Thread (11 messages) flat view 11 messages, 3 authors, 2021-03-24

Re: [PATCH] [v2] drm/imx: imx-ldb: fix out of bounds array access warning

From: Joe Perches <joe@perches.com>
Date: 2021-03-24 16:52:56
Also in: dri-devel, lkml

On Wed, 2021-03-24 at 17:42 +0100, Arnd Bergmann wrote:
On Wed, Mar 24, 2021 at 3:20 PM Joe Perches [off-list ref] wrote:
[]
quoted
quoted
diff --git a/drivers/gpu/drm/imx/imx-ldb.c b/drivers/gpu/drm/imx/imx-ldb.c
[]
quoted
@@ -197,6 +197,12 @@ static void imx_ldb_encoder_enable(struct drm_encoder *encoder)
      int dual = ldb->ldb_ctrl & LDB_SPLIT_MODE_EN;
      int mux = drm_of_encoder_active_port_id(imx_ldb_ch->child, encoder);

+     if (mux < 0 || mux >= ARRAY_SIZE(ldb->clk_sel)) {
+             dev_warn(ldb->dev, "%s: invalid mux %d\n",
+                      __func__, ERR_PTR(mux));
This does not compile without warnings.

drivers/gpu/drm/imx/imx-ldb.c: In function ‘imx_ldb_encoder_enable’:
drivers/gpu/drm/imx/imx-ldb.c:201:22: warning: format ‘%d’ expects argument of type ‘int’, but argument 4 has type ‘void *’ [-Wformat=]
  201 |   dev_warn(ldb->dev, "%s: invalid mux %d\n",
      |                      ^~~~~~~~~~~~~~~~~~~~~~

If you want to use ERR_PTR, the %d should be %pe as ERR_PTR
is converting an int a void * to decode the error type and
emit it as a string.
Sorry about that.

I decided against using ERR_PTR() in order to also check for
positive array overflow, but the version I tested was different from
the version I sent.

v3 coming.
Thanks.  No worries.

Up to you, vsprintf would emit the positive mux as a funky hashed
hex value by default if you use ERR_PTR with mux > ARRAY_SIZE so
perhaps %d without the ERR_PTR use makes the most sense.




_______________________________________________
linux-arm-kernel mailing list
linux-arm-kernel@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-arm-kernel
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help