X86 platform drivers
 help / color / mirror / Atom feed
From: Alessandro Guido <ag@alessandroguido.name>
To: Mattia Dongili <malattia@linux.it>
Cc: platform-driver-x86@vger.kernel.org
Subject: [RESEND] Re: NULL pointer dereference in sony-laptop
Date: Fri, 01 Apr 2011 15:17:50 +0200	[thread overview]
Message-ID: <4D95D07E.8060908@alessandroguido.name> (raw)
In-Reply-To: <20110401002935.GA25651@kamineko.org>

[-- Attachment #1: Type: text/plain, Size: 1329 bytes --]

[First try got blocked from platform-driver-x86 antispam filter]

On Fri, Apr 1, 2011 at 2:29 AM, Mattia Dongili <malattia@linux.it> wrote:

> Hi Alessandro,
>
> I am under the impression that the SNC devices gets a notification early
> during initialization when we still haven't read the available handles.
> This patch should fix it but if my thoughts are incorrect then it may
> break something else later.
> Give it a try and let me know (it may apply with a little fuzz).
> Also, could you try to load the module with and without the patch using
> the parameter debug=1 ?
>
> diff --git a/drivers/platform/x86/sony-laptop.c
> b/drivers/platform/x86/sony-laptop.c
> index cfe4493..bed6ebd 100644
> --- a/drivers/platform/x86/sony-laptop.c
> +++ b/drivers/platform/x86/sony-laptop.c
> @@ -808,6 +808,11 @@ static int sony_nc_handles_cleanup(struct
> platform_device *pd)
>  static int sony_find_snc_handle(int handle)
>  {
>        int i;
> +
> +       /* not initialized yet, return early */
> +       if (!handles)
> +               return -1;
> +
>        for (i = 0; i < 0x10; i++) {
>                if (handles->cap[i] == handle) {
>                        dprintk("found handle 0x%.4x (offset: 0x%.2x)\n",


It works, thanks!

I've attached debug output from sony-laptop with and without the patch 
as you requested.


[-- Attachment #2: patched.dmesg --]
[-- Type: application/octet-stream, Size: 989 bytes --]

sony-laptop: Sony Notebook Control Driver v0.6.
sony-laptop: method: name: GBRT, args 0
sony-laptop: method: name: SBRT, args 1
sony-laptop: method: name: GPBR, args 0
sony-laptop: method: name: SPBR, args 1
sony-laptop: method: name: PWAK, args 0
sony-laptop: method: name: GHKE, args 0
sony-laptop: method: name: GWDP, args 0
sony-laptop: method: name: GSNE, args 1
sony-laptop: method: name: SSNE, args 1
sony-laptop: method: name: CSXB, args 1
sony-laptop: method: name: SODV, args 1
sony-laptop: method: name: GDDI, args 0
sony-laptop: method: name: STCS, args 1
sony-laptop: method: name: RBMF, args 1
sony-laptop: method: name: RSBI, args 1
sony-laptop: method: name: CBMF, args 1
input: Sony Vaio Keys as /devices/LNXSYSTM:00/device:00/PNP0A03:00/device:18/SNY5001:00/input/input11
input: Sony Vaio Jogdial as /devices/virtual/input/input12
sony-laptop: Found brightness_default getter: GPBR
sony-laptop: Found brightness_default setter: SPBR
sony-laptop: Found fnkey getter: GHKE

[-- Attachment #3: unpatched.dmesg --]
[-- Type: application/octet-stream, Size: 3169 bytes --]

sony-laptop: Sony Notebook Control Driver v0.6.
sony-laptop: method: name: GBRT, args 0
sony-laptop: method: name: SBRT, args 1
sony-laptop: method: name: GPBR, args 0
sony-laptop: method: name: SPBR, args 1
sony-laptop: method: name: PWAK, args 0
sony-laptop: method: name: GHKE, args 0
sony-laptop: method: name: GWDP, args 0
sony-laptop: method: name: GSNE, args 1
sony-laptop: method: name: SSNE, args 1
sony-laptop: method: name: CSXB, args 1
sony-laptop: method: name: SODV, args 1
sony-laptop: method: name: GDDI, args 0
sony-laptop: method: name: STCS, args 1
sony-laptop: method: name: RBMF, args 1
sony-laptop: method: name: RSBI, args 1
sony-laptop: method: name: CBMF, args 1
input: Sony Vaio Keys as /devices/LNXSYSTM:00/device:00/PNP0A03:00/device:18/SNY5001:00/input/input11
input: Sony Vaio Jogdial as /devices/virtual/input/input12
BUG: unable to handle kernel NULL pointer dereference at   (null)
IP: [<f8021060>] sony_find_snc_handle+0x10/0x70 [sony_laptop]
*pde = 00000000 
Oops: 0000 [#1] PREEMPT 
last sysfs file: /sys/devices/platform/sony-laptop/uevent
Modules linked in: sony_laptop(+)

