From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id AE9DBC433F5 for ; Tue, 1 Feb 2022 00:33:40 +0000 (UTC) Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id C479D8141E; Tue, 1 Feb 2022 01:33:38 +0100 (CET) Authentication-Results: phobos.denx.de; dmarc=none (p=none dis=none) header.from=konsulko.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (1024-bit key; unprotected) header.d=konsulko.com header.i=@konsulko.com header.b="e/5CwBoz"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id 1974C83025; Tue, 1 Feb 2022 01:33:38 +0100 (CET) Received: from mail-qv1-xf35.google.com (mail-qv1-xf35.google.com [IPv6:2607:f8b0:4864:20::f35]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id 7A07680882 for ; Tue, 1 Feb 2022 01:33:34 +0100 (CET) Authentication-Results: phobos.denx.de; dmarc=none (p=none dis=none) header.from=konsulko.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=trini@konsulko.com Received: by mail-qv1-xf35.google.com with SMTP id d8so14562662qvv.2 for ; Mon, 31 Jan 2022 16:33:34 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com; s=google; h=date:from:to:subject:message-id:mime-version:content-disposition; bh=m84tkJb5RI75RF4Wv1V4Mk0XHR3J4KKTUIeApYc3VCY=; b=e/5CwBozRP5uMm+J149A/pqO6lL/Lkq5YSrY3h9Dcm1FsoZeVxPNH6G1ViFZ5mERT8 69o0gvqlRXmW3LCaX67aArk/cQUJLwapqw51XLy0eJaPQQLOzohOaDsKc4G1xYFiIFvQ uljKsxdBvfXaWZQWmbZGlxjYJXY6zMNZqgwZI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:date:from:to:subject:message-id:mime-version :content-disposition; bh=m84tkJb5RI75RF4Wv1V4Mk0XHR3J4KKTUIeApYc3VCY=; b=0RwZtmZpRKJDPAkuTF8Ya0dQsYN1NI7XnXmiwTFR6sOil3MbWaNN4LdpJeLMa9o6cM BvS11v6AWDKToNiqHq97i/B3jIknZ8sR2jjtZy6qpEIAFX1wVxuD2/vscyaQALuAl93t uKBTh0XQc1Re4Ohl22uyE8mTwDLntU+ayKwGNvlUaO/gsG3182Ybz7nw407VS9V2cLEW qd1zI4+VrJ0L9xZb38IrF28PxUVIcT6Pd7VWfFYwVJ5eECd3UrqqaGDeHvq/srIaa8XE 649P5s4TrZscAJyxD7Wiix2c9JpGcirHsMbRY6ILepMGbP8Wcx44eWk3aPavxg7g1ktY EpGg== X-Gm-Message-State: AOAM532vGDcg9cdE9faXVi4jJvkQjb82Qq5s+zoDv3Ijl77Lfum9crlj +s6eurqTypClSySvIOUy3LNj1UBr88I6cA== X-Google-Smtp-Source: ABdhPJwHqoQUfN4AIfdQ0p2UrxdUkMvxDRtAojJN+2wuvuVd2gDOdT1wGljWCgXSCqCehQjYFEV8xw== X-Received: by 2002:ad4:4eee:: with SMTP id dv14mr20215111qvb.100.1643675612969; Mon, 31 Jan 2022 16:33:32 -0800 (PST) Received: from bill-the-cat (2603-6081-7b01-cbda-2ef0-5dff-fedb-a8ba.res6.spectrum.com. [2603:6081:7b01:cbda:2ef0:5dff:fedb:a8ba]) by smtp.gmail.com with ESMTPSA id l11sm10252803qkp.86.2022.01.31.16.33.31 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 31 Jan 2022 16:33:32 -0800 (PST) Date: Mon, 31 Jan 2022 19:33:30 -0500 From: Tom Rini To: u-boot@lists.denx.de, Ilias Apalodimas , Heinrich Schuchardt , Simon Glass , AKASHI Takahiro Subject: [scan-admin@coverity.com: New Defects reported by Coverity Scan for Das U-Boot] Message-ID: <20220201003330.GM7515@bill-the-cat> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="lnCRbaW8TcgsIoW0" Content-Disposition: inline X-Clacks-Overhead: GNU Terry Pratchett X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.39 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.5 at phobos.denx.de X-Virus-Status: Clean --lnCRbaW8TcgsIoW0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Hey folks, Here's the latest report and I think some of these are new tests rather than new code. ----- Forwarded