From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
alan@lxorguk.ukuu.org.uk, Kevin Daughtridge <kevin@kdau.com>,
Jiri Kosina <jkosina@suse.cz>
Subject: [ 36/58] HID: keep dev_rdesc unmodified and use it for comparisons
Date: Thu, 4 Oct 2012 14:19:43 -0700 [thread overview]
Message-ID: <20121004210639.974132799@linuxfoundation.org> (raw)
In-Reply-To: <20121004210635.449598766@linuxfoundation.org>
3.5-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kevin Daughtridge <kevin@kdau.com>
commit 86e6b77eb7cf9ca2e9c7092b4dfd588f0a3307b6 upstream.
The dev_rdesc member of the hid_device structure is meant to store the original
report descriptor received from the device, but it is currently passed to any
report_fixup method before it is copied to the rdesc member. This patch uses a
temporary buffer to shield dev_rdesc from the side effects of many HID drivers'
report_fixup implementations.
usbhid's hid_post_reset checks the report descriptor currently returned by the
device against a descriptor that may have been modified by a driver's
report_fixup method. That leaves some devices nonfunctional after a resume, with
a "reset_resume error 1" reported. This patch checks the new descriptor against
the unmodified dev_rdesc instead and uses the original, instead of modified,
report size.
BugLink: http://bugs.launchpad.net/bugs/1049623
Signed-off-by: Kevin Daughtridge <kevin@kdau.com>
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hid/hid-core.c | 16 +++++++++++++---
drivers/hid/usbhid/hid-core.c | 6 +++---
2 files changed, 16 insertions(+), 6 deletions(-)
--- a/drivers/hid/hid-core.c
+++ b/drivers/hid/hid-core.c
@@ -757,6 +757,7 @@ int hid_open_report(struct hid_device *d
struct hid_item item;
unsigned int size;
__u8 *start;
+ __u8 *buf;
__u8 *end;
int ret;
static int (*dispatch_type[])(struct hid_parser *parser,
@@ -775,12 +776,21 @@ int hid_open_report(struct hid_device *d
return -ENODEV;
size = device->dev_rsize;
+ buf = kmemdup(start, size, GFP_KERNEL);
+ if (buf == NULL)
+ return -ENOMEM;
+
if (device->driver->report_fixup)
- start = device->driver->report_fixup(device, start, &size);
+ start = device->driver->report_fixup(device, buf, &size);
+ else
+ start = buf;
- device->rdesc = kmemdup(start, size, GFP_KERNEL);
- if (device->rdesc == NULL)
+ start = kmemdup(start, size, GFP_KERNEL);
+ kfree(buf);
+ if (start == NULL)
return -ENOMEM;
+
+ device->rdesc = start;
device->rsize = size;
parser = vzalloc(sizeof(struct hid_parser));
--- a/drivers/hid/usbhid/hid-core.c
+++ b/drivers/hid/usbhid/hid-core.c
@@ -1423,20 +1423,20 @@ static int hid_post_reset(struct usb_int
* configuration descriptors passed, we already know that
* the size of the HID report descriptor has not changed.
