Commit Graph
2003 Commits
Author SHA1 Message Date
Marco Trevisan (Treviño) ecbc2affb2 upektc_img: Cleanup image bits on deactivation
Also ensure we never leak data
2026-07-13 08:13:46 +00:00
Marco Trevisan (Treviño) 44dd97bf5e upektc_img: Prevent image frame overflow
The frame length and the offset (which depends on the device-supplied
frame type) are derived from device bytes, so validate both the source
read (against the response buffer) and the destination write (against
the image buffer) before copying.
A malicious or malfunctioning device could otherwise drive a negative
(huge once unsigned) or out-of-bounds length.

Note: the response is reassembled across several USB transfers, so the
bound here is the response buffer capacity rather than a single
transfer's actual_length.

Reported by: Keith Linneman (LinnemanLabs)
2026-07-13 08:13:46 +00:00
Marco Trevisan (Treviño) 07152e43ef realtek: Fail on shorter data read that may lead to an underflow
Reported by: Keith Linneman (LinnemanLabs)
2026-07-13 08:13:46 +00:00
Marco Trevisan (Treviño) 2e2ba8b227 uru4000: Unset allocated data on completion 2026-07-13 08:13:46 +00:00
Marco Trevisan (Treviño) 657c764b73 uru4000: Ensure we do not overflow image buffer on reading
Reported by: Keith Linneman (LinnemanLabs)
2026-07-13 08:13:46 +00:00
Marco Trevisan (Treviño) ad8a6f6b17 uru4000: Prevent a buffer overflow on reading the device image data
num_lines comes from the device for each block and is summed into
the source row index (r) and destination byte offset (to).
Neither the per-block value nor the running totals are otherwise bound,
so a malicious device could drive the copy past the source
(IMAGE_HEIGHT rows) or destination buffer.

Reported by: Keith Linneman (LinnemanLabs)
2026-07-13 08:13:46 +00:00
Marco Trevisan (Treviño) 63be3884d6 etes603: Handle buffer over/under-flows
Reported by: Keith Linneman (LinnemanLabs)
2026-07-13 08:13:46 +00:00
Marco Trevisan (Treviño) c025abcd15 fpc: Prevent overflow when reading the print identity
Reported by: Keith Linneman (LinnemanLabs)
2026-07-13 08:13:46 +00:00
Marco Trevisan (Treviño) 3cc0ae79e7 fpc: Prevent a buffer-overflow on data reading
Reported by: Keith Linneman (LinnemanLabs)
2026-07-13 08:13:46 +00:00
Marco Trevisan (Treviño) 092c0dfc31 fpcmoc: Copy the error before sending to the SSM
The SSM error is stolen and then we pass to the resume/suspend callback
potentially leading to a double-free.

So copy it before re-using it.

Reported by: Keith Linneman (LinnemanLabs)
2026-07-13 08:13:46 +00:00
Marco Trevisan (Treviño) 3138ad0c8a goodixmoc: Cleanup the byte reader usage 2026-07-13 08:13:46 +00:00
Marco Trevisan (Treviño) 0c0baf639e goodixmoc: Ensure we do not overflow when reading the payload
Reported by: Keith Linneman (LinnemanLabs)
2026-07-13 08:13:46 +00:00
Marco Trevisan (Treviño) f15a62b5aa goodixmoc: Handle invalid finger number
A modified device may supply invalid data, leading to libfprint crashes

Reported by: Keith Linneman (LinnemanLabs)
2026-07-13 08:13:46 +00:00
Marco Trevisan (Treviño) d9374963cd goodixmoc: Handle cases in which the header lenght is smaller than CRC size
Reported by: Keith Linneman (LinnemanLabs)
2026-07-13 08:13:46 +00:00
Marco Trevisan (Treviño) 19719bf2da goodixmoc: Add missing return on CRC failure
Reported by: Keith Linneman (LinnemanLabs)
2026-07-13 08:13:46 +00:00
Marco Trevisan (Treviño) 11b8930d35 fpi-device: Fix device action error docstring and transfer 2026-07-13 08:13:46 +00:00
Marco Trevisan (Treviño) 5597082804 uncrustify: Add g_autolist and g_autoslist to auto types 2026-07-12 13:17:35 +02:00
Marco Trevisan (Treviño) dac36a8d59 fp-device: Fix double free in device finalization with pending timeout sources
fp_device_finalize calls g_slist_free_full() to destroy any still-pending
timeout sources.
Each g_source_destroy call triggers timeout_finalize, which tries to
remove the current source from the sources list.
This may lead to a double-free, as iterating over a list deleting items
is not supported.

