Blame view

kernel/linux-rt-4.4.41/scripts/coccinelle/api/memdup_user.cocci 1.27 KB
5113f6f70   김현기   kernel add
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
  /// Use memdup_user rather than duplicating its implementation
  /// This is a little bit restricted to reduce false positives
  ///
  // Confidence: High
  // Copyright: (C) 2010-2012 Nicolas Palix.  GPLv2.
  // Copyright: (C) 2010-2012 Julia Lawall, INRIA/LIP6.  GPLv2.
  // Copyright: (C) 2010-2012 Gilles Muller, INRIA/LiP6.  GPLv2.
  // URL: http://coccinelle.lip6.fr/
  // Comments:
  // Options: --no-includes --include-headers
  
  virtual patch
  virtual context
  virtual org
  virtual report
  
  @depends on patch@
  expression from,to,size,flag;
  identifier l1,l2;
  @@
  
  -  to = \(kmalloc\|kzalloc\)(size,flag);
  +  to = memdup_user(from,size);
     if (
  -      to==NULL
  +      IS_ERR(to)
                   || ...) {
     <+... when != goto l1;
  -  -ENOMEM
  +  PTR_ERR(to)
     ...+>
     }
  -  if (copy_from_user(to, from, size) != 0) {
  -    <+... when != goto l2;
  -    -EFAULT
  -    ...+>
  -  }
  
  @r depends on !patch@
  expression from,to,size,flag;
  position p;
  statement S1,S2;
  @@
  
  *  to = \(kmalloc@p\|kzalloc@p\)(size,flag);
     if (to==NULL || ...) S1
     if (copy_from_user(to, from, size) != 0)
     S2
  
  @script:python depends on org@
  p << r.p;
  @@
  
  coccilib.org.print_todo(p[0], "WARNING opportunity for memdup_user")
  
  @script:python depends on report@
  p << r.p;
  @@
  
  coccilib.report.print_report(p[0], "WARNING opportunity for memdup_user")