mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] usb: misc: usbio: Handle negative error code from usb_control_msg()
@ 2026-10-03 14:28 Serhat Kumral
  2026-10-03 15:13 ` Greg KH
  0 siblings, 1 reply; 3+ messages in thread
From: Serhat Kumral @ 2026-10-03 14:28 UTC (permalink / raw)
  To: israel.a.cepeda.lopez, hansg, gregkh
  Cc: sakari.ailus, linux-usb, linux-kernel, Serhat Kumral

The sizeof(*cpkt) is unsigned, so comparing "ret < sizeof(*cpkt)" promotes
"ret" to unsigned and negative error codes from usb_control_msg() are
not caught. Cast the sizeof to int so the error handling works.

Fixes: 121a0f839dbb ("usb: misc: Add Intel USBIO bridge driver")
Assisted-by: LLM
Signed-off-by: Serhat Kumral <serhatkumral1@gmail.com>
---
found by smatch:
- drivers/usb/misc/usbio.c:187 usbio_ctrl_msg() warn: error code type promoted to positive: 'ret'

 drivers/usb/misc/usbio.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/usb/misc/usbio.c b/drivers/usb/misc/usbio.c
index fe093e7760d5..3f73f7c3d68a 100644
--- a/drivers/usb/misc/usbio.c
+++ b/drivers/usb/misc/usbio.c
@@ -184,7 +184,7 @@ static int usbio_ctrl_msg(struct usbio_device *usbio, u8 type, u8 cmd,
 	dev_dbg(usbio->dev, "control in %d hdr %*phN data %*phN\n", ret,
 		(int)sizeof(*cpkt), cpkt, (int)cpkt->len, cpkt->data);
 
-	if (ret < sizeof(*cpkt)) {
+	if (ret < (int)sizeof(*cpkt)) {
 		dev_err(usbio->dev, "USB control in failed: %d\n", ret);
 		return (ret < 0) ? ret : -EPROTO;
 	}
-- 
2.53.0


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] usb: misc: usbio: Handle negative error code from usb_control_msg()
  2026-10-03 14:28 [PATCH] usb: misc: usbio: Handle negative error code from usb_control_msg() Serhat Kumral
@ 2026-10-03 15:13 ` Greg KH
  2026-10-03 16:18   ` Serhat Kumral
  0 siblings, 1 reply; 3+ messages in thread
From: Greg KH @ 2026-10-03 15:13 UTC (permalink / raw)
  To: Serhat Kumral
  Cc: israel.a.cepeda.lopez, hansg, sakari.ailus, linux-usb, linux-kernel

On Sat, Oct 03, 2026 at 05:28:38PM +0300, Serhat Kumral wrote:
> The sizeof(*cpkt) is unsigned, so comparing "ret < sizeof(*cpkt)" promotes
> "ret" to unsigned and negative error codes from usb_control_msg() are
> not caught. Cast the sizeof to int so the error handling works.
> 
> Fixes: 121a0f839dbb ("usb: misc: Add Intel USBIO bridge driver")
> Assisted-by: LLM
> Signed-off-by: Serhat Kumral <serhatkumral1@gmail.com>
> ---
> found by smatch:
> - drivers/usb/misc/usbio.c:187 usbio_ctrl_msg() warn: error code type promoted to positive: 'ret'
> 
>  drivers/usb/misc/usbio.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/usb/misc/usbio.c b/drivers/usb/misc/usbio.c
> index fe093e7760d5..3f73f7c3d68a 100644
> --- a/drivers/usb/misc/usbio.c
> +++ b/drivers/usb/misc/usbio.c
> @@ -184,7 +184,7 @@ static int usbio_ctrl_msg(struct usbio_device *usbio, u8 type, u8 cmd,
>  	dev_dbg(usbio->dev, "control in %d hdr %*phN data %*phN\n", ret,
>  		(int)sizeof(*cpkt), cpkt, (int)cpkt->len, cpkt->data);
>  
> -	if (ret < sizeof(*cpkt)) {
> +	if (ret < (int)sizeof(*cpkt)) {

Ick, really?  There's no compiler check for this type of thing?

This whole function needs to be rewritten to use the "modern" control
message functions.  I gave it a go once, but it quickly got messy as
this is an abused function and it really should be massivly cleaned up.

Do you have the hardware for this to test changes?

thanks,

greg k-h

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] usb: misc: usbio: Handle negative error code from usb_control_msg()
  2026-10-03 15:13 ` Greg KH
@ 2026-10-03 16:18   ` Serhat Kumral
  0 siblings, 0 replies; 3+ messages in thread
From: Serhat Kumral @ 2026-10-03 16:18 UTC (permalink / raw)
  To: gregkh
  Cc: hansg, israel.a.cepeda.lopez, linux-kernel, linux-usb,
	sakari.ailus, serhatkumral1

On Sat, Oct 03, 2026 at 17:13:45 +0200, Greg KH wrote: 
> Ick, really?  There's no compiler check for this type of thing?

> This whole function needs to be rewritten to use the "modern" control
> message functions.  I gave it a go once, but it quickly got messy as
> this is an abused function and it really should be massivly cleaned up.

> Do you have the hardware for this to test changes?

Unfortunately I don't have the hardware. I relied on static analysis
and tried to keep things quite simple

thanks,
Serhat

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-10-03 16:18 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-03 14:28 [PATCH] usb: misc: usbio: Handle negative error code from usb_control_msg() Serhat Kumral
2026-10-03 15:13 ` Greg KH
2026-10-03 16:18   ` Serhat Kumral

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®