Input: rpckbd - fix a leak of the IRQ during init failure
[pandora-kernel.git] / drivers / input / evdev.c
index 68f09a8..7f42d3a 100644 (file)
@@ -8,6 +8,8 @@
  * the Free Software Foundation.
  */
 
+#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
+
 #define EVDEV_MINOR_BASE       64
 #define EVDEV_MINORS           32
 #define EVDEV_MIN_BUFFER_SIZE  64U
@@ -319,6 +321,9 @@ static ssize_t evdev_write(struct file *file, const char __user *buffer,
        struct input_event event;
        int retval;
 
+       if (count < input_event_size())
+               return -EINVAL;
+
        retval = mutex_lock_interruptible(&evdev->mutex);
        if (retval)
                return retval;
@@ -328,17 +333,16 @@ static ssize_t evdev_write(struct file *file, const char __user *buffer,
                goto out;
        }
 
-       while (retval < count) {
-
+       do {
                if (input_event_from_user(buffer + retval, &event)) {
                        retval = -EFAULT;
                        goto out;
                }
+               retval += input_event_size();
 
                input_inject_event(&evdev->handle,
                                   event.type, event.code, event.value);
-               retval += input_event_size();
-       }
+       } while (retval + input_event_size() <= count);
 
  out:
        mutex_unlock(&evdev->mutex);
@@ -522,12 +526,11 @@ static int handle_eviocgbit(struct input_dev *dev,
        if (type == EV_KEY && size == OLD_KEY_MAX) {
                len = OLD_KEY_MAX;
                if (printk_timed_ratelimit(&keymax_warn_time, 10 * 1000))
-                       printk(KERN_WARNING
-                               "evdev.c(EVIOCGBIT): Suspicious buffer size %u, "
-                               "limiting output to %zu bytes. See "
-                               "http://userweb.kernel.org/~dtor/eviocgbit-bug.html\n",
-                               OLD_KEY_MAX,
-                               BITS_TO_LONGS(OLD_KEY_MAX) * sizeof(long));
+                       pr_warning("(EVIOCGBIT): Suspicious buffer size %u, "
+                                  "limiting output to %zu bytes. See "
+                                  "http://userweb.kernel.org/~dtor/eviocgbit-bug.html\n",
+                                  OLD_KEY_MAX,
+                                  BITS_TO_LONGS(OLD_KEY_MAX) * sizeof(long));
        }
 
        return bits_to_user(bits, len, size, p, compat_mode);
@@ -686,6 +689,10 @@ static long evdev_do_ioctl(struct file *file, unsigned int cmd,
 #define EVIOC_MASK_SIZE(nr)    ((nr) & ~(_IOC_SIZEMASK << _IOC_SIZESHIFT))
        switch (EVIOC_MASK_SIZE(cmd)) {
 
+       case EVIOCGPROP(0):
+               return bits_to_user(dev->propbit, INPUT_PROP_MAX,
+                                   size, p, compat_mode);
+
        case EVIOCGKEY(0):
                return bits_to_user(dev->key, KEY_MAX, size, p, compat_mode);
 
@@ -897,7 +904,7 @@ static int evdev_connect(struct input_handler *handler, struct input_dev *dev,
                        break;
 
        if (minor == EVDEV_MINORS) {
-               printk(KERN_ERR "evdev: no more free evdev devices\n");
+               pr_err("no more free evdev devices\n");
                return -ENFILE;
        }