media: cec: silence shift wrapping warning in __cec_s_log_addrs()
authorDan Carpenter <dan.carpenter@oracle.com>
Tue, 5 May 2020 08:25:56 +0000 (10:25 +0200)
committerMauro Carvalho Chehab <mchehab+huawei@kernel.org>
Tue, 5 May 2020 15:27:03 +0000 (17:27 +0200)
The log_addrs->log_addr_type[i] value is a u8 which is controlled by
the user and comes from the ioctl.  If it's over 31 then that results in
undefined behavior (shift wrapping) and that leads to a Smatch static
checker warning.  We already cap the value later so we can silence the
warning just by re-ordering the existing checks.

I think the UBSan checker will also catch this bug at runtime and
generate a warning.  But otherwise the bug is harmless.

Fixes: 9881fe0ca187 ("[media] cec: add HDMI CEC framework (adapter)")
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: Hans Verkuil <hverkuil-cisco@xs4all.nl>
Signed-off-by: Mauro Carvalho Chehab <mchehab+huawei@kernel.org>
drivers/media/cec/core/cec-adap.c

index 6c95dc471d4c6c63d53f5fdab61acd150bf15a40..6a04d19a96b2e75d6694e48333ce2d0dbfa74e5c 100644 (file)
@@ -1734,6 +1734,10 @@ int __cec_s_log_addrs(struct cec_adapter *adap,
                unsigned j;
 
                log_addrs->log_addr[i] = CEC_LOG_ADDR_INVALID;
+               if (log_addrs->log_addr_type[i] > CEC_LOG_ADDR_TYPE_UNREGISTERED) {
+                       dprintk(1, "unknown logical address type\n");
+                       return -EINVAL;
+               }
                if (type_mask & (1 << log_addrs->log_addr_type[i])) {
                        dprintk(1, "duplicate logical address type\n");
                        return -EINVAL;
@@ -1754,10 +1758,6 @@ int __cec_s_log_addrs(struct cec_adapter *adap,
                        dprintk(1, "invalid primary device type\n");
                        return -EINVAL;
                }
-               if (log_addrs->log_addr_type[i] > CEC_LOG_ADDR_TYPE_UNREGISTERED) {
-                       dprintk(1, "unknown logical address type\n");
-                       return -EINVAL;
-               }
                for (j = 0; j < feature_sz; j++) {
                        if ((features[j] & 0x80) == 0) {
                                if (op_is_dev_features)