HID: rmi: check report length before trimming sentinel bytes

rmi_check_sanity() trims trailing 0xff sentinel bytes, but its loop
reads data[valid_size - 1] before checking that valid_size is non-zero.

Reverse the condition so the length is proved before the last byte is
inspected.

Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
This commit is contained in:
Pengpeng Hou 2026-06-30 14:52:45 +08:00 committed by Jiri Kosina
parent 08d8814521
commit 28a3e326fa

View File

@ -365,7 +365,7 @@ static int rmi_check_sanity(struct hid_device *hdev, u8 *data, int size)
* such reports here.
*/
while ((data[valid_size - 1] == 0xff) && valid_size > 0)
while (valid_size > 0 && data[valid_size - 1] == 0xff)
valid_size--;
return valid_size;