From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.dvmed.net (srv5.dvmed.net [207.36.208.214]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by ozlabs.org (Postfix) with ESMTPS id 38C6FDDFCF for ; Thu, 22 May 2008 20:27:23 +1000 (EST) Message-ID: <48354A7E.5070105@garzik.org> Date: Thu, 22 May 2008 06:27:10 -0400 From: Jeff Garzik MIME-Version: 1.0 To: Julia Lawall Subject: Re: [PATCH 4/6] drivers/net/fs_enet: remove null pointer dereference References: In-Reply-To: Content-Type: text/plain; charset=ISO-8859-1; format=flowed Cc: netdev@vger.kernel.org, kernel-janitors@vger.kernel.org, linux-kernel@vger.kernel.org, linuxppc-dev@ozlabs.org, vbordug@ru.mvista.com List-Id: Linux on PowerPC Developers Mail List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Julia Lawall wrote: > From: Julia Lawall > > The following code appears in the function fs_init_instance in the file drivers/net/fs_enet/fs_enet-main.c. > > if (fep->ops == NULL) { > printk(KERN_ERR DRV_MODULE_NAME > ": %s No matching ops found (%d).\n", > ndev->name, fpi->fs_no); > err = -EINVAL; > goto err; > } > > This code implies that at the point of err, fep->ops can be NULL, so an > extra test is needed before dereferencing this value. > > > This problem was found using the following semantic match > (http://www.emn.fr/x-info/coccinelle/) > > // > @@ > expression E, E1; > identifier f; > statement S1,S2,S3; > @@ > > * if (E == NULL) > { > ... when != if (E == NULL) S1 else S2 > when != E = E1 > * E->f > ... when any > return ...; > } > else S3 > // > > Signed-off-by: Julia Lawall applied