usb: typec: ucsi: skip connector validation before init

JIRA: https://issues.redhat.com/browse/RHEL-147798

commit 5a1140404cbf7ba40137dfb1fb96893aa9a67d68
Author: Nathan Rebello <nathan.c.rebello@gmail.com>
Date: Tue, 7 Apr 2026 02:39:58 -0400

  Notifications can arrive before ucsi_init() has populated
  ucsi->cap.num_connectors via GET_CAPABILITY. At that point
  num_connectors is still 0, causing all valid connector numbers to be
  incorrectly rejected as bogus.

  Skip the bounds check when num_connectors is 0 (not yet initialized).
  Pre-init notifications are already handled safely by the early-event
  guard in ucsi_connector_change().

  Reported-by: Takashi Iwai <tiwai@suse.de>
  Fixes: d2d8c17ac01a ("usb: typec: ucsi: validate connector number in ucsi_notify_common()")
  Cc: stable@vger.kernel.org
  Signed-off-by: Nathan Rebello <nathan.c.rebello@gmail.com>
  Tested-by: Takashi Iwai <tiwai@suse.de>
  Link: https://patch.msgid.link/20260407063958.863-1-nathan.c.rebello@gmail.com
  Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Signed-off-by: Desnes Nunes <desnesn@redhat.com>
This commit is contained in:
Desnes Nunes
2026-07-14 23:41:09 -03:00
parent 63f1a0fade
commit e2746380c5
+2 -1
View File
@@ -44,7 +44,8 @@ void ucsi_notify_common(struct ucsi *ucsi, u32 cci)
return;
if (UCSI_CCI_CONNECTOR(cci)) {
if (UCSI_CCI_CONNECTOR(cci) <= ucsi->cap.num_connectors)
if (!ucsi->cap.num_connectors ||
UCSI_CCI_CONNECTOR(cci) <= ucsi->cap.num_connectors)
ucsi_connector_change(ucsi, UCSI_CCI_CONNECTOR(cci));
else
dev_err(ucsi->dev, "bogus connector number in CCI: %lu\n",