*/
- rdesc = kmalloc(hid->rsize, GFP_KERNEL);
+ rdesc = kmalloc(hid->dev_rsize, GFP_KERNEL);
if (!rdesc) {
dbg_hid("couldn't allocate rdesc memory (post_reset)\n");
return 1;
}
status = hid_get_class_descriptor(dev,
interface->desc.bInterfaceNumber,
- HID_DT_REPORT, rdesc, hid->rsize);
+ HID_DT_REPORT, rdesc, hid->dev_rsize);
if (status < 0) {
dbg_hid("reading report descriptor failed (post_reset)\n");
kfree(rdesc);
return 1;
}
- status = memcmp(rdesc, hid->rdesc, hid->rsize);
+ status = memcmp(rdesc, hid->dev_rdesc, hid->dev_rsize);
kfree(rdesc);
if (status != 0) {
dbg_hid("report descriptor changed\n");
next prev parent reply other threads:[~2012-10-04 21:22 UTC|newest]
Thread overview: 59+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-10-04 21:19 [ 00/58] 3.5.6-stable review Greg Kroah-Hartman
2012-10-04 21:19 ` [ 01/58] vfs: dcache: fix deadlock in tree traversal Greg Kroah-Hartman
2012-10-04 21:19 ` [ 02/58] dm mpath: only retry ioctl when no paths if queue_if_no_path set Greg Kroah-Hartman
2012-10-04 21:19 ` [ 03/58] dm: handle requests beyond end of device instead of using BUG_ON Greg Kroah-Hartman
2012-10-04 21:19 ` [ 04/58] dm table: clear add_random unless all devices have it set Greg Kroah-Hartman
2012-10-04 21:19 ` [ 05/58] dm verity: fix overflow check Greg Kroah-Hartman
2012-10-04 21:19 ` [ 06/58] usb: gadget: make g_printer enumerate again Greg Kroah-Hartman
2012-10-04 21:19 ` [ 07/58] usb: gadget: initialize the strings in tcm_usb_gadget properly Greg Kroah-Hartman
2012-10-04 21:19 ` [ 08/58] USB: option: blacklist QMI interface on ZTE MF683 Greg Kroah-Hartman
2012-10-04 21:19 ` [ 09/58] USB: ftdi_sio: add TIAO USB Multi-Protocol Adapter (TUMPA) support Greg Kroah-Hartman
2012-10-04 21:19 ` [ 10/58] USB: qcaux: add Pantech vendor class match Greg Kroah-Hartman
2012-10-04 21:19 ` [ 11/58] usb: host: xhci: Fix Null pointer dereferencing with 71c731a for non-x86 systems Greg Kroah-Hartman
2012-10-04 21:19 ` [ 12/58] USB: serial: fix up bug with missing {} Greg Kroah-Hartman
2012-10-04 21:19 ` [ 13/58] staging: speakup_soft: Fix reading of init string Greg Kroah-Hartman
2012-10-04 21:19 ` [ 14/58] tty: keyboard.c: Remove locking from vt_get_leds Greg Kroah-Hartman
2012-10-04 21:19 ` [ 15/58] staging: r8712u: Do not queue cloned skb Greg Kroah-Hartman
2012-10-04 21:19 ` [ 16/58] staging: comedi: s626: dont dereference insn->data Greg Kroah-Hartman
2012-10-04 21:19 ` [ 17/58] staging: comedi: jr3_pci: fix iomem dereference Greg Kroah-Hartman
2012-10-04 21:19 ` [ 18/58] staging: comedi: dont dereference user memory for INSN_INTTRIG Greg Kroah-Hartman
2012-10-04 21:19 ` [ 19/58] staging: comedi: fix memory leak for saved channel list Greg Kroah-Hartman
2012-10-04 21:19 ` [ 20/58] Remove BUG_ON from n_tty_read() Greg Kroah-Hartman
2012-10-04 21:19 ` [ 21/58] TTY: ttyprintk, dont touch behind tty->write_buf Greg Kroah-Hartman
2012-10-04 21:19 ` [ 22/58] serial: omap: fix software flow control Greg Kroah-Hartman
2012-10-04 21:19 ` [ 23/58] serial: pl011: handle corruption at high clock speeds Greg Kroah-Hartman
2012-10-04 21:19 ` [ 24/58] serial: set correct baud_base for EXSYS EX-41092 Dual 16950 Greg Kroah-Hartman
2012-10-04 21:19 ` [ 25/58] tools/hv: Fix file handle leak Greg Kroah-Hartman
2012-10-04 21:19 ` [ 26/58] tools/hv: Fix exit() error code Greg Kroah-Hartman
