[PATCH] rtc: sun6i: Use struct_size() in kzalloc()

Subsystems: real time clock (rtc) subsystem, the rest

STALE2896d

5 messages, 3 authors, 2018-08-27 · open the first message on its own page

[PATCH] rtc: sun6i: Use struct_size() in kzalloc()

From: Gustavo A. R. Silva <hidden>
Date: 2018-08-23 18:52:31

One of the more common cases of allocation size calculations is finding
the size of a structure that has a zero-sized array at the end, along
with memory for some number of elements for that array. For example:

struct foo { 
	int stuff;
        void *entry[];
};

instance = kzalloc(sizeof(struct foo) + sizeof(void *) * count, GFP_KERNEL);

Instead of leaving these open-coded and prone to type mistakes, we can
now use the new struct_size() helper:

instance = kzalloc(struct_size(instance, entry, count), GFP_KERNEL);

Signed-off-by: Gustavo A. R. Silva <redacted>
---
 drivers/rtc/rtc-sun6i.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/rtc/rtc-sun6i.c b/drivers/rtc/rtc-sun6i.c
index 2cd5a7b..fe07310 100644
--- a/drivers/rtc/rtc-sun6i.c
+++ b/drivers/rtc/rtc-sun6i.c
@@ -199,8 +199,7 @@ static void __init sun6i_rtc_clk_init(struct device_node *node)
 	if (!rtc)
 		return;
 
-	clk_data = kzalloc(sizeof(*clk_data) + (sizeof(*clk_data->hws) * 2),
-			   GFP_KERNEL);
+	clk_data = kzalloc(struct_size(clk_data, hws, 2), GFP_KERNEL);
 	if (!clk_data) {
 		kfree(rtc);
 		return;
-- 
2.7.4

Re: [PATCH] rtc: sun6i: Use struct_size() in kzalloc()

From: Kees Cook <hidden>
Date: 2018-08-23 20:56:43

On Thu, Aug 23, 2018 at 11:51 AM, Gustavo A. R. Silva
[off-list ref] wrote:
quoted hunk
One of the more common cases of allocation size calculations is finding
the size of a structure that has a zero-sized array at the end, along
with memory for some number of elements for that array. For example:

struct foo {
        int stuff;
        void *entry[];
};

instance = kzalloc(sizeof(struct foo) + sizeof(void *) * count, GFP_KERNEL);

Instead of leaving these open-coded and prone to type mistakes, we can
now use the new struct_size() helper:

instance = kzalloc(struct_size(instance, entry, count), GFP_KERNEL);

Signed-off-by: Gustavo A. R. Silva <redacted>
---
 drivers/rtc/rtc-sun6i.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/rtc/rtc-sun6i.c b/drivers/rtc/rtc-sun6i.c
index 2cd5a7b..fe07310 100644
--- a/drivers/rtc/rtc-sun6i.c
+++ b/drivers/rtc/rtc-sun6i.c
@@ -199,8 +199,7 @@ static void __init sun6i_rtc_clk_init(struct device_node *node)
        if (!rtc)
                return;

-       clk_data = kzalloc(sizeof(*clk_data) + (sizeof(*clk_data->hws) * 2),
-                          GFP_KERNEL);
+       clk_data = kzalloc(struct_size(clk_data, hws, 2), GFP_KERNEL);
        if (!clk_data) {
                kfree(rtc);
                return;
This looks like entirely correct to me, but I'm surprised the
Coccinelle script didn't discover this. I guess the isomorphisms don't
cover the parenthesis?

-Kees

-- 
Kees Cook
Pixel Security

Re: [PATCH] rtc: sun6i: Use struct_size() in kzalloc()

From: Gustavo A. R. Silva <hidden>
Date: 2018-08-23 22:01:31


On 8/23/18 3:56 PM, Kees Cook wrote:
quoted
-       clk_data = kzalloc(sizeof(*clk_data) + (sizeof(*clk_data->hws) * 2),
-                          GFP_KERNEL);
+       clk_data = kzalloc(struct_size(clk_data, hws, 2), GFP_KERNEL);
        if (!clk_data) {
                kfree(rtc);
                return;
This looks like entirely correct to me, but I'm surprised the
Coccinelle script didn't discover this. I guess the isomorphisms don't
cover the parenthesis?
Apparently.

If I manually remove the ()s, the cocci script successfully generates a patch.

--
Gustavo

Re: [PATCH] rtc: sun6i: Use struct_size() in kzalloc()

From: Kees Cook <hidden>
Date: 2018-08-23 21:57:04

On Thu, Aug 23, 2018 at 11:51 AM, Gustavo A. R. Silva
[off-list ref] wrote:
quoted hunk
One of the more common cases of allocation size calculations is finding
the size of a structure that has a zero-sized array at the end, along
with memory for some number of elements for that array. For example:

struct foo {
        int stuff;
        void *entry[];
};

instance = kzalloc(sizeof(struct foo) + sizeof(void *) * count, GFP_KERNEL);

Instead of leaving these open-coded and prone to type mistakes, we can
now use the new struct_size() helper:

instance = kzalloc(struct_size(instance, entry, count), GFP_KERNEL);

Signed-off-by: Gustavo A. R. Silva <redacted>
---
 drivers/rtc/rtc-sun6i.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/rtc/rtc-sun6i.c b/drivers/rtc/rtc-sun6i.c
index 2cd5a7b..fe07310 100644
--- a/drivers/rtc/rtc-sun6i.c
+++ b/drivers/rtc/rtc-sun6i.c
@@ -199,8 +199,7 @@ static void __init sun6i_rtc_clk_init(struct device_node *node)
        if (!rtc)
                return;

-       clk_data = kzalloc(sizeof(*clk_data) + (sizeof(*clk_data->hws) * 2),
-                          GFP_KERNEL);
+       clk_data = kzalloc(struct_size(clk_data, hws, 2), GFP_KERNEL);
        if (!clk_data) {
                kfree(rtc);
                return;
Reviewed-by: Kees Cook <redacted>

-Kees

-- 
Kees Cook
Pixel Security

Re: [PATCH] rtc: sun6i: Use struct_size() in kzalloc()

From: Alexandre Belloni <alexandre.belloni@bootlin.com>
Date: 2018-08-27 21:02:47

On 23/08/2018 13:51:40-0500, Gustavo A. R. Silva wrote:
One of the more common cases of allocation size calculations is finding
the size of a structure that has a zero-sized array at the end, along
with memory for some number of elements for that array. For example:

struct foo { 
	int stuff;
        void *entry[];
};

instance = kzalloc(sizeof(struct foo) + sizeof(void *) * count, GFP_KERNEL);

Instead of leaving these open-coded and prone to type mistakes, we can
now use the new struct_size() helper:

instance = kzalloc(struct_size(instance, entry, count), GFP_KERNEL);

Signed-off-by: Gustavo A. R. Silva <redacted>
---
 drivers/rtc/rtc-sun6i.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)
Applied, thanks.

-- 
Alexandre Belloni, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help