From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751919AbcFWJHG (ORCPT ); Thu, 23 Jun 2016 05:07:06 -0400 Received: from mout.kundenserver.de ([212.227.126.134]:58173 "EHLO mout.kundenserver.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751798AbcFWJHC convert rfc822-to-8bit (ORCPT ); Thu, 23 Jun 2016 05:07:02 -0400 From: Arnd Bergmann To: Ville =?ISO-8859-1?Q?Syrj=E4l=E4?= Cc: Tomi Valkeinen , Jean-Christophe Plagniol-Villard , Ingo Molnar , "Luis R. Rodriguez" , Borislav Petkov , linux-fbdev@vger.kernel.org, linux-kernel@vger.kernel.org Subject: Re: [PATCH] fbdev: atyfb: fix array overflow Date: Thu, 23 Jun 2016 11:06:11 +0200 Message-ID: <4078476.C7oJjrxxdA@wuerfel> User-Agent: KMail/5.1.3 (Linux/4.4.0-22-generic; KDE/5.18.0; x86_64; ; ) In-Reply-To: <20160623002825.GA12365@sci.fi> References: <20160622123822.1262383-1-arnd@arndb.de> <20160623002825.GA12365@sci.fi> MIME-Version: 1.0 Content-Transfer-Encoding: 8BIT Content-Type: text/plain; charset="iso-8859-1" X-Provags-ID: V03:K0:n5ikbycLN9s1V9PoJK7m/T8SAaOTDMIISlRN0JYWGRqEsJ+nyfh 6IRw/8tKhjTyy1ubdARCWj4tddo/etoKeLZD9fUzA+43FNl5NaaoWHpQvHe/aj4OZBU6Bvu rdHuWdpD5CIrZK1Vxb/ePZ//Sze4rh3HL6UhdwB9xr12yDqKqJj0UTSNWlBrRyNbY/hjmlB nEHoZKWeh8781q/kFDBhA== X-UI-Out-Filterresults: notjunk:1;V01:K0:osd6VmO1iBk=:iUI1JQlrnIYwLSbWrIZ3WG LkHqMjppILxLTSKEYAaE9Wf/0Xdv7i4kp2p137a3OcSftY1Mq8r8e8Tm9L4A5J/3nb5DpQMoC 3lK+XknxIGDtrwswSPa4M6TLqW/8sfGcQ+cmpd9sptj5gEHFaRqydDKMUrEVb/XjSua++WLz4 XlNA9A+9enMQTsTb3F23/H3ySCcjOeuRUWgU6n0DUQ/4bghsNNWoUPgXe/ZWXHbs2fmsEYDym 2tQuJVkrYPpwfisCxs8OS7JWsqgeJnRRjMiloaF8fdJuBD2jZZ4R1DEjOAPMrMB2l2uNy9kXI KzcgCdQzmH2u6h7z51/f2Wz/0nr3f62G6ISFrt13TIGQU6Fcmub4jsObYY2Wlx4a0q0nB05Ab 6wrIlu225FPxKhdJ62s3brUtU+0WvCsZqi59reriMYrKoVXL7dyMEwxJApOlwQ3Z2dstu3LMM 7MezeTtWioBVLvJZFWIT4xwW3SDzpqw5lLG3cL0a5O0MBde4ixJXawJAfG/kC0RVyfuHVu9uY uc08QcTf41FKkqEsbdkoOOh6juajI2D9rEGpuuribIyXwsmoiQsTif+4UEFnVOjDFPLVj+2h1 Zk8D7b+AoYoTltWXLIbhgXMSR5GJY1Cj35SylXW/LzyUhY2RGyEdMq/5OBe4HlSiAfJMRy2ws wiry2lgr3vq0qUx9YTCXmJWhG2YpJisC4saWG2fanhSQdDrRoe5tHiyWIgkNfHr+vIRjlDSLT Sf63Who45HHK0Ao8 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Thursday, June 23, 2016 3:28:25 AM CEST Ville Syrjälä wrote: > On Wed, Jun 22, 2016 at 02:37:11PM +0200, Arnd Bergmann wrote: > > When building with CONFIG_UBSAN_SANITIZE_ALL on ARM, I get this > > gcc warning for atyfb: > > > > drivers/video/fbdev/aty/atyfb_base.c: In function 'aty_bl_update_status': > > drivers/video/fbdev/aty/atyfb_base.c:167:33: warning: array subscript is above array bounds [-Warray-bounds] > > drivers/video/fbdev/aty/atyfb_base.c:152:26: warning: array subscript is above array bounds [-Warray-bounds] > > > > Apparently the warning is correct and there is indeed an overflow, > > Nope. All the LCD register indexes on the Rage LT (the only relevant > chip for this code path) should stay below the table size. At least > I can't see any place where we'd walk past the end. I don't understand what you mean: the warning is about LCD_MISC_CNTL, which is defined as 0x14, while the array size is 9 and that is smaller. Is there something more subtle going on than what gcc sees? Arnd