From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f44.google.com (mail-pj1-f44.google.com [209.85.216.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6A9CC2E2DF2 for ; Mon, 3 Aug 2026 01:22:44 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.44 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785720167; cv=none; b=gTwRmT2X0Ade68uDmoEoJWUORw/bt/TUtFtX0fOrweX4lxREKFtO9BKOyFDLGK9f+CY+YAhEWeiRhZpoF4hDV+emqelGEHYxknIoVeIs3oqGPB2QhrgS3yP/KgP4jAWwr16gwWq6YJsuBdGJ0QdKBlUIr1+FvjCA++EmKJzyWrw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785720167; c=relaxed/simple; bh=w60xHHDm9F8SAZ2d6EJehwap+FjePOGuUHew2BGk1MY=; h=Date:From:To:Cc:Subject:Message-ID:MIME-Version:Content-Type: Content-Disposition; b=MO1CIAeutPsg0Ii8wrQ+A22c59I3C1V8I3n78IjINSiqhDTtVzt0y4zwY/dHM9P10KFhfYCJjDo6TKm5t3NhSXbSLQ4GEDHWisYoFaK8Q4Q0VFXG8vQXEqO/GiVS0+3Vh1vxaxyiHqY+taZoVfdBw8mLK7VqGBPap+hKaWUmdko= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=r6mg78If; arc=none smtp.client-ip=209.85.216.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="r6mg78If" Received: by mail-pj1-f44.google.com with SMTP id 98e67ed59e1d1-38fdeaed181so198061a91.1 for ; Sun, 02 Aug 2026 18:22:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785720163; x=1786324963; darn=vger.kernel.org; h=content-disposition:content-type:mime-version:message-id:subject:cc :to:from:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=pinT79H7PFWF2UbBIjosXbbXUGgPnltGssDiSYyEm60=; b=r6mg78IfClrED0yFkVm8CpmWD5SxI9GYXTvQ7ZisiLfDEKpTGlFMAI2wP7Oi73neVu sXU8bXoIqHEdWv61GH/CfcUxZ1b36pKtraaZPnarsDCkTsPsE63o80v16zk5BmVxdjZE 0d/TedcQgV/wCsmSTIBMUrPLQs3tDvmJ/v2/nbZliYBeQ2IDItBjUTHwPs9U2UP3uZro qLApBVw7dVr1bp9R1dIBRf/NDI9QuDKf5b+P/C2BGJ5aD0xXKenqyJF/wmvKZNSfx/k7 55MPwYgLJQ6NW1DnIWP8SjRq7TUcZRLY0kbxLrcVsXMzv/tmzRnImUuwhG29X0zO0E8z vsQw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785720163; x=1786324963; h=content-disposition:content-type:mime-version:message-id:subject:cc :to:from:date:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=pinT79H7PFWF2UbBIjosXbbXUGgPnltGssDiSYyEm60=; b=NtGHgrUm2Zpvytd/sn1vM2CLZD/4mUOuT6GMk/onR0JDWCgeVdISky30J/C/MioV68 wwI57t5XZGhQf8fDEUFGdkyb6P816jnP5WpyR6LrLY7CCuwvydVRs8Go8ipKMJk0O300 yo1j5regrXVcS8ItmZDRiPyd4iTnlAyDAT0yI5HMlalIOlxtLneIi+fjeQDeAx/lXVTW Wqb7VFEAktAjpbLU8J6puSTk/CNu5D1ha7Na9YkrEcFvuhHtW9l+YYjfkEQHYqCr+JA2 UerX9poLiVzd1rnCRTZ4Z5S/ljbGcUGFbUCJFmzOP9U802hZn+515fIW5+LQKJVE+crc 94lA== X-Forwarded-Encrypted: i=1; AHgh+Rr2VVwNETjtt/o46Jc5i3/jTiByre3XtcGQB+rtzX9UIw2cyxZ5Ksw3ONdCuIryeo2TJT8Y9a2jMu7DBjY=@vger.kernel.org X-Gm-Message-State: AOJu0Yx3Ay3ShB33Fo57A9f/1CPTHLpgtTO810MR6hTNy4doCCS4V7eQ 2e7Gsbnuwe3u07nTg8S2u/NH+rb2wmAyx/EcOa6DT++1BzDdx8EmcGkn X-Gm-Gg: AR+sD11830TWQJyvmVOrcr4Tgib50xWE1ZU4e05KdeSFil8Wz1wzfsdRf4zQvkxMsGv wL/cbzob6YtLUM9OHJMBQD6DynQoBtabvAXbrX/PlUBm7J2UMfsJMkBM/BTgtxjfWpgnWDQRT0k d0ZXm1NmsjU/Az2D59E2ljz+8+45xrKylsb73U3pkVUWHS/V8eLVpy0y4x+MIrGV3eVnX3jZjz4 Vo6x2wMI4NgSTeoN3E8TnuPB+KXv5yKDpJLMOsh0MS6giU8/6Whk8MBCYJ+utk6Ev96ZGXyHize kIDCe8qKvz10BeqoNdVsAf1XmFD1GTDuQWYNMSQQU9b5tx7X62cxdYN8mEYzITmOyiJxlG0pwrq 