[REGRESSION] 6.18.y: HID: asus: ROG keyboard 0b05:19b6 stops working after 56d1b33e644c backport; missing buffer size fix e82ae34af29e

From: André Pinheiro <hidden>
Date: 2026-09-30 04:30:18
Also in: regressions, stable

Hi,

Since 6.18.49, the internal keyboard of ASUS ROG Zephyrus G16 GU605MV
(USB 0b05:19b6, ITE Device(8910), bcdDevice 0.03) can stop sending input
events. 6.18.42 works. 6.18.51 is broken. I did not test 6.18.49/6.18.50.

Cause: the backport of 56d1b33e644c ("HID: asus: simplify RGB init
sequence") made asus_kbd_get_functions() run for QUIRK_ROG_NKEY_KEYBOARD
devices too. That function reads feature report 0x5A into a buffer of
FEATURE_KBD_REPORT_SIZE = 16 bytes. This device answers with 63 bytes, so
the transfer fails with EOVERFLOW. The buffer size fix is in mainline as
e82ae34af29e ("HID: asus: fortify keyboard handshake", 
FEATURE_KBD_REPORT_SIZE
16 -> 64; its message says "Since the response is more than 16 bytes,
increase the buffer size to 64 as well to avoid overflow errors"). It is in
the same series as 56d1b33e644c but was not backported. v7.0 has the value
64 (checked in the source, not booted on this machine).

Symptom (6.18.51):
   asus 0003:0B05:19B6.0001: Asus failed to request functions: -75
   asus 0003:0B05:19B6.0001: Failed to initialize backlight.
usbmon:
   S Ci:1:002:0 s a1 01 035a 0000 0010 16 <
   C Ci:1:002:0 -75 0

The HID report descriptor (1102 bytes, from sysfs) declares Feature report
0x5A as 62 data bytes plus the report ID (63). The device matches its own
descriptor; the driver buffer is too small.

Evidence. Same physical device and USB host controller (xhci on 6.18.42) in
both runs, only the guest kernel driving the HID device changes; bytes read
from the evdev node while typing:
   guest 6.18.42: 16776 bytes in 12 s
   guest 6.18.51: -75 as above, 0 bytes in 12 s

Requests sent by hand on 6.18.42 through hidraw (HIDIOCGFEATURE on report
0x5A), device re-enumerated before each case, bytes in 5 s windows:
   GET 16, no SET before:  7488 -> EOVERFLOW -> 0
   GET 32, no SET before:  7776 -> EOVERFLOW -> 0
   GET 64, no SET before:  8208 -> ok, 63 bytes returned -> 8568
   SET 5a 05 20 31 00 08, then GET 64: 8496 -> ok, 63 bytes -> 7920
   SET, then GET 16:       7848 -> EOVERFLOW -> 7056 (did not silence 
this run)
   (an earlier run of SET, GET 16: 2736 -> 6984 after SET -> 0 after GET)
With a 64-byte buffer byte 6 of the reply is 0x83, i.e. 
SUPPORT_KBD_BACKLIGHT
is set. So with the fix the driver would register the backlight instead of
failing. One or two runs per case, only this device tested.

Request: please backport e82ae34af29e (or at least the 
FEATURE_KBD_REPORT_SIZE
16 -> 64 change) to 6.18.y, and to any other stable branch that received
56d1b33e644c. Alternatively drop 56d1b33e644c there.

Thanks,
André
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help