Merge "ASoC: wcd9xxx: Add check for NULL pointer and buffer overflow"

This commit is contained in:
Linux Build Service Account
2014-04-06 21:58:52 -07:00
committed by Gerrit - the friendly Code Review server
5 changed files with 51 additions and 14 deletions
-1
View File
@@ -1719,7 +1719,6 @@ static int wcd9xxx_slim_device_down(struct slim_device *sldev)
{
struct wcd9xxx *wcd9xxx = slim_get_devicedata(sldev);
dev_info(wcd9xxx->dev, "%s: device down\n", __func__);
if (!wcd9xxx) {
pr_err("%s: wcd9xxx is NULL\n", __func__);
return -EINVAL;
+12
View File
@@ -615,6 +615,10 @@ static int phyirq_to_virq(struct wcd9xxx_core_resource *wcd9xxx_res, int offset)
static int virq_to_phyirq(struct wcd9xxx_core_resource *wcd9xxx_res, int virq)
{
struct irq_data *irq_data = irq_get_irq_data(virq);
if (unlikely(!irq_data)) {
pr_err("%s: irq_data is NULL", __func__);
return -EINVAL;
}
return irq_data->hwirq;
}
@@ -664,6 +668,10 @@ static int __devinit wcd9xxx_irq_probe(struct platform_device *pdev)
} else {
dev_dbg(&pdev->dev, "%s: virq = %d\n", __func__, irq);
domain = irq_find_host(pdev->dev.of_node);
if (unlikely(!domain)) {
pr_err("%s: domain is NULL", __func__);
return -EINVAL;
}
data = (struct wcd9xxx_irq_drv_data *)domain->host_data;
data->irq = irq;
wmb();
@@ -679,6 +687,10 @@ static int wcd9xxx_irq_remove(struct platform_device *pdev)
struct wcd9xxx_irq_drv_data *data;
domain = irq_find_host(pdev->dev.of_node);
if (unlikely(!domain)) {
pr_err("%s: domain is NULL", __func__);
return -EINVAL;
}
data = (struct wcd9xxx_irq_drv_data *)domain->host_data;
data->irq = 0;
wmb();
+30 -10
View File
@@ -1513,6 +1513,7 @@ static int wcd9306_put_dec_enum(struct snd_kcontrol *kcontrol,
u16 tx_mux_ctl_reg;
u8 adc_dmic_sel = 0x0;
int ret = 0;
char *srch = NULL;
if (ucontrol->value.enumerated.item[0] > e->max - 1)
return -EINVAL;
@@ -1531,8 +1532,12 @@ static int wcd9306_put_dec_enum(struct snd_kcontrol *kcontrol,
ret = -EINVAL;
goto out;
}
ret = kstrtouint(strpbrk(dec_name, "1234"), 10, &decimator);
srch = strpbrk(dec_name, "1234");
if (srch == NULL) {
pr_err("%s: Invalid decimator name %s\n", __func__, dec_name);
return -EINVAL;
}
ret = kstrtouint(srch, 10, &decimator);
if (ret < 0) {
pr_err("%s: Invalid decimator = %s\n", __func__, dec_name);
ret = -EINVAL;
@@ -2023,8 +2028,15 @@ static int tapan_codec_enable_dmic(struct snd_soc_dapm_widget *w,
s32 *dmic_clk_cnt;
unsigned int dmic;
int ret;
char *srch = NULL;
ret = kstrtouint(strpbrk(w->name, "1234"), 10, &dmic);
srch = strpbrk(w->name, "1234");
if (srch == NULL) {
pr_err("%s: Invalid widget name %s\n", __func__, w->name);
return -EINVAL;
}
ret = kstrtouint(srch, 10, &dmic);
if (ret < 0) {
pr_err("%s: Invalid DMIC line on the codec\n", __func__);
return -EINVAL;
@@ -2356,6 +2368,7 @@ static int tapan_codec_enable_dec(struct snd_soc_dapm_widget *w,
u16 dec_reset_reg, tx_vol_ctl_reg, tx_mux_ctl_reg;
u8 dec_hpf_cut_of_freq;
int offset;
char *srch = NULL;
dev_dbg(codec->dev, "%s %d\n", __func__, event);
