linux-i2c.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH 11/27] drivers/i2c: Use memdup_user
@ 2010-05-22  8:21 Julia Lawall
       [not found] ` <Pine.LNX.4.64.1005221021270.13021-QfmoRoYWmW9knbxzx/v8hQ@public.gmane.org>
  0 siblings, 1 reply; 2+ messages in thread
From: Julia Lawall @ 2010-05-22  8:21 UTC (permalink / raw)
  To: Jean Delvare (PC drivers, core), Ben Dooks (em, bedded platforms),
	linux-i2c, linux-kernel, kernel-janit

From: Julia Lawall <julia@diku.dk>

Use memdup_user when user data is immediately copied into the allocated
region.  Note that in the second case, the ++i is no longer necessary, as
the last value is already freed if needed by the call to memdup_user.

The semantic patch that makes this change is as follows:
(http://coccinelle.lip6.fr/)

// <smpl>
@@
expression from,to,size,flag;
position p;
identifier l1,l2;
@@

-  to = \(kmalloc@p\|kzalloc@p\)(size,flag);
+  to = memdup_user(from,size);
   if (
-      to==NULL
+      IS_ERR(to)
                 || ...) {
   <+... when != goto l1;
-  -ENOMEM
+  PTR_ERR(to)
   ...+>
   }
-  if (copy_from_user(to, from, size) != 0) {
-    <+... when != goto l2;
-    -EFAULT
-    ...+>
-  }
// </smpl>

Signed-off-by: Julia Lawall <julia@diku.dk>

---
 drivers/i2c/i2c-dev.c |   22 ++++++----------------
 1 file changed, 6 insertions(+), 16 deletions(-)

diff --git a/drivers/i2c/i2c-dev.c b/drivers/i2c/i2c-dev.c
index e0694e4..03e9ef8 100644
--- a/drivers/i2c/i2c-dev.c
+++ b/drivers/i2c/i2c-dev.c
@@ -167,13 +167,9 @@ static ssize_t i2cdev_write(struct file *file, const char __user *buf,
 	if (count > 8192)
 		count = 8192;
 
-	tmp = kmalloc(count, GFP_KERNEL);
-	if (tmp == NULL)
-		return -ENOMEM;
-	if (copy_from_user(tmp, buf, count)) {
-		kfree(tmp);
-		return -EFAULT;
-	}
+	tmp = memdup_user(buf, count);
+	if (IS_ERR(tmp))
+		return PTR_ERR(tmp);
 
 	pr_debug("i2c-dev: i2c-%d writing %zu bytes.\n",
 		iminor(file->f_path.dentry->d_inode), count);
@@ -247,15 +243,9 @@ static noinline int i2cdev_ioctl_rdrw(struct i2c_client *client,
 			break;
 		}
 		data_ptrs[i] = (u8 __user *)rdwr_pa[i].buf;
-		rdwr_pa[i].buf = kmalloc(rdwr_pa[i].len, GFP_KERNEL);
-		if (rdwr_pa[i].buf == NULL) {
-			res = -ENOMEM;
-			break;
-		}
-		if (copy_from_user(rdwr_pa[i].buf, data_ptrs[i],
-				   rdwr_pa[i].len)) {
-				++i; /* Needs to be kfreed too */
-				res = -EFAULT;
+		rdwr_pa[i].buf = memdup_user(data_ptrs[i], rdwr_pa[i].len);
+		if (IS_ERR(rdwr_pa[i].buf)) {
+			res = PTR_ERR(rdwr_pa[i].buf);
 			break;
 		}
 	}

^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH 11/27] drivers/i2c: Use memdup_user
       [not found] ` <Pine.LNX.4.64.1005221021270.13021-QfmoRoYWmW9knbxzx/v8hQ@public.gmane.org>
@ 2010-06-01 11:14   ` Jean Delvare
  0 siblings, 0 replies; 2+ messages in thread
From: Jean Delvare @ 2010-06-01 11:14 UTC (permalink / raw)
  To: Julia Lawall
  Cc: Ben Dooks, linux-i2c-u79uwXL29TY76Z2rM5mHXA,
	linux-kernel-u79uwXL29TY76Z2rM5mHXA,
	kernel-janitors-u79uwXL29TY76Z2rM5mHXA