message from scan-admin@coverity.com ----- Date: Mon, 31 Jan 2022 23:09:01 +0000 (UTC) =46rom: scan-admin@coverity.com To: tom.rini@gmail.com Subject: New Defects reported by Coverity Scan for Das U-Boot Hi, Please find the latest report on new defect(s) introduced to Das U-Boot fou= nd with Coverity Scan. 9 new defect(s) introduced to Das U-Boot found with Coverity Scan. 5 defect(s), reported by Coverity Scan earlier, were marked fixed in the re= cent build analyzed by Coverity Scan. New defect(s) Reported-by: Coverity Scan Showing 9 of 9 defect(s) ** CID 345920: API usage errors (CHAR_IO) /tools/bmp_logo.c: 165 in main() ___________________________________________________________________________= _____________________________ *** CID 345920: API usage errors (CHAR_IO) /tools/bmp_logo.c: 165 in main() 159 "#define __BMP_LOGO_DATA_H__\n\n"); 160 =20 161 /* read and print the palette information */ 162 printf("unsigned short bmp_logo_palette[] =3D {\n"); 163 =20 164 for (i=3D0; i>> CID 345920: API usage errors (CHAR_IO) >>> Assigning the return value of "fgetc" to char "b->palette[(int)(i *= 3 + 2)]" truncates its value. 165 b->palette[(int)(i*3+2)] =3D fgetc(fp); 166 b->palette[(int)(i*3+1)] =3D fgetc(fp); 167 b->palette[(int)(i*3+0)] =3D fgetc(fp); 168 x=3Dfgetc(fp); 169 =20 170 printf ("%s0x0%X%X%X,%s", ** CID 345919: Resource leaks (RESOURCE_LEAK) /tools/image-host.c: 969 in fit_config_get_regions() ___________________________________________________________________________= _____________________________ *** CID 345919: Resource leaks (RESOURCE_LEAK) /tools/image-host.c: 969 in fit_config_get_regions() 963 len +=3D strlen(node_inc.strings[i]) + 1; 964 } 965 region_prop =3D malloc(len); 966 if (!region_prop) { 967 printf("Out of memory setting up regions for configuration '%s/%s= '\n", 968 conf_name, sig_name); >>> CID 345919: Resource leaks (RESOURCE_LEAK) >>> Variable "region" going out of scope leaks the storage it points to. 969 return -ENOMEM; 970 } 971 for (i =3D len =3D 0; i < node_inc.count; 972 len +=3D strlen(node_inc.strings[i]) + 1, i++) 973 strcpy(region_prop + len, node_inc.strings[i]); 974 strlist_free(&node_inc); ** CID 345918: Error handling issues (CHECKED_RETURN) /tools/bmp_logo.c: 41 in skip_bytes() ___________________________________________________________________________= _____________________________ *** CID 345918: Error handling issues (CHECKED_RETURN) /tools/bmp_logo.c: 41 in skip_bytes() 35 return val; 36 } 37 =20 38 void skip_bytes (FILE *fp, int n) 39 { 40 while (n-- > 0) >>> CID 345918: Error handling issues (CHECKED_RETURN) >>> Calling "fgetc(fp)" without checking return value. This library fun= ction may fail and return an error code. [Note: The source code implementat= ion of the function has been overridden by a builtin model.] 