kernel-janitors.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH 10/27] drivers/infiniband/core: Use memdup_user
@ 2010-05-22  8:21 Julia Lawall
       [not found] ` <Pine.LNX.4.64.1005221021030.13021-QfmoRoYWmW9knbxzx/v8hQ@public.gmane.org>
  2010-05-26  4:11 ` Roland Dreier
  0 siblings, 2 replies; 4+ messages in thread
From: Julia Lawall @ 2010-05-22  8:21 UTC (permalink / raw)
  To: Roland Dreier, Sean Hefty, Hal Rosenstock, linux-rdma,
	linux-kernel, kernel-jani

From: Julia Lawall <julia@diku.dk>

Use memdup_user when user data is immediately copied into the
allocated region.

The semantic patch that makes this change is as follows:
(http://coccinelle.lip6.fr/)

// <smpl>
@@
expression from,to,size,flag;
position p;
identifier l1,l2;
@@

-  to = \(kmalloc@p\|kzalloc@p\)(size,flag);
+  to = memdup_user(from,size);
   if (
-      to=NULL
+      IS_ERR(to)
                 || ...) {
   <+... when != goto l1;
-  -ENOMEM
+  PTR_ERR(to)
   ...+>
   }
-  if (copy_from_user(to, from, size) != 0) {
-    <+... when != goto l2;
-    -EFAULT
-    ...+>
-  }
// </smpl>

Signed-off-by: Julia Lawall <julia@diku.dk>

---
 drivers/infiniband/core/ucm.c |   11 +++--------
 1 file changed, 3 insertions(+), 8 deletions(-)

diff --git a/drivers/infiniband/core/ucm.c b/drivers/infiniband/core/ucm.c
index 4647484..08f948d 100644
--- a/drivers/infiniband/core/ucm.c
+++ b/drivers/infiniband/core/ucm.c
@@ -706,14 +706,9 @@ static int ib_ucm_alloc_data(const void **dest, u64 src, u32 len)
 	if (!len)
 		return 0;
 
-	data = kmalloc(len, GFP_KERNEL);
-	if (!data)
-		return -ENOMEM;
-
-	if (copy_from_user(data, (void __user *)(unsigned long)src, len)) {
-		kfree(data);
-		return -EFAULT;
-	}
+	data = memdup_user((void __user *)(unsigned long)src, len);
+	if (IS_ERR(data))
+		return PTR_ERR(data);
 
 	*dest = data;
 	return 0;

^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [PATCH 10/27] drivers/infiniband/core: Use memdup_user
       [not found] ` <Pine.LNX.4.64.1005221021030.13021-QfmoRoYWmW9knbxzx/v8hQ@public.gmane.org>
@ 2010-05-22  9:39   ` walter harms
       [not found]     ` <4BF7A65D.1070501-fPG8STNUNVg@public.gmane.org>
  0 siblings, 1 reply; 4+ messages in thread
From: walter harms @ 2010-05-22  9:39 UTC (permalink / raw)
  To: Julia Lawall
  Cc: Roland Dreier, Sean Hefty, Hal Rosenstock,
	linux-rdma-u79uwXL29TY76Z2rM5mHXA,
	linux-kernel-u79uwXL29TY76Z2rM5mHXA,
	kernel-janitors-u79uwXL29TY76Z2rM5mHXA



