mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] iio: imu: st_lsm6dsx: Allocate ext_channels with ARRAY_SIZE()
@ 2026-09-17 21:13 Kees Cook
  2026-09-18  6:40 ` Lorenzo Bianconi
  0 siblings, 1 reply; 2+ messages in thread
From: Kees Cook @ 2026-09-17 21:13 UTC (permalink / raw)
  To: Lorenzo Bianconi
  Cc: Kees Cook, Kees Cook, Jonathan Cameron, David Lechner,
	Nuno Sá,
	Andy Shevchenko, linux-iio, linux-kernel, linux-hardening

From: Kees Cook <kees+treewide@kernel.org>

In preparation for making the devm_kmalloc family of allocators type
aware, we need to make sure that the returned type from the allocation
matches the type of the variable being assigned. (Before, the allocator
would always return "void *", which can be implicitly cast to any
pointer type.)

This is allocating a copy of magn_channels, which is an array of struct
iio_chan_spec, but the size was taken from the whole array, which would
make the allocation type a pointer to the array rather than the
"struct iio_chan_spec *" being assigned. Allocate ARRAY_SIZE-many
entries instead. The resulting allocation size is the same.

Build tested ARCH=x86_64 allmodconfig with GCC 16.2.0:
drivers/iio/imu/st_lsm6dsx/st_lsm6dsx_shub.o

Assisted-by: LLM coccinelle
Signed-off-by: Kees Cook <kees+treewide@kernel.org>
---
Cc: Lorenzo Bianconi <lorenzo@kernel.org>
Cc: Jonathan Cameron <jic23@kernel.org>
Cc: David Lechner <dlechner@baylibre.com>
Cc: "Nuno Sá" <nuno.sa@analog.com>
Cc: Andy Shevchenko <andy@kernel.org>
Cc: <linux-iio@vger.kernel.org>
---
 drivers/iio/imu/st_lsm6dsx/st_lsm6dsx_shub.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/iio/imu/st_lsm6dsx/st_lsm6dsx_shub.c b/drivers/iio/imu/st_lsm6dsx/st_lsm6dsx_shub.c
index d6a1eeb151ca..cbc47fa5b101 100644
--- a/drivers/iio/imu/st_lsm6dsx/st_lsm6dsx_shub.c
+++ b/drivers/iio/imu/st_lsm6dsx/st_lsm6dsx_shub.c
@@ -766,8 +766,8 @@ st_lsm6dsx_shub_alloc_iiodev(struct st_lsm6dsx_hw *hw,
 			IIO_CHAN_SOFT_TIMESTAMP(3),
 		};
 
-		ext_channels = devm_kzalloc(hw->dev, sizeof(magn_channels),
-					    GFP_KERNEL);
+		ext_channels = devm_kcalloc(hw->dev, ARRAY_SIZE(magn_channels),
+					    sizeof(*ext_channels), GFP_KERNEL);
 		if (!ext_channels)
 			return NULL;
 
-- 
2.34.1


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH] iio: imu: st_lsm6dsx: Allocate ext_channels with ARRAY_SIZE()
  2026-09-17 21:13 [PATCH] iio: imu: st_lsm6dsx: Allocate ext_channels with ARRAY_SIZE() Kees Cook
@ 2026-09-18  6:40 ` Lorenzo Bianconi
  0 siblings, 0 replies; 2+ messages in thread
From: Lorenzo Bianconi @ 2026-09-18  6:40 UTC (permalink / raw)
  To: Kees Cook
  Cc: Kees Cook, Jonathan Cameron, David Lechner, Nuno Sá,
	Andy Shevchenko, linux-iio, linux-kernel, linux-hardening

[-- Attachment #1: Type: text/plain, Size: 2007 bytes --]

> From: Kees Cook <kees+treewide@kernel.org>
> 
> In preparation for making the devm_kmalloc family of allocators type
> aware, we need to make sure that the returned type from the allocation
> matches the type of the variable being assigned. (Before, the allocator
> would always return "void *", which can be implicitly cast to any
> pointer type.)
> 
> This is allocating a copy of magn_channels, which is an array of struct
> iio_chan_spec, but the size was taken from the whole array, which would
> make the allocation type a pointer to the array rather than the
> "struct iio_chan_spec *" being assigned. Allocate ARRAY_SIZE-many
> entries instead. The resulting allocation size is the same.
> 
> Build tested ARCH=x86_64 allmodconfig with GCC 16.2.0:
> drivers/iio/imu/st_lsm6dsx/st_lsm6dsx_shub.o
> 
> Assisted-by: LLM coccinelle
> Signed-off-by: Kees Cook <kees+treewide@kernel.org>

Acked-by: Lorenzo Bianconi <lorenzo@kernel.org>

> ---
> Cc: Lorenzo Bianconi <lorenzo@kernel.org>
> Cc: Jonathan Cameron <jic23@kernel.org>
> Cc: David Lechner <dlechner@baylibre.com>
> Cc: "Nuno Sá" <nuno.sa@analog.com>
> Cc: Andy Shevchenko <andy@kernel.org>
> Cc: <linux-iio@vger.kernel.org>
> ---
>  drivers/iio/imu/st_lsm6dsx/st_lsm6dsx_shub.c | 4 ++--
>  1 file changed, 2 insertions(+), 2 deletions(-)
> 
> diff --git a/drivers/iio/imu/st_lsm6dsx/st_lsm6dsx_shub.c b/drivers/iio/imu/st_lsm6dsx/st_lsm6dsx_shub.c
> index d6a1eeb151ca..cbc47fa5b101 100644
> --- a/drivers/iio/imu/st_lsm6dsx/st_lsm6dsx_shub.c
> +++ b/drivers/iio/imu/st_lsm6dsx/st_lsm6dsx_shub.c
> @@ -766,8 +766,8 @@ st_lsm6dsx_shub_alloc_iiodev(struct st_lsm6dsx_hw *hw,
>  			IIO_CHAN_SOFT_TIMESTAMP(3),
>  		};
>  
> -		ext_channels = devm_kzalloc(hw->dev, sizeof(magn_channels),
> -					    GFP_KERNEL);
> +		ext_channels = devm_kcalloc(hw->dev, ARRAY_SIZE(magn_channels),
> +					    sizeof(*ext_channels), GFP_KERNEL);
>  		if (!ext_channels)
>  			return NULL;
>  
> -- 
> 2.34.1
> 

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 228 bytes --]

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-18  6:40 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-17 21:13 [PATCH] iio: imu: st_lsm6dsx: Allocate ext_channels with ARRAY_SIZE() Kees Cook
2026-09-18  6:40 ` Lorenzo Bianconi

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®