From nobody Sun Jul 26 01:47:32 2026 Received: from mail-qk1-f176.google.com (mail-qk1-f176.google.com [209.85.222.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 919242D1916 for ; Fri, 10 Jul 2026 02:29:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.176 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783650544; cv=none; b=lvbUyXc40QBTfABWcoadgW/ykiDyYofMJsGmSjNYGkvsMDDk4lSJ3hhbcmVAOvkfO6qgyseHalVkRD6693GwQz7LPP74oz8THLz4Ca6U1JCetV5OLVi1EaYL/gpVu3MezTxPgWAXMXvqvgNoZEDZ5LD+W/e84w4Rw8SDFuJsjHQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783650544; c=relaxed/simple; bh=Xw9MV5+tUH91OggMUmq95ucMnBMqMCwFdkfsgGxUsO0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=JI3F4JWW6w28h+FgSUHK0+HT/+w+yHt/c2+1EaiI4hKq5JNbgxa1gRcYhXR4f1X1heuLj2rZou/kpNy+BiY1SG0T5vGlsLDBwvuICVRoSCN4l/tUcaonb/QdoT5B+PnY1/WxkW0ppVQh71cuH0EMmEuVhLAuIhvQaX7n/nJFSiM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=dwzJ0DGW; arc=none smtp.client-ip=209.85.222.176 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="dwzJ0DGW" Received: by mail-qk1-f176.google.com with SMTP id af79cd13be357-92e602d2c0fso93735585a.0 for ; Thu, 09 Jul 2026 19:29:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783650541; x=1784255341; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=qddLIoiRhTm7oXx/mi01gsuC6rzOXTw4K1iEgY1KrG0=; b=dwzJ0DGW7BUBPpqc5p98Oq48MJutxTn3/qCpjSJKkMsrM1TeqTp9lGJC+C1F/LJhbi YJbQU45ADJCa4/PsiaR9iIF0Ot2qf7WZtV5f+bRq/sxGTYvUya8sZA3AjejiAg8StKX6 1IzlGG+fJzr3+QyVcgRgwbYP1d23+7sw5tDgw4Prtb3cCK8RYkhJrmhXn9XTDq6YXACY fzI7LHe8lL9m0zhM+tuhW7wBSFagbcRDoc1oygJeDHRBADFNj90v+tEr1jX1FH1+QZjM 51+chwgWvMKx0FGCeDAwZCKQ0KHgiyMfpSHLac3QZtn7nR/JJswCN7Iq8yXymyRyf+f2 JXqg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783650541; x=1784255341; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=qddLIoiRhTm7oXx/mi01gsuC6rzOXTw4K1iEgY1KrG0=; b=jmtPR46xuvC4mF7AUao3XoHUtkDzC3VkNFKJs+j5mlW8zkiZONlUtkhfggDvCWtpX2 UuEq6tvNJ3ldS8UEHx2l4NTie3sX6VU+42KkXMUok3Bp8EGYteIng58CLYnWvJAVRsCp ffQfKutiKNfjqAXKq7OgPJslOVcV5GGLZjHAMG8r/6qSRzvmba2TaCy0b12VJTK3688U BuSDiFvlpkEcosBksaZHuksG9VlPb4HMuEp3B1pqxoI63bnnXYJZz/kZpnls3X/P90/E PhHpJ9aKwF5A5fOE3GvPI7YcGWBH4KGxG+divI70DD9CwGt3lrlDDYKVEVi5cZUsRRr+ HL3w== X-Forwarded-Encrypted: i=1; AHgh+RpG0euy5ndGhqADFIu1a0q1y+l51hAUJzwUFirDkLdvmOnohAnEV6EcsxiofR2bt3QCyDB+PoQPPL+7u8w=@vger.kernel.org X-Gm-Message-State: AOJu0YzsyKnxDHSgefimcRvPXHLIcEwynPOmTvzaXIo4Ce+Zy1JdLa2K Te4tftAOP/C/h0OI/BNx7YQllRGeFdFrCqfi+uxXMVUcMRG5YWoWMxKi X-Gm-Gg: AfdE7cloh88nEE4D/8xHDT76fxem3CKsWa7CFeLJq6iSszY0pBuafpgmU+suO4m3Fhd SSkDFlZoV+/a4lN8EuOubt+eGALxhAIAUtwNtblTSt0NOApTlQtQJGGV928wsuY/Ad5GMNOxtg0 y/6fVnfUydCTGyX6fwUuixNupI90pmT2iGe91jIVd5EsGer1zHSf0uUqvRtVfSlr9xnK7H5wqCG LgbDdtH/qwCJZ9TdSaD2nhKYhX9WO65npqRlRy8AEPOgws2YvZwcPCSm/XCarzRj9o7maaDOr2Q