@@ -39,6 +39,28 @@ identifier l1,l2;
39
39
- ...+>
40
40
- }
41
41
42
+ @depends on patch@
43
+ expression from,to,size;
44
+ identifier l1,l2;
45
+ @@
46
+
47
+ - to = \(kvmalloc\|kvzalloc\)(size,\(GFP_KERNEL\|GFP_USER\));
48
+ + to = vmemdup_user(from,size);
49
+ if (
50
+ - to==NULL
51
+ + IS_ERR(to)
52
+ || ... ) {
53
+ <+ ... when != goto l1;
54
+ - -ENOMEM
55
+ + PTR_ERR(to)
56
+ ... +>
57
+ }
58
+ - if (copy_from_user(to, from, size) != 0) {
59
+ - <+... when != goto l2;
60
+ - -EFAULT
61
+ - ...+>
62
+ - }
63
+
42
64
@r depends on !patch@
43
65
expression from,to,size;
44
66
position p;
@@ -52,6 +74,17 @@ statement S1,S2;
52
74
if (copy_from_user(to, from, size) != 0)
53
75
S2
54
76
77
+ @rv depends on !patch@
78
+ expression from,to,size;
79
+ position p;
80
+ statement S1,S2;
81
+ @@
82
+
83
+ * to = \(kvmalloc@p\|kvzalloc@p\)(size,\(GFP_KERNEL\|GFP_USER\));
84
+ if (to==NULL || ... ) S1
85
+ if (copy_from_user(to, from, size) != 0)
86
+ S2
87
+
55
88
@script:python depends on org@
56
89
p << r.p;
57
90
@@
@@ -63,3 +96,15 @@ p << r.p;
63
96
@@
64
97
65
98
coccilib.report.print_report(p[0 ], " WARNING opportunity for memdup_user" )
99
+
100
+ @script:python depends on org@
101
+ p << rv.p;
102
+ @@
103
+
104
+ coccilib.org.print_todo(p[0 ], " WARNING opportunity for vmemdup_user" )
105
+
106
+ @script:python depends on report@
107
+ p << rv.p;
108
+ @@
109
+
110
+ coccilib.report.print_report(p[0 ], " WARNING opportunity for vmemdup_user" )
0 commit comments