| 
									
										
										
										
											2012-01-14 23:41:54 +01:00
										 |  |  | /// Use memdup_user rather than duplicating its implementation | 
					
						
							| 
									
										
										
										
											2010-08-24 17:39:07 +02:00
										 |  |  | /// This is a little bit restricted to reduce false positives | 
					
						
							|  |  |  | /// | 
					
						
							|  |  |  | // Confidence: High | 
					
						
							| 
									
										
										
										
											2012-01-14 23:41:54 +01:00
										 |  |  | // Copyright: (C) 2010-2012 Nicolas Palix.  GPLv2. | 
					
						
							|  |  |  | // Copyright: (C) 2010-2012 Julia Lawall, INRIA/LIP6.  GPLv2. | 
					
						
							|  |  |  | // Copyright: (C) 2010-2012 Gilles Muller, INRIA/LiP6.  GPLv2. | 
					
						
							| 
									
										
										
										
											2010-08-24 17:39:07 +02:00
										 |  |  | // URL: http://coccinelle.lip6.fr/ | 
					
						
							|  |  |  | // Comments: | 
					
						
							|  |  |  | // Options: -no_includes -include_headers | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | virtual patch | 
					
						
							| 
									
										
										
										
											2012-01-14 23:41:54 +01:00
										 |  |  | virtual context | 
					
						
							|  |  |  | virtual org | 
					
						
							|  |  |  | virtual report | 
					
						
							| 
									
										
										
										
											2010-08-24 17:39:07 +02:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2012-01-14 23:41:54 +01:00
										 |  |  | @depends on patch@ | 
					
						
							| 
									
										
										
										
											2010-08-24 17:39:07 +02:00
										 |  |  | expression from,to,size,flag; | 
					
						
							|  |  |  | identifier l1,l2; | 
					
						
							|  |  |  | @@ | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2012-01-14 23:41:54 +01:00
										 |  |  | -  to = \(kmalloc\|kzalloc\)(size,flag); | 
					
						
							| 
									
										
										
										
											2010-08-24 17:39:07 +02:00
										 |  |  | +  to = memdup_user(from,size); | 
					
						
							|  |  |  |    if ( | 
					
						
							|  |  |  | -      to==NULL | 
					
						
							|  |  |  | +      IS_ERR(to) | 
					
						
							|  |  |  |                  || ...) { | 
					
						
							|  |  |  |    <+... when != goto l1; | 
					
						
							|  |  |  | -  -ENOMEM | 
					
						
							|  |  |  | +  PTR_ERR(to) | 
					
						
							|  |  |  |    ...+> | 
					
						
							|  |  |  |    } | 
					
						
							|  |  |  | -  if (copy_from_user(to, from, size) != 0) { | 
					
						
							|  |  |  | -    <+... when != goto l2; | 
					
						
							|  |  |  | -    -EFAULT | 
					
						
							|  |  |  | -    ...+> | 
					
						
							|  |  |  | -  } | 
					
						
							| 
									
										
										
										
											2012-01-14 23:41:54 +01:00
										 |  |  | 
 | 
					
						
							|  |  |  | @r depends on !patch@ | 
					
						
							|  |  |  | expression from,to,size,flag; | 
					
						
							|  |  |  | position p; | 
					
						
							|  |  |  | statement S1,S2; | 
					
						
							|  |  |  | @@ | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | *  to = \(kmalloc@p\|kzalloc@p\)(size,flag); | 
					
						
							|  |  |  |    if (to==NULL || ...) S1 | 
					
						
							|  |  |  |    if (copy_from_user(to, from, size) != 0) | 
					
						
							|  |  |  |    S2 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | @script:python depends on org@ | 
					
						
							|  |  |  | p << r.p; | 
					
						
							|  |  |  | @@ | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | coccilib.org.print_todo(p[0], "WARNING opportunity for memdep_user") | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | @script:python depends on report@ | 
					
						
							|  |  |  | p << r.p; | 
					
						
							|  |  |  | @@ | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | coccilib.report.print_report(p[0], "WARNING opportunity for memdep_user") |