Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1720760 > unrolled thread
| Started by | Christophe JAILLET <christophe.jaillet@wanadoo.fr> |
|---|---|
| First post | 2017-08-27 08:50 +0200 |
| Last post | 2017-08-28 19:20 +0200 |
| Articles | 3 — 2 participants |
Back to article view | Back to linux.kernel
[PATCH] igb: check memory allocation failure Christophe JAILLET <christophe.jaillet@wanadoo.fr> - 2017-08-27 08:50 +0200
Re: [PATCH] igb: check memory allocation failure "Waskiewicz Jr, Peter" <peter.waskiewicz.jr@intel.com> - 2017-08-28 01:10 +0200
Re: [PATCH] igb: check memory allocation failure Christophe JAILLET <christophe.jaillet@wanadoo.fr> - 2017-08-28 19:20 +0200
| From | Christophe JAILLET <christophe.jaillet@wanadoo.fr> |
|---|---|
| Date | 2017-08-27 08:50 +0200 |
| Subject | [PATCH] igb: check memory allocation failure |
| Message-ID | <uiZyq-40C-9@gated-at.bofh.it> |
Check memory allocation failures and return -ENOMEM in such cases, as
already done for other memory allocations in this function.
This avoids NULL pointers dereference.
Signed-off-by: Christophe JAILLET <christophe.jaillet@wanadoo.fr>
---
drivers/net/ethernet/intel/igb/igb_main.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/net/ethernet/intel/igb/igb_main.c b/drivers/net/ethernet/intel/igb/igb_main.c
index fd4a46b03cc8..837d9b46a390 100644
--- a/drivers/net/ethernet/intel/igb/igb_main.c
+++ b/drivers/net/ethernet/intel/igb/igb_main.c
@@ -3162,6 +3162,8 @@ static int igb_sw_init(struct igb_adapter *adapter)
/* Setup and initialize a copy of the hw vlan table array */
adapter->shadow_vfta = kcalloc(E1000_VLAN_FILTER_TBL_SIZE, sizeof(u32),
GFP_ATOMIC);
+ if (!adapter->shadow_vfta)
+ return -ENOMEM;
/* This call may decrease the number of queues */
if (igb_init_interrupt_scheme(adapter, true)) {
--
2.11.0
[toc] | [next] | [standalone]
| From | "Waskiewicz Jr, Peter" <peter.waskiewicz.jr@intel.com> |
|---|---|
| Date | 2017-08-28 01:10 +0200 |
| Message-ID | <ujeQN-5Zx-1@gated-at.bofh.it> |
| In reply to | #1720760 |
On 8/27/17 2:42 AM, Christophe JAILLET wrote: > Check memory allocation failures and return -ENOMEM in such cases, as > already done for other memory allocations in this function. > > This avoids NULL pointers dereference. > > Signed-off-by: Christophe JAILLET <christophe.jaillet@wanadoo.fr> > --- > drivers/net/ethernet/intel/igb/igb_main.c | 2 ++ > 1 file changed, 2 insertions(+) > > diff --git a/drivers/net/ethernet/intel/igb/igb_main.c b/drivers/net/ethernet/intel/igb/igb_main.c > index fd4a46b03cc8..837d9b46a390 100644 > --- a/drivers/net/ethernet/intel/igb/igb_main.c > +++ b/drivers/net/ethernet/intel/igb/igb_main.c > @@ -3162,6 +3162,8 @@ static int igb_sw_init(struct igb_adapter *adapter) > /* Setup and initialize a copy of the hw vlan table array */ > adapter->shadow_vfta = kcalloc(E1000_VLAN_FILTER_TBL_SIZE, sizeof(u32), > GFP_ATOMIC); > + if (!adapter->shadow_vfta) > + return -ENOMEM; Looks reasonable to me. A larger issue though I see in this function is that if we return -ENOMEM here, and if we return -ENOMEM from igb_init_interrupt_scheme() below on failure, we leak adapter->mac_table (and adapter->shadow_vfta in the latter). We should add a proper unwind to free up the memory on failure. -PJ
[toc] | [prev] | [next] | [standalone]
| From | Christophe JAILLET <christophe.jaillet@wanadoo.fr> |
|---|---|
| Date | 2017-08-28 19:20 +0200 |
| Message-ID | <ujvRD-8lV-9@gated-at.bofh.it> |
| In reply to | #1720940 |
Le 28/08/2017 à 01:09, Waskiewicz Jr, Peter a écrit : > On 8/27/17 2:42 AM, Christophe JAILLET wrote: >> Check memory allocation failures and return -ENOMEM in such cases, as >> already done for other memory allocations in this function. >> >> This avoids NULL pointers dereference. >> >> Signed-off-by: Christophe JAILLET <christophe.jaillet@wanadoo.fr> >> --- >> drivers/net/ethernet/intel/igb/igb_main.c | 2 ++ >> 1 file changed, 2 insertions(+) >> >> diff --git a/drivers/net/ethernet/intel/igb/igb_main.c b/drivers/net/ethernet/intel/igb/igb_main.c >> index fd4a46b03cc8..837d9b46a390 100644 >> --- a/drivers/net/ethernet/intel/igb/igb_main.c >> +++ b/drivers/net/ethernet/intel/igb/igb_main.c >> @@ -3162,6 +3162,8 @@ static int igb_sw_init(struct igb_adapter *adapter) >> /* Setup and initialize a copy of the hw vlan table array */ >> adapter->shadow_vfta = kcalloc(E1000_VLAN_FILTER_TBL_SIZE, sizeof(u32), >> GFP_ATOMIC); >> + if (!adapter->shadow_vfta) >> + return -ENOMEM; > Looks reasonable to me. > > A larger issue though I see in this function is that if we return > -ENOMEM here, and if we return -ENOMEM from igb_init_interrupt_scheme() > below on failure, we leak adapter->mac_table (and adapter->shadow_vfta > in the latter). We should add a proper unwind to free up the memory on > failure. > > -PJ > Hi, in fact, there is no leak because the only caller of 'igb_sw_init()' (i.e. 'igb_probe()'), already frees these resources in case of error, see [1] These resources are also freed in 'igb_remove()'. Best reagrds, CJ [1]: https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/tree/drivers/net/ethernet/intel/igb/igb_main.c#n2775
[toc] | [prev] | [standalone]
Back to top | Article view | linux.kernel
csiph-web