41 fgetc (fp); 42 } 43 =20 44 __attribute__ ((__noreturn__)) 45 int error (char * msg, FILE *fp) 46 { ** CID 345917: Resource leaks (RESOURCE_LEAK) /tools/mkeficapsule.c: 121 in read_bin_file() ___________________________________________________________________________= _____________________________ *** CID 345917: Resource leaks (RESOURCE_LEAK) /tools/mkeficapsule.c: 121 in read_bin_file() 115 =20 116 *data =3D buf; 117 *bin_size =3D bin_stat.st_size; 118 err: 119 fclose(g); 120 =20 >>> CID 345917: Resource leaks (RESOURCE_LEAK) >>> Variable "buf" going out of scope leaks the storage it points to. 121 return ret; 122 } 123 =20 124 /** 125 * write_capsule_file - write a capsule file 126 * @bin: FILE stream ** CID 345916: Code maintainability issues (UNUSED_VALUE) /tools/bmp_logo.c: 168 in main() ___________________________________________________________________________= _____________________________ *** CID 345916: Code maintainability issues (UNUSED_VALUE) /tools/bmp_logo.c: 168 in main() 162 printf("unsigned short bmp_logo_palette[] =3D {\n"); 163 =20 164 for (i=3D0; ipalette[(int)(i*3+2)] =3D fgetc(fp); 166 b->palette[(int)(i*3+1)] =3D fgetc(fp); 167 b->palette[(int)(i*3+0)] =3D fgetc(fp); >>> CID 345916: Code maintainability issues (UNUSED_VALUE) >>> Assigning value from "fgetc(fp)" to "x" here, but that stored value= is overwritten before it can be used. 168 x=3Dfgetc(fp); 169 =20 170 printf ("%s0x0%X%X%X,%s", 171 ((i%8) =3D=3D 0) ? "\t" : " ", 172 (b->palette[(int)(i*3+0)] >> 4) & 0x0F, 173 (b->palette[(int)(i*3+1)] >> 4) & 0x0F, ** CID 345915: Control flow issues (NO_EFFECT) /lib/image-sparse.c: 214 in write_sparse_image() ___________________________________________________________________________= _____________________________ *** CID 345915: Control flow issues (NO_EFFECT) /lib/image-sparse.c: 214 in write_sparse_image() 208 response); 209 return -1; 210 } 211 =20 212 blks =3D write_sparse_chunk_raw(info, blk, blkcnt, 213 data, response); >>> CID 345915: Control flow issues (NO_EFFECT) >>> This less-than-zero comparison of an unsigned value is never true. = "blks < 0UL". 214 if (blks < 0) 215 return -1; 216 =20 217 blk +=3D blks; 218 bytes_written +=3D ((u64)blkcnt) * info->blksz; 219 total_blocks +=3D chunk_header->chunk_sz; ** CID 345914: Integer handling issues (CONSTANT_EXPRESSION_RESULT) /tools/mkeficapsule.c: 96 in read_bin_file() ___________________________________________________________________________= _____________________________ *** CID 345914: Integer handling issues (CONSTANT_EXPRESSION_RESULT) /tools/mkeficapsule.c: 96 in read_bin_file() 90 } 91 if (stat(bin, &bin_stat) < 0) { 92 fprintf(stderr, "cannot determine the size of %s\n", bin); 93 ret =3D -1; 94 goto err; 95 } >>> CID 345914: Integer handling issues (CONSTANT_EXPRESSION_RESULT) >>> "bin_stat.st_size > 18446744073709551615UL" is always false regardl= ess of the values of its operands. This occurs as the logical operand of "i= f". 96 if (bin_stat.st_size > SIZE_MAX) { 97 fprintf(stderr, "file size is too large for malloc: %s\n", bin); 98 ret =3D -1; 99 goto err; 100 } 101 buf =3D malloc(bin_stat.st_size); ** CID 345913: (TAINTED_SCALAR) /drivers/core/ofnode.c: 477 in ofnode_read_string_list() ___________________________________________________________________________= _____________________________ *** CID 345913: (TAINTED_SCALAR) /drivers/core/ofnode.c: 473 in ofnode_read_string_list() 467 count =3D ofnode_read_string_count(node, property); 468 if (count < 0) 469 return count; 470 if (!count) 471 return 0; 472 =20 >>> CID 345913: (TAINTED_SCALAR) >>> Passing tainted expression "count + 1" to "dlcalloc", which uses it= as an offset. 