Re: [PATCH] usb: r8a66597-hcd: fix buffer overflow on odd-length FIFO reads
From: Karl Mehltretter
Date: Mon Oct 05 2026 - 00:26:03 EST
Hi Geert,
On Sat, Oct 03, 2026 at 02:42:48PM +0100, Geert Uytterhoeven wrote:
> > + count = len / 2;
> > + ioread16_rep(fifoaddr, buf, count);
>
> Or just:
>
> ioread16_rep(fifoaddr, buf, len / 2);
>
> > +
> > + if (len & 0x00000001) {
>
> "len & 1"?
>
Thanks for suggesting that! I will use len / 2 and len & 1, and a
plain byte store instead of the memcpy().
>
> Seriously: a *_rep() function for a single iteration?
>
I'd like to keep this one. ioread16_rep() does not byte swap.
ioread16() goes through readw(), which swaps on big endian on most
architectures.
The words before the last one are read with ioread16_rep(), so reading
the last word the same way puts its first FIFO byte first in memory on
every architecture.
Thanks,
Karl