mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] HID: amd_sfh: Fix report type of get_report replies
@ 2026-09-30  1:16 Erik Gonzalez
  0 siblings, 0 replies; only message in thread
From: Erik Gonzalez @ 2026-09-30  1:16 UTC (permalink / raw)
  To: Basavaraj Natikar, Jiri Kosina, Benjamin Tissoires
  Cc: linux-input, linux-kernel, stable

amd_sfh_work() passes the reply to a get_report request to
hid_input_report() with cli_data->report_type[] as the report type. That
array has never been written since the driver was added, so it is always
0 (HID_INPUT_REPORT), and replies to feature report requests reach the
HID core as input reports.

The HID core then checks the payload against the input report with the
same ID. Since commit 0a3fe972a7cb ("HID: core: Mitigate potential OOB
by removing bogus memset()"), a report shorter than that is rejected
instead of being zero-padded. On an ASUS ProArt PX13 (HN7306EAC) running
7.2.6 this logs:

  hid-sensor-hub 0020:1022:0001.0005: Event data for report 1 was too short (15 vs 14)
  hid-sensor-hub 0020:1022:0001.0006: Event data for report 4 was too short (18 vs 14)

14 bytes is the size of feature reports 1 and 4 in the report
descriptors the driver provides; 15 and 18 bytes are the input reports
with those IDs. Attributes backed by feature reports then read wrong
values: the accelerometer's in_accel_sampling_frequency reads 10.000000
instead of 12.500000, and in_accel_hysteresis reads 0.000000 instead of
1.270000. Input reports are not affected, because their type happens to
be 0.

Pass the type of the request being completed instead, and remove the
unused report_type[] array.

The same "report 4 was too short (18 vs 14)" message has been reported
for the Lenovo Legion Go S, where the accelerometer and gyroscope do not
register. That may be the same bug; I have not tested that device.

The bug was found, and this change and description were written, with
the help of an AI coding assistant. The analysis was checked against the
report descriptors of the PX13, and the change was tested on it by
loading amd_sfh built for the running 7.2.6 kernel without and with it:
without it, the messages and values above; with it, no messages, and
sampling frequency and hysteresis read 12.500000 and 1.270000.

Fixes: 4b2c53d93a4b ("SFH:Transport Driver to add support of AMD Sensor Fusion Hub (SFH)")
Link: https://github.com/ublue-os/bazzite/issues/5796
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Erik Gonzalez <dev@gonzalezerik.com>
---
Not tested: other devices with the AMD Sensor Fusion Hub (including the
Legion Go S), and a booted hid.git kernel. The code this touches is the
same in hid.git for-next and 7.2.6; the patch was build-tested on
for-next (clang, W=1, no new warnings) and runtime-tested on 7.2.6.

 drivers/hid/amd-sfh-hid/amd_sfh_client.c | 4 ++--
 drivers/hid/amd-sfh-hid/amd_sfh_hid.h    | 1 -
 2 files changed, 2 insertions(+), 3 deletions(-)

diff --git a/drivers/hid/amd-sfh-hid/amd_sfh_client.c b/drivers/hid/amd-sfh-hid/amd_sfh_client.c
index ae6add0b9..a68b275f0 100644
--- a/drivers/hid/amd-sfh-hid/amd_sfh_client.c
+++ b/drivers/hid/amd-sfh-hid/amd_sfh_client.c
@@ -95,7 +95,7 @@ void amd_sfh_work(struct work_struct *work)
 						    cli_data->feature_report[current_index]);
 		if (report_size)
 			hid_input_report(cli_data->hid_sensor_hubs[current_index],
-					 cli_data->report_type[current_index],
+					 node_type,
 					 cli_data->feature_report[current_index], report_size, 0);
 		else
 			pr_err("AMDSFH: Invalid report size\n");
@@ -104,7 +104,7 @@ void amd_sfh_work(struct work_struct *work)
 		report_size = mp2_ops->get_in_rep(current_index, sensor_index, report_id, in_data);
 		if (report_size)
 			hid_input_report(cli_data->hid_sensor_hubs[current_index],
-					 cli_data->report_type[current_index],
+					 node_type,
 					 in_data->input_report[current_index], report_size, 0);
 		else
 			pr_err("AMDSFH: Invalid report size\n");
diff --git a/drivers/hid/amd-sfh-hid/amd_sfh_hid.h b/drivers/hid/amd-sfh-hid/amd_sfh_hid.h
index 7452b0302..928cff682 100644
--- a/drivers/hid/amd-sfh-hid/amd_sfh_hid.h
+++ b/drivers/hid/amd-sfh-hid/amd_sfh_hid.h
@@ -45,7 +45,6 @@ struct amdtp_cl_data {
 	dma_addr_t sensor_dma_addr[MAX_HID_DEVICES];
 	u32 sensor_sts[MAX_HID_DEVICES];
 	u32 sensor_requested_cnt[MAX_HID_DEVICES];
-	u8 report_type[MAX_HID_DEVICES];
 	u8 report_id[MAX_HID_DEVICES];
 	u8 sensor_idx[MAX_HID_DEVICES];
 	u8 *feature_report[MAX_HID_DEVICES];

base-commit: 145c2b2e9a5c0f794fb4009bcb072ab19f8ccfcd
-- 
2.55.0



^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-30  1:16 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-30  1:16 [PATCH] HID: amd_sfh: Fix report type of get_report replies Erik Gonzalez

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®