diff options
author | Prashant Malani <pmalani@chromium.org> | 2019-08-24 01:36:19 -0700 |
---|---|---|
committer | David S. Miller <davem@davemloft.net> | 2019-08-25 19:52:59 -0700 |
commit | f53a7ad189594a112167efaf17ea8d0242b5ac00 (patch) | |
tree | a6fb436fa2844b808f326a64e62ae315d9204b1d | |
parent | 7177895154e6a35179d332f4a584d396c50d0612 (diff) | |
download | linux-stable-f53a7ad189594a112167efaf17ea8d0242b5ac00.tar.gz linux-stable-f53a7ad189594a112167efaf17ea8d0242b5ac00.tar.bz2 linux-stable-f53a7ad189594a112167efaf17ea8d0242b5ac00.zip |
r8152: Set memory to all 0xFFs on failed reg reads
get_registers() blindly copies the memory written to by the
usb_control_msg() call even if the underlying urb failed.
This could lead to junk register values being read by the driver, since
some indirect callers of get_registers() ignore the return values. One
example is:
ocp_read_dword() ignores the return value of generic_ocp_read(), which
calls get_registers().
So, emulate PCI "Master Abort" behavior by setting the buffer to all
0xFFs when usb_control_msg() fails.
This patch is copied from the r8152 driver (v2.12.0) published by
Realtek (www.realtek.com).
Signed-off-by: Prashant Malani <pmalani@chromium.org>
Acked-by: Hayes Wang <hayeswang@realtek.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
-rw-r--r-- | drivers/net/usb/r8152.c | 5 |
1 files changed, 4 insertions, 1 deletions
diff --git a/drivers/net/usb/r8152.c b/drivers/net/usb/r8152.c index 0cc03a9ff545..eee0f5007ee3 100644 --- a/drivers/net/usb/r8152.c +++ b/drivers/net/usb/r8152.c @@ -799,8 +799,11 @@ int get_registers(struct r8152 *tp, u16 value, u16 index, u16 size, void *data) ret = usb_control_msg(tp->udev, usb_rcvctrlpipe(tp->udev, 0), RTL8152_REQ_GET_REGS, RTL8152_REQT_READ, value, index, tmp, size, 500); + if (ret < 0) + memset(data, 0xff, size); + else + memcpy(data, tmp, size); - memcpy(data, tmp, size); kfree(tmp); return ret; |