@@ -758,66 +758,66 @@ int rndis_filter_open(struct hv_device *dev)intrndis_filter_close(structhv_device*dev){-structnetvsc_device*netDevice=hv_get_drvdata(dev);+structnetvsc_device*nvdev=hv_get_drvdata(dev);-if(!netDevice)+if(!nvdev)return-EINVAL;-returnrndis_filter_close_device(netDevice->extension);+returnrndis_filter_close_device(nvdev->extension);}intrndis_filter_send(structhv_device*dev,structhv_netvsc_packet*pkt){intret;-structrndis_filter_packet*filterPacket;-structrndis_message*rndisMessage;-structrndis_packet*rndisPacket;-u32rndisMessageSize;+structrndis_filter_packet*filter_pkt;+structrndis_message*rndis_msg;+structrndis_packet*rndis_pkt;+u32rndis_msg_size;/* Add the rndis header */-filterPacket=(structrndis_filter_packet*)pkt->extension;+filter_pkt=(structrndis_filter_packet*)pkt->extension;-memset(filterPacket,0,sizeof(structrndis_filter_packet));+memset(filter_pkt,0,sizeof(structrndis_filter_packet));-rndisMessage=&filterPacket->msg;-rndisMessageSize=RNDIS_MESSAGE_SIZE(structrndis_packet);+rndis_msg=&filter_pkt->msg;+rndis_msg_size=RNDIS_MESSAGE_SIZE(structrndis_packet);-rndisMessage->ndis_msg_type=REMOTE_NDIS_PACKET_MSG;-rndisMessage->msg_len=pkt->total_data_buflen+-rndisMessageSize;+rndis_msg->ndis_msg_type=REMOTE_NDIS_PACKET_MSG;+rndis_msg->msg_len=pkt->total_data_buflen++rndis_msg_size;-rndisPacket=&rndisMessage->msg.pkt;-rndisPacket->data_offset=sizeof(structrndis_packet);-rndisPacket->data_len=pkt->total_data_buflen;+rndis_pkt=&rndis_msg->msg.pkt;+rndis_pkt->data_offset=sizeof(structrndis_packet);+rndis_pkt->data_len=pkt->total_data_buflen;pkt->is_data_pkt=true;-pkt->page_buf[0].pfn=virt_to_phys(rndisMessage)>>PAGE_SHIFT;+pkt->page_buf[0].pfn=virt_to_phys(rndis_msg)>>PAGE_SHIFT;pkt->page_buf[0].offset=-(unsignedlong)rndisMessage&(PAGE_SIZE-1);-pkt->page_buf[0].len=rndisMessageSize;+(unsignedlong)rndis_msg&(PAGE_SIZE-1);+pkt->page_buf[0].len=rndis_msg_size;/* Add one page_buf if the rndis msg goes beyond page boundary */-if(pkt->page_buf[0].offset+rndisMessageSize>PAGE_SIZE){+if(pkt->page_buf[0].offset+rndis_msg_size>PAGE_SIZE){inti;for(i=pkt->page_buf_cnt;i>1;i--)pkt->page_buf[i]=pkt->page_buf[i-1];pkt->page_buf_cnt++;pkt->page_buf[0].len=PAGE_SIZE-pkt->page_buf[0].offset;pkt->page_buf[1].pfn=virt_to_phys((void*)((ulong)-rndisMessage+pkt->page_buf[0].len))>>PAGE_SHIFT;+rndis_msg+pkt->page_buf[0].len))>>PAGE_SHIFT;pkt->page_buf[1].offset=0;-pkt->page_buf[1].len=rndisMessageSize-pkt->page_buf[0].len;+pkt->page_buf[1].len=rndis_msg_size-pkt->page_buf[0].len;}/* Save the packet send completion and context */-filterPacket->completion=pkt->completion.send.send_completion;-filterPacket->completion_ctx=+filter_pkt->completion=pkt->completion.send.send_completion;+filter_pkt->completion_ctx=pkt->completion.send.send_completion_ctx;/* Use ours */pkt->completion.send.send_completion=rndis_filter_send_completion;-pkt->completion.send.send_completion_ctx=filterPacket;+pkt->completion.send.send_completion_ctx=filter_pkt;ret=netvsc_send(dev,pkt);if(ret!=0){
@@ -826,9 +826,9 @@ int rndis_filter_send(struct hv_device *dev,*above*/pkt->completion.send.send_completion=-filterPacket->completion;+filter_pkt->completion;pkt->completion.send.send_completion_ctx=-filterPacket->completion_ctx;+filter_pkt->completion_ctx;}returnret;
@@ -836,10 +836,10 @@ int rndis_filter_send(struct hv_device *dev,staticvoidrndis_filter_send_completion(void*ctx){-structrndis_filter_packet*filterPacket=ctx;+structrndis_filter_packet*filter_pkt=ctx;/* Pass it back to the original handler */-filterPacket->completion(filterPacket->completion_ctx);+filter_pkt->completion(filter_pkt->completion_ctx);}
The first assignment to variable "net" is wrong, but overridden by the
latter assignments. So the bug isn't manifested.
Signed-off-by: Haiyang Zhang <haiyangz@microsoft.com>
Signed-off-by: K. Y. Srinivasan <kys@microsoft.com>
---
drivers/net/hyperv/netvsc_drv.c | 7 ++-----
1 files changed, 2 insertions(+), 5 deletions(-)
The memory has been allocated by kzalloc, so it's unnecessary to memset
again.
