>>>> The address of a data structure member was determined before >>>> a corresponding null pointer check in the implementation of >>>> the function “ics5342_init”. >>>> >>>> Thus avoid the risk for undefined behaviour by moving the assignment >>>> for the variable “info” behind a condition check. >>>> >>>> This issue was detected by using the Coccinelle software. >>> >>> There is no "risk" here. >>> It just adds an offset to a potential NULL value (which isn't then used >>> afterwards). >> Does your understanding of programming language details differ from the view >> of >> SEI CERT C Coding Standard (from the Carnegie Mellon University)? >> https://cmu-sei.github.io/secure-coding-standards/sei-cert-c-coding-standard/rules/expressions-exp/exp34-c/ > My statement still stands. > Try to find the difference between the code and the examples on that website > yourself. > Tip: The relevant part is the "&" and in doubt look at the generated assembly > code. Do any more code reviewers take another look at results from undefined behaviour sanitizers?
* https://clang.llvm.org/docs/UndefinedBehaviorSanitizer.html#introduction * https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/Documentation/dev-tools/ubsan.rst?h=v7.2-rc3#n6 See also: https://stackoverflow.com/questions/79662603/why-do-compilers-not-warn-about-this-null-dereferencing-even-when-they-detect-i#answer-79663272 Regards, Markus

