Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

wifi: at76c50x: prefer struct_size over open coded arithmetic

This is an effort to get rid of all multiplications from allocation
functions in order to prevent integer overflows [1][2].

As the "cmd_buf" variable is a pointer to "struct at76_command" and
this structure ends in a flexible array:

struct at76_command {
[...]
u8 data[];
} __packed;

the preferred way in the kernel is to use the struct_size() helper to
do the arithmetic instead of the calculation "size + count" in the
kmalloc() function.

Also, declare a new variable (total_size) since the return value of the
struct_size() helper is used several times.

At the same time, prepare for the coming implementation by GCC and Clang
of the __counted_by attribute. Flexible array members annotated with
__counted_by can have their accesses bounds-checked at run-time via
CONFIG_UBSAN_BOUNDS (for array indexing) and CONFIG_FORTIFY_SOURCE (for
strcpy/memcpy-family functions). In this case, it is important to note
that the attribute used is "__counted_by_le" since the counter type is
"__le16".

This way, the code is more readable and safer.

Link: https://www.kernel.org/doc/html/latest/process/deprecated.html#open-coded-arithmetic-in-allocator-arguments [1]
Link: https://github.com/KSPP/linux/issues/160 [2]
Signed-off-by: Erick Archer <erick.archer@outlook.com>
Signed-off-by: Kalle Valo <kvalo@kernel.org>
Link: https://msgid.link/AS8PR02MB7237578654CEDDFE5F8C17BA8BFE2@AS8PR02MB7237.eurprd02.prod.outlook.com

authored by

Erick Archer and committed by
Kalle Valo
bbef1d00 aea9165c

+7 -7
+6 -6
drivers/net/wireless/atmel/at76c50x-usb.c
··· 721 721 int buf_size) 722 722 { 723 723 int ret; 724 - struct at76_command *cmd_buf = kmalloc(sizeof(struct at76_command) + 725 - buf_size, GFP_KERNEL); 724 + size_t total_size; 725 + struct at76_command *cmd_buf; 726 726 727 + total_size = struct_size(cmd_buf, data, buf_size); 728 + cmd_buf = kmalloc(total_size, GFP_KERNEL); 727 729 if (!cmd_buf) 728 730 return -ENOMEM; 729 731 ··· 734 732 cmd_buf->size = cpu_to_le16(buf_size); 735 733 memcpy(cmd_buf->data, buf, buf_size); 736 734 737 - at76_dbg_dump(DBG_CMD, cmd_buf, sizeof(struct at76_command) + buf_size, 735 + at76_dbg_dump(DBG_CMD, cmd_buf, total_size, 738 736 "issuing command %s (0x%02x)", 739 737 at76_get_cmd_string(cmd), cmd); 740 738 741 739 ret = usb_control_msg(udev, usb_sndctrlpipe(udev, 0), 0x0e, 742 740 USB_TYPE_VENDOR | USB_DIR_OUT | USB_RECIP_DEVICE, 743 - 0, 0, cmd_buf, 744 - sizeof(struct at76_command) + buf_size, 745 - USB_CTRL_GET_TIMEOUT); 741 + 0, 0, cmd_buf, total_size, USB_CTRL_GET_TIMEOUT); 746 742 kfree(cmd_buf); 747 743 return ret; 748 744 }
+1 -1
drivers/net/wireless/atmel/at76c50x-usb.h
··· 151 151 u8 cmd; 152 152 u8 reserved; 153 153 __le16 size; 154 - u8 data[]; 154 + u8 data[] __counted_by_le(size); 155 155 } __packed; 156 156 157 157 /* Length of Atmel-specific Rx header before 802.11 frame */