Signed-off-by: Haiyang Zhang <haiyangz@microsoft.com>
Signed-off-by: K. Y. Srinivasan <kys@microsoft.com>
---
drivers/net/hyperv/rndis_filter.c | 2 --
1 files changed, 0 insertions(+), 2 deletions(-)
@@ -758,66 +758,66 @@ int rndis_filter_open(struct hv_device *dev)intrndis_filter_close(structhv_device*dev){-structnetvsc_device*netDevice=hv_get_drvdata(dev);+structnetvsc_device*nvdev=hv_get_drvdata(dev);-if(!netDevice)+if(!nvdev)return-EINVAL;-returnrndis_filter_close_device(netDevice->extension);+returnrndis_filter_close_device(nvdev->extension);}intrndis_filter_send(structhv_device*dev,structhv_netvsc_packet*pkt){intret;-structrndis_filter_packet*filterPacket;-structrndis_message*rndisMessage;-structrndis_packet*rndisPacket;-u32rndisMessageSize;+structrndis_filter_packet*filter_pkt;+structrndis_message*rndis_msg;+structrndis_packet*rndis_pkt;+u32rndis_msg_size;/* Add the rndis header */-filterPacket=(structrndis_filter_packet*)pkt->extension;+filter_pkt=(structrndis_filter_packet*)pkt->extension;-memset(filterPacket,0,sizeof(structrndis_filter_packet));+memset(filter_pkt,0,sizeof(structrndis_filter_packet));-rndisMessage=&filterPacket->msg;-rndisMessageSize=RNDIS_MESSAGE_SIZE(structrndis_packet);+rndis_msg=&filter_pkt->msg;+rndis_msg_size=RNDIS_MESSAGE_SIZE(structrndis_packet);-rndisMessage->ndis_msg_type=REMOTE_NDIS_PACKET_MSG;-rndisMessage->msg_len=pkt->total_data_buflen+-rndisMessageSize;+rndis_msg->ndis_msg_type=REMOTE_NDIS_PACKET_MSG;+rndis_msg->msg_len=pkt->total_data_buflen++rndis_msg_size;-rndisPacket=&rndisMessage->msg.pkt;-rndisPacket->data_offset=sizeof(structrndis_packet);-rndisPacket->data_len=pkt->total_data_buflen;+rndis_pkt=&rndis_msg->msg.pkt;+rndis_pkt->data_offset=sizeof(structrndis_packet);+rndis_pkt->data_len=pkt->total_data_buflen;pkt->is_data_pkt=true;-pkt->page_buf[0].pfn=virt_to_phys(rndisMessage)>>PAGE_SHIFT;+pkt->page_buf[0].pfn=virt_to_phys(rndis_msg)>>PAGE_SHIFT;pkt->page_buf[0].offset=-(unsignedlong)rndisMessage&(PAGE_SIZE-1);-pkt->page_buf[0].len=rndisMessageSize;+(unsignedlong)rndis_msg&(PAGE_SIZE-1);+pkt->page_buf[0].len=rndis_msg_size;/* Add one page_buf if the rndis msg goes beyond page boundary */-if(pkt->page_buf[0].offset+rndisMessageSize>PAGE_SIZE){+if(pkt->page_buf[0].offset+rndis_msg_size>PAGE_SIZE){inti;for(i=pkt->page_buf_cnt;i>1;i--)pkt->page_buf[i]=pkt->page_buf[i-1];pkt->page_buf_cnt++;pkt->page_buf[0].len=PAGE_SIZE-pkt->page_buf[0].offset;pkt->page_buf[1].pfn=virt_to_phys((void*)((ulong)-rndisMessage+pkt->page_buf[0].len))>>PAGE_SHIFT;+rndis_msg+pkt->page_buf[0].len))>>PAGE_SHIFT;pkt->page_buf[1].offset=0;-pkt->page_buf[1].len=rndisMessageSize-pkt->page_buf[0].len;+pkt->page_buf[1].len=rndis_msg_size-pkt->page_buf[0].len;}/* Save the packet send completion and context */-filterPacket->completion=pkt->completion.send.send_completion;-filterPacket->completion_ctx=+filter_pkt->completion=pkt->completion.send.send_completion;+filter_pkt->completion_ctx=pkt->completion.send.send_completion_ctx;/* Use ours */pkt->completion.send.send_completion=rndis_filter_send_completion;-pkt->completion.send.send_completion_ctx=filterPacket;+pkt->completion.send.send_completion_ctx=filter_pkt;ret=netvsc_send(dev,pkt);if(ret!=0){
@@ -826,9 +826,9 @@ int rndis_filter_send(struct hv_device *dev,*above*/pkt->completion.send.send_completion=-filterPacket->completion;+filter_pkt->completion;pkt->completion.send.send_completion_ctx=-filterPacket->completion_ctx;+filter_pkt->completion_ctx;}returnret;
@@ -836,10 +836,10 @@ int rndis_filter_send(struct hv_device *dev,staticvoidrndis_filter_send_completion(void*ctx){-structrndis_filter_packet*filterPacket=ctx;+structrndis_filter_packet*filter_pkt=ctx;/* Pass it back to the original handler */-filterPacket->completion(filterPacket->completion_ctx);+filter_pkt->completion(filter_pkt->completion_ctx);}
The first assignment to variable "net" is wrong, but overridden by the
latter assignments. So the bug isn't manifested.
Signed-off-by: Haiyang Zhang <haiyangz@microsoft.com>
Signed-off-by: K. Y. Srinivasan <kys@microsoft.com>
The memory has been allocated by kzalloc, so it's unnecessary to memset
again.
Signed-off-by: Haiyang Zhang <haiyangz@microsoft.com>
Signed-off-by: K. Y. Srinivasan <kys@microsoft.com>