Re: [PATCH] Input: raydium_i2c_ts - validate report parameters
flat view
From: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Date: 2026-09-28 02:39:00
Also in:
lkml
Hi Pooyan, On Sun, Sep 27, 2026 at 01:44:25PM +0200, Pooyan Azad wrote:
The controller supplies packet and per-contact sizes used to allocate and parse touch reports. The driver trusts these values without validation. A packet size smaller than the two-byte checksum makes report_size wrap, allowing the IRQ handler to read beyond the report buffer. A zero or undersized contact size can cause a divide by zero or make the contact parser read beyond a record. Validate both sizes before publishing them, and reject reports that describe more contacts than the input device has slots. Allocate the report buffer once valid main firmware information is available, and resize it if a firmware update changes the packet size. This also handles devices that probe in bootloader mode, where the packet size is not known yet. Finally, return main firmware query failures from initialization so probe and firmware update do not continue with invalid report parameters. Keep bootloader HWID query failures non-fatal so the recovery interface remains available.
It looks like there ate 3 somewhat independent changes. Please split the incoming data validation from the buffer management and handling bootloader query failures. I think only the data validation needs to go into stable, the rest are regular behavior improvements. Thanks. -- Dmitry