[PATCH 1/2] opal: Fix the overflow of message notifiers head array

Michael Ellerman mpe at ellerman.id.au
Wed Feb 11 14:14:38 AEDT 2015


On Tue, 2015-02-10 at 22:44 +0530, Neelesh Gupta wrote:

You forgot to write the changelog.

> Signed-off-by: Neelesh Gupta <neelegup at linux.vnet.ibm.com>
> Reviewed-by: Vasant Hegde <hegdevasant at linux.vnet.ibm.com>
> ---
>  arch/powerpc/platforms/powernv/opal.c |   12 ++++--------
>  1 file changed, 4 insertions(+), 8 deletions(-)
> 
> diff --git a/arch/powerpc/platforms/powernv/opal.c b/arch/powerpc/platforms/powernv/opal.c
> index f10b9ec..2651e22 100644
> --- a/arch/powerpc/platforms/powernv/opal.c
> +++ b/arch/powerpc/platforms/powernv/opal.c
> @@ -305,16 +305,12 @@ void opal_notifier_disable(void)
>  int opal_message_notifier_register(enum OpalMessageType msg_type,
>  					struct notifier_block *nb)
>  {
> -	if (!nb) {
> -		pr_warning("%s: Invalid argument (%p)\n",
> -			   __func__, nb);
> -		return -EINVAL;
> -	}
> -	if (msg_type > OPAL_MSG_TYPE_MAX) {
> -		pr_warning("%s: Invalid message type argument (%d)\n",
> +	if (!nb || msg_type >= OPAL_MSG_TYPE_MAX) {
> +		pr_warning("%s: Invalid arguments, msg_type:%d\n",
>  			   __func__, msg_type);
>  		return -EINVAL;
>  	}
> +
>  	return atomic_notifier_chain_register(
>  				&opal_msg_notifier_head[msg_type], nb);
>  }
> @@ -351,7 +347,7 @@ static void opal_handle_message(void)
>  	type = be32_to_cpu(msg.msg_type);
>  
>  	/* Sanity check */
> -	if (type > OPAL_MSG_TYPE_MAX) {
> +	if (type >= OPAL_MSG_TYPE_MAX) {
>  		pr_warning("%s: Unknown message type: %u\n", __func__, type);
>  		return;
>  	}
> 






More information about the Linuxppc-dev mailing list