Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1594425 > unrolled thread

[PATCH] iio: multiplexer: fix unsigned check with less than zero

Started byColin King <colin.king@canonical.com>
First post2017-03-07 17:50 +0100
Last post2017-03-11 19:40 +0100
Articles 3 — 3 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH] iio: multiplexer: fix unsigned check with less than zero Colin King <colin.king@canonical.com> - 2017-03-07 17:50 +0100
    Re: [PATCH] iio: multiplexer: fix unsigned check with less than zero Colin Ian King <colin.king@canonical.com> - 2017-03-08 10:10 +0100
      Re: [PATCH v2] iio: multiplexer: fix unsigned check with less than  zero Jonathan Cameron <jic23@kernel.org> - 2017-03-11 19:40 +0100

#1594425 — [PATCH] iio: multiplexer: fix unsigned check with less than zero

FromColin King <colin.king@canonical.com>
Date2017-03-07 17:50 +0100
Subject[PATCH] iio: multiplexer: fix unsigned check with less than zero
Message-ID<tiqtd-1LM-27@gated-at.bofh.it>
From: Colin Ian King <colin.king@canonical.com>

Comparing a size_t with less than zero is always false as size_t
is unsigned. The intent of the comparison was to check if the size
was -1 (that is, undefined), so use that instead.

Detected by CoverityScan, CID#1415278 ("Unsigned compared against 0")

Signed-off-by: Colin Ian King <colin.king@canonical.com>
---
 drivers/iio/multiplexer/iio-mux.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/iio/multiplexer/iio-mux.c b/drivers/iio/multiplexer/iio-mux.c
index 94d40f9b..6c23033 100644
--- a/drivers/iio/multiplexer/iio-mux.c
+++ b/drivers/iio/multiplexer/iio-mux.c
@@ -61,7 +61,7 @@ static int iio_mux_select(struct mux *mux, int idx)
 
 			cache = &child->ext_info_cache[i];
 
-			if (cache->size < 0)
+			if (cache->size == (size_t)-1)
 				continue;
 
 			ret = iio_write_channel_ext_info(mux->parent, attr,
-- 
2.10.2

[toc] | [next] | [standalone]


#1594964

FromColin Ian King <colin.king@canonical.com>
Date2017-03-08 10:10 +0100
Message-ID<tiFLB-4fF-43@gated-at.bofh.it>
In reply to#1594425
On 08/03/17 08:59, Peter Rosin wrote:
> On 2017-03-07 16:06, Colin King wrote:
>> From: Colin Ian King <colin.king@canonical.com>
>>
>> Comparing a size_t with less than zero is always false as size_t
>> is unsigned. The intent of the comparison was to check if the size
>> was -1 (that is, undefined), so use that instead.
>>
>> Detected by CoverityScan, CID#1415278 ("Unsigned compared against 0")
>>
>> Signed-off-by: Colin Ian King <colin.king@canonical.com>
> 
> Hi!
> 
> Oops, thanks for highlighting this! However, I think I prefer to instead
> change the type of the struct mux_ext_info_cache member 'size' to ssize_t.
> That way, there is no annoying explicit cast. And perhaps add an early
> check
> 
> 	if (len >= PAGE_SIZE)
> 		return -EINVAL;
> 
> to mux_write_ext_info (because the sysfs read function in use for iio ext
> info can't handle more than a page anyway, IIUC). That way it is fairly
> certain that the ssize_t type will always be big enough. :-)

Sounds like a far better solution.

> 
> So, I'm going send out a patch like that instead, unless someone happens to
> beat me to it...
> 
> Cheers,
> peda

Thanks,

Colin
> 
>> ---
>>  drivers/iio/multiplexer/iio-mux.c | 2 +-
>>  1 file changed, 1 insertion(+), 1 deletion(-)
>>
>> diff --git a/drivers/iio/multiplexer/iio-mux.c b/drivers/iio/multiplexer/iio-mux.c
>> index 94d40f9b..6c23033 100644
>> --- a/drivers/iio/multiplexer/iio-mux.c
>> +++ b/drivers/iio/multiplexer/iio-mux.c
>> @@ -61,7 +61,7 @@ static int iio_mux_select(struct mux *mux, int idx)
>>  
>>  			cache = &child->ext_info_cache[i];
>>  
>> -			if (cache->size < 0)
>> +			if (cache->size == (size_t)-1)
>>  				continue;
>>  
>>  			ret = iio_write_channel_ext_info(mux->parent, attr,
>>
> 

[toc] | [prev] | [next] | [standalone]


#1598407 — Re: [PATCH v2] iio: multiplexer: fix unsigned check with less than zero

FromJonathan Cameron <jic23@kernel.org>
Date2017-03-11 19:40 +0100
SubjectRe: [PATCH v2] iio: multiplexer: fix unsigned check with less than zero
Message-ID<tjU5Q-6Jb-17@gated-at.bofh.it>
In reply to#1594964
On 08/03/17 13:28, Peter Rosin wrote:
> Comparing a size_t with less than zero is always false as size_t
> is unsigned. So, change the type of the variable to ssize_t and
> replicate the size check from mux_configure_channel() into
> mux_write_ext_info() thus ensuring that the size will fit in the
> ssize_t variable.
> 
> Detected by CoverityScan, CID#1415278 ("Unsigned compared against 0")
> 
> Reported-by: Colin Ian King <colin.king@canonical.com>
> Signed-off-by: Peter Rosin <peda@axentia.se>
For what it's worth, looks good to me.

Jonathan
> ---
>  drivers/iio/multiplexer/iio-mux.c | 5 ++++-
>  1 file changed, 4 insertions(+), 1 deletion(-)
> 
> Hi!
> 
> Here's what intend to queue up.
> 
> Cheers,
> peda
> 
> diff --git a/drivers/iio/multiplexer/iio-mux.c b/drivers/iio/multiplexer/iio-mux.c
> index 94d40f9b..bab9e69 100644
> --- a/drivers/iio/multiplexer/iio-mux.c
> +++ b/drivers/iio/multiplexer/iio-mux.c
> @@ -21,7 +21,7 @@
>  
>  struct mux_ext_info_cache {
>  	char *data;
> -	size_t size;
> +	ssize_t size;
>  };
>  
>  struct mux_child {
> @@ -206,6 +206,9 @@ static ssize_t mux_write_ext_info(struct iio_dev *indio_dev, uintptr_t private,
>  	char *new;
>  	ssize_t ret;
>  
> +	if (len >= PAGE_SIZE)
> +		return -EINVAL;
> +
>  	ret = iio_mux_select(mux, idx);
>  	if (ret < 0)
>  		return ret;
> 

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web