* [Patch] Negative index in drivers/usb/host/isp116x-hcd.c
@ 2006-05-31 22:33 Eric Sesterhenn
0 siblings, 0 replies; only message in thread
From: Eric Sesterhenn @ 2006-05-31 22:33 UTC (permalink / raw)
To: ok; +Cc: linux-usb-devel, linux-kernel
hi,
This fixes coverity Bug #390.
With the following code
ret = ep->branch = balance(isp116x, ep->period, ep->load);
if (ret < 0)
goto fail;
the problem is that ret and balance are of the type int, and ep->branch is u16.
so the int balance() returns gets reduced to u16 and then converted to an int again,
which removes the sign. Maybe the following little c program can explain it better:
----snip----
int foo() {
return -5;
}
int main(int argc, char **argv) {
int a;
unsigned short b;
a = b = foo();
if (a < 0)
puts("case 1 works\n");
b = a = foo();
if (a < 0 )
puts("case 2 works\n");
}
----snip----
only the case 2 output is visible.
Signed-off-by: Eric Sesterhenn <snakebyte@gmx.de>
--- linux-2.6.17-rc5/drivers/usb/host/isp116x-hcd.c.orig 2006-06-01 00:25:32.000000000 +0200
+++ linux-2.6.17-rc5/drivers/usb/host/isp116x-hcd.c 2006-06-01 00:26:18.000000000 +0200
@@ -781,7 +781,7 @@ static int isp116x_urb_enqueue(struct us
if (ep->branch < PERIODIC_SIZE)
break;
- ret = ep->branch = balance(isp116x, ep->period, ep->load);
+ ep->branch = ret = balance(isp116x, ep->period, ep->load);
if (ret < 0)
goto fail;
ret = 0;
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2006-05-31 22:33 UTC | newest]
Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2006-05-31 22:33 [Patch] Negative index in drivers/usb/host/isp116x-hcd.c Eric Sesterhenn
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®