media: uvcvideo: Fix dereference of out-of-bound list iterator
authorDaniel W. S. Almeida <dwlsalmeida@gmail.com>
Fri, 7 Aug 2020 08:35:30 +0000 (10:35 +0200)
committerMauro Carvalho Chehab <mchehab+huawei@kernel.org>
Thu, 10 Sep 2020 12:06:27 +0000 (14:06 +0200)
Fixes the following coccinelle report:

drivers/media/usb/uvc/uvc_ctrl.c:1860:5-11:
ERROR: invalid reference to the index variable of the iterator on line 1854

by adding a boolean variable to check if the loop has found the

Found using - Coccinelle (http://coccinelle.lip6.fr)

[Replace cursor variable with bool found]

Signed-off-by: Daniel W. S. Almeida <dwlsalmeida@gmail.com>
Signed-off-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab+huawei@kernel.org>
drivers/media/usb/uvc/uvc_ctrl.c

index dbebc6083e85285e068f408bbcd6acd24c5629dd..76e4c885987186a3088cc774a37f3b8c5399a9ef 100644 (file)
@@ -1844,30 +1844,35 @@ int uvc_xu_ctrl_query(struct uvc_video_chain *chain,
 {
        struct uvc_entity *entity;
        struct uvc_control *ctrl;
-       unsigned int i, found = 0;
+       unsigned int i;
+       bool found;
        u32 reqflags;
        u16 size;
        u8 *data = NULL;
        int ret;
 
        /* Find the extension unit. */
+       found = false;
        list_for_each_entry(entity, &chain->entities, chain) {
                if (UVC_ENTITY_TYPE(entity) == UVC_VC_EXTENSION_UNIT &&
-                   entity->id == xqry->unit)
+                   entity->id == xqry->unit) {
+                       found = true;
                        break;
+               }
        }
 
-       if (entity->id != xqry->unit) {
+       if (!found) {
                uvc_trace(UVC_TRACE_CONTROL, "Extension unit %u not found.\n",
                        xqry->unit);
                return -ENOENT;
        }
 
        /* Find the control and perform delayed initialization if needed. */
+       found = false;
        for (i = 0; i < entity->ncontrols; ++i) {
                ctrl = &entity->controls[i];
                if (ctrl->index == xqry->selector - 1) {
-                       found = 1;
+                       found = true;
                        break;
                }
        }