Thread (5 messages) 5 messages, 3 authors, 2021-06-25

Re: [PATCH] i2c: robotfuzz-osif: fix control-request directions

From: Wolfram Sang <wsa@kernel.org>
Date: 2021-06-24 20:10:25
Also in: linux-i2c, lkml, stable

On Wed, Jun 23, 2021 at 10:52:04AM +0200, Johan Hovold wrote:
On Mon, May 24, 2021 at 11:09:12AM +0200, Johan Hovold wrote:
quoted
The direction of the pipe argument must match the request-type direction
bit or control requests may fail depending on the host-controller-driver
implementation.

Control transfers without a data stage are treated as OUT requests by
the USB stack and should be using usb_sndctrlpipe(). Failing to do so
will now trigger a warning.

Fix the OSIFI2C_SET_BIT_RATE and OSIFI2C_STOP requests which erroneously
used the osif_usb_read() helper and set the IN direction bit.

Reported-by: syzbot+9d7dadd15b8819d73f41@syzkaller.appspotmail.com
Fixes: 83e53a8f120f ("i2c: Add bus driver for for OSIF USB i2c device.")
Cc: stable@vger.kernel.org      # 3.14
Cc: Andrew Lunn <andrew@lunn.ch>
Signed-off-by: Johan Hovold <johan@kernel.org>
---
Wolfram, can you pick this one up for 5.14?
Sorry, I thought Andrew was the maintainer of this driver and was
waiting for his ack. But he is not, this driver is unmaintained. So, I
trust you and picked it up now.

Applied to for-current, thanks!

Attachments

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help