Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1336244
| From | Srinivas Kandagatla <srinivas.kandagatla@linaro.org> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH] nvmem: core: fix error path in nvmem_add_cells() |
| Date | 2016-02-17 11:50 +0100 |
| Message-ID | <r37Qe-59r-29@gated-at.bofh.it> (permalink) |
| References | <r01eh-2kE-13@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Hi Rasmus, Thanks for the patch, On 08/02/16 21:04, Rasmus Villemoes wrote: > The current code fails to nvmem_cell_drop(cells[0]) - even worse, if > the loop above fails already at i==0, we'll enter an essentially > infinite loop doing nvmem_cell_drop on cells[-1], cells[-2], ... which > is unlikely to end well. I agree, it would fail in case of zero. > > Also, we're not freeing the temporary backing array cells on the error > path. > > Signed-off-by: Rasmus Villemoes <linux@rasmusvillemoes.dk> > --- > drivers/nvmem/core.c | 4 +++- > 1 file changed, 3 insertions(+), 1 deletion(-) > > diff --git a/drivers/nvmem/core.c b/drivers/nvmem/core.c > index 6fd4e5a5ef4a..1e65eccfea83 100644 > --- a/drivers/nvmem/core.c > +++ b/drivers/nvmem/core.c > @@ -288,9 +288,11 @@ static int nvmem_add_cells(struct nvmem_device *nvmem, > > return 0; > err: > - while (--i) > + while (i--) > nvmem_cell_drop(cells[i]); No, this will not work. 3 issues, 1> If we enter this err path from nvmem_cell_info_to_nvmem_cell() failures, you would be accessing already freed cells[i]. 2> accessing un-allocated cells[i]. 3> you would be trying to drop cells which are not in the list. This is what you need here to fix it correctly. while (--i >= 0) > > + kfree(cells); This change looks good. > + > return rval; > } > > --srini
Back to linux.kernel | Previous | Next — Next in thread | Find similar | Unroll thread
Re: [PATCH] nvmem: core: fix error path in nvmem_add_cells() Srinivas Kandagatla <srinivas.kandagatla@linaro.org> - 2016-02-17 11:50 +0100
Re: [PATCH] nvmem: core: fix error path in nvmem_add_cells() Rasmus Villemoes <linux@rasmusvillemoes.dk> - 2016-02-18 06:40 +0100
Re: [PATCH] nvmem: core: fix error path in nvmem_add_cells() Srinivas Kandagatla <srinivas.kandagatla@linaro.org> - 2016-02-18 10:10 +0100
csiph-web