mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH 1/3] regmap: debugfs: Avoid overflows for very small reads
@ 2012-12-10 16:25 Mark Brown
  2012-12-10 16:25 ` [PATCH 2/3] regmap: debugfs: Factor out initial seek Mark Brown
  2012-12-10 16:25 ` [PATCH 3/3] regmap: debugfs: Cache offsets of valid regions for dump Mark Brown
  0 siblings, 2 replies; 3+ messages in thread
From: Mark Brown @ 2012-12-10 16:25 UTC (permalink / raw)
  To: linux-kernel; +Cc: Mark Brown

If count is less than the size of a register then we may hit integer
wraparound when trying to move backwards to check if we're still in
the buffer. Instead move the position forwards to check if it's still
in the buffer, we are unlikely to be able to allocate a buffer
sufficiently big to overflow here.

Signed-off-by: Mark Brown <broonie@opensource.wolfsonmicro.com>
---
 drivers/base/regmap/regmap-debugfs.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/base/regmap/regmap-debugfs.c b/drivers/base/regmap/regmap-debugfs.c
index 00fbd58..3df274e 100644
--- a/drivers/base/regmap/regmap-debugfs.c
+++ b/drivers/base/regmap/regmap-debugfs.c
@@ -93,7 +93,7 @@ static ssize_t regmap_read_debugfs(struct regmap *map, unsigned int from,
 		/* If we're in the region the user is trying to read */
 		if (p >= *ppos) {
 			/* ...but not beyond it */
-			if (buf_pos >= count - 1 - map->debugfs_tot_len)
+			if (buf_pos + 1 + map->debugfs_tot_len >= count)
 				break;
 
 			/* Format the register */
-- 
1.7.10.4


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2012-12-10 16:25 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2012-12-10 16:25 [PATCH 1/3] regmap: debugfs: Avoid overflows for very small reads Mark Brown
2012-12-10 16:25 ` [PATCH 2/3] regmap: debugfs: Factor out initial seek Mark Brown
2012-12-10 16:25 ` [PATCH 3/3] regmap: debugfs: Cache offsets of valid regions for dump Mark Brown

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®