473 prop =3D calloc(count + 1, sizeof(char *)); 474 if (!prop) 475 return -ENOMEM; 476 =20 477 for (i =3D 0; i < count; i++) 478 ofnode_read_string_index(node, property, i, &prop[i]); /drivers/core/ofnode.c: 477 in ofnode_read_string_list() 471 return 0; 472 =20 473 prop =3D calloc(count + 1, sizeof(char *)); 474 if (!prop) 475 return -ENOMEM; 476 =20 >>> CID 345913: (TAINTED_SCALAR) >>> Using tainted variable "count" as a loop boundary. 477 for (i =3D 0; i < count; i++) 478 ofnode_read_string_index(node, property, i, &prop[i]); 479 prop[count] =3D NULL; 480 *listp =3D prop; 481 =20 482 return count; ** CID 345912: Null pointer dereferences (FORWARD_NULL) /lib/efi_loader/efi_signature.c: 232 in efi_signature_lookup_digest() ___________________________________________________________________________= _____________________________ *** CID 345912: Null pointer dereferences (FORWARD_NULL) /lib/efi_loader/efi_signature.c: 232 in efi_signature_lookup_digest() 226 sig_data =3D sig_data->next) { 227 #ifdef DEBUG 228 EFI_PRINT("Msg digest in database:\n"); 229 print_hex_dump(" ", DUMP_PREFIX_OFFSET, 16, 1, 230 sig_data->data, sig_data->size, false); 231 #endif >>> CID 345912: Null pointer dereferences (FORWARD_NULL) >>> Passing null pointer "hash" to "memcmp", which dereferences it. [No= te: The source code implementation of the function has been overridden by a= builtin model.] 232 if (sig_data->size =3D=3D size && 233 !memcmp(sig_data->data, hash, size)) { 234 found =3D true; 235 free(hash); 236 goto out; 237 } ___________________________________________________________________________= _____________________________ To view the defects in Coverity Scan visit, https://u15810271.ct.sendgrid.n= et/ls/click?upn=3DHRESupC-2F2Czv4BOaCWWCy7my0P0qcxCbhZ31OYv50yoA22WlOQ-2By3= ieUvdbKmOyw68TMVT4Kip-2BBzfOGWXJ5yIiYplmPF9KAnKIja4Zd7tU-3DDKue_EEm8SbLgSDs= aDZif-2Bv7ch8WqhKpLoKErHi4nXpwDNTuSTR0FmiqU27GON2I9OwY5WGDhGm0B966wHcuXU1-2= FAw3I1WyHwNMgtGMOCa3zfgzO3mwIYqjUojcuMoMoDYdcvewXSwAEhrjnoEUuW1P7jZMkKegPKN= ElHEFXfD5RSxi9z9qHMwR-2BQoDabuhKt6QcxRUxX6HfnI4Rx23wgFEhKyA-3D-3D To manage Coverity Scan email notifications for "tom.rini@gmail.com", cli= ck https://u15810271.ct.sendgrid.net/ls/click?upn=3DHRESupC-2F2Czv4BOaCWWCy= 7my0P0qcxCbhZ31OYv50yped04pjJnmXOsUBtKYNIXxWeIHzDeopm-2BEWQ6S6K-2FtUHv9ZTk8= qZbuzkkz9sa-2BJFw4elYDyedRVZOC-2ButxjBZdouVmTGuWB6Aj6G7lm7t25-2Biv1B-2B9082= pHzCCex2kqMs-3Dt4lb_EEm8SbLgSDsaDZif-2Bv7ch8WqhKpLoKErHi4nXpwDNTuSTR0FmiqU2= 7GON2I9OwY5iQ6QEKvvgo3kbcKQQzCeMzyYZUUiCCaPfKKIlYQsIBBmoj-2F-2F-2FVcReszYTf= 2sW-2Fwd1PrbdSELsWk-2FBSCGTEz-2B3dJauXj8pwgVdMYO3Z-2B05o5wBxdS6CNyX1ZFmrg4u= beFG97RpOh-2Fk-2FvV3V-2F9EveHkw-3D-3D ----- End forwarded message ----- --=20 Tom --lnCRbaW8TcgsIoW0 Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQGzBAABCgAdFiEEGjx/cOCPqxcHgJu/FHw5/5Y0tywFAmH4f9QACgkQFHw5/5Y0 tywtrQv8CO3Ev4IIhgqbWFqQwq4ErXHMQfUty6t7eqP5dUDxE5MGkRCICpqDUIZ/ XUw2WTBN8cJH6Smcdy4rntIkWqxBgstkQMpKwypiQ4TzDOPauLzhG7UexHNgyzOd oEwy2ZBrEvFQqVt/+8AV2clzJ212MoKW9mSlC/vhl+SeTdhh4ed3N5oqyuSUCyrJ 6mcG0ejduPEaGBzqT+eG3pVh75phqN40SPDb1zLA0fDzxQz2WGK1wDpUn+AX0g2I kvWiHqoKKFmkkKKIRQL8YSWeU0WNYXCAc7I+kpwUuCFjMUIKQPjncYTCa6h9qNpA 92aG/JZSHdnR/Toxy7f3LE6ycYQ6vJqXatbfVhYVXc77QYnieUw8koVny3/Xvxh0 COLWhI9M9L/5NqBDvLuG/kNe+1sXVEZWBsvDTSomnziRxUznENJGOOd7s5XmOYd0 lj7er3qfCqbRqI8qcXhfCgu5yR6FW0/zyXenPmHkcDv1xeEXSqSwFU9cXPCRqchg 5Hqn7g6Y =C/EL -----END PGP SIGNATURE----- --lnCRbaW8TcgsIoW0--