Thread (10 messages) 10 messages, 3 authors, 1d ago

Re: [PATCH] Input: raydium_i2c_ts - validate report parameters

flat view

From: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Date: 2026-09-28 02:39:00
Also in: lkml

Hi Pooyan,

On Sun, Sep 27, 2026 at 01:44:25PM +0200, Pooyan Azad wrote:
The controller supplies packet and per-contact sizes used to allocate and
parse touch reports. The driver trusts these values without validation.

A packet size smaller than the two-byte checksum makes report_size wrap,
allowing the IRQ handler to read beyond the report buffer. A zero or
undersized contact size can cause a divide by zero or make the contact
parser read beyond a record.

Validate both sizes before publishing them, and reject reports that
describe more contacts than the input device has slots.

Allocate the report buffer once valid main firmware information is
available, and resize it if a firmware update changes the packet size.
This also handles devices that probe in bootloader mode, where the packet
size is not known yet.

Finally, return main firmware query failures from initialization so probe
and firmware update do not continue with invalid report parameters. Keep
bootloader HWID query failures non-fatal so the recovery interface remains
available.
It looks like there ate 3 somewhat independent changes. Please split the
incoming data validation from the buffer management and handling
bootloader query failures. I think only the data validation needs to go
into stable, the rest are regular behavior improvements.

Thanks.

-- 
Dmitry
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help