Re: [PATCH] Input: raydium_i2c_ts - validate report parameters

From: Pooyan Azadparvar

Date: Mon Sep 28 2026 - 02:05:01 EST


Thanks Dmitry,

Sure, I'll split these up in v2 and keep the validation fix separate for stable.

Thanks,
Pooyan


On Mon, Sep 28, 2026 at 4:38 AM Dmitry Torokhov
<dmitry.torokhov@xxxxxxxxx> wrote:
>
> Hi Pooyan,
>
> On Sun, Sep 27, 2026 at 01:44:25PM +0200, Pooyan Azad wrote:
> > The controller supplies packet and per-contact sizes used to allocate and
> > parse touch reports. The driver trusts these values without validation.
> >
> > A packet size smaller than the two-byte checksum makes report_size wrap,
> > allowing the IRQ handler to read beyond the report buffer. A zero or
> > undersized contact size can cause a divide by zero or make the contact
> > parser read beyond a record.
> >
> > Validate both sizes before publishing them, and reject reports that
> > describe more contacts than the input device has slots.
> >
> > Allocate the report buffer once valid main firmware information is
> > available, and resize it if a firmware update changes the packet size.
> > This also handles devices that probe in bootloader mode, where the packet
> > size is not known yet.
> >
> > Finally, return main firmware query failures from initialization so probe
> > and firmware update do not continue with invalid report parameters. Keep
> > bootloader HWID query failures non-fatal so the recovery interface remains
> > available.
>
> It looks like there ate 3 somewhat independent changes. Please split the
> incoming data validation from the buffer management and handling
> bootloader query failures. I think only the data validation needs to go
> into stable, the rest are regular behavior improvements.
>
> Thanks.
>
> --
> Dmitry