lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20161215211655.GA39589@f23x64.localdomain>
Date:   Thu, 15 Dec 2016 13:16:55 -0800
From:   Darren Hart <dvhart@...radead.org>
To:     Andy Shevchenko <andriy.shevchenko@...ux.intel.com>
Cc:     Darren Hart <dvhart@...ux.intel.com>, Lyude <lyude@...hat.com>,
        Henrique de Moraes Holschuh <hmh@....eng.br>,
        linux-next@...r.kernel.org, linux-kernel@...r.kernel.org,
        platform-driver-x86@...r.kernel.org
Subject: Re: [PATCH v2] platform/x86: thinkpad_acpi: Initialize local
 in_tablet_mode and type

On Thu, Dec 15, 2016 at 08:15:02PM +0200, Andy Shevchenko wrote:
> On Wed, 2016-12-14 at 20:14 -0800, Darren Hart wrote:
> > linux-next reported in_tablet_mode and type may be used uninitialized
> > after:
> > 
> > b31800283868 ("platform/x86: thinkpad_acpi: Move tablet detection into
> > separate function")
> > 
> > This turns out to be a false positive as the pr_info call cannot be
> > reached if tp_features.hotkey_tablet (global scope) is 0, and
> > in_tablet_mode and type are assigned in both places
> > tp_features.hotkey_tablet is assigned.
> > 
> > Regardless, to make it explicit and avoid further reports, initialize
> > in_tablet_mode to 0 and type to "".
> > 
> 
> @@ -3143,8 +3143,8 @@ typedef tpacpi_keymap_entry_t
> > tpacpi_keymap_t[TPACPI_HOTKEY_MAP_LEN];
> >  
> >  static int hotkey_init_tablet_mode(void)
> >  {
> > -	int in_tablet_mode, res;
> > -	char *type;
> > +	int in_tablet_mode = 0, res;
> > +	char *type = "";
> 
> Subtle correction
> NULL will work either and takes less memory ;)
> 
> P.S. Even pr_*() is NULL-aware

Agreed. Fixed, pushed, tagged. Thanks all.

-- 
Darren Hart
Intel Open Source Technology Center

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