All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] udlfb: fix some inconsistent NULL checking
@ 2018-10-10 10:36   ` Dan Carpenter
  0 siblings, 0 replies; 4+ messages in thread
From: Dan Carpenter @ 2018-10-10 10:36 UTC (permalink / raw)
  To: Bernie Thompson
  Cc: linux-fbdev, kernel-janitors, dri-devel, Bartlomiej Zolnierkiewicz

In the current kernel, then kzalloc() can't fail for small allocations,
but if it did fail then we would have a NULL dereference in the error
handling.  Also in dlfb_usb_disconnect() if "info" were NULL then it
would cause an Oops inside the unregister_framebuffer() function but it
can't be NULL so let's remove that check.

Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>

diff --git a/drivers/video/fbdev/udlfb.c b/drivers/video/fbdev/udlfb.c
index 070026a7e55a..1d034dddc556 100644
--- a/drivers/video/fbdev/udlfb.c
+++ b/drivers/video/fbdev/udlfb.c
@@ -1598,7 +1598,7 @@ static int dlfb_usb_probe(struct usb_interface *intf,
 	dlfb = kzalloc(sizeof(*dlfb), GFP_KERNEL);
 	if (!dlfb) {
 		dev_err(&intf->dev, "%s: failed to allocate dlfb\n", __func__);
-		goto error;
+		return -ENOMEM;
 	}
 
 	INIT_LIST_HEAD(&dlfb->deferred_free);
@@ -1703,7 +1703,7 @@ static int dlfb_usb_probe(struct usb_interface *intf,
 error:
 	if (dlfb->info) {
 		dlfb_ops_destroy(dlfb->info);
-	} else if (dlfb) {
+	} else {
 		usb_put_dev(dlfb->udev);
 		kfree(dlfb);
 	}
@@ -1730,12 +1730,10 @@ static void dlfb_usb_disconnect(struct usb_interface *intf)
 	/* this function will wait for all in-flight urbs to complete */
 	dlfb_free_urb_list(dlfb);
 
-	if (info) {
-		/* remove udlfb's sysfs interfaces */
-		for (i = 0; i < ARRAY_SIZE(fb_device_attrs); i++)
-			device_remove_file(info->dev, &fb_device_attrs[i]);
-		device_remove_bin_file(info->dev, &edid_attr);
-	}
+	/* remove udlfb's sysfs interfaces */
+	for (i = 0; i < ARRAY_SIZE(fb_device_attrs); i++)
+		device_remove_file(info->dev, &fb_device_attrs[i]);
+	device_remove_bin_file(info->dev, &edid_attr);
 
 	unregister_framebuffer(info);
 }

^ permalink raw reply related	[flat|nested] 4+ messages in thread

* [PATCH] udlfb: fix some inconsistent NULL checking
@ 2018-10-10 10:36   ` Dan Carpenter
  0 siblings, 0 replies; 4+ messages in thread
From: Dan Carpenter @ 2018-10-10 10:36 UTC (permalink / raw)
  To: Bernie Thompson
  Cc: linux-fbdev, kernel-janitors, dri-devel, Bartlomiej Zolnierkiewicz

In the current kernel, then kzalloc() can't fail for small allocations,
but if it did fail then we would have a NULL dereference in the error
handling.  Also in dlfb_usb_disconnect() if "info" were NULL then it
would cause an Oops inside the unregister_framebuffer() function but it
can't be NULL so let's remove that check.

Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>

diff --git a/drivers/video/fbdev/udlfb.c b/drivers/video/fbdev/udlfb.c
index 070026a7e55a..1d034dddc556 100644
--- a/drivers/video/fbdev/udlfb.c
+++ b/drivers/video/fbdev/udlfb.c
@@ -1598,7 +1598,7 @@ static int dlfb_usb_probe(struct usb_interface *intf,
 	dlfb = kzalloc(sizeof(*dlfb), GFP_KERNEL);
 	if (!dlfb) {
 		dev_err(&intf->dev, "%s: failed to allocate dlfb\n", __func__);
-		goto error;
+		return -ENOMEM;
 	}
 
