From: Krzysztof Kozlowski <krzk@kernel.org>
To: Aleksandr Mishin <amishin@t-argos.ru>,
Samuel Ortiz <sameo@linux.intel.com>
Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org,
lvc-project@linuxtesting.org
Subject: Re: [PATCH] nfc: pn533: Add poll mod list filling check
Date: Wed, 3 Jul 2024 07:02:40 +0200 [thread overview]
Message-ID: <d146fb2c-50bb-4339-b330-155f22879446@kernel.org> (raw)
In-Reply-To: <20240702093924.12092-1-amishin@t-argos.ru>
On 02/07/2024 11:39, Aleksandr Mishin wrote:
> In case of im_protocols value is 1 and tm_protocols value is 0 this
Which im protocol has value 1 in the mask?
The pn533_poll_create_mod_list() handles all possible masks, so your
case is just not possible to happen.
This patch is purely to satisfy (your) static analyzers, so this should
be clear in commit msg. You are not fixing any bug but adding sort of
defensive code and suppresion of false-positive warning...
> combination successfully passes the check
> 'if (!im_protocols && !tm_protocols)' in the nfc_start_poll().
> But then after pn533_poll_create_mod_list() call in pn533_start_poll()
> poll mod list will remain empty and dev->poll_mod_count will remain 0
> which lead to division by zero.
>
> Add poll mod list filling check.
>
> Found by Linux Verification Center (linuxtesting.org) with SVACE.
>
> Fixes: dfccd0f58044 ("NFC: pn533: Add some polling entropy")
> Signed-off-by: Aleksandr Mishin <amishin@t-argos.ru>
> ---
> drivers/nfc/pn533/pn533.c | 5 +++++
> 1 file changed, 5 insertions(+)
>
> diff --git a/drivers/nfc/pn533/pn533.c b/drivers/nfc/pn533/pn533.c
> index b19c39dcfbd9..e2bc67300a91 100644
> --- a/drivers/nfc/pn533/pn533.c
> +++ b/drivers/nfc/pn533/pn533.c
> @@ -1723,6 +1723,11 @@ static int pn533_start_poll(struct nfc_dev *nfc_dev,
> }
>
> pn533_poll_create_mod_list(dev, im_protocols, tm_protocols);
> + if (!dev->poll_mod_count) {
> + nfc_err(dev->dev,
> + "Poll mod list is empty\n");
Odd wrapping.
> + return -EINVAL;
> + }
>
> /* Do not always start polling from the same modulation */
> get_random_bytes(&rand_mod, sizeof(rand_mod));
Best regards,
Krzysztof
next prev parent reply other threads:[~2024-07-03 5:02 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-07-02 9:39 Aleksandr Mishin
2024-07-03 5:02 ` Krzysztof Kozlowski [this message]
2024-07-03 7:26 ` Aleksandr Mishin
2024-07-04 12:07 ` Krzysztof Kozlowski
2024-08-05 8:47 ` [lvc-project] " Fedor Pchelkin
2024-08-27 8:48 ` [PATCH v2] " Aleksandr Mishin
2024-08-29 8:26 ` Paolo Abeni
2024-08-29 8:30 ` Paolo Abeni
2024-08-29 9:06 ` Krzysztof Kozlowski
2024-08-29 9:33 ` Paolo Abeni
2024-08-29 9:34 ` Paolo Abeni
2024-08-29 10:02 ` Krzysztof Kozlowski
2024-08-29 10:21 ` patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=d146fb2c-50bb-4339-b330-155f22879446@kernel.org \
--to=krzk@kernel.org \
--cc=amishin@t-argos.ru \
--cc=linux-kernel@vger.kernel.org \
--cc=lvc-project@linuxtesting.org \
--cc=netdev@vger.kernel.org \
--cc=sameo@linux.intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®