2009/10/17 FUJITA Tomonori [off-list ref]:
On Tue, 13 Oct 2009 18:10:17 +0900
Akinobu Mita [off-list ref] wrote:
quoted
My user space testing exposed off-by-one error find_next_zero_area
in iommu-helper. Some zero area cannot be found by this bug.
Subject: [PATCH] Fix off-by-one error in find_next_zero_area
Signed-off-by: Akinobu Mita <akinobu.mita@gmail.com>
---
=A0lib/iommu-helper.c | =A0 =A02 +-
=A01 files changed, 1 insertions(+), 1 deletions(-)
diff --git a/lib/iommu-helper.c b/lib/iommu-helper.c
index 75dbda0..afc58bc 100644
--- a/lib/iommu-helper.c
+++ b/lib/iommu-helper.c
=A0 =A0 =A0 index =3D (index + align_mask) & ~align_mask;
=A0 =A0 =A0 end =3D index + nr;
- =A0 =A0 if (end >=3D size)
+ =A0 =A0 if (end > size)
I think that this is intentional; the last byte of the limit doesn't
work.
It looks ok to me. Without above change, find_next_zero_area cannot
find a 64 bits zeroed area in next sample code.
unsigned long offset;
DECLARE_BITMAP(map, 64);
bitmap_clear(map, 0, 64);
offset =3D find_next_zero_area(map, 64, 0, 64, 0);
if (offset >=3D 64)
printf("not found\n");
else
printf("found\n");