 	INIT_LIST_HEAD(&dlfb->deferred_free);
@@ -1703,7 +1703,7 @@ static int dlfb_usb_probe(struct usb_interface *intf,
 error:
 	if (dlfb->info) {
 		dlfb_ops_destroy(dlfb->info);
-	} else if (dlfb) {
+	} else {
 		usb_put_dev(dlfb->udev);
 		kfree(dlfb);
 	}
@@ -1730,12 +1730,10 @@ static void dlfb_usb_disconnect(struct usb_interface *intf)
 	/* this function will wait for all in-flight urbs to complete */
 	dlfb_free_urb_list(dlfb);
 
-	if (info) {
-		/* remove udlfb's sysfs interfaces */
-		for (i = 0; i < ARRAY_SIZE(fb_device_attrs); i++)
-			device_remove_file(info->dev, &fb_device_attrs[i]);
-		device_remove_bin_file(info->dev, &edid_attr);
-	}
+	/* remove udlfb's sysfs interfaces */
+	for (i = 0; i < ARRAY_SIZE(fb_device_attrs); i++)
+		device_remove_file(info->dev, &fb_device_attrs[i]);
+	device_remove_bin_file(info->dev, &edid_attr);
 
 	unregister_framebuffer(info);
 }
_______________________________________________
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel

^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [PATCH] udlfb: fix some inconsistent NULL checking
  2018-10-10 10:36   ` Dan Carpenter
@ 2018-12-20 15:34     ` Bartlomiej Zolnierkiewicz
  -1 siblings, 0 replies; 4+ messages in thread
From: Bartlomiej Zolnierkiewicz @ 2018-12-20 15:34 UTC (permalink / raw)
  To: Dan Carpenter
  Cc: linux-fbdev, kernel-janitors, Bernie Thompson, dri-devel,
	Mikulas Patocka, Colin Ian King, Wen Yang, Alexey Khoroshilov


[ added Mikulas, Alexey, Colin & Wen to Cc: ]

On 10/10/2018 12:36 PM, Dan Carpenter wrote:
> In the current kernel, then kzalloc() can't fail for small allocations,
> but if it did fail then we would have a NULL dereference in the error
> handling.  Also in dlfb_usb_disconnect() if "info" were NULL then it
> would cause an Oops inside the unregister_framebuffer() function but it
> can't be NULL so let's remove that check.
> 
> Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>

Patch queued for 4.21, thanks (also sorry for the delay).

[ Mikulas, Alexey, Colin & Wen: please verify that there are no known
  issues with udlfb left with this patch applied (thanks!). ]

> diff --git a/drivers/video/fbdev/udlfb.c b/drivers/video/fbdev/udlfb.c
> index 070026a7e55a..1d034dddc556 100644
> --- a/drivers/video/fbdev/udlfb.c
> +++ b/drivers/video/fbdev/udlfb.c
> @@ -1598,7 +1598,7 @@ static int dlfb_usb_probe(struct usb_interface *intf,
>  	dlfb = kzalloc(sizeof(*dlfb), GFP_KERNEL);
>  	if (!dlfb) {
>  		dev_err(&intf->dev, "%s: failed to allocate dlfb\n", __func__);
> -		goto error;
> +		return -ENOMEM;
>  	}
>  
>  	INIT_LIST_HEAD(&dlfb->deferred_free);
> @@ -1703,7 +1703,7 @@ static int dlfb_usb_probe(struct usb_interface *intf,
>  error:
>  	if (dlfb->info) {
>  		dlfb_ops_destroy(dlfb->info);
> -	} else if (dlfb) {
> +	} else {
>  		usb_put_dev(dlfb->udev);
>  		kfree(dlfb);
>  	}
> @@ -1730,12 +1730,10 @@ static void dlfb_usb_disconnect(struct usb_interface *intf)
>  	/* this function will wait for all in-flight urbs to complete */
>  	dlfb_free_urb_list(dlfb);
>  
> -	if (info) {
> -		/* remove udlfb's sysfs interfaces */
> -		for (i = 0; i < ARRAY_SIZE(fb_device_attrs); i++)
> -			device_remove_file(info->dev, &fb_device_attrs[i]);
> -		device_remove_bin_file(info->dev, &edid_attr);
> -	}
> +	/* remove udlfb's sysfs interfaces */
> +	for (i = 0; i < ARRAY_SIZE(fb_device_attrs); i++)
> +		device_remove_file(info->dev, &fb_device_attrs[i]);
> +	device_remove_bin_file(info->dev, &edid_attr);
>  
>  	unregister_framebuffer(info);
>  }