@@ -2371,8 +2384,12 @@ static int tapan_codec_enable_dec(struct snd_soc_dapm_widget *w,
ret = -EINVAL;
goto out;
}
ret = kstrtouint(strpbrk(dec_name, "123456789"), 10, &decimator);
srch = strpbrk(dec_name, "123456789");
if (srch == NULL) {
pr_err("%s: Invalid decimator name %s\n", __func__, dec_name);
return -EINVAL;
}
ret = kstrtouint(srch, 10, &decimator);
if (ret < 0) {
pr_err("%s: Invalid decimator = %s\n", __func__, dec_name);
ret = -EINVAL;
@@ -3316,7 +3333,7 @@ static void tapan_shutdown(struct snd_pcm_substream *substream,
dev_dbg(dai->codec->dev, "%s(): substream = %s stream = %d\n",
__func__, substream->name, substream->stream);
if (dai->id <= NUM_CODEC_DAIS) {
if (dai->id < NUM_CODEC_DAIS) {
if (tapan->dai[dai->id].ch_mask) {
active = 1;
dev_dbg(dai->codec->dev, "%s(): Codec DAI: chmask[%d] = 0x%lx\n",
@@ -3435,7 +3452,7 @@ static int tapan_set_channel_map(struct snd_soc_dai *dai,
{
struct tapan_priv *tapan = snd_soc_codec_get_drvdata(dai->codec);
struct wcd9xxx *core = dev_get_drvdata(dai->codec->dev->parent);
if (!tx_slot && !rx_slot) {
if (!tx_slot || !rx_slot) {
pr_err("%s: Invalid\n", __func__);
return -EINVAL;
}
@@ -4852,9 +4869,9 @@ static int tapan_handle_pdata(struct tapan_priv *tapan)
struct snd_soc_codec *codec = tapan->codec;
struct wcd9xxx_pdata *pdata = tapan->resmgr.pdata;
int k1, k2, k3, rc = 0;
u8 txfe_bypass = pdata->amic_settings.txfe_enable;
u8 txfe_buff = pdata->amic_settings.txfe_buff;
u8 flag = pdata->amic_settings.use_pdata;
u8 txfe_bypass;
u8 txfe_buff;
u8 flag;
u8 i = 0, j = 0;
u8 val_txfe = 0, value = 0;
u8 dmic_sample_rate_value = 0;
@@ -4866,6 +4883,9 @@ static int tapan_handle_pdata(struct tapan_priv *tapan)
rc = -ENODEV;
goto done;
}
txfe_bypass = pdata->amic_settings.txfe_enable;
txfe_buff = pdata->amic_settings.txfe_buff;
flag = pdata->amic_settings.use_pdata;
/* Make sure settings are correct */
if ((pdata->micbias.ldoh_v > WCD9XXX_LDOH_3P0_V) ||
+8 -2
View File
@@ -552,7 +552,13 @@ static int get_impedance_index(u32 imped)
__func__);
goto ret;
}
for (i = 0; i < ARRAY_SIZE(imped_index); i++) {
if (imped >= imped_index[ARRAY_SIZE(imped_index) - 1].imped_val) {
pr_debug("%s, detected impedance is greater than 32164 Ohm\n",
__func__);
i = ARRAY_SIZE(imped_index) - 1;
goto ret;
}
for (i = 0; i < ARRAY_SIZE(imped_index) - 1; i++) {
if (imped >= imped_index[i].imped_val &&
imped < imped_index[i + 1].imped_val)
break;
@@ -569,7 +575,7 @@ void wcd9xxx_clsh_imped_config(struct snd_soc_codec *codec,
int i = 0;
int index = 0;
index = get_impedance_index(imped);
if (index > ARRAY_SIZE(imped_index)) {
if (index >= ARRAY_SIZE(imped_index)) {
pr_err("%s, invalid imped = %d\n", __func__, imped);
return;
}
+1 -1
View File
@@ -1608,7 +1608,7 @@ wcd9xxx_find_plug_type(struct wcd9xxx_mbhc *mbhc,
continue;
}
if ((i > 0) && (d->_type != dprev->_type)) {
if ((i > 0) && (dprev != NULL) && (d->_type != dprev->_type)) {
pr_debug("%s: Invalid, inconsistent types\n", __func__);
type = PLUG_TYPE_INVALID;
goto exit;