From: David Laight <david.laight.linux@gmail.com>
To: Sergey Shtylyov <s.shtylyov@auroraos.dev>
Cc: Andrew Lunn <andrew+netdev@lunn.ch>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
<linux-usb@vger.kernel.org>, <netdev@vger.kernel.org>
Subject: Re: [PATCH] r8152: simplify loops in generic_ocp_{read,write}()
Date: Sun, 23 Aug 2026 10:51:10 +0100 [thread overview]
Message-ID: <20260823105110.231a88bc@pumpkin> (raw)
In-Reply-To: <4a7604ab-c6ef-4552-b63b-3e7146ff42d0@auroraos.dev>
On Sun, 23 Aug 2026 11:20:30 +0300
Sergey Shtylyov <s.shtylyov@auroraos.dev> wrote:
> On 8/23/26 11:11 AM, David Laight wrote:
> [...]
>
> >>> In generic_ocp_{read,write}(), the *while* loops look very strange:
> >>> the last iteration is executed differently to the prior ones, doing
> >>> some useless assignments before *break*. Move the code for the last
> >>> iteration out of the loop bodies, dropping the pointless statements
> >>> as well...
> >>>
> >>> Found by Linux Verification Center (linuxtesting.org) with the Svace
> >>> static analysis tool.
> >>>
> >>> Signed-off-by: Sergey Shtylyov <s.shtylyov@auroraos.dev>
> >>
> >> Actually, scratch this patch -- it's not entirely correct... :-/
> >>
> >> [...]
> >>
> >>> diff --git a/drivers/net/usb/r8152.c b/drivers/net/usb/r8152.c>>> index f61686433031..de9738bdce85 100644
> >>> --- a/drivers/net/usb/r8152.c
> >>> +++ b/drivers/net/usb/r8152.c
> >>> @@ -1431,27 +1431,19 @@ static int generic_ocp_read(struct r8152 *tp, u16 index, u16 size,
> >>> if ((u32)index + (u32)size > 0xffff)
> >>> return -EPERM;
> >>>
> >>> - while (size) {
> >>> - if (size > limit) {
> >>> - ret = get_registers(tp, index, type, limit, data);
> >>> - if (ret < 0)
> >>> - break;
> >>> -
> >>> - index += limit;
> >>> - data += limit;
> >>> - size -= limit;
> >>> - } else {
> >>> - ret = get_registers(tp, index, type, size, data);
> >>> - if (ret < 0)
> >>> - break;
> >>> + while (size > limit) {
> >>> + ret = get_registers(tp, index, type, limit, data);
> >>> + if (ret < 0)
> >>> + goto error1;
> >>>
> >>> - index += size;
> >>> - data += size;
> >>> - size = 0;
> >>> - break;
> >>> - }
> >>> + index += limit;
> >>> + data += limit;
> >>> + size -= limit;
> >>> }
> >>>
> >>
> >> I forgot to check size for 0 here...
> >
> > I don't think it can be zero - assuming it isn't zero on entry.
>
> Even if so, anyways it can -- if size % limit == 0 on entry...
Not with the 'size > limit' check at the top of the loop.
David
>
> > David
> [...]
>
> MBR, Sergey
>
>
next prev parent reply other threads:[~2026-08-23 9:51 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-22 20:21 [PATCH] r8152: simplify loops in generic_ocp_{read,write}() Sergey Shtylyov
2026-08-22 20:26 ` Sergey Shtylyov
2026-08-22 20:58 ` Jakub Kicinski
2026-08-23 8:37 ` Sergey Shtylyov
2026-08-24 17:59 ` Jakub Kicinski
2026-08-22 21:03 ` Michal Pecio
2026-08-23 8:16 ` David Laight
2026-08-24 16:00 ` Sergey Shtylyov
2026-08-23 7:52 ` Sergey Shtylyov
2026-08-23 8:11 ` David Laight
2026-08-23 8:20 ` Sergey Shtylyov
2026-08-23 9:51 ` David Laight [this message]
2026-08-23 18:00 ` Sergey Shtylyov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260823105110.231a88bc@pumpkin \
--to=david.laight.linux@gmail.com \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=kuba@kernel.org \
--cc=linux-usb@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=s.shtylyov@auroraos.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.