kim @ 2025-08-13 8:39 ` Benjamin Tissoires 0 siblings, 0 replies; 4+ messages in thread From: Benjamin Tissoires @ 2025-08-13 8:39 UTC (permalink / raw) To: Minjong Kim; +Cc: Jiri Kosina, linux-input, linux-kernel On Aug 13 2025, Minjong Kim wrote: > On Tue, Aug 12, 2025 at 02:46:24PM +0200, Jiri Kosina wrote: > > > > I know that mixing declarations and code is fine these days, but we > > haven't been progressive enough to switch to that coding style in HID > > subsystem yet :) Would you be willing to move it below the declarations? > > > > From 75e52defd4b2fd138285c5ad953942e2e6cf2fbb Mon Sep 17 00:00:00 2001 > From: Minjong Kim <minbell.kim@samsung.com> > Date: Thu, 17 Jul 2025 14:37:47 +0900 > Subject: [PATCH v2] HID: hid-ntrig: fix unable to handle page fault in > ntrig_report_version() > > in ntrig_report_version(), hdev parameter passed from hid_probe(). > sending descriptor to /dev/uhid can make hdev->dev.parent->parent to null > if hdev->dev.parent->parent is null, usb_dev has > invalid address(0xffffffffffffff58) that hid_to_usb_dev(hdev) returned > when usb_rcvctrlpipe() use usb_dev,it trigger > page fault error for address(0xffffffffffffff58) > > add null check logic to ntrig_report_version() > before calling hid_to_usb_dev() > > Signed-off-by: Minjong Kim <minbell.kim@samsung.com> > --- > drivers/hid/hid-ntrig.c | 3 +++ > 1 file changed, 3 insertions(+) > > diff --git a/drivers/hid/hid-ntrig.c b/drivers/hid/hid-ntrig.c > index 2738ce947434..fa948d9e236c 100644 > --- a/drivers/hid/hid-ntrig.c > +++ b/drivers/hid/hid-ntrig.c > @@ -144,6 +144,9 @@ static void ntrig_report_version(struct hid_device *hdev) > struct usb_device *usb_dev = hid_to_usb_dev(hdev); > unsigned char *data = kmalloc(8, GFP_KERNEL); > > + if (!hdev->dev.parent->parent) Why simply not use if(!hid_is_usb(hdev)) instead? Cheers, Benjamin > + return; > + > if (!data) > goto err_free; > > -- > 2.34.1 > > I move it below the declarations. > > Best regards, > ^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2025-08-13 11:53 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
[not found] <CGME20250813103051epcas1p39a9dacf48770020ca234e0c648bb01d2@epcas1p3.samsung.com>
2025-08-13 10:30 ` [PATCH v2] HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() Minjong Kim
2025-08-13 11:53 ` Benjamin Tissoires
[not found] <CGME20250717061154epcas1p329022ab54ed143d2a8d5b3f8b7554b38@epcas1p3.samsung.com>
2025-07-17 6:11 ` [PATCH] " Minjong Kim
2025-08-12 12:46 ` Jiri Kosina
2025-08-13 5:17 ` [PATCH v2] " Minjong Kim
2025-08-13 8:39 ` Benjamin Tissoires
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox