Re: Re: [PATCH v2 1/4] HID: intel-ish-hid: fix report_list iterator pointer arithmetic
From: grayhat@xxxxxxxxxxx
Date: Thu Jul 30 2026 - 21:39:20 EST
Thanks, +Lixu noted.
Corrected tag:
Assisted-by: Hermes:kimi-k3
(The last hunk of that patch is stray -- please discard it; it
removes the trailing newline after MODULE_LICENSE.)
Let me know if you want it resent as a proper [PATCH v2].
Thanks,
Shen Yongchao
>+Lixu
>
>On Thu, 2026-07-30 at 20:52 +0800, Shen Yongchao wrote:
>> Since commit 63cafaf47a83 ("HID: ishtp-hid-client: replace
>> fake-flex arrays with flex-array members", v6.13), the
>> HOSTIF_PUBLISH_INPUT_REPORT_LIST handler iterates over sub-reports
>> using a struct report * pointer:
>>
>> report += sizeof(*report) + payload_len;
>>
>> Because report is a struct report * (not a char *), the compiler
>> multiplies the advance by sizeof(struct report) = 8, making the
>> actual stride (8 + payload_len) * 8 bytes instead of the intended
>> 8 + payload_len bytes. On v6.13+ a legitimate aggregated list
>> with num_of_reports >= 2 drives the second iteration far outside
>> the message buffer.
>>
>> Replace the struct report * iterator with a byte-granular u8 *pos
>> so the advance is computed in bytes.
>>
>>
>> Assisted-by: LLM
>
>Need to follow:
>
>https://docs.kernel.org/process/coding-assistants.html
>
>Assisted-by: AGENT_NAME:MODEL_VERSION [TOOL1] [TOOL2]
>
>Lixu,
>Please give a test on few devices. Not sure if we have such device.
>
>Thanks,
>Srinivas
>
>> Signed-off-by: Shen Yongchao <grayhat@xxxxxxxxxxx>
>> Fixes: 63cafaf47a83 ("HID: ishtp-hid-client: replace fake-flex arrays
>> with flex-array members")
>> Cc: stable@xxxxxxxxxxxxxxx
>> ---
>> diff --git a/drivers/hid/intel-ish-hid/ishtp-hid-client.c
>> b/drivers/hid/intel-ish-hid/ishtp-hid-client.c
>> index 6d64008f2..ba52e185c 100644
>> --- a/drivers/hid/intel-ish-hid/ishtp-hid-client.c
>> +++ b/drivers/hid/intel-ish-hid/ishtp-hid-client.c
>> @@ -74,6 +74,7 @@ static void process_recv(struct ishtp_cl
>> *hid_ishtp_cl, void *recv_buf,
>> int report_type;
>> struct report_list *reports_list;
>> struct report *report;
>> + u8 *pos;
>> size_t report_len;
>> struct ishtp_cl_data *client_data =
>> ishtp_get_client_data(hid_ishtp_cl);
>> int curr_hid_dev = client_data->cur_hid_dev;
>> @@ -280,9 +281,10 @@ static void process_recv(struct ishtp_cl
>> *hid_ishtp_cl, void *recv_buf,
>> case HOSTIF_PUBLISH_INPUT_REPORT_LIST:
>> report_type = HID_INPUT_REPORT;
>> reports_list = (struct report_list
>> *)payload;
>> - report = reports_list->reports;
>> + pos = (u8 *)reports_list->reports;
>>
>> for (j = 0; j < reports_list-
>> >num_of_reports; j++) {
>> + report = (struct report *)pos;
>> recv_msg = container_of(&report-
>> >msg,
>> struct
>> hostif_msg, hdr);
>> report_len = report->size;
>> @@ -303,7 +305,7 @@ static void process_recv(struct ishtp_cl
>> *hid_ishtp_cl, void *recv_buf,
>> 0);
>> }
>>
>> - report += sizeof(*report) +
>> payload_len;
>> + pos += sizeof(struct report) +
>> payload_len;
>> }
>> break;
>> default:
>> @@ -956,4 +958,4 @@ MODULE_AUTHOR("Daniel Drubin
>> <daniel.drubin@xxxxxxxxx>");
>> */
>> MODULE_AUTHOR("Srinivas Pandruvada
>> <srinivas.pandruvada@xxxxxxxxxxxxxxx>");
>>
>> -MODULE_LICENSE("GPL");
>> +MODULE_LICENSE("GPL");
>> \ No newline at end of file