Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1594425 > unrolled thread
| Started by | Colin King <colin.king@canonical.com> |
|---|---|
| First post | 2017-03-07 17:50 +0100 |
| Last post | 2017-03-11 19:40 +0100 |
| Articles | 3 — 3 participants |
Back to article view | Back to linux.kernel
[PATCH] iio: multiplexer: fix unsigned check with less than zero Colin King <colin.king@canonical.com> - 2017-03-07 17:50 +0100
Re: [PATCH] iio: multiplexer: fix unsigned check with less than zero Colin Ian King <colin.king@canonical.com> - 2017-03-08 10:10 +0100
Re: [PATCH v2] iio: multiplexer: fix unsigned check with less than zero Jonathan Cameron <jic23@kernel.org> - 2017-03-11 19:40 +0100
| From | Colin King <colin.king@canonical.com> |
|---|---|
| Date | 2017-03-07 17:50 +0100 |
| Subject | [PATCH] iio: multiplexer: fix unsigned check with less than zero |
| Message-ID | <tiqtd-1LM-27@gated-at.bofh.it> |
From: Colin Ian King <colin.king@canonical.com>
Comparing a size_t with less than zero is always false as size_t
is unsigned. The intent of the comparison was to check if the size
was -1 (that is, undefined), so use that instead.
Detected by CoverityScan, CID#1415278 ("Unsigned compared against 0")
Signed-off-by: Colin Ian King <colin.king@canonical.com>
---
drivers/iio/multiplexer/iio-mux.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/iio/multiplexer/iio-mux.c b/drivers/iio/multiplexer/iio-mux.c
index 94d40f9b..6c23033 100644
--- a/drivers/iio/multiplexer/iio-mux.c
+++ b/drivers/iio/multiplexer/iio-mux.c
@@ -61,7 +61,7 @@ static int iio_mux_select(struct mux *mux, int idx)
cache = &child->ext_info_cache[i];
- if (cache->size < 0)
+ if (cache->size == (size_t)-1)
continue;
ret = iio_write_channel_ext_info(mux->parent, attr,
--
2.10.2
[toc] | [next] | [standalone]
| From | Colin Ian King <colin.king@canonical.com> |
|---|---|
| Date | 2017-03-08 10:10 +0100 |
| Message-ID | <tiFLB-4fF-43@gated-at.bofh.it> |
| In reply to | #1594425 |
On 08/03/17 08:59, Peter Rosin wrote:
> On 2017-03-07 16:06, Colin King wrote:
>> From: Colin Ian King <colin.king@canonical.com>
>>
>> Comparing a size_t with less than zero is always false as size_t
>> is unsigned. The intent of the comparison was to check if the size
>> was -1 (that is, undefined), so use that instead.
>>
>> Detected by CoverityScan, CID#1415278 ("Unsigned compared against 0")
>>
>> Signed-off-by: Colin Ian King <colin.king@canonical.com>
>
> Hi!
>
> Oops, thanks for highlighting this! However, I think I prefer to instead
> change the type of the struct mux_ext_info_cache member 'size' to ssize_t.
> That way, there is no annoying explicit cast. And perhaps add an early
> check
>
> if (len >= PAGE_SIZE)
> return -EINVAL;
>
> to mux_write_ext_info (because the sysfs read function in use for iio ext
> info can't handle more than a page anyway, IIUC). That way it is fairly
> certain that the ssize_t type will always be big enough. :-)
Sounds like a far better solution.
>
> So, I'm going send out a patch like that instead, unless someone happens to
> beat me to it...
>
> Cheers,
> peda
Thanks,
Colin
>
>> ---
>> drivers/iio/multiplexer/iio-mux.c | 2 +-
>> 1 file changed, 1 insertion(+), 1 deletion(-)
>>
>> diff --git a/drivers/iio/multiplexer/iio-mux.c b/drivers/iio/multiplexer/iio-mux.c
>> index 94d40f9b..6c23033 100644
>> --- a/drivers/iio/multiplexer/iio-mux.c
>> +++ b/drivers/iio/multiplexer/iio-mux.c
>> @@ -61,7 +61,7 @@ static int iio_mux_select(struct mux *mux, int idx)
>>
>> cache = &child->ext_info_cache[i];
>>
>> - if (cache->size < 0)
>> + if (cache->size == (size_t)-1)
>> continue;
>>
>> ret = iio_write_channel_ext_info(mux->parent, attr,
>>
>
[toc] | [prev] | [next] | [standalone]
| From | Jonathan Cameron <jic23@kernel.org> |
|---|---|
| Date | 2017-03-11 19:40 +0100 |
| Subject | Re: [PATCH v2] iio: multiplexer: fix unsigned check with less than zero |
| Message-ID | <tjU5Q-6Jb-17@gated-at.bofh.it> |
| In reply to | #1594964 |
On 08/03/17 13:28, Peter Rosin wrote:
> Comparing a size_t with less than zero is always false as size_t
> is unsigned. So, change the type of the variable to ssize_t and
> replicate the size check from mux_configure_channel() into
> mux_write_ext_info() thus ensuring that the size will fit in the
> ssize_t variable.
>
> Detected by CoverityScan, CID#1415278 ("Unsigned compared against 0")
>
> Reported-by: Colin Ian King <colin.king@canonical.com>
> Signed-off-by: Peter Rosin <peda@axentia.se>
For what it's worth, looks good to me.
Jonathan
> ---
> drivers/iio/multiplexer/iio-mux.c | 5 ++++-
> 1 file changed, 4 insertions(+), 1 deletion(-)
>
> Hi!
>
> Here's what intend to queue up.
>
> Cheers,
> peda
>
> diff --git a/drivers/iio/multiplexer/iio-mux.c b/drivers/iio/multiplexer/iio-mux.c
> index 94d40f9b..bab9e69 100644
> --- a/drivers/iio/multiplexer/iio-mux.c
> +++ b/drivers/iio/multiplexer/iio-mux.c
> @@ -21,7 +21,7 @@
>
> struct mux_ext_info_cache {
> char *data;
> - size_t size;
> + ssize_t size;
> };
>
> struct mux_child {
> @@ -206,6 +206,9 @@ static ssize_t mux_write_ext_info(struct iio_dev *indio_dev, uintptr_t private,
> char *new;
> ssize_t ret;
>
> + if (len >= PAGE_SIZE)
> + return -EINVAL;
> +
> ret = iio_mux_select(mux, idx);
> if (ret < 0)
> return ret;
>
[toc] | [prev] | [standalone]
Back to top | Article view | linux.kernel
csiph-web