Pid: 1494, comm: modprobe Not tainted 2.6.39-rc1-00103-g6aba74f #3 Sony Corporation VGN-FS215S
EIP: 0060:[<f8021060>] EFLAGS: 00010282 CPU: 0
EIP is at sony_find_snc_handle+0x10/0x70 [sony_laptop]
EAX: 0000012f EBX: 00000000 ECX: 00000000 EDX: 00000000
ESI: f6559e04 EDI: f652f400 EBP: 00000000 ESP: f6559db0
 DS: 007b ES: 007b FS: 0000 GS: 0033 SS: 0068
Process modprobe (pid: 1494, ti=f6558000 task=f5d06a40 task.ti=f6558000)
Stack:
 00000000 f6559e04 f652f400 00000000 f8023126 f8022900 00000000 00000000
 00000000 f6512300 00000000 c10f35b5 f6559e18 f5c27f00 f6559e18 c10f2dcc
 c10f2ad3 000041ed f6403c00 f5c268a0 f6512300 00000000 f652f400 f8025840
Call Trace:
 [<f8023126>] ? sony_nc_add+0x286/0x8b0 [sony_laptop]
 [<f8022900>] ? sony_nc_update_status_ng+0x30/0x30 [sony_laptop]
 [<c10f35b5>] ? sysfs_do_create_link+0xc5/0x1f0
 [<c10f2dcc>] ? sysfs_add_one+0x1c/0xc0
 [<c10f2ad3>] ? sysfs_addrm_finish+0x13/0xa0
 [<c11820a2>] ? acpi_device_probe+0x37/0xee
 [<c11c6e15>] ? driver_probe_device+0x85/0x190
 [<c11824a1>] ? acpi_match_device_ids+0x27/0x4d
 [<c11c6f99>] ? __driver_attach+0x79/0x80
 [<c11c6f20>] ? driver_probe_device+0x190/0x190
 [<c11c608b>] ? bus_for_each_dev+0x4b/0x70
 [<c11c6b36>] ? driver_attach+0x16/0x20
 [<c11c6f20>] ? driver_probe_device+0x190/0x190
 [<c11c6827>] ? bus_add_driver+0x197/0x270
 [<c1181fdf>] ? acpi_device_hid+0x13/0x13
 [<c11c7497>] ? driver_register+0x57/0xf0
 [<f808104d>] ? sony_laptop_init+0x4d/0x79 [sony_laptop]
 [<c10011f3>] ? do_one_initcall+0x33/0x170
 [<c1042c3d>] ? __blocking_notifier_call_chain+0x4d/0x60
 [<f8081000>] ? 0xf8080fff
 [<c10523f1>] ? sys_init_module+0x151/0x1a50
 [<c10a38c9>] ? sys_close+0x69/0xe0
 [<c131d30c>] ? sysenter_do_call+0x12/0x22
Code: d0 c3 89 f6 8d bc 27 00 00 00 00 83 fa 01 b8 ea ff ff ff 0f 47 d0 eb e7 8d 76 00 53 31 db 83 ec 0c 8b 0d 6c 64 02 f8 8d 74 26 00 <0f> b7 14 59 39 c2 74 20 43 83 fb 10 75 f2 8b 15 14 64 02 f8 85 
EIP: [<f8021060>] sony_find_snc_handle+0x10/0x70 [sony_laptop] SS:ESP 0068:f6559db0
CR2: 0000000000000000
---[ end trace 6fd3f5669318a954 ]---

  reply	other threads:[~2011-04-01 13:17 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-03-31 17:28 NULL pointer dereference in sony-laptop Alessandro Guido
2011-04-01  0:29 ` Mattia Dongili
2011-04-01 13:17   ` Alessandro Guido [this message]
2011-04-01 17:36   ` Matthew Garrett
2011-04-02  1:06     ` Mattia Dongili

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4D95D07E.8060908@alessandroguido.name \
    --to=ag@alessandroguido.name \
    --cc=malattia@linux.it \
    --cc=platform-driver-x86@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox