From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751478AbdH2UFr (ORCPT ); Tue, 29 Aug 2017 16:05:47 -0400 Received: from aserp1040.oracle.com ([141.146.126.69]:36704 "EHLO aserp1040.oracle.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751186AbdH2UFo (ORCPT ); Tue, 29 Aug 2017 16:05:44 -0400 Date: Tue, 29 Aug 2017 23:04:11 +0300 From: Dan Carpenter To: Colin King Cc: Greg Kroah-Hartman , Jiri Slaby , Andy Shevchenko , Phil Elwell , Jan Kiszka , Eric Anholt , Thor Thayer , Rafael Gago , David Lechner , linux-serial@vger.kernel.org, kernel-janitors@vger.kernel.org, linux-kernel@vger.kernel.org Subject: Re: [PATCH][serial-next] serial: 8250: don't dereference em485 until it has been null checked Message-ID: <20170829200411.wbqdsihcnhpg2gmr@mwanda> References: <20170829165815.23429-1-colin.king@canonical.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20170829165815.23429-1-colin.king@canonical.com> User-Agent: NeoMutt/20170113 (1.7.2) X-Source-IP: userv0022.oracle.com [156.151.31.74] Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Tue, Aug 29, 2017 at 05:58:15PM +0100, Colin King wrote: > From: Colin Ian King > > Currently, the pointer em485 is dereferenced to get p and then later > em485 is checked to see if it is null before calling __start_tx. In > the case where em485 is null, we get a null pointer dereference. Fix > this by moving the deference and the associated spinlock/unlocks on > p to the code block where em485 is known to be not null. > > Detected by CoverityScan, CID#14555001 ("Dereference before null check") > > Fixes 6e0a5de2136b ("serial: 8250: Use hrtimers for rs485 delays") I don't understand which tree this commit is from. I have it fetched but when I do a git log on drivers/tty/serial/8250/8250_port.c then I don't see it. I have today's linux-next. > Signed-off-by: Colin Ian King > --- > drivers/tty/serial/8250/8250_port.c | 8 ++++---- > 1 file changed, 4 insertions(+), 4 deletions(-) > > diff --git a/drivers/tty/serial/8250/8250_port.c b/drivers/tty/serial/8250/8250_port.c > index 4726aa276968..c20b581313f0 100644 > --- a/drivers/tty/serial/8250/8250_port.c > +++ b/drivers/tty/serial/8250/8250_port.c > @@ -1606,18 +1606,18 @@ static inline void start_tx_rs485(struct uart_port *port) > static enum hrtimer_restart serial8250_em485_handle_start_tx(struct hrtimer *t) I'm pretty sure "t" isn't ever NULL. regards, dan carpenter