Hi Julia,

On Sat, 22 May 2010 10:21:45 +0200 (CEST), Julia Lawall wrote:
> From: Julia Lawall <julia-dAYI7NvHqcQ@public.gmane.org>
> 
> Use memdup_user when user data is immediately copied into the allocated
> region.  Note that in the second case, the ++i is no longer necessary, as
> the last value is already freed if needed by the call to memdup_user.
> 
> The semantic patch that makes this change is as follows:
> (http://coccinelle.lip6.fr/)
> 
> // <smpl>
> @@
> expression from,to,size,flag;
> position p;
> identifier l1,l2;
> @@
> 
> -  to = \(kmalloc@p\|kzalloc@p\)(size,flag);
> +  to = memdup_user(from,size);
>    if (
> -      to==NULL
> +      IS_ERR(to)
>                  || ...) {
>    <+... when != goto l1;
> -  -ENOMEM
> +  PTR_ERR(to)
>    ...+>
>    }
> -  if (copy_from_user(to, from, size) != 0) {
> -    <+... when != goto l2;
> -    -EFAULT
> -    ...+>
> -  }
> // </smpl>
> 
> Signed-off-by: Julia Lawall <julia-dAYI7NvHqcQ@public.gmane.org>
> 
> ---
>  drivers/i2c/i2c-dev.c |   22 ++++++----------------
>  1 file changed, 6 insertions(+), 16 deletions(-)
> 
> diff --git a/drivers/i2c/i2c-dev.c b/drivers/i2c/i2c-dev.c
> index e0694e4..03e9ef8 100644
> --- a/drivers/i2c/i2c-dev.c
> +++ b/drivers/i2c/i2c-dev.c
> @@ -167,13 +167,9 @@ static ssize_t i2cdev_write(struct file *file, const char __user *buf,
>  	if (count > 8192)
>  		count = 8192;
>  
> -	tmp = kmalloc(count, GFP_KERNEL);
> -	if (tmp == NULL)
> -		return -ENOMEM;
> -	if (copy_from_user(tmp, buf, count)) {
> -		kfree(tmp);
> -		return -EFAULT;
> -	}
> +	tmp = memdup_user(buf, count);
> +	if (IS_ERR(tmp))
> +		return PTR_ERR(tmp);
>  
>  	pr_debug("i2c-dev: i2c-%d writing %zu bytes.\n",
>  		iminor(file->f_path.dentry->d_inode), count);
> @@ -247,15 +243,9 @@ static noinline int i2cdev_ioctl_rdrw(struct i2c_client *client,
>  			break;
>  		}
>  		data_ptrs[i] = (u8 __user *)rdwr_pa[i].buf;
> -		rdwr_pa[i].buf = kmalloc(rdwr_pa[i].len, GFP_KERNEL);
> -		if (rdwr_pa[i].buf == NULL) {
> -			res = -ENOMEM;
> -			break;
> -		}
> -		if (copy_from_user(rdwr_pa[i].buf, data_ptrs[i],
> -				   rdwr_pa[i].len)) {
> -				++i; /* Needs to be kfreed too */
> -				res = -EFAULT;
> +		rdwr_pa[i].buf = memdup_user(data_ptrs[i], rdwr_pa[i].len);
> +		if (IS_ERR(rdwr_pa[i].buf)) {
> +			res = PTR_ERR(rdwr_pa[i].buf);
>  			break;
>  		}
>  	}

Applied, thanks.

-- 
Jean Delvare

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2010-06-01 11:14 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-05-22  8:21 [PATCH 11/27] drivers/i2c: Use memdup_user Julia Lawall
     [not found] ` <Pine.LNX.4.64.1005221021270.13021-QfmoRoYWmW9knbxzx/v8hQ@public.gmane.org>
2010-06-01 11:14   ` Jean Delvare

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).