On Mon, Feb 14, 2022 at 01:31:57AM +1100, Jonathan Gray wrote:
> On Sun, Feb 13, 2022 at 03:17:27PM +0100, Theo Buehler wrote:
> > On Sun, Feb 13, 2022 at 02:30:21PM +0100, Tobias Heider wrote:
> > > OF_getproplen() will return -1 if "reset-gpios" is not found which
> > > currently causes a panic:
> > > 
> > > panic: malloc: allocation too large, type = 2, size = 4294967295
> > > 
> > > Below is a fix.
> > 
> > There are more of these:
> > 
> > dev/ofw/ofw_regulator.c:336:    if ((glen = OF_getproplen(node, "gpios")) 
> > <= 0)
> > dev/ofw/ofw_regulator.c:338:    if ((slen = OF_getproplen(node, "states")) 
> > <= 0)
> > dev/ofw/ofw_regulator.c:401:    if ((glen = OF_getproplen(node, "gpios")) 
> > <= 0)
> > dev/ofw/ofw_regulator.c:403:    if ((slen = OF_getproplen(node, "states")) 
> > <= 0)
> > 
> > where glen and slen are size_t and
> > 
> > arch/sparc64/sparc64/pmap.c:806:        sz = OF_getproplen(memh, 
> > "available") + sizeof(struct mem_region);
> > 
> > with a size_t sz.
> 
> another in imxspi

some more

ssdfb.c has a size_t sc_gpiolen but stores the
result in a ssize_t and tests that before storing to it

Index: dev/fdt/simpleamp.c
===================================================================
RCS file: /cvs/src/sys/dev/fdt/simpleamp.c,v
retrieving revision 1.1
diff -u -p -r1.1 simpleamp.c
--- dev/fdt/simpleamp.c 10 Jun 2020 23:59:07 -0000      1.1
+++ dev/fdt/simpleamp.c 13 Feb 2022 14:35:09 -0000
@@ -42,7 +42,7 @@ struct simpleamp_softc {
        struct dai_device       sc_dai;
 
        uint32_t                *sc_gpio;
-       size_t                  sc_gpiolen;
+       int                     sc_gpiolen;
        uint32_t                sc_vcc;
 };
 
Index: arch/arm64/dev/aplhidev.c
===================================================================
RCS file: /cvs/src/sys/arch/arm64/dev/aplhidev.c,v
retrieving revision 1.4
diff -u -p -r1.4 aplhidev.c
--- arch/arm64/dev/aplhidev.c   11 Dec 2021 20:36:26 -0000      1.4
+++ arch/arm64/dev/aplhidev.c   13 Feb 2022 14:33:57 -0000
@@ -117,7 +117,7 @@ struct aplhidev_softc {
        uint8_t                 sc_msgid;
 
        uint32_t                *sc_gpio;
-       size_t                  sc_gpiolen;
+       int                     sc_gpiolen;
 
        struct device           *sc_kbd;
        uint8_t                 sc_kbddesc[APLHIDEV_DESC_MAX];

Reply via email to