Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

ide: silence some underflow warnings

Back in the day we used to just say this code was root only so it was
ok that the bounds checking was sloppy. These days it annoys static
checkers so we fix it.

In the original code "c > INT_MAX" was never true since "c" was an int.
I am not sure what was intended so I left it alone. But because I made
"c" unsigned it means we don't have a warning any more.

The second warning is that we cap "i" but allow negatives leading to an
underflow of the ide_disks_chs[] array. The third set of warnings is
because these values come from the user and we cap most of the upper
bounds but allow negative values. Negative cylinders doesn't make
sense.

drivers/ide/ide.c:262 ide_set_disk_chs() warn: impossible condition '(c > ((~0 >> 1))) => (s32min-s32max > s32max)'
drivers/ide/ide.c:270 ide_set_disk_chs() warn: check 'ide_disks_chs[i]' for negative offsets 'i' = s32min. extra = 's32min-19'
drivers/ide/ide.c:271 ide_set_disk_chs() warn: no lower bound on 'h'

Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: David S. Miller <davem@davemloft.net>

authored by

Dan Carpenter and committed by
David S. Miller
0860bf94 5807fcaa

+8 -8
+8 -8
drivers/ide/ide.c
··· 178 178 179 179 static int ide_set_dev_param_mask(const char *s, const struct kernel_param *kp) 180 180 { 181 - int a, b, i, j = 1; 181 + unsigned int a, b, i, j = 1; 182 182 unsigned int *dev_param_mask = (unsigned int *)kp->arg; 183 183 184 184 /* controller . device (0 or 1) [ : 1 (set) | 0 (clear) ] */ 185 - if (sscanf(s, "%d.%d:%d", &a, &b, &j) != 3 && 186 - sscanf(s, "%d.%d", &a, &b) != 2) 185 + if (sscanf(s, "%u.%u:%u", &a, &b, &j) != 3 && 186 + sscanf(s, "%u.%u", &a, &b) != 2) 187 187 return -EINVAL; 188 188 189 189 i = a * MAX_DRIVES + b; 190 190 191 - if (i >= MAX_HWIFS * MAX_DRIVES || j < 0 || j > 1) 191 + if (i >= MAX_HWIFS * MAX_DRIVES || j > 1) 192 192 return -EINVAL; 193 193 194 194 if (j) ··· 246 246 247 247 static int ide_set_disk_chs(const char *str, struct kernel_param *kp) 248 248 { 249 - int a, b, c = 0, h = 0, s = 0, i, j = 1; 249 + unsigned int a, b, c = 0, h = 0, s = 0, i, j = 1; 250 250 251 251 /* controller . device (0 or 1) : Cylinders , Heads , Sectors */ 252 252 /* controller . device (0 or 1) : 1 (use CHS) | 0 (ignore CHS) */ 253 - if (sscanf(str, "%d.%d:%d,%d,%d", &a, &b, &c, &h, &s) != 5 && 254 - sscanf(str, "%d.%d:%d", &a, &b, &j) != 3) 253 + if (sscanf(str, "%u.%u:%u,%u,%u", &a, &b, &c, &h, &s) != 5 && 254 + sscanf(str, "%u.%u:%u", &a, &b, &j) != 3) 255 255 return -EINVAL; 256 256 257 257 i = a * MAX_DRIVES + b; 258 258 259 - if (i >= MAX_HWIFS * MAX_DRIVES || j < 0 || j > 1) 259 + if (i >= MAX_HWIFS * MAX_DRIVES || j > 1) 260 260 return -EINVAL; 261 261 262 262 if (c > INT_MAX || h > 255 || s > 255)