Add a regression test that adds a timeout with a long delay and immediately
finalizes the device while the timeout is still pending.
2026-07-12 13:17:35 +02:00
Marco Trevisan (Treviño) 55b934b02e tests/fpi-device: Increase warmup/cooldown test timeouts
The slack of 250ms wasn't enough on loaded CI systems, causing frequent
flaky failures (e.g. 2276ms actual vs 2250ms limit, or 2294ms vs 2250ms).

Double the slacks to 500ms for the 2s transitions and 1000ms for the
5s transition to absorb system load noise while still catching real
timing regressions.
2026-07-12 13:17:35 +02:00
Marco Trevisan (Treviño) 3cae9ea4ae build/tests: Add ability to define more per-test meson parameters 2026-07-12 13:17:35 +02:00
Marco Trevisan (Treviño) a1713fab6b synaptics: Fix a comment typo 2026-07-12 13:17:35 +02:00
Marco Trevisan (Treviño) 18f60cb47f fpi-device: Improve logging on driver reported data
And perform data allocations only if debug logging is enabled
2026-07-12 13:17:35 +02:00
Marco Trevisan (Treviño) ebcab4ac1a fp-device: Use GLib API to deep copy the prints gallery 2026-07-12 13:17:35 +02:00
Marco Trevisan (Treviño) 91dd69475f tests/fpi-device: Add test identifying with an empty gallery
We're still going into the device in this case because technically the
identify operation may still return a print, although never a match of
course.

Adding tests so that we are not tempted to modify the behavior of the
identify function to return an error on prints->len == 0 or to just not
call the driver on such case.
2026-07-12 13:17:35 +02:00
Marco Trevisan (Treviño) 7e579f0f36 fpi-device: Warn if a device returns a scanned print that is not matching match
Devices can scan even without a match, but if they do match a print then
they must match.

Ensure this in code to prevent drivers to return inconsistent data.
2026-07-12 13:17:34 +02:00
Marco Trevisan (Treviño) 2f6b46b91f tests-fpi-device: Do not hardcode the gallery random pick limit 2026-07-12 13:16:33 +02:00
Marco Trevisan (Treviño) b4d78e7c0f fpi-print: Add function to check if two prints match
While for raw prints this is just an equality check, for NBIS prints
they match if at least one of the minutiae match
2026-07-12 13:16:33 +02:00
Marco Trevisan (Treviño) 3ac3c7b082 tests-fpi-device: Add unit tests for prints equality 2026-07-12 13:16:33 +02:00
Marco Trevisan (Treviño) 7730146af0 fp-print: Just consider equal prints pointers to be equal 2026-07-12 13:16:33 +02:00
Marco Trevisan (Treviño) 7e3453e796 fpi-device: Do not potentially leak a nested error 2026-07-12 13:16:33 +02:00
Marco Trevisan (Treviño) cb862ccfad fpi-device: Remove commented function 2026-07-12 13:16:33 +02:00
Marco Trevisan (Treviño) c5e49592cd drivers: Remove redundant verify implementations
As per recent changes, drivers can just avoid implementing verify vfunc
unless the driver has specific commands to do it.

So let's just drop the duplicated code in drivers that have the very
same code path for both identification and verification.
2026-07-12 12:58:52 +02:00
Marco Trevisan (Treviño) bebaa80c99 fp-image-device: Drop explicit verification support
It's just the same logic repeated across one or multiple templates, so
let's just define one
2026-07-12 12:58:52 +02:00
Marco Trevisan (Treviño) 7fee92884d fp-device: Implement verify using identification
In case a device has not support for verification through an explicit
verify function, the verification can still be implemented using
identification with a gallery of a single print.