5J9esBVlUFD4PRQQTkx61E3rvE7hxTBbEgE+2uN/7yTxMGUx7nerCqwy/ExY0ugzPIDuyegD/Yl DgS3uY9PPSoo93zJIXk/9Pxflj/PeV31jg/q9Q4vCXV40x6d7vHLuxU2AkETyD+YuVAa03htfZt 5s+2RlZ9FesfRxkDf2GKcc4GHy6Nw== X-Received: by 2002:a05:6a21:3390:b0:3c4:3ada:384d with SMTP id adf61e73a8af0-3c92a57baf2mr7063094637.30.1785720163372; Sun, 02 Aug 2026 18:22:43 -0700 (PDT) Received: from google.com ([2a00:79e0:2ebe:8:4fff:876c:cdae:e53c]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3153db2f911sm35037247eec.0.2026.08.02.18.22.42 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 02 Aug 2026 18:22:42 -0700 (PDT) Date: Sun, 2 Aug 2026 18:22:40 -0700 From: Dmitry Torokhov To: linux-input@vger.kernel.org Cc: Richard Davies , Mathias Gottschlag , Hans de Goede , linux-kernel@vger.kernel.org Subject: [PATCH] Input: focaltech - use signed coordinates to prevent underflow Message-ID: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline focaltech_finger_state stores finger coordinates x and y as unsigned int. When processing relative packets, negative deltas can cause unsigned integer underflow if the finger moves past the left or bottom boundary of the touchpad, wrapping the coordinates to values near UINT_MAX. When clamping the coordinates in focaltech_report_state(), these underflowed values are clamped against priv->x_max / priv->y_max instead of 0, causing the cursor to jump erratically to the opposite edge of the touchpad. Change the coordinate variables and limits to signed int so that negative values resulting from relative movements clamp correctly to 0. Fixes: 05be1d079ec0 ("Input: psmouse - support for the FocalTech PS/2 protocol extensions") Reported-by: sashiko-bot@kernel.org Assisted-by: Antigravity:gemini-3.6-flash Signed-off-by: Dmitry Torokhov --- drivers/input/mouse/focaltech.c | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/drivers/input/mouse/focaltech.c b/drivers/input/mouse/focaltech.c index d3ad4af5aa09..c6f6540e3e29 100644 --- a/drivers/input/mouse/focaltech.c +++ b/drivers/input/mouse/focaltech.c @@ -78,8 +78,8 @@ struct focaltech_finger_state { * Absolute position (from the bottom left corner) of the * finger. */ - unsigned int x; - unsigned int y; + int x; + int y; }; /* @@ -108,7 +108,7 @@ struct focaltech_hw_state { }; struct focaltech_data { - unsigned int x_max, y_max; + int x_max, y_max; struct focaltech_hw_state state; }; @@ -126,14 +126,14 @@ static void focaltech_report_state(struct psmouse *psmouse) input_mt_slot(dev, i); input_mt_report_slot_state(dev, MT_TOOL_FINGER, active); if (active) { - unsigned int clamped_x, clamped_y; + int clamped_x, clamped_y; /* * The touchpad might report invalid data, so we clamp * the resulting values so that we do not confuse * userspace. */ - clamped_x = clamp(finger->x, 0U, priv->x_max); - clamped_y = clamp(finger->y, 0U, priv->y_max); + clamped_x = clamp(finger->x, 0, priv->x_max); + clamped_y = clamp(finger->y, 0, priv->y_max); input_report_abs(dev, ABS_MT_POSITION_X, clamped_x); input_report_abs(dev, ABS_MT_POSITION_Y, priv->y_max - clamped_y); -- 2.55.0.508.g3f0d502094-goog -- Dmitry