From: Chris J Arges <hidden> Date: 2016-05-23 01:42:31
I've noticed crashes when using my x60t using a coreboot bios. When using
the pen I can produce a crash simply by tapping a few times. This
generates an event which has an idx of 0xc. This in turn crashes the
machine because the array access is greater than W8001_MAX_LENGTH. This
patch checks for bogus values and filters them in order to prevent crashes.
Signed-off-by: Chris J Arges <redacted>
---
drivers/input/touchscreen/wacom_w8001.c | 9 +++++++++
1 file changed, 9 insertions(+)
Hi Chris,
On Sun, May 22, 2016 at 6:42 PM, Chris J Arges
[off-list ref] wrote:
I've noticed crashes when using my x60t using a coreboot bios. When using
the pen I can produce a crash simply by tapping a few times. This
generates an event which has an idx of 0xc. This in turn crashes the
machine because the array access is greater than W8001_MAX_LENGTH. This
patch checks for bogus values and filters them in order to prevent crashes.
Thank you for submitting a patch in addition to reporting the issue.
I don't have an x60t system to test with. I wonder if your system
supports two finger touch or not. We at least have a bug in the code
since W8001_MAX_LENGTH should be 13 instead of 11. How come no one had
encountered that issue before?
I'm going to email a patch to the list. Please test it and let us know
your result. Maybe we still need your patch if your device doesn't
support two finger touch or the idx=0xc can't be fixed by
W8001_MAX_LENGTH=13.
Thanks,
Ping
switch (w8001->idx++) {
case 0:
if ((data & W8001_LEAD_MASK) != W8001_LEAD_BYTE) {
--
2.7.4
--
To unsubscribe from this list: send the line "unsubscribe linux-input" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
On Sun, May 22, 2016 at 10:21:45PM -0700, Ping Cheng wrote:
Hi Chris,
On Sun, May 22, 2016 at 6:42 PM, Chris J Arges
[off-list ref] wrote:
quoted
I've noticed crashes when using my x60t using a coreboot bios. When using
the pen I can produce a crash simply by tapping a few times. This
generates an event which has an idx of 0xc. This in turn crashes the
machine because the array access is greater than W8001_MAX_LENGTH. This
patch checks for bogus values and filters them in order to prevent crashes.
Thank you for submitting a patch in addition to reporting the issue.
I don't have an x60t system to test with. I wonder if your system
supports two finger touch or not. We at least have a bug in the code
since W8001_MAX_LENGTH should be 13 instead of 11. How come no one had
encountered that issue before?
I'm going to email a patch to the list. Please test it and let us know
your result. Maybe we still need your patch if your device doesn't
support two finger touch or the idx=0xc can't be fixed by
W8001_MAX_LENGTH=13.
Just so we are clear this version of the patch is buggy as we check the
index only after [potentially] writing past the array bounds of
w8001->data[].
Thanks.
--
Dmitry
On Mon, May 23, 2016 at 9:52 AM, Dmitry Torokhov
[off-list ref] wrote:
On Sun, May 22, 2016 at 10:21:45PM -0700, Ping Cheng wrote:
quoted
Hi Chris,
On Sun, May 22, 2016 at 6:42 PM, Chris J Arges
[off-list ref] wrote:
quoted
I've noticed crashes when using my x60t using a coreboot bios. When using
the pen I can produce a crash simply by tapping a few times. This
generates an event which has an idx of 0xc. This in turn crashes the
machine because the array access is greater than W8001_MAX_LENGTH. This
patch checks for bogus values and filters them in order to prevent crashes.
Thank you for submitting a patch in addition to reporting the issue.
I don't have an x60t system to test with. I wonder if your system
supports two finger touch or not. We at least have a bug in the code
since W8001_MAX_LENGTH should be 13 instead of 11. How come no one had
encountered that issue before?
I'm going to email a patch to the list. Please test it and let us know
your result. Maybe we still need your patch if your device doesn't
support two finger touch or the idx=0xc can't be fixed by
W8001_MAX_LENGTH=13.
Just so we are clear this version of the patch is buggy as we check the
index only after [potentially] writing past the array bounds of
w8001->data[].
Thanks for the heads up. I noticed that last night. Since it breaks
two-finger touch, we won't use it anyway.
My other patch is still necessary though. You'll need to change:
From: wacom <redacted>
to
From: Ping Cheng <redacted>
I made it on a brand new system, which I didn't setup the environment
properly. I can update the patch if that's what you like...
Ping