In fact that's what most of drivers these days do it, so let's just
avoid to them to handle this duplication unless a driver has really some
specific commands to do it.
2026-07-12 12:58:50 +02:00
Emanuele Bertolucci 111a3af462 data: Remove now-duplicate 27c6:6382 entry from unsupported-devices block
Companion fix to 51b8712: the static hwdb file had the same duplicate
the generator now avoids.
2026-07-08 16:20:24 +02:00
Emanuele Bertolucci 51b8712d51 fprint-list-udev-hwdb: Drop 27c6:6382 from the unsupported-devices list
It is now supported by the goodixmoc driver, so listing it here too
caused a duplicate VID:PID entry (the hwdb generator aborts on
duplicates).
2026-07-08 16:20:05 +02:00
Emanuele Bertolucci ca45b08bbe data: Add Goodix 27c6:6382 to autosuspend hwdb
Keeps the static hwdb in sync with the goodixmoc driver's id_table
(test-generated-hwdb.sh enforces this consistency).
2026-07-08 16:19:35 +02:00
Emanuele Bertolucci 6218b74436 goodixmoc: Add support for Goodix 27c6:6382 (Dell XPS 13 9315)
Same MOC protocol family as the already-supported 27c6:6384/631C.
Verified against real hardware: open, enroll, verify, identify and
delete all succeed. Dell's own driver .inf for this PID (extracted
from Goodix-Fingerprint-Sensor-Driver_T2VK3_WIN64_40.10.1.100_A05_01.EXE)
confirms it uses the plain (non-SecureFingerprint) MOC protocol.
2026-07-08 16:19:13 +02:00
Marco Trevisan (Treviño) 0e64435628 focaltech_moc: Simplify interface claiming error handling 2026-07-02 13:18:26 +02:00
Daniel SchaeferandMarco Trevisan (Treviño) 4061d76218 focaltech_moc: Handle errors
If the reader does not respond, currently the plugin segfaults.
The error should be handled gracefully.

With this change, an error is printed instead of crashing:
  failed to claim device:
  GDBus.Error:net.reactivated.Fprint.Error.Internal:
  Open failed with error: Can't get response!!

Signed-off-by: Daniel Schaefer <dhs@frame.work>
2026-07-02 12:46:48 +02:00
Sebastian van de MeerandMarco Trevisan 0fa670f7f8 nb1010: Add support for NB-2020-U fingerprint reader
Add USB PID 0x2020 (NB-2020-U) to the nb1010 driver's id_table.

The NB-2020-U is an embedded variant of the NB-1010-U using an
identical sensor die (confirmed by independent teardown reports from
System Plus Consulting/Yole Group). USB endpoint layout, command
protocol and image format are identical between both devices.

Tested on a Fujitsu notebook with integrated NB-2020-U reader
(USB ID 298d:2020): device enumeration, finger detection polling
and image capture all work correctly with the existing nb1010
driver code.

Signed-off-by: Sebastian van de Meer <kernel-error@kernel-error.com>
2026-07-02 00:37:30 +00:00
Marco Trevisan (Treviño) 3c4bee9e82 ci: Add test build in s390x to verify BE behavior
Most of drivers supports both endiannesses but we do not test this so
let's add a CI job to verify this
2026-07-02 02:14:37 +02:00
Marco Trevisan (Treviño) 72188c0eb8 aes2501: Fix endianness of instogram 2026-07-02 02:14:37 +02:00
Marco Trevisan (Treviño) 141a63b0a4 egis_etu905: Use fpi writer to build the commit data 2026-07-01 17:59:34 +02:00
Marco Trevisan (Treviño) a042240b67 egis_etu905: Use little endian commit data in all the archs 2026-07-01 17:56:41 +02:00
Marco Trevisan (Treviño) 1d6ebb0ee8 uru4000: Fix computation of num lines in big endian 2026-07-01 17:49:34 +02:00
Marco Trevisan (Treviño) e2ff73df3f elan: Use guint16 in LE for frame value 2026-07-01 17:49:34 +02:00
Marco Trevisan (Treviño) e821d0f83f build: Enable elanspi in big endian archs
It works fine so no need to do anything there
2026-07-01 17:49:34 +02:00
Marco Trevisan (Treviño) 2ff99be5db goodixmoc: Fix handling of CRC32 in big endian archs 2026-07-01 17:49:34 +02:00
Marco Trevisan (Treviño) 2dec3f57ea mafpmoc: Use fpi-bytes-writer to build command packet 2026-07-01 17:49:34 +02:00