Julia Lawall schrieb:
> From: Julia Lawall <julia@diku.dk>
> 
> Use memdup_user when user data is immediately copied into the
> allocated region.
> 
> The semantic patch that makes this change is as follows:
> (http://coccinelle.lip6.fr/)
> 
> // <smpl>
> @@
> expression from,to,size,flag;
> position p;
> identifier l1,l2;
> @@
> 
> -  to = \(kmalloc@p\|kzalloc@p\)(size,flag);
> +  to = memdup_user(from,size);
>    if (
> -      to=NULL
> +      IS_ERR(to)
>                  || ...) {
>    <+... when != goto l1;
> -  -ENOMEM
> +  PTR_ERR(to)
>    ...+>
>    }
> -  if (copy_from_user(to, from, size) != 0) {
> -    <+... when != goto l2;
> -    -EFAULT
> -    ...+>
> -  }
> // </smpl>
> 
> Signed-off-by: Julia Lawall <julia@diku.dk>
> 
> ---
>  drivers/infiniband/core/ucm.c |   11 +++--------
>  1 file changed, 3 insertions(+), 8 deletions(-)
> 
> diff --git a/drivers/infiniband/core/ucm.c b/drivers/infiniband/core/ucm.c
> index 4647484..08f948d 100644
> --- a/drivers/infiniband/core/ucm.c
> +++ b/drivers/infiniband/core/ucm.c
> @@ -706,14 +706,9 @@ static int ib_ucm_alloc_data(const void **dest, u64 src, u32 len)
>  	if (!len)
>  		return 0;
>  
> -	data = kmalloc(len, GFP_KERNEL);
> -	if (!data)
> -		return -ENOMEM;
> -
> -	if (copy_from_user(data, (void __user *)(unsigned long)src, len)) {
> -		kfree(data);
> -		return -EFAULT;
> -	}
> +	data = memdup_user((void __user *)(unsigned long)src, len);
> +	if (IS_ERR(data))
> +		return PTR_ERR(data);
>  
>  	*dest = data;
>  	return 0;
> --

This cast look strange, can it happen that (unsigned long)<(u64) ?
(is there a 32bit infiniband) ?

just my 2 cents,
 wh





^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH 10/27] drivers/infiniband/core: Use memdup_user
       [not found]     ` <4BF7A65D.1070501-fPG8STNUNVg@public.gmane.org>
@ 2010-05-22 15:15       ` Roland Dreier
  0 siblings, 0 replies; 4+ messages in thread
From: Roland Dreier @ 2010-05-22 15:15 UTC (permalink / raw)
  To: wharms-fPG8STNUNVg
  Cc: Julia Lawall, Roland Dreier, Sean Hefty, Hal Rosenstock,
	linux-rdma-u79uwXL29TY76Z2rM5mHXA,
	linux-kernel-u79uwXL29TY76Z2rM5mHXA,
	kernel-janitors-u79uwXL29TY76Z2rM5mHXA

 > > +	data = memdup_user((void __user *)(unsigned long)src, len);
 > > +	if (IS_ERR(data))
 > > +		return PTR_ERR(data);

 > This cast look strange, can it happen that (unsigned long)<(u64) ?
 > (is there a 32bit infiniband) ?

There is 32-bit infiniband.  Linux kernel assumes that unsigned long is
equivalent to uintptr_t -- in other words all pointers are the same size
as longs.  So when casting from integer to pointer we add a cast to
unsigned long to avoid a warning precisely in the 32-bit case -- we
would get a warning about cast to pointer from integer of different size
when casting from 64-bit integer to 32-bit pointer.
-- 
Roland Dreier <rolandd@cisco.com> || For corporate legal information go to:
http://www.cisco.com/web/about/doing_business/legal/cri/index.html

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH 10/27] drivers/infiniband/core: Use memdup_user
  2010-05-22  8:21 [PATCH 10/27] drivers/infiniband/core: Use memdup_user Julia Lawall
       [not found] ` <Pine.LNX.4.64.1005221021030.13021-QfmoRoYWmW9knbxzx/v8hQ@public.gmane.org>
@ 2010-05-26  4:11 ` Roland Dreier
  1 sibling, 0 replies; 4+ messages in thread
From: Roland Dreier @ 2010-05-26  4:11 UTC (permalink / raw)
  To: Julia Lawall
  Cc: Roland Dreier, Sean Hefty, Hal Rosenstock, linux-rdma,
	linux-kernel, kernel-janitors

thanks, applied.
-- 
Roland Dreier <rolandd@cisco.com> || For corporate legal information go to:
http://www.cisco.com/web/about/doing_business/legal/cri/index.html

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2010-05-26  4:11 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-05-22  8:21 [PATCH 10/27] drivers/infiniband/core: Use memdup_user Julia Lawall
     [not found] ` <Pine.LNX.4.64.1005221021030.13021-QfmoRoYWmW9knbxzx/v8hQ@public.gmane.org>
2010-05-22  9:39   ` walter harms
     [not found]     ` <4BF7A65D.1070501-fPG8STNUNVg@public.gmane.org>
2010-05-22 15:15       ` Roland Dreier
2010-05-26  4:11 ` Roland Dreier

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).