lu4HiglEknFEWHXHqu+ATYS1sOFQKKuXgr9asFkCtytKNmPnSO6ERBALPJmV9LCYdzZWFAXZQ4r dWam8EKotHJSv+CT4QpaVald/4Rl6BeBdOY68GHoqTc0z9BObodDR7K3eV70BCndajnqrnKSe8C U3RJHsp8ddnBzl8F6/pprvuiNKPL+aso0+WWJ8cY+yRGmC1pFjXC9+YpXe6x+AhVypztvUYdSVo X76wN49xlkVo/0tYWeTHb7JH4Mag1jZ X-Received: by 2002:a05:620a:1993:b0:92e:7d7f:9102 with SMTP id af79cd13be357-92ee54ab5d8mr206888585a.2.1783650541428; Thu, 09 Jul 2026 19:29:01 -0700 (PDT) Received: from server0.tail6e7dd.ts.net (c-68-48-65-54.hsd1.mi.comcast.net. [68.48.65.54]) by smtp.gmail.com with ESMTPSA id af79cd13be357-92ee5b86276sm90507885a.11.2026.07.09.19.28.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 09 Jul 2026 19:29:00 -0700 (PDT) From: Michael Bommarito To: Jiri Kosina , Benjamin Tissoires , kys@microsoft.com, Haiyang Zhang , Wei Liu Cc: Dexuan Cui , Long Li , linux-input@vger.kernel.org, linux-hyperv@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH 1/2] HID: hyperv: validate initial device info bounds Date: Thu, 9 Jul 2026 22:28:53 -0400 Message-ID: <20260710022854.3739558-2-michael.bommarito@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260710022854.3739558-1-michael.bommarito@gmail.com> References: <20260710022854.3739558-1-michael.bommarito@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The Hyper-V synthetic HID host supplies SYNTH_HID_INITIAL_DEVICE_INFO messages that contain a HID descriptor followed by the report descriptor bytes. mousevsc_on_receive_device_info() trusts bLength and wDescriptorLength without checking that the received packet contains both byte ranges. A malformed host or backend message can therefore make the guest read past the received VMBus packet while copying the report descriptor. Pass the received initial-device-info size into the parser and reject descriptor lengths that exceed the packet. Impact: A malicious Hyper-V host or backend can crash a guest by sending a short initial device-info message with an oversized HID report descriptor length. Fixes: b95f5bcb811e ("HID: Move the hid-hyperv driver out of staging") Cc: stable@vger.kernel.org Assisted-by: Codex:gpt-5-5-xhigh Signed-off-by: Michael Bommarito --- drivers/hid/hid-hyperv.c | 27 ++++++++++++++++++++++++--- 1 file changed, 24 insertions(+), 3 deletions(-) diff --git a/drivers/hid/hid-hyperv.c b/drivers/hid/hid-hyperv.c index 7d2b0063df151..fd90196430e29 100644 --- a/drivers/hid/hid-hyperv.c +++ b/drivers/hid/hid-hyperv.c @@ -171,18 +171,32 @@ static void mousevsc_free_device(struct mousevsc_dev = *device) } =20 static void mousevsc_on_receive_device_info(struct mousevsc_dev *input_dev= ice, - struct synthhid_device_info *device_info) + struct synthhid_device_info *device_info, + u32 device_info_size) { int ret =3D 0; struct hid_descriptor *desc; struct mousevsc_prt_msg ack; + size_t desc_offset; + size_t desc_size; =20 input_device->dev_info_status =3D -ENOMEM; =20 + if (device_info_size < sizeof(*device_info)) { + input_device->dev_info_status =3D -EINVAL; + goto cleanup; + } + input_device->hid_dev_info =3D device_info->hid_dev_info; desc =3D &device_info->hid_descriptor; + desc_offset =3D offsetof(struct synthhid_device_info, hid_descriptor); + desc_size =3D device_info_size - desc_offset; if (desc->bLength =3D=3D 0) goto cleanup; + if (desc->bLength < sizeof(*desc) || desc->bLength > desc_size) { + input_device->dev_info_status =3D -EINVAL; + goto cleanup; + } =20 /* The pointer is not NULL when we resume from hibernation */ kfree(input_device->hid_desc); @@ -197,6 +211,10 @@ static void mousevsc_on_receive_device_info(struct mou= sevsc_dev *input_device, input_device->dev_info_status =3D -EINVAL; goto cleanup; } + if (input_device->report_desc_size > desc_size - desc->bLength) { + input_device->dev_info_status =3D -EINVAL; + goto cleanup; + } =20 /* The pointer is not NULL when we resume from hibernation */ kfree(input_device->report_desc); @@ -273,14 +291,17 @@ static void mousevsc_on_receive(struct hv_device *dev= ice, break; =20 case SYNTH_HID_INITIAL_DEVICE_INFO: - WARN_ON(pipe_msg->size < sizeof(struct hv_input_dev_info)); + if (WARN_ON_ONCE(pipe_msg->size < + sizeof(struct synthhid_device_info))) + break; =20 /* * Parse out the device info into device attr, * hid desc and report desc */ mousevsc_on_receive_device_info(input_dev, - (struct synthhid_device_info *)pipe_msg->data); + (struct synthhid_device_info *)pipe_msg->data, + pipe_msg->size); break; case SYNTH_HID_INPUT_REPORT: input_report =3D --=20 2.53.0 From nobody Sun Jul 26 01:47:32 2026 Received: from mail-qk1-f179.google.com (mail-qk1-f179.google.com [209.85.222.179]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 59CE22DF6E9 for ; Fri, 10 Jul 2026 02:29:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.179 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783650546; cv=none; b=c4PgsuqNmJWQgrhitHl9kYybHLMui2TbkiieQqD48woV8YS7JI2SLLVWU9qlKxfX1TgSAJ7YAlQrRJ2PtpLF7/on67Tg4aeKf1V7UUM53OeFrYLHn9CX0aHw28JFbKRygkVbQAKyp1SUGvWqp+fAjrfMDLP3E76BmHF3TNLnIUM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783650546; c=relaxed/simple; bh=GoEUjL9uCDds3bFd5UbAdn2JckJTHLD8D7KtLu1awmU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=BQiyUq/m8xgb+Zuyk5CxzWCQk7Il9ZgczV4BdI55xUa1WBxxg8z3NLq5oJI0ieRlVvMIDmu26fzxKK/knKSsl2vNIjHVbMnPzDz9YKxK22I+SjVH/4i09MhmF0mRYqDEIv9+S4l8ib9eXe4hGP1+sZohUtas1r3jLpFkzrl0ask= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=q/S7o5G9; arc=none smtp.client-ip=209.85.222.179 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="q/S7o5G9" Received: by mail-qk1-f179.google.com with SMTP id af79cd13be357-9217d13c276so18289085a.1 for ; Thu, 09 Jul 2026 19:29:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783650543; x=1784255343; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=w88OZllgC2a2Srw7/0oeygAu1BDvnNAAlvecR7ZdXpM=; b=q/S7o5G9Ldx/fWD1O1SZpD0y/RvsyA4p8oGQNIgof+yglSY6yOtSQHxXqMDRkGk/Ik 2ym3MRSeQr0aUhymqI+eymVIsdV3lg88b27L9cfG4tLg+HpOANsSUkzZPg6T2FGdb8MX 43S/ZD4jg9kRwu5ugxp8OhfIU3sQfr6ybjjeWvFVloq6B6hIpqoGxZEDHtavwUabRzrw 4VvVQdfdEB9Ye/U5gsx1GmysdNYzEbr3ipFb1JRozbRYPqchher6WKsUNhjkNfXk4OfW 991rdWBpxbc1czKq1onohjKPk+KxeAytsZ+FUOmhsJzwv3LMAqsBp7p9oJwwpIGKUutp u4Rw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783650543; x=1784255343; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=w88OZllgC2a2Srw7/0oeygAu1BDvnNAAlvecR7ZdXpM=; b=LL6XguxCBzUxKTM1JatXgn0TLdEDV2lg0nSpB8QB7zXd2PsLnMg0+h2+DAeG2hVHad CMyenDikcea09JUFs4QtIFE55aqQx1V3//ltmgDwUfTe00Dl+OIvGsdOUDQGnIN0at+G 9qAOg/STGfj0GjjTtd3QbvB86MgwLug+Oaerqss9/diHLjWXP1f6S+Ig0SPfQUWuPEsC rUj7Wt4t18aGEHM64Ouqc6eGm5c6JJhbAVIe4Dt0NMWaM1pzSQ+YbmuxUmesrrXJmbB2 65RuAQMfUkMuXbcrVQBqCPptwq3SLAeA3Easw4EWE9rMnvRpWKS9QB0knDT6CV1CErTP Jzjw== X-Forwarded-Encrypted: i=1; AHgh+RrqlA4fgh9qoP2HyAXdZnVA8VHB4D6TyxYH8AdWCO+0FmZaN8V3yPuOhMogupMluZwNA1D0wwQY6DdRr8g=@vger.kernel.org X-Gm-Message-State: AOJu0YwyowY2YP+nupnGP8OKBQlsKCyhCm59Prw/wtxUN7PzRaV/xXVF MJJp9E1jqe85rE/GuhmfPIMVf4jkJVUvttBu3WevOrGzuWCwWOmtF0ti X-Gm-Gg: AfdE7cnicVhkGsHNPFBB/cLBFfmiitavgDlq9QIJkEXyqI3XXyHPMPg/e/7oWxlM8dy B8l2cmQK/V1w/sHvM72L7X6Bdc1N+f9PGn9E/KtcFqEVNgw7iol+PUes6IA7qNPIoumNcvL4HbN zMC6ZWbjg5u6tz1pcb3W+s2Y5oVTxJ0J5iJR+9p26oygPk9NiD5pCLoJfqEHxak+0dOoPHonyrp AsRd3QV35bKtBMwco6ar5BKld761oX7crZKSVHe6xc8owN32MFKoruTbJJfb4xfdar9/fPQyZUi TeLwR1/RP6ofuGNoOvwy6EtXaqZDqj6pgC4HgyzqtwN9CPf6rEW+RWxU8MU6a71VQJupNqD9GIe TF2Y8huRKp8Ei52hYMaQxEVvAOtpBhKHbrcp37cU6nKHESES5RvZHbOeta/GxjKEjynJIo0j+Eg hN+kvjgaUZXdi/dHKSfW9mWTaF0q6ui/NIn6X6ui6aBa9cGmJ4vO8qdiFihhaoSnqTSlIYQFEfU wUwWRMs5SC+paZAjpmBALSQDS6rhagX X-Received: by 2002:a05:620a:2953:b0:92e:7a3c:add7 with SMTP id af79cd13be357-92ecf5f3e9amr1050972485a.27.1783650543205; Thu, 09 Jul 2026 19:29:03 -0700 (PDT) Received: from server0.tail6e7dd.ts.net (c-68-48-65-54.hsd1.mi.comcast.net. [68.48.65.54]) by smtp.gmail.com with ESMTPSA id af79cd13be357-92ee5b86276sm90507885a.11.2026.07.09.19.29.01 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 09 Jul 2026 19:29:02 -0700 (PDT) From: Michael Bommarito To: Jiri Kosina , Benjamin Tissoires , kys@microsoft.com, Haiyang Zhang , Wei Liu Cc: Dexuan Cui , Long Li , linux-input@vger.kernel.org, linux-hyperv@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH 2/2] HID: hyperv: add KUnit coverage for device info bounds Date: Thu, 9 Jul 2026 22:28:54 -0400 Message-ID: <20260710022854.3739558-3-michael.bommarito@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260710022854.3739558-1-michael.bommarito@gmail.com> References: <20260710022854.3739558-1-michael.bommarito@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Add KUnit coverage for Hyper-V synthetic HID initial device-info parsing. The tests cover zero bLength, a valid descriptor plus report descriptor, and a malformed report descriptor length that exceeds the received message. The same-translation-unit test uses a KUnit-only ACK bypass so parser coverage does not require a live VMBus channel. Assisted-by: Codex:gpt-5-5-xhigh Signed-off-by: Michael Bommarito --- drivers/hid/Kconfig | 10 ++++ drivers/hid/hid-hyperv.c | 117 ++++++++++++++++++++++++++++++++++++--- 2 files changed, 120 insertions(+), 7 deletions(-) diff --git a/drivers/hid/Kconfig b/drivers/hid/Kconfig index c1d9f7c6a5f23..41ca48d9adc9e 100644 --- a/drivers/hid/Kconfig +++ b/drivers/hid/Kconfig @@ -1183,6 +1183,16 @@ config HID_HYPERV_MOUSE help Select this option to enable the Hyper-V mouse driver. =20 +config HID_HYPERV_MOUSE_KUNIT_TEST + bool "KUnit tests for Hyper-V mouse driver" if !KUNIT_ALL_TESTS + depends on KUNIT && HID_HYPERV_MOUSE + default KUNIT_ALL_TESTS + help + Builds unit tests for the Hyper-V synthetic HID driver. + These tests exercise the initial device-info parser with + malformed host-provided HID descriptors and are only useful + for kernel developers running KUnit. + config HID_SMARTJOYPLUS tristate "SmartJoy PLUS PS2/USB adapter support" help diff --git a/drivers/hid/hid-hyperv.c b/drivers/hid/hid-hyperv.c index fd90196430e29..6579bd19da13a 100644 --- a/drivers/hid/hid-hyperv.c +++ b/drivers/hid/hid-hyperv.c @@ -13,6 +13,9 @@ #include #include =20 +#if IS_ENABLED(CONFIG_HID_HYPERV_MOUSE_KUNIT_TEST) +#include +#endif =20 struct hv_input_dev_info { unsigned int size; @@ -240,13 +243,18 @@ static void mousevsc_on_receive_device_info(struct mo= usevsc_dev *input_device, ack.ack.header.size =3D 1; ack.ack.reserved =3D 0; =20 - ret =3D vmbus_sendpacket(input_device->device->channel, - &ack, - sizeof(struct pipe_prt_msg) + - sizeof(struct synthhid_device_info_ack), - (unsigned long)&ack, - VM_PKT_DATA_INBAND, - VMBUS_DATA_PACKET_FLAG_COMPLETION_REQUESTED); + if (IS_ENABLED(CONFIG_HID_HYPERV_MOUSE_KUNIT_TEST) && + !input_device->device) { + ret =3D 0; + } else { + ret =3D vmbus_sendpacket(input_device->device->channel, + &ack, + sizeof(struct pipe_prt_msg) + + sizeof(struct synthhid_device_info_ack), + (unsigned long)&ack, + VM_PKT_DATA_INBAND, + VMBUS_DATA_PACKET_FLAG_COMPLETION_REQUESTED); + } =20 if (!ret) input_device->dev_info_status =3D 0; @@ -635,5 +643,100 @@ static void __exit mousevsc_exit(void) MODULE_LICENSE("GPL"); MODULE_DESCRIPTION("Microsoft Hyper-V Synthetic HID Driver"); =20 +#if IS_ENABLED(CONFIG_HID_HYPERV_MOUSE_KUNIT_TEST) +static struct mousevsc_dev *mousevsc_kunit_alloc_dev(struct kunit *test) +{ + struct mousevsc_dev *input_dev; + + input_dev =3D kunit_kzalloc(test, sizeof(*input_dev), GFP_KERNEL); + if (!input_dev) + return NULL; + + init_completion(&input_dev->wait_event); + + return input_dev; +} + +static void mousevsc_device_info_zero_blength(struct kunit *test) +{ + struct synthhid_device_info *info; + struct mousevsc_dev *input_dev; + + input_dev =3D mousevsc_kunit_alloc_dev(test); + KUNIT_ASSERT_NOT_NULL(test, input_dev); + info =3D kunit_kzalloc(test, sizeof(*info), GFP_KERNEL); + KUNIT_ASSERT_NOT_NULL(test, info); + + info->hid_descriptor.bLength =3D 0; + + mousevsc_on_receive_device_info(input_dev, info, sizeof(*info)); + + KUNIT_EXPECT_EQ(test, input_dev->dev_info_status, -ENOMEM); +} + +static void mousevsc_device_info_valid_descriptor(struct kunit *test) +{ + struct synthhid_device_info *info; + struct mousevsc_dev *input_dev; + u8 *report; + + input_dev =3D mousevsc_kunit_alloc_dev(test); + KUNIT_ASSERT_NOT_NULL(test, input_dev); + info =3D kunit_kzalloc(test, sizeof(*info) + 4, GFP_KERNEL); + KUNIT_ASSERT_NOT_NULL(test, info); + + info->hid_descriptor.bLength =3D sizeof(struct hid_descriptor); + info->hid_descriptor.rpt_desc.wDescriptorLength =3D cpu_to_le16(4); + report =3D ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength; + memset(report, 0x42, 4); + + mousevsc_on_receive_device_info(input_dev, info, sizeof(*info) + 4); + + KUNIT_EXPECT_EQ(test, input_dev->dev_info_status, 0); + KUNIT_EXPECT_EQ(test, input_dev->report_desc_size, 4); + KUNIT_EXPECT_MEMEQ(test, input_dev->report_desc, report, 4); + + kfree(input_dev->hid_desc); + kfree(input_dev->report_desc); +} + +static void mousevsc_device_info_report_desc_oob(struct kunit *test) +{ + struct synthhid_device_info *info; + struct mousevsc_dev *input_dev; + u8 *report; + + input_dev =3D mousevsc_kunit_alloc_dev(test); + KUNIT_ASSERT_NOT_NULL(test, input_dev); + info =3D kunit_kzalloc(test, sizeof(*info) + 8, GFP_KERNEL); + KUNIT_ASSERT_NOT_NULL(test, info); + + info->hid_descriptor.bLength =3D sizeof(struct hid_descriptor); + info->hid_descriptor.rpt_desc.wDescriptorLength =3D cpu_to_le16(64); + report =3D ((u8 *)&info->hid_descriptor) + info->hid_descriptor.bLength; + memset(report, 0x42, 8); + + mousevsc_on_receive_device_info(input_dev, info, sizeof(*info) + 8); + + KUNIT_EXPECT_EQ(test, input_dev->dev_info_status, -EINVAL); + + kfree(input_dev->hid_desc); +} + +static struct kunit_case mousevsc_test_cases[] =3D { + KUNIT_CASE(mousevsc_device_info_zero_blength), + KUNIT_CASE(mousevsc_device_info_valid_descriptor), + KUNIT_CASE(mousevsc_device_info_report_desc_oob), + {} +}; + +static struct kunit_suite mousevsc_test_suite =3D { + .name =3D "hid_hyperv_mouse", + .test_cases =3D mousevsc_test_cases, +}; + +kunit_test_suite(mousevsc_test_suite); +#endif + module_init(mousevsc_init); module_exit(mousevsc_exit); --=20 2.53.0