mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] hwmon: scmi: Fix info[] allocation type
@ 2026-09-17 21:13 Kees Cook
  0 siblings, 0 replies; only message in thread
From: Kees Cook @ 2026-09-17 21:13 UTC (permalink / raw)
  To: Sudeep Holla
  Cc: Kees Cook, Kees Cook, Cristian Marussi, Guenter Roeck, arm-scmi,
	linux-arm-kernel, linux-hwmon, linux-kernel, linux-hardening

From: Kees Cook <kees+treewide@kernel.org>

In preparation for making the devm_kmalloc family of allocators type
aware, we need to make sure that the returned type from the allocation
matches the type of the variable being assigned. (Before, the allocator
would always return "void *", which can be implicitly cast to any
pointer type.)

The assigned type of "scmi_sensors->info[type]" is
"const struct scmi_sensor_info **", but the converted allocation type
would be "const struct scmi_sensor_info ***", as the size was taken from
"*scmi_sensors->info", which is one level of indirection too many.
Luckily both element types are pointers of the same size. Take the size
from the element type of the assignment target.

Build tested ARCH=x86_64 allmodconfig with GCC 16.2.0:
drivers/hwmon/scmi-hwmon.o

Assisted-by: LLM coccinelle
Signed-off-by: Kees Cook <kees+treewide@kernel.org>
---
Cc: Sudeep Holla <sudeep.holla@kernel.org>
Cc: Cristian Marussi <cristian.marussi@arm.com>
Cc: Guenter Roeck <linux@roeck-us.net>
Cc: <arm-scmi@vger.kernel.org>
Cc: <linux-arm-kernel@lists.infradead.org>
Cc: <linux-hwmon@vger.kernel.org>
---
 drivers/hwmon/scmi-hwmon.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/hwmon/scmi-hwmon.c b/drivers/hwmon/scmi-hwmon.c
index eec223d174c0..9ae8f774297e 100644
--- a/drivers/hwmon/scmi-hwmon.c
+++ b/drivers/hwmon/scmi-hwmon.c
@@ -305,7 +305,8 @@ static int scmi_hwmon_probe(struct scmi_device *sdev)
 
 		scmi_sensors->info[type] =
 			devm_kcalloc(dev, nr_count[type],
-				     sizeof(*scmi_sensors->info), GFP_KERNEL);
+				     sizeof(*scmi_sensors->info[type]),
+				     GFP_KERNEL);
 		if (!scmi_sensors->info[type])
 			return -ENOMEM;
 	}
-- 
2.34.1


^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-17 21:13 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-17 21:13 [PATCH] hwmon: scmi: Fix info[] allocation type Kees Cook

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®