Linux wireless drivers development
 help / color / mirror / Atom feed
From: Dan Carpenter <dan.carpenter@oracle.com>
To: zajec5@gmail.com
Cc: linux-wireless@vger.kernel.org, b43-dev@lists.infradead.org
Subject: re: b43: N-PHY: implement RSSI calibration for rev3+
Date: Wed, 25 Jan 2012 11:18:15 +0300	[thread overview]
Message-ID: <20120125081815.GA19911@elgon.mountain> (raw)

Hello Rafał Miłecki,

The patch e0c9a0219a8f: "b43: N-PHY: implement RSSI calibration for 
rev3+" from Jan 5, 2012, leads to the following Smatch warning:
drivers/net/wireless/b43/phy_n.c +1381 b43_nphy_rev3_rssi_cal()
	 error: buffer overflow 'results[j]' 4 <= 4


+               for (i = 0; i < 4; i++) {
+                       s32 curr;
+                       s32 mind = 40;
+                       s32 minpoll = 249;
+                       u8 minvcm = 0;
+                       if (2 * core != i)
+                               continue;
+                       for (j = 0; j < 8; j++) {
+                               curr = results[j][i] * results[j][i] +
+                                       results[j][i + 1] * results[j][i];
                                                   ^^^^^
On the last iteration through the loop "i + 1" = 4.

+                               if (curr < mind) {
+                                       mind = curr;
+                                       minvcm = j;
+                               }
+                               if (results[j][i] < minpoll)
+                                       minpoll = results[j][i];
+                       }
+                       vcm_final = minvcm;
+                       results_min[i] = minpoll;
+               }

I don't know the code well enough to say if this can happen or not.
Perhaps on the last iteration we always hit the "if (2 * core != i)
continue" condition.  Anyway, since this is the first time this has hit
linux-next, I thought I would let you know.

regards,
dan carpenter


             reply	other threads:[~2012-01-25  8:18 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2012-01-25  8:18 Dan Carpenter [this message]
2012-01-25 12:42 ` b43: N-PHY: implement RSSI calibration for rev3+ Larry Finger

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20120125081815.GA19911@elgon.mountain \
    --to=dan.carpenter@oracle.com \
    --cc=b43-dev@lists.infradead.org \
    --cc=linux-wireless@vger.kernel.org \
    --cc=zajec5@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox