Re: [PATCH 1/2] b43legacy: fix a lower bounds test

Michael Büsch <[email protected]>
Newsgroups org.infradead.lists.b43-dev,org.kernel.vger.kernel-janitors,org.kernel.vger.linux-wireless
Message-ID <20211006181358.67a23e18@wiggum>
On Wed, 6 Oct 2021 10:35:42 +0300
Dan Carpenter <[email protected]> wrote:

> The problem is that "channel" is an unsigned int, when it's less 5 the
> value of "channel - 5" is not a negative number as one would expect but
> is very high positive value instead.
> 
> This means that "start" becomes a very high positive value.  The result
> of that is that we never enter the "for (i = start; i <= end; i++) {"
> loop.  Instead of storing the result from b43legacy_radio_aci_detect()
> it just uses zero.
> 
> Fixes: 75388acd0cd8 ("[B43LEGACY]: add mac80211-based driver for legacy BCM43xx devices")
> Signed-off-by: Dan Carpenter <[email protected]>
> ---
> This fix is correct, but making dead code go live can sometimes expose
> bugs which were previously hiding and is always carries a slight risk.
> 
>  drivers/net/wireless/broadcom/b43legacy/radio.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/net/wireless/broadcom/b43legacy/radio.c b/drivers/net/wireless/broadcom/b43legacy/radio.c
> index 06891b4f837b..fdf78c10a05c 100644
> --- a/drivers/net/wireless/broadcom/b43legacy/radio.c
> +++ b/drivers/net/wireless/broadcom/b43legacy/radio.c
> @@ -283,7 +283,7 @@ u8 b43legacy_radio_aci_scan(struct b43legacy_wldev *dev)
>  			    & 0x7FFF);
>  	b43legacy_set_all_gains(dev, 3, 8, 1);
>  
> -	start = (channel - 5 > 0) ? channel - 5 : 1;
> +	start = (channel > 5) ? channel - 5 : 1;
>  	end = (channel + 5 < 14) ? channel + 5 : 13;
>  
>  	for (i = start; i <= end; i++) {

Nice finding.

Acked-by: Michael Büsch <[email protected]>


-- 
Michael

https://bues.ch/

_______________________________________________
b43-dev mailing list
[email protected]
http://lists.infradead.org/mailman/listinfo/b43-dev
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEihRzkKVZOnT2ipsS9TK+HZCNiw4FAmFdy0YACgkQ9TK+HZCN
iw5iWA//Qsq+DuoC10lMYoTH3WkopAMR9mKhwbe5FTZUUe0eWQM3r9a7uGKGKOX2
LW47biXVl/9u0PiUulvLWklyV2Kg6QKCewOLmUHbZB7XBPW0PVf/67KRL3Y4Iz7p
0nZhcOzkv00cyoQ5wIOBcjrrqwK9+u0BgK1VUDRWd8yblOyK8jPTaIEf6x0E1VPT
1Ve7yeETJzioF8xeTCgBoY2SUUGAfZ91C/w5dtctfPkuW8RSHwqFH0553f9QICQS
z9XDBvESlPY7GLzDSXv/TulyRPqK3K+jZA5zuiOlW5XJpXiOax1xdNyq/GwcGpV7
a332WOmx4Q0Edc/183OUpx1xoIHFLQiMfs6kpmkvgoaqWdCdjzF7yTr9xXOcM3S7
YSR3Be18aarCLhGR354xz+Wbvb69IIS7hEwK7lBZwD7u6Jd/KyLU+3k77D69gdzl
y+33iLFxH1pWtsw/wGwZrPH1hl9LUE18s3S4vfKpJ4EqJ20+nIGIPgf2EPGhEaEW
IUnA5es/jscNcYdCTvfffyeKRwyo1NZhJHBslqVqF6InC+MMilFHBZo+2ZA3Swey
NBdDueAsTFF/XAdep9Y32U1l1aiXfUoVROXPFQtGnX1V7qP3Aucx1Kpt9ZPiqk4Y
QI85MyfpA7WDWEYLjBP9APcX2uI29nTHrRsztGJxx+SDycGymWU=
=mGEZ
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.