On Wed, Nov 23, 2016 at 12:27:36PM -0500, Nayna Jain wrote: > sizep = of_get_property(np, "linux,sml-size", NULL); > + if (of_property_match_string(np, "compatible", "IBM,vtpm") < 0) > + log_size = be32_to_cpup(sizep); > + else > + log_size = *sizep; > +
Uh, no, sizep can be null at this point: > basep = of_get_property(np, "linux,sml-base", NULL); > if (sizep == NULL && basep == NULL) > return -ENODEV; > if (sizep == NULL || basep == NULL) > return -EIO; Move the if here. > - if (*sizep == 0) { > + if (log_size == 0) { > dev_warn(&chip->dev, "%s: Event log area empty\n", __func__); > return -EIO; > } > > - log->bios_event_log = kmalloc(*sizep, GFP_KERNEL); > + log->bios_event_log = kmalloc(log_size, GFP_KERNEL); > if (!log->bios_event_log) > return -ENOMEM; > > - log->bios_event_log_end = log->bios_event_log + *sizep; > + log->bios_event_log_end = log->bios_event_log + log_size; > > - memcpy(log->bios_event_log, __va(*basep), *sizep); > + if (of_property_match_string(np, "compatible", "IBM,vtpm") < 0) > + memcpy(chip->log.bios_event_log, __va(be64_to_cpup(basep)), > + log_size); > + else > + memcpy(chip->log.bios_event_log, __va(*basep), > log_size); And move the conditional swap of basep up to be along side sizep as well (ie get rid of the second of_property_match_string) Jason