From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pg1-f174.google.com (mail-pg1-f174.google.com [209.85.215.174]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 687EF390C8D for ; Wed, 29 Jul 2026 06:00:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.174 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785304830; cv=none; b=pBFZuki1PEok+jQJwNQElRC1hYZ2c8oBozqkWRyuExhM/pSFDf0/cRaXPDrZNPhgb2dzZTKPHB5Rc0FjnVDNO/3M8z+XeryOdd/SyL6OmjkexTX4YvjIMcPeGZI5zC0BjCXFyc+KP6GBq3+OIMZ+d4G9LyOhokcXhE/GdXvg+Wg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785304830; c=relaxed/simple; bh=3uOFEjPnMnUccJZMetPT3Gaw/TbJJKA+mh1hwKmYbz4=; h=Date:From:To:Cc:Subject:Message-ID:MIME-Version:Content-Type: Content-Disposition; b=K8HPSDl6aXzDAK0wGvm+NsJ6HfUSV23zw0lGYZk/2HLg+Q4nofi9/UGuMQAyp3OSOiOruPVJLbcyRERXR+wEu6WoMhy2/7pqlWXnC4iLzs6nJOVR+eaTYsR8bzDSnxFXKW6ZcdtWFBTiHq+KAwOsjsLR9Buf+VkjUrcYSckVsZE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=BtiTONOW; arc=none smtp.client-ip=209.85.215.174 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="BtiTONOW" Received: by mail-pg1-f174.google.com with SMTP id 41be03b00d2f7-c9cf07d2df6so365357a12.2 for ; Tue, 28 Jul 2026 23:00:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785304827; x=1785909627; darn=vger.kernel.org; h=content-disposition:content-type:mime-version:message-id:subject:cc :to:from:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=F3U12xTMjb/SxJ8KmAFJLEVtQeA5qw3lxjMjThYvljA=; b=BtiTONOWATUdjuFHZZ/86ez5oNfTXiR/6o0o506HwXQcVzmrU163DWKHE57OjQtSWf m42KvYqkOv3cV1WpQtWBdkw/gvMc73COxUD9Xkhs/PxbH+Sej01+BQG3g+VPYXEbB0FV Y2mvimOVNxyqvJeDWY0vOoY7Yk9TKfgurIg9FGt3TgnFC72Uu5BTlG04tjQ15OtTnjj5 9hR9stCkZ8Qzqc4jo5rEXltqmvBQl2863YuFNyRVXluRxN/JgL4MnPK//RsTCWk2nUWJ ZdMeM2fqx9nBC/m4XdmW/lyfDA6oFEv82v+pCM4oIKgquuROYO2O0cA3t60DXwKARq0Q 0LOQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785304827; x=1785909627; h=content-disposition:content-type:mime-version:message-id:subject:cc :to:from:date:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=F3U12xTMjb/SxJ8KmAFJLEVtQeA5qw3lxjMjThYvljA=; b=jDNSe34ZrY27FmSRurPAjQeISGgQI+GmPWDtyzErJLI5sowiquUUPaLZ3k7t+M+DJ/ 25faM2pcEMpoaj4M5CvD/spc2VPiccRZIWEVGYb2itRoj13J0UYq3Mbvc6gvp27jqkNv 3Ah5Sv+jUm+8dX8PvR2SLpDFtIEZO78KMKAKNTrxA8QaP2ZnkJWpKpc73wyBkmILSjoQ 80/8E0x3TAT90euLD9ZWaM+A+Tqb1KPPT1sEYYrzmj3nOFHJNUxfTfyy5AwfYWc5zMIU 0wJOiM7Ne4o4xI1YBXKeMKWnKqFfZcnGM25m1I9j5pTQHynhaneX78t1hZQYyoGhIpJp O+RQ== X-Forwarded-Encrypted: i=1; AHgh+RpjosmJbbAwa85fFlyLqSEObYOS06HjXtBU/pkSul4x1eyO/6L7ZQXG6gHrm/uSOEY8sesnEXuBkJ8ZCfM=@vger.kernel.org X-Gm-Message-State: AOJu0YxNEU3hkGf+/v+Aol8a5/TFl5zvVUax7ANd/fLE5ITX1jH5K4jV /sUaKTh5duUJPX2DbL0VgZA+eOqpeMvPwvF7l/R/YqtzTJD6QFc8tPWI X-Gm-Gg: AR+sD13bIIZ1lM99WjIAh0T//+26H9ypSayCWHr1HjYb3lRylR+Sa3Qf321MFm/4LH8 czYtyo8XB3yTABhc75iYdYbSWRIbGmDKq/tsPY7XM2BnNQfU7d2DJ2LMBnEL2z6XH+YPCSLeXzK 