[PATCH 1/3] Input: cyttsp5 - fix bug when parsing reset sentinel packet
From: Marc-Olivier Champagne
Date: Fri Oct 02 2026 - 14:43:34 EST
When parsing a reset sentinel packet (0x0000), read size in
cyttsp5_read() will be zero, and we exit early with success (0), but
without modifying the response buffer.
If this happens when the response buffer has previous data in it, it can
lead to improper interpretation as a new packet.
Fix this by always writing 0x0000 to response buffer in cyttsp5_read(),
and comment the reset sentinel behaviour in cyttsp5_handle_irq().
Fixes: 5b0c03e24a06 ("Input: Add driver for Cypress Generation 5 touchscreen")
Cc: stable@xxxxxxxxxxxxxxx
Suggested-by: Hugo Villeneuve <hvilleneuve@xxxxxxxxxxxx>
Signed-off-by: Marc-Olivier Champagne <marc-olivier.champagne@xxxxxxxxxxxxxxxxxxxx>
---
drivers/input/touchscreen/cyttsp5.c | 12 +++++++++++-
1 file changed, 11 insertions(+), 1 deletion(-)
diff --git a/drivers/input/touchscreen/cyttsp5.c b/drivers/input/touchscreen/cyttsp5.c
index e878a02dc9b7..04e141eceb45 100644
--- a/drivers/input/touchscreen/cyttsp5.c
+++ b/drivers/input/touchscreen/cyttsp5.c
@@ -221,6 +221,12 @@ static int cyttsp5_read(struct cyttsp5 *ts, u8 *buf, u32 max)
u32 size;
u8 temp[2];
+ /*
+ * Buffer may contain previous data. Make sure to indicate that
+ * packet has zero length in case size is 0 or 2, or if we exit early.
+ */
+ memset(buf, 0, 2);
+
/* Read the frame to retrieve the size */
error = regmap_bulk_read(ts->regmap, HID_INPUT_REG, temp, sizeof(temp));
if (error)
@@ -705,7 +711,11 @@ static irqreturn_t cyttsp5_handle_irq(int irq, void *handle)
size = get_unaligned_le16(&ts->input_buf[0]);
if (size == 0) {
- /* reset */
+ /*
+ * Interrupt is asserted after bootloader or application is
+ * started to indicate device is ready for communication
+ * (reset sentinel packet).
+ */
report_id = 0;
size = 2;
} else {
--
2.34.1