Bluetooth: mgmt: Use struct_size() helper
authorGustavo A. R. Silva <gustavo@embeddedor.com>
Mon, 25 Feb 2019 19:11:37 +0000 (13:11 -0600)
committerMarcel Holtmann <marcel@holtmann.org>
Tue, 26 Feb 2019 08:46:49 +0000 (09:46 +0100)
Make use of the struct_size() helper instead of an open-coded version
in order to avoid any potential type mistakes, in particular in the
context in which this code is being used.

So, change the following form:

sizeof(*rp) + (sizeof(rp->entry[0]) * count);

to :

struct_size(rp, entry, count)

Notice that, in this case, variable rp_len is not necessary, hence
it is removed.

This code was detected with the help of Coccinelle.

Signed-off-by: Gustavo A. R. Silva <gustavo@embeddedor.com>
Signed-off-by: Marcel Holtmann <marcel@holtmann.org>
net/bluetooth/mgmt.c

index ccce954f814682a40ba5d8af0ab463d5b0bfda3b..1e2acaddcdfdccabccca7a6509636367b4519e8a 100644 (file)
@@ -474,7 +474,6 @@ static int read_ext_index_list(struct sock *sk, struct hci_dev *hdev,
 {
        struct mgmt_rp_read_ext_index_list *rp;
        struct hci_dev *d;
-       size_t rp_len;
        u16 count;
        int err;
 
@@ -488,8 +487,7 @@ static int read_ext_index_list(struct sock *sk, struct hci_dev *hdev,
                        count++;
        }
 
-       rp_len = sizeof(*rp) + (sizeof(rp->entry[0]) * count);
-       rp = kmalloc(rp_len, GFP_ATOMIC);
+       rp = kmalloc(struct_size(rp, entry, count), GFP_ATOMIC);
        if (!rp) {
                read_unlock(&hci_dev_list_lock);
                return -ENOMEM;
@@ -525,7 +523,6 @@ static int read_ext_index_list(struct sock *sk, struct hci_dev *hdev,
        }
 
        rp->num_controllers = cpu_to_le16(count);
-       rp_len = sizeof(*rp) + (sizeof(rp->entry[0]) * count);
 
        read_unlock(&hci_dev_list_lock);
 
@@ -538,7 +535,8 @@ static int read_ext_index_list(struct sock *sk, struct hci_dev *hdev,
        hci_sock_clear_flag(sk, HCI_MGMT_UNCONF_INDEX_EVENTS);
 
        err = mgmt_cmd_complete(sk, MGMT_INDEX_NONE,
-                               MGMT_OP_READ_EXT_INDEX_LIST, 0, rp, rp_len);
+                               MGMT_OP_READ_EXT_INDEX_LIST, 0, rp,
+                               struct_size(rp, entry, count));
 
        kfree(rp);