32mf9jK7F631SMg62On17x4p7Tlwq37n6qoqCTUSwtsNk5ZLISujtiiijs2UJ4o3p9FJxBrJtGk ln8e0HB55OtZPHPd+lmSpVJGNnUjDxDxonSapPDHx8E4x+MsVnlFj94OQbbKkp4QgCAJ/4hiYWh 70norMJ/T1D/zlyv3Zn7kBRvXhlJZv/49iPHS6TKd05gHbWfgs1aLxAAmOSf4HHfRxyvOq8Qbhs 4y/lb+xCTmDPqx1hnACcFfbguBDrjxUbvPLRonNdVYQlpa9K1INY2YvY5SFfTwWHiiLXL3gsfcM 5NqyF3LJ3vROR+5XwY34HmefJ+Y4yE6P7XPcrW0K9CLecUnVyKUdxnJZEMIUbi19psNtHSCi97/ 3dob6FAyDJI5DHcgMvL9fzO3cnBew== X-Received: by 2002:a05:6a21:4685:b0:3c3:f5ff:8c9b with SMTP id adf61e73a8af0-3c8ba70c0bbmr6325745637.71.1785304827393; Tue, 28 Jul 2026 23:00:27 -0700 (PDT) Received: from google.com ([2a00:79e0:2ebe:8:3062:3727:f62a:314c]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-31504b67063sm6302046eec.9.2026.07.28.23.00.25 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 23:00:26 -0700 (PDT) Date: Tue, 28 Jul 2026 23:00:23 -0700 From: Dmitry Torokhov To: Andi Shyti Cc: Wolfram Sang , Bryam Vargas , linux-i2c@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH v2] i2c: smbus: make i2c_smbus_read_block_data() safer Message-ID: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline i2c_smbus_read_block_data() is dangerous to use because it may deliver up to I2C_SMBUS_BLOCK_MAX (32) bytes, which may be surprising to the caller. Callers tend to allocate buffers of sizes big enough to hold data from a well-behaving device and do not expect that i2c_smbus_read_block_data() may attempt to write more data than expected. To make i2c_smbus_read_block_data() safer to use, change it so that it accepts size of the supplied buffer as another argument and ensure that it will not copy more data than the size of the buffer. Signal oversized responses with -EMSGSIZE. To allow users to gradually transition to the new API employ some macro trickery allowing calling i2c_smbus_read_block_data() with either 3 or 4 arguments. When called with 3 arguments it is assumed that the buffer size is I2C_SMBUS_BLOCK_MAX bytes. Once everyone is transitioned to the 4 argument form the macros should be removed. Signed-off-by: Dmitry Torokhov --- v2: - dropped incorrect changes to Documentation (Andi) - signal oversized responses with -EMSGSIZE (Andi) drivers/i2c/i2c-core-smbus.c | 24 ++++++++++++++++-------- include/linux/i2c.h | 19 +++++++++++++++++-- 2 files changed, 33 insertions(+), 10 deletions(-) diff --git a/drivers/i2c/i2c-core-smbus.c b/drivers/i2c/i2c-core-smbus.c index fa63bee0b345..57f55bbab8a1 100644 --- a/drivers/i2c/i2c-core-smbus.c +++ b/drivers/i2c/i2c-core-smbus.c @@ -208,11 +208,11 @@ s32 i2c_smbus_write_word_data(const struct i2c_client *client, u8 command, EXPORT_SYMBOL(i2c_smbus_write_word_data); /** - * i2c_smbus_read_block_data - SMBus "block read" protocol + * __i2c_smbus_read_block_data - SMBus "block read" protocol * @client: Handle to slave device * @command: Byte