Best regards,
--
Bartlomiej Zolnierkiewicz
Samsung R&D Institute Poland
Samsung Electronics

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH] udlfb: fix some inconsistent NULL checking
@ 2018-12-20 15:34     ` Bartlomiej Zolnierkiewicz
  0 siblings, 0 replies; 4+ messages in thread
From: Bartlomiej Zolnierkiewicz @ 2018-12-20 15:34 UTC (permalink / raw)
  To: Dan Carpenter
  Cc: linux-fbdev, kernel-janitors, Bernie Thompson, dri-devel,
	Mikulas Patocka, Colin Ian King, Wen Yang, Alexey Khoroshilov


[ added Mikulas, Alexey, Colin & Wen to Cc: ]

On 10/10/2018 12:36 PM, Dan Carpenter wrote:
> In the current kernel, then kzalloc() can't fail for small allocations,
> but if it did fail then we would have a NULL dereference in the error
> handling.  Also in dlfb_usb_disconnect() if "info" were NULL then it
> would cause an Oops inside the unregister_framebuffer() function but it
> can't be NULL so let's remove that check.
> 
> Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>

Patch queued for 4.21, thanks (also sorry for the delay).

[ Mikulas, Alexey, Colin & Wen: please verify that there are no known
  issues with udlfb left with this patch applied (thanks!). ]

> diff --git a/drivers/video/fbdev/udlfb.c b/drivers/video/fbdev/udlfb.c
> index 070026a7e55a..1d034dddc556 100644
> --- a/drivers/video/fbdev/udlfb.c
> +++ b/drivers/video/fbdev/udlfb.c
> @@ -1598,7 +1598,7 @@ static int dlfb_usb_probe(struct usb_interface *intf,
>  	dlfb = kzalloc(sizeof(*dlfb), GFP_KERNEL);
>  	if (!dlfb) {
>  		dev_err(&intf->dev, "%s: failed to allocate dlfb\n", __func__);
> -		goto error;
> +		return -ENOMEM;
>  	}
>  
>  	INIT_LIST_HEAD(&dlfb->deferred_free);
> @@ -1703,7 +1703,7 @@ static int dlfb_usb_probe(struct usb_interface *intf,
>  error:
>  	if (dlfb->info) {
>  		dlfb_ops_destroy(dlfb->info);
> -	} else if (dlfb) {
> +	} else {
>  		usb_put_dev(dlfb->udev);
>  		kfree(dlfb);
>  	}
> @@ -1730,12 +1730,10 @@ static void dlfb_usb_disconnect(struct usb_interface *intf)
>  	/* this function will wait for all in-flight urbs to complete */
>  	dlfb_free_urb_list(dlfb);
>  
> -	if (info) {
> -		/* remove udlfb's sysfs interfaces */
> -		for (i = 0; i < ARRAY_SIZE(fb_device_attrs); i++)
> -			device_remove_file(info->dev, &fb_device_attrs[i]);
> -		device_remove_bin_file(info->dev, &edid_attr);
> -	}
> +	/* remove udlfb's sysfs interfaces */
> +	for (i = 0; i < ARRAY_SIZE(fb_device_attrs); i++)
> +		device_remove_file(info->dev, &fb_device_attrs[i]);
> +	device_remove_bin_file(info->dev, &edid_attr);
>  
>  	unregister_framebuffer(info);
>  }

Best regards,
--
Bartlomiej Zolnierkiewicz
Samsung R&D Institute Poland
Samsung Electronics
_______________________________________________
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2018-12-20 15:34 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
     [not found] <CGME20181010103633epcas1p458ccb431c4dfc9e866e274639acc2c65@epcas1p4.samsung.com>
2018-10-10 10:36 ` [PATCH] udlfb: fix some inconsistent NULL checking Dan Carpenter
2018-10-10 10:36   ` Dan Carpenter
2018-12-20 15:34   ` Bartlomiej Zolnierkiewicz
2018-12-20 15:34     ` Bartlomiej Zolnierkiewicz

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.