diff options
| author | Phil Carmody <ext-phil.2.carmody@nokia.com> | 2010-04-16 08:00:09 -0400 | 
|---|---|---|
| committer | Samuel Ortiz <sameo@linux.intel.com> | 2010-05-27 19:37:40 -0400 | 
| commit | fffba64ca37e8f06020f89e878f0d76a8e121c4e (patch) | |
| tree | 51d6cd2b044aa6a030d7ec321a67b7cc2574e948 | |
| parent | da1e368032d7ff241b9cf1059fa059d781cfeba7 (diff) | |
mfd: Fix error in wm8400 reg cache access check
Accessing num_reg elements in the interval [reg .. reg+num_regs)
is permitted if (reg+numregs <= array size), so barf when that
excluded upper bound is > array size. The prior -1 would give
access to one too many elements.
Signed-off-by: Phil Carmody <ext-phil.2.carmody@nokia.com>
Signed-off-by: Samuel Ortiz <sameo@linux.intel.com>
| -rw-r--r-- | drivers/mfd/wm8400-core.c | 4 | 
1 files changed, 2 insertions, 2 deletions
| diff --git a/drivers/mfd/wm8400-core.c b/drivers/mfd/wm8400-core.c index 865ce013a821..e08aafa663dc 100644 --- a/drivers/mfd/wm8400-core.c +++ b/drivers/mfd/wm8400-core.c | |||
| @@ -118,7 +118,7 @@ static int wm8400_read(struct wm8400 *wm8400, u8 reg, int num_regs, u16 *dest) | |||
| 118 | { | 118 | { | 
| 119 | int i, ret = 0; | 119 | int i, ret = 0; | 
| 120 | 120 | ||
| 121 | BUG_ON(reg + num_regs - 1 > ARRAY_SIZE(wm8400->reg_cache)); | 121 | BUG_ON(reg + num_regs > ARRAY_SIZE(wm8400->reg_cache)); | 
| 122 | 122 | ||
| 123 | /* If there are any volatile reads then read back the entire block */ | 123 | /* If there are any volatile reads then read back the entire block */ | 
| 124 | for (i = reg; i < reg + num_regs; i++) | 124 | for (i = reg; i < reg + num_regs; i++) | 
| @@ -144,7 +144,7 @@ static int wm8400_write(struct wm8400 *wm8400, u8 reg, int num_regs, | |||
| 144 | { | 144 | { | 
| 145 | int ret, i; | 145 | int ret, i; | 
| 146 | 146 | ||
| 147 | BUG_ON(reg + num_regs - 1 > ARRAY_SIZE(wm8400->reg_cache)); | 147 | BUG_ON(reg + num_regs > ARRAY_SIZE(wm8400->reg_cache)); | 
| 148 | 148 | ||
| 149 | for (i = 0; i < num_regs; i++) { | 149 | for (i = 0; i < num_regs; i++) { | 
| 150 | BUG_ON(!reg_data[reg + i].writable); | 150 | BUG_ON(!reg_data[reg + i].writable); | 
