mirror of
https://github.com/adulau/aha.git
synced 2024-12-27 03:06:10 +00:00
drivers/video/via/viafbdev.c: correct code taking the size of a pointer
sizeof(viafb_gamma_table) is just the size of the pointer. This is changed to the size used when calling kmalloc to initialize the pointer. A simplified version of the semantic patch that finds this problem is as follows: (http://coccinelle.lip6.fr/) // <smpl> @@ expression *x; expression f; type T; @@ *f(...,(T)x,...) // </smpl> Signed-off-by: Julia Lawall <julia@diku.dk> Acked-by: Florian Tobias Schandinat <FlorianSchandinat@gmx.de> Cc: Joseph Chan <JosephChan@via.com.tw> Cc: Scott Fang <ScottFang@viatech.com.cn> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
This commit is contained in:
parent
312ea07bf0
commit
0f05058531
1 changed files with 2 additions and 2 deletions
|
@ -680,7 +680,7 @@ static int viafb_ioctl(struct fb_info *info, u_int cmd, u_long arg)
|
|||
if (!viafb_gamma_table)
|
||||
return -ENOMEM;
|
||||
if (copy_from_user(viafb_gamma_table, argp,
|
||||
sizeof(viafb_gamma_table))) {
|
||||
256 * sizeof(u32))) {
|
||||
kfree(viafb_gamma_table);
|
||||
return -EFAULT;
|
||||
}
|
||||
|
@ -694,7 +694,7 @@ static int viafb_ioctl(struct fb_info *info, u_int cmd, u_long arg)
|
|||
return -ENOMEM;
|
||||
viafb_get_gamma_table(viafb_gamma_table);
|
||||
if (copy_to_user(argp, viafb_gamma_table,
|
||||
sizeof(viafb_gamma_table))) {
|
||||
256 * sizeof(u32))) {
|
||||
kfree(viafb_gamma_table);
|
||||
return -EFAULT;
|
||||
}
|
||||
|
|
Loading…
Reference in a new issue