Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1556497 > unrolled thread

[PATCH] ALSA: hda/ca0132 - fix possible NULL pointer use

Started byArnd Bergmann <arnd@arndb.de>
First post2017-01-11 14:50 +0100
Last post2017-01-11 17:30 +0100
Articles 2 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH] ALSA: hda/ca0132 - fix possible NULL pointer use Arnd Bergmann <arnd@arndb.de> - 2017-01-11 14:50 +0100
    Re: [PATCH] ALSA: hda/ca0132 - fix possible NULL pointer use Takashi Iwai <tiwai@suse.de> - 2017-01-11 17:30 +0100

#1556497 — [PATCH] ALSA: hda/ca0132 - fix possible NULL pointer use

FromArnd Bergmann <arnd@arndb.de>
Date2017-01-11 14:50 +0100
Subject[PATCH] ALSA: hda/ca0132 - fix possible NULL pointer use
Message-ID<sYrrQ-7xT-29@gated-at.bofh.it>
gcc-7 caught what it considers a NULL pointer dereference:

sound/pci/hda/patch_ca0132.c: In function 'dspio_scp.constprop':
sound/pci/hda/patch_ca0132.c:1487:4: error: argument 1 null where non-null expected [-Werror=nonnull]

This is plausible from looking at the function, as we compare 'reply'
to NULL earlier in it. I have not tried to analyze if there are constraints
that make it impossible to hit the bug, but adding another NULL check in
the end kills the warning and makes the function more robust.

Signed-off-by: Arnd Bergmann <arnd@arndb.de>
---
 sound/pci/hda/patch_ca0132.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/sound/pci/hda/patch_ca0132.c b/sound/pci/hda/patch_ca0132.c
index bd7c29f8ab1e..07a9deb17477 100644
--- a/sound/pci/hda/patch_ca0132.c
+++ b/sound/pci/hda/patch_ca0132.c
@@ -1482,6 +1482,9 @@ static int dspio_scp(struct hda_codec *codec,
 		} else if (ret_size != reply_data_size) {
 			codec_dbg(codec, "RetLen and HdrLen .NE.\n");
 			return -EINVAL;
+		} else if (!reply) {
+			codec_dbg(codec, "NULL reply\n");
+			return -EINVAL;
 		} else {
 			*reply_len = ret_size*sizeof(unsigned int);
 			memcpy(reply, scp_reply.data, *reply_len);
-- 
2.9.0

[toc] | [next] | [standalone]


#1556691

FromTakashi Iwai <tiwai@suse.de>
Date2017-01-11 17:30 +0100
Message-ID<sYtWG-In-25@gated-at.bofh.it>
In reply to#1556497
On Wed, 11 Jan 2017 14:39:44 +0100,
Arnd Bergmann wrote:
> 
> gcc-7 caught what it considers a NULL pointer dereference:
> 
> sound/pci/hda/patch_ca0132.c: In function 'dspio_scp.constprop':
> sound/pci/hda/patch_ca0132.c:1487:4: error: argument 1 null where non-null expected [-Werror=nonnull]
> 
> This is plausible from looking at the function, as we compare 'reply'
> to NULL earlier in it. I have not tried to analyze if there are constraints
> that make it impossible to hit the bug, but adding another NULL check in
> the end kills the warning and makes the function more robust.
> 
> Signed-off-by: Arnd Bergmann <arnd@arndb.de>

Applied, thanks.


Takashi

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web