aboutsummaryrefslogtreecommitdiffstats
path: root/drivers/infiniband/hw
diff options
context:
space:
mode:
authorDan Carpenter <dan.carpenter@oracle.com>2014-08-12 19:20:04 -0400
committerRoland Dreier <roland@purestorage.com>2014-08-13 01:00:03 -0400
commit859976da0307618d1169616f9cb03936716106eb (patch)
treed7b5e0e805a0411553495476cd8f56482c23ba70 /drivers/infiniband/hw
parent64aa90f26c06e1cb2aacfb98a7d0eccfbd6c1a91 (diff)
RDMA/amso1100: Check for integer overflow in c2_alloc_cq_buf()
This is a static checker fix. The static checker says that q_size comes from the user and can be any 32 bit value. The call tree is: --> ib_uverbs_create_cq() --> c2_create_cq() --> c2_init_cq() Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com> Signed-off-by: Doug Ledford <dledford@redhat.com> Signed-off-by: Roland Dreier <roland@purestorage.com>
Diffstat (limited to 'drivers/infiniband/hw')
-rw-r--r--drivers/infiniband/hw/amso1100/c2_cq.c7
1 files changed, 5 insertions, 2 deletions
diff --git a/drivers/infiniband/hw/amso1100/c2_cq.c b/drivers/infiniband/hw/amso1100/c2_cq.c
index 49e0e8533f74..1b63185b4ad4 100644
--- a/drivers/infiniband/hw/amso1100/c2_cq.c
+++ b/drivers/infiniband/hw/amso1100/c2_cq.c
@@ -260,11 +260,14 @@ static void c2_free_cq_buf(struct c2_dev *c2dev, struct c2_mq *mq)
260 mq->msg_pool.host, dma_unmap_addr(mq, mapping)); 260 mq->msg_pool.host, dma_unmap_addr(mq, mapping));
261} 261}
262 262
263static int c2_alloc_cq_buf(struct c2_dev *c2dev, struct c2_mq *mq, int q_size, 263static int c2_alloc_cq_buf(struct c2_dev *c2dev, struct c2_mq *mq,
264 int msg_size) 264 size_t q_size, size_t msg_size)
265{ 265{
266 u8 *pool_start; 266 u8 *pool_start;
267 267
268 if (q_size > SIZE_MAX / msg_size)
269 return -EINVAL;
270
268 pool_start = dma_alloc_coherent(&c2dev->pcidev->dev, q_size * msg_size, 271 pool_start = dma_alloc_coherent(&c2dev->pcidev->dev, q_size * msg_size,
269 &mq->host_dma, GFP_KERNEL); 272 &mq->host_dma, GFP_KERNEL);
270 if (!pool_start) 273 if (!pool_start)