stm32mp: fix various array bounds checks

In all these cases, the index on the LHS is immediately afterwards
used to access the array appearing in the ARRAY_SIZE() on the RHS - so
if that index is equal to the array size, we'll access
one-past-the-end of the array.

Signed-off-by: Rasmus Villemoes <rasmus.villemoes@prevas.dk>
Reviewed-by: Patrice Chotard <patrice.chotard@foss.st.com>
Reviewed-by: Patrick Delaunay <patrick.delaunay@foss.st.com>
This commit is contained in:
Rasmus Villemoes 2023-03-24 08:55:19 +01:00 committed by Patrice Chotard
parent bb03520098
commit daf07215e8
3 changed files with 4 additions and 4 deletions

View file

@ -190,7 +190,7 @@ static void setup_boot_mode(void)
__func__, boot_ctx, boot_mode, instance, forced_mode); __func__, boot_ctx, boot_mode, instance, forced_mode);
switch (boot_mode & TAMP_BOOT_DEVICE_MASK) { switch (boot_mode & TAMP_BOOT_DEVICE_MASK) {
case BOOT_SERIAL_UART: case BOOT_SERIAL_UART:
if (instance > ARRAY_SIZE(serial_addr)) if (instance >= ARRAY_SIZE(serial_addr))
break; break;
/* serial : search associated node in devicetree */ /* serial : search associated node in devicetree */
sprintf(cmd, "serial@%x", serial_addr[instance]); sprintf(cmd, "serial@%x", serial_addr[instance]);
@ -220,7 +220,7 @@ static void setup_boot_mode(void)
break; break;
case BOOT_FLASH_SD: case BOOT_FLASH_SD:
case BOOT_FLASH_EMMC: case BOOT_FLASH_EMMC:
if (instance > ARRAY_SIZE(sdmmc_addr)) if (instance >= ARRAY_SIZE(sdmmc_addr))
break; break;
/* search associated sdmmc node in devicetree */ /* search associated sdmmc node in devicetree */
sprintf(cmd, "mmc@%x", sdmmc_addr[instance]); sprintf(cmd, "mmc@%x", sdmmc_addr[instance]);

View file

@ -872,7 +872,7 @@ int mmc_get_boot(void)
STM32_SDMMC3_BASE STM32_SDMMC3_BASE
}; };
if (instance > ARRAY_SIZE(sdmmc_addr)) if (instance >= ARRAY_SIZE(sdmmc_addr))
return 0; return 0;
/* search associated sdmmc node in devicetree */ /* search associated sdmmc node in devicetree */

View file

@ -391,7 +391,7 @@ bool stm32mp1_ddr_interactive(void *priv,
if (next_step < 0) if (next_step < 0)
return false; return false;
if (step < 0 || step > ARRAY_SIZE(step_str)) { if (step < 0 || step >= ARRAY_SIZE(step_str)) {
printf("** step %d ** INVALID\n", step); printf("** step %d ** INVALID\n", step);
return false; return false;
} }