Devices may probe in bootloader mode, where the main firmware packet size
is not available yet. Allocating the report buffer from probe in this state
requests zero bytes and leaves a ZERO_SIZE_PTR until firmware is updated.
Allocate the buffer from the main firmware information query instead. The
query runs before the IRQ is requested during normal probe and with the IRQ
disabled after a firmware update, so changing the allocation point does not
introduce a race with the IRQ handler.
Link: https://lore.kernel.org/r/20260927114425.442803-1-pooyan.azadparvar@gmail.com/ (local)
Reviewed-by: Muhammad Bilal <redacted>
Signed-off-by: Pooyan Azad <redacted>
---
drivers/input/touchscreen/raydium_i2c_ts.c | 7 +------
1 file changed, 1 insertion(+), 6 deletions(-)
diff --git a/drivers/input/touchscreen/raydium_i2c_ts.c b/drivers/input/touchscreen/raydium_i2c_ts.c
index 00990c61010f..1d7f53d0b9fe 100644
--- a/drivers/input/touchscreen/raydium_i2c_ts.c
+++ b/drivers/input/touchscreen/raydium_i2c_ts.c
@@ -373,7 +373,7 @@ static int raydium_i2c_query_ts_info(struct raydium_data *ts)
if (error)
continue;
- if (ts->report_data && ts->pkg_size != data_info.pkg_size) {
+ if (!ts->report_data || ts->pkg_size != data_info.pkg_size) {
report_data = devm_krealloc(&client->dev, ts->report_data,
data_info.pkg_size, GFP_KERNEL);
if (!report_data)@@ -1135,11 +1135,6 @@ static int raydium_i2c_probe(struct i2c_client *client)
return error;
}
- ts->report_data = devm_kmalloc(&client->dev,
- ts->pkg_size, GFP_KERNEL);
- if (!ts->report_data)
- return -ENOMEM;
-
ts->input = devm_input_allocate_device(&client->dev);
if (!ts->input) {
dev_err(&client->dev, "Failed to allocate input device\n");--
2.43.0