interpreted by slave - * @values: Byte array into which data will be read; big enough to hold - * the data returned by the slave. SMBus allows at most 32 bytes. + * @length: size of the @values array. SMBus allows at most 32 bytes + * @values: Byte array into which data will be read * * This executes the SMBus "block read" protocol, returning negative errno * else the number of data bytes in the slave's response. @@ -222,22 +222,30 @@ EXPORT_SYMBOL(i2c_smbus_write_word_data); * support this; its emulation through I2C messaging relies on a specific * mechanism (I2C_M_RECV_LEN) which may not be implemented. */ -s32 i2c_smbus_read_block_data(const struct i2c_client *client, u8 command, - u8 *values) +s32 __i2c_smbus_read_block_data(const struct i2c_client *client, u8 command, + u8 length, u8 *values) { union i2c_smbus_data data; + int ret_len; int status; + if (length > I2C_SMBUS_BLOCK_MAX) + return -EINVAL; + status = i2c_smbus_xfer(client->adapter, client->addr, client->flags, I2C_SMBUS_READ, command, I2C_SMBUS_BLOCK_DATA, &data); if (status) return status; - memcpy(values, &data.block[1], data.block[0]); - return data.block[0]; + ret_len = data.block[0]; + if (ret_len > length) + return -EMSGSIZE; + + memcpy(values, &data.block[1], ret_len); + return ret_len; } -EXPORT_SYMBOL(i2c_smbus_read_block_data); +EXPORT_SYMBOL(__i2c_smbus_read_block_data); /** * i2c_smbus_write_block_data - SMBus "block write" protocol diff --git a/include/linux/i2c.h b/include/linux/i2c.h index 14ab4d3055af..3e685476fa15 100644 --- a/include/linux/i2c.h +++ b/include/linux/i2c.h @@ -174,8 +174,23 @@ i2c_smbus_write_word_swapped(const struct i2c_client *client, } /* Returns the number of read bytes */ -s32 i2c_smbus_read_block_data(const struct i2c_client *client, - u8 command, u8 *values); +s32 __i2c_smbus_read_block_data(const struct i2c_client *client, + u8 command, u8 length, u8 *values); +/* + * This monstrosity allows to call i2c_smbus_read_block_data() with either + * 3 or 4 arguments and will be removed once all users have been switched + * to the 4 argument version. + */ +#define __i2c_smbus_read_block_data_3arg(client, cmd, values) \ + __i2c_smbus_read_block_data(client, cmd, I2C_SMBUS_BLOCK_MAX, values) +#define __i2c_smbus_read_block_data_4arg(client, cmd, length, values) \ + __i2c_smbus_read_block_data(client, cmd, length, values) +#define __i2c_smbus_read_block_data_impl(_1, _2, _3, _4, impl, ...) impl +#define i2c_smbus_read_block_data(client, cmd, varargs...) \ + __i2c_smbus_read_block_data_impl(client, cmd, varargs, \ + __i2c_smbus_read_block_data_4arg, \ + __i2c_smbus_read_block_data_3arg) \ + (client, cmd, varargs) s32 i2c_smbus_write_block_data(const struct i2c_client *client, u8 command, u8 length, const u8 *values); /* Returns the number of read bytes */ -- 2.55.0.487.gaf234c4eb3-goog -- Dmitry