From: Kees Cook <[email protected]>

In preparation for making the devm_kmalloc family of allocators type
aware, we need to make sure that the returned type from the allocation
matches the type of the variable being assigned. (Before, the allocator
would always return "void *", which can be implicitly cast to any
pointer type.)

The assigned type of "scmi_sensors->info[type]" is
"const struct scmi_sensor_info **", but the converted allocation type
would be "const struct scmi_sensor_info ***", as the size was taken from
"*scmi_sensors->info", which is one level of indirection too many.
Luckily both element types are pointers of the same size. Take the size
from the element type of the assignment target.

Build tested ARCH=x86_64 allmodconfig with GCC 16.2.0:
drivers/hwmon/scmi-hwmon.o

Assisted-by: LLM coccinelle
Signed-off-by: Kees Cook <[email protected]>
---
Cc: Sudeep Holla <[email protected]>
Cc: Cristian Marussi <[email protected]>
Cc: Guenter Roeck <[email protected]>
Cc: <[email protected]>
Cc: <[email protected]>
Cc: <[email protected]>
---
 drivers/hwmon/scmi-hwmon.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/hwmon/scmi-hwmon.c b/drivers/hwmon/scmi-hwmon.c
index eec223d174c0..9ae8f774297e 100644
--- a/drivers/hwmon/scmi-hwmon.c
+++ b/drivers/hwmon/scmi-hwmon.c
@@ -305,7 +305,8 @@ static int scmi_hwmon_probe(struct scmi_device *sdev)
 
                scmi_sensors->info[type] =
                        devm_kcalloc(dev, nr_count[type],
-                                    sizeof(*scmi_sensors->info), GFP_KERNEL);
+                                    sizeof(*scmi_sensors->info[type]),
+                                    GFP_KERNEL);
                if (!scmi_sensors->info[type])
                        return -ENOMEM;
        }
-- 
2.34.1


Reply via email to