public inbox for kernel-janitors@vger.kernel.org
 help / color / mirror / Atom feed
* [patch] staging: comedi: usbdux: allocating too much data
@ 2013-08-20  9:06 Dan Carpenter
  2013-08-20 10:09 ` Ian Abbott
  0 siblings, 1 reply; 2+ messages in thread
From: Dan Carpenter @ 2013-08-20  9:06 UTC (permalink / raw)
  To: kernel-janitors

We only need to allocate enough space for a pointer.  We allocate the
space for the urbs themselves with the call to usb_alloc_urb() a few
lines later.

Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
---
Untested.

diff --git a/drivers/staging/comedi/drivers/usbdux.c b/drivers/staging/comedi/drivers/usbdux.c
index 7e91f15..701ad1a 100644
--- a/drivers/staging/comedi/drivers/usbdux.c
+++ b/drivers/staging/comedi/drivers/usbdux.c
@@ -1558,9 +1558,9 @@ static int usbdux_alloc_usb_buffers(struct comedi_device *dev)
 	devpriv->dux_commands = kzalloc(SIZEOFDUXBUFFER, GFP_KERNEL);
 	devpriv->in_buf = kzalloc(SIZEINBUF, GFP_KERNEL);
 	devpriv->insn_buf = kzalloc(SIZEINSNBUF, GFP_KERNEL);
-	devpriv->ai_urbs = kcalloc(devpriv->n_ai_urbs, sizeof(*urb),
+	devpriv->ai_urbs = kcalloc(devpriv->n_ai_urbs, sizeof(void *),
 				   GFP_KERNEL);
-	devpriv->ao_urbs = kcalloc(devpriv->n_ao_urbs, sizeof(*urb),
+	devpriv->ao_urbs = kcalloc(devpriv->n_ao_urbs, sizeof(void *),
 				   GFP_KERNEL);
 	if (!devpriv->dux_commands || !devpriv->in_buf || !devpriv->insn_buf ||
 	    !devpriv->ai_urbs || !devpriv->ao_urbs)

^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [patch] staging: comedi: usbdux: allocating too much data
  2013-08-20  9:06 [patch] staging: comedi: usbdux: allocating too much data Dan Carpenter
@ 2013-08-20 10:09 ` Ian Abbott
  0 siblings, 0 replies; 2+ messages in thread
From: Ian Abbott @ 2013-08-20 10:09 UTC (permalink / raw)
  To: kernel-janitors

On 2013-08-20 10:06, Dan Carpenter wrote:
> We only need to allocate enough space for a pointer.  We allocate the
> space for the urbs themselves with the call to usb_alloc_urb() a few
> lines later.
>
> Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
> ---
> Untested.
>
> diff --git a/drivers/staging/comedi/drivers/usbdux.c b/drivers/staging/comedi/drivers/usbdux.c
> index 7e91f15..701ad1a 100644
> --- a/drivers/staging/comedi/drivers/usbdux.c
> +++ b/drivers/staging/comedi/drivers/usbdux.c
> @@ -1558,9 +1558,9 @@ static int usbdux_alloc_usb_buffers(struct comedi_device *dev)
>   	devpriv->dux_commands = kzalloc(SIZEOFDUXBUFFER, GFP_KERNEL);
>   	devpriv->in_buf = kzalloc(SIZEINBUF, GFP_KERNEL);
>   	devpriv->insn_buf = kzalloc(SIZEINSNBUF, GFP_KERNEL);
> -	devpriv->ai_urbs = kcalloc(devpriv->n_ai_urbs, sizeof(*urb),
> +	devpriv->ai_urbs = kcalloc(devpriv->n_ai_urbs, sizeof(void *),
>   				   GFP_KERNEL);
> -	devpriv->ao_urbs = kcalloc(devpriv->n_ao_urbs, sizeof(*urb),
> +	devpriv->ao_urbs = kcalloc(devpriv->n_ao_urbs, sizeof(void *),
>   				   GFP_KERNEL);
>   	if (!devpriv->dux_commands || !devpriv->in_buf || !devpriv->insn_buf ||
>   	    !devpriv->ai_urbs || !devpriv->ao_urbs)
>

Acked-by: Ian Abbott <abbotti@mev.co.uk>

Also, usbduxsigma.c has the same problem.

-- 
-=( Ian Abbott @ MEV Ltd.    E-mail: <abbotti@mev.co.uk>        )=-
-=( Tel: +44 (0)161 477 1898   FAX: +44 (0)161 718 3587         )=-

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2013-08-20 10:09 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2013-08-20  9:06 [patch] staging: comedi: usbdux: allocating too much data Dan Carpenter
2013-08-20 10:09 ` Ian Abbott

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox