From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-8.3 required=3.0 tests=HEADER_FROM_DIFFERENT_DOMAINS, INCLUDES_PATCH,MAILING_LIST_MULTI,SIGNED_OFF_BY,SPF_HELO_NONE,SPF_PASS, URIBL_BLOCKED,USER_AGENT_SANE_1 autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 24E23C352A3 for ; Tue, 11 Feb 2020 08:35:06 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id E43EA2086A for ; Tue, 11 Feb 2020 08:35:05 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727579AbgBKIfF (ORCPT ); Tue, 11 Feb 2020 03:35:05 -0500 Received: from seldsegrel01.sonyericsson.com ([37.139.156.29]:4107 "EHLO SELDSEGREL01.sonyericsson.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1727264AbgBKIfF (ORCPT ); Tue, 11 Feb 2020 03:35:05 -0500 Subject: Re: [PATCH] HID: Extend report buffer size To: Alan Stern , Johan Korsnes CC: Jiri Kosina , Greg Kroah-Hartman , Kernel development list , References: From: peter enderborg Message-ID: <91e0077e-b229-e43f-6f5c-5088b0c0f561@sony.com> Date: Tue, 11 Feb 2020 09:35:02 +0100 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.9.0 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Content-Language: en-GB X-SEG-SpamProfiler-Analysis: v=2.3 cv=V88DLtvi c=1 sm=1 tr=0 a=T5MYTZSj1jWyQccoVcawfw==:117 a=jpOVt7BSZ2e4Z31A5e1TngXxSK0=:19 a=IkcTkHD0fZMA:10 a=l697ptgUJYAA:10 a=z6gsHLkEAAAA:8 a=fs2oqwGesLN0DGMJwG0A:9 a=QEXdDO2ut3YA:10 a=d-OLMTCWyvARjPbQ-enb:22 X-SEG-SpamProfiler-Score: 0 Sender: stable-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: stable@vger.kernel.org On 2/10/20 4:01 PM, Alan Stern wrote: > On Mon, 10 Feb 2020, Peter Enderborg wrote: > >> In the patch "HID: Fix slab-out-of-bounds read in hid_field_extract" >> there added a check for buffer overruns. This made Elgato StreamDeck >> to fail. This patch extend the buffer to 8192 to solve this. It also >> adds a print of the requested length if it fails on this test. >> >> Signed-off-by: Peter Enderborg >> --- >> drivers/hid/hid-core.c | 2 +- >> include/linux/hid.h | 2 +- >> 2 files changed, 2 insertions(+), 2 deletions(-) >> >> diff --git a/drivers/hid/hid-core.c b/drivers/hid/hid-core.c >> index 851fe54ea59e..28841219b3d2 100644 >> --- a/drivers/hid/hid-core.c >> +++ b/drivers/hid/hid-core.c >> @@ -290,7 +290,7 @@ static int hid_add_field(struct hid_parser *parser, unsigned report_type, unsign >> >> /* Total size check: Allow for possible report index byte */ >> if (report->size > (HID_MAX_BUFFER_SIZE - 1) << 3) { >> - hid_err(parser->device, "report is too long\n"); >> + hid_err(parser->device, "report is too long (%d)\n", report->size); >> return -1; >> } >> >> diff --git a/include/linux/hid.h b/include/linux/hid.h >> index cd41f209043f..875f71132b14 100644 >> --- a/include/linux/hid.h >> +++ b/include/linux/hid.h >> @@ -492,7 +492,7 @@ struct hid_report_enum { >> }; >> >> #define HID_MIN_BUFFER_SIZE 64 /* make sure there is at least a packet size of space */ >> -#define HID_MAX_BUFFER_SIZE 4096 /* 4kb */ >> +#define HID_MAX_BUFFER_SIZE 8192 /* 8kb */ >> #define HID_CONTROL_FIFO_SIZE 256 /* to init devices with >100 reports */ >> #define HID_OUTPUT_FIFO_SIZE 64 > The second part of this patch is identical to the "HID: core: increase > HID report buffer size to 8KiB" patch submitted by Johan Korsnes a few > weeks ago. You might want to submit just the first part of your patch, > or not submit anything at all. > > Alan Stern > > Korsnes patch is not in Torvalds tree nor is it requested for stable. How do we get it there?