* [PATCH] [media] hackrf: don't emit dev debug on a kfree'd or null dev
@ 2015-11-11 15:05 Colin King
2015-11-11 15:41 ` Antti Palosaari
0 siblings, 1 reply; 2+ messages in thread
From: Colin King @ 2015-11-11 15:05 UTC (permalink / raw)
To: Antti Palosaari, Mauro Carvalho Chehab, linux-media; +Cc: linux-kernel
From: Colin Ian King <colin.king@canonical.com>
Static analysis with smatch detected a couple of issues:
drivers/media/usb/hackrf/hackrf.c:1533 hackrf_probe()
error: we previously assumed 'dev' could be null (see line 1366)
drivers/media/usb/hackrf/hackrf.c:1533 hackrf_probe()
error: dereferencing freed memory 'dev'
A dev_dbg message is being output on a kfree'd dev. Worse, if dev
is not allocated earlier, on, a null pointer deference on dev->dev
can occur onthe deb_dbg call. Clean this up by only printing a debug
message if dev is not null and has not been kfree'd.
Signed-off-by: Colin Ian King <colin.king@canonical.com>
---
drivers/media/usb/hackrf/hackrf.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/media/usb/hackrf/hackrf.c b/drivers/media/usb/hackrf/hackrf.c
index e05bfec..faf3670 100644
--- a/drivers/media/usb/hackrf/hackrf.c
+++ b/drivers/media/usb/hackrf/hackrf.c
@@ -1528,9 +1528,9 @@ err_v4l2_ctrl_handler_free_tx:
err_v4l2_ctrl_handler_free_rx:
v4l2_ctrl_handler_free(&dev->rx_ctrl_handler);
err_kfree:
+ dev_dbg(dev->dev, "failed=%d\n", ret);
kfree(dev);
err:
- dev_dbg(dev->dev, "failed=%d\n", ret);
return ret;
}
--
2.5.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH] [media] hackrf: don't emit dev debug on a kfree'd or null dev
2015-11-11 15:05 [PATCH] [media] hackrf: don't emit dev debug on a kfree'd or null dev Colin King
@ 2015-11-11 15:41 ` Antti Palosaari
0 siblings, 0 replies; 2+ messages in thread
From: Antti Palosaari @ 2015-11-11 15:41 UTC (permalink / raw)
To: Colin King, Mauro Carvalho Chehab, linux-media; +Cc: linux-kernel
On 11/11/2015 05:05 PM, Colin King wrote:
> From: Colin Ian King <colin.king@canonical.com>
>
> Static analysis with smatch detected a couple of issues:
>
> drivers/media/usb/hackrf/hackrf.c:1533 hackrf_probe()
> error: we previously assumed 'dev' could be null (see line 1366)
> drivers/media/usb/hackrf/hackrf.c:1533 hackrf_probe()
> error: dereferencing freed memory 'dev'
>
> A dev_dbg message is being output on a kfree'd dev. Worse, if dev
> is not allocated earlier, on, a null pointer deference on dev->dev
> can occur onthe deb_dbg call. Clean this up by only printing a debug
> message if dev is not null and has not been kfree'd.
It is already fixed:
https://patchwork.linuxtv.org/patch/31712/
>
> Signed-off-by: Colin Ian King <colin.king@canonical.com>
> ---
> drivers/media/usb/hackrf/hackrf.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/media/usb/hackrf/hackrf.c b/drivers/media/usb/hackrf/hackrf.c
> index e05bfec..faf3670 100644
> --- a/drivers/media/usb/hackrf/hackrf.c
> +++ b/drivers/media/usb/hackrf/hackrf.c
> @@ -1528,9 +1528,9 @@ err_v4l2_ctrl_handler_free_tx:
> err_v4l2_ctrl_handler_free_rx:
> v4l2_ctrl_handler_free(&dev->rx_ctrl_handler);
> err_kfree:
> + dev_dbg(dev->dev, "failed=%d\n", ret);
> kfree(dev);
> err:
> - dev_dbg(dev->dev, "failed=%d\n", ret);
> return ret;
> }
>
>
regards
Antti
--
http://palosaari.fi/
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2015-11-11 15:41 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-11-11 15:05 [PATCH] [media] hackrf: don't emit dev debug on a kfree'd or null dev Colin King
2015-11-11 15:41 ` Antti Palosaari
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).