2012-10-04 21:19 ` [ 27/58] tools/hv: Check for read/write errors Greg Kroah-Hartman
2012-10-04 21:19 ` [ 28/58] b43legacy: Fix crash on unload when firmware not available Greg Kroah-Hartman
2012-10-04 21:19 ` [ 29/58] firmware: Add missing attributes to EFI variable attribute print out from sysfs Greg Kroah-Hartman
2012-10-04 21:19 ` [ 30/58] xhci: Intel Panther Point BEI quirk Greg Kroah-Hartman
2012-10-04 21:19 ` [ 31/58] xHCI: add cmd_ring_state Greg Kroah-Hartman
2012-10-04 21:19 ` [ 32/58] xHCI: add aborting command ring function Greg Kroah-Hartman
2012-10-04 21:19 ` [ 33/58] xHCI: cancel command after command timeout Greg Kroah-Hartman
2012-10-04 21:19 ` [ 34/58] xHCI: handle command after aborting the command ring Greg Kroah-Hartman
2012-10-04 21:19 ` [ 35/58] Increase XHCI suspend timeout to 16ms Greg Kroah-Hartman
2012-10-04 21:19 ` Greg Kroah-Hartman [this message]
2012-10-04 21:19 ` [ 37/58] ath9k: Disable ASPM only for AR9285 Greg Kroah-Hartman
2012-10-04 21:19 ` [ 38/58] xen/pciback: Restore the PCI config space after an FLR Greg Kroah-Hartman
2012-10-04 21:19 ` [ 39/58] coredump: prevent double-free on an error path in core dumper Greg Kroah-Hartman
2012-10-04 21:19 ` [ 40/58] n_gsm.c: Implement 3GPP27.010 DLC start-up procedure in MUX Greg Kroah-Hartman
2012-10-04 21:19 ` [ 41/58] n_gsm: uplink SKBs accumulate on list Greg Kroah-Hartman
2012-10-04 21:19 ` [ 42/58] n_gsm: added interlocking for gsm_data_lock for certain code paths Greg Kroah-Hartman
2012-10-04 21:19 ` [ 43/58] n_gsm: memory leak in uplink error path Greg Kroah-Hartman
2012-10-04 21:19 ` [ 44/58] UBI: fix autoresize handling in R/O mode Greg Kroah-Hartman
2012-10-04 21:19 ` [ 45/58] UBI: erase free PEB with bitflip in EC header Greg Kroah-Hartman
2012-10-04 21:19 ` [ 46/58] Yama: handle 32-bit userspace prctl Greg Kroah-Hartman
2012-10-04 21:19 ` [ 47/58] SCSI: ibmvscsi: Fix host config length field overflow Greg Kroah-Hartman
2012-10-04 21:19 ` [ 48/58] SCSI: hpsa: Use LUN reset instead of target reset Greg Kroah-Hartman
2012-10-04 21:19 ` [ 49/58] can: mscan-mpc5xxx: fix return value check in mpc512x_can_get_clock() Greg Kroah-Hartman
2012-10-04 21:19 ` [ 50/58] remoteproc: select VIRTIO to avoid build breakage Greg Kroah-Hartman
2012-10-04 21:19 ` [ 51/58] remoteproc: fix a potential NULL-dereference on cleanup Greg Kroah-Hartman
2012-10-04 21:19 ` [ 52/58] IPoIB: Fix use-after-free of multicast object Greg Kroah-Hartman
2012-10-04 21:20 ` [ 53/58] IB/srp: Fix use-after-free in srp_reset_req() Greg Kroah-Hartman
2012-10-04 21:20 ` [ 54/58] IB/srp: Avoid having aborted requests hang Greg Kroah-Hartman
2012-10-04 21:20 ` [ 55/58] isci: fix isci_pci_probe() generates warning on efi failure path Greg Kroah-Hartman
2012-10-04 21:20 ` [ 56/58] x86/alternatives: Fix p6 nops on non-modular kernels Greg Kroah-Hartman
2012-10-04 21:20 ` [ 57/58] SCSI: scsi_remove_target: fix softlockup regression on hot remove Greg Kroah-Hartman
2012-10-04 21:20 ` [ 58/58] SCSI: scsi_dh_alua: Enable STPG for unavailable ports Greg Kroah-Hartman
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20121004210639.974132799@linuxfoundation.org \
--to=gregkh@linuxfoundation.org \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=jkosina@suse.cz \
--cc=kevin@kdau.com \
--cc=linux-kernel@vger.kernel.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).