Re: [PATCH] Input: raydium_i2c_ts - validate report parameters
From: Dmitry Torokhov
Date: Sun Sep 27 2026 - 22:39:08 EST
Hi Pooyan,
On Sun, Sep 27, 2026 at 01:44:25PM +0200, Pooyan Azad wrote:
> The controller supplies packet and per-contact sizes used to allocate and
> parse touch reports. The driver trusts these values without validation.
>
> A packet size smaller than the two-byte checksum makes report_size wrap,
> allowing the IRQ handler to read beyond the report buffer. A zero or
> undersized contact size can cause a divide by zero or make the contact
> parser read beyond a record.
>
> Validate both sizes before publishing them, and reject reports that
> describe more contacts than the input device has slots.
>
> Allocate the report buffer once valid main firmware information is
> available, and resize it if a firmware update changes the packet size.
> This also handles devices that probe in bootloader mode, where the packet
> size is not known yet.
>
> Finally, return main firmware query failures from initialization so probe
> and firmware update do not continue with invalid report parameters. Keep
> bootloader HWID query failures non-fatal so the recovery interface remains
> available.
It looks like there ate 3 somewhat independent changes. Please split the
incoming data validation from the buffer management and handling
bootloader query failures. I think only the data validation needs to go
into stable, the rest are regular behavior improvements.
Thanks.
--
Dmitry