mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH resend] drivers/md: remove null pointer dereference
@ 2008-07-02 19:38 Julia Lawall
  0 siblings, 0 replies; only message in thread
From: Julia Lawall @ 2008-07-02 19:38 UTC (permalink / raw)
  To: agk, dm-devel, linux-kernel, kernel-janitors

From: Julia Lawall <julia@diku.dk>

If pgpath->pg->ps.type is NULL, it is not possible to access its name
field.  Alasdair G Kergon suggested that the field type is actually known
never to be NULL; instead it is its field reinstate_path that is supposed
to be tested.


This problem was found using the following semantic match
(http://www.emn.fr/x-info/coccinelle/)

// <smpl>
@@
expression E, E1;
identifier f;
statement S1,S2,S3;
@@

* if (E == NULL)
{
  ... when != if (E == NULL) S1 else S2
      when != E = E1
* E->f
  ... when any
  return ...;
}
else S3
// </smpl>

Signed-off-by: Julia Lawall <julia@diku.dk>

---

diff -u -p a/drivers/md/dm-mpath.c b/drivers/md/dm-mpath.c
--- a/drivers/md/dm-mpath.c
+++ b/drivers/md/dm-mpath.c
@@ -883,7 +883,7 @@ static int reinstate_path(struct pgpath 
 	if (pgpath->path.is_active)
 		goto out;
 
-	if (!pgpath->pg->ps.type) {
+	if (!pgpath->pg->ps.type->reinstate_path) {
 		DMWARN("Reinstate path not supported by path selector %s",
 		       pgpath->pg->ps.type->name);
 		r = -EINVAL;

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2008-07-02 19:38 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2008-07-02 19:38 [PATCH resend] drivers/md: remove null pointer dereference Julia Lawall

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®