From: Kees Cook <[email protected]>

In preparation for converting the kmalloc family of allocators to the
type-aware kmalloc_obj family, we need to make sure that the returned
type from the allocation matches the type of the variable being
assigned. (The kmalloc family returns "void *", which can be implicitly
cast to any pointer type.)

These allocate as many pointers as ebc_key_maps and ebc_func_table hold,
but the sizes were taken from the whole arrays, which would make the
allocation types pointers to those arrays rather than the "u_short **"
and "char **" being assigned. Allocate ARRAY_SIZE-many entries instead.
The resulting allocation sizes are the same.

Build tested ARCH=s390 allmodconfig with GCC s390x-linux-gnu 16.1.0:
drivers/s390/char/keyboard.o

Assisted-by: LLM coccinelle
Signed-off-by: Kees Cook <[email protected]>
---
Cc: Heiko Carstens <[email protected]>
Cc: Vasily Gorbik <[email protected]>
Cc: Alexander Gordeev <[email protected]>
Cc: Christian Borntraeger <[email protected]>
Cc: Sven Schnelle <[email protected]>
Cc: <[email protected]>
---
 drivers/s390/char/keyboard.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/drivers/s390/char/keyboard.c b/drivers/s390/char/keyboard.c
index ecd9ace2b3aa..63bcb52d6e87 100644
--- a/drivers/s390/char/keyboard.c
+++ b/drivers/s390/char/keyboard.c
@@ -81,7 +81,8 @@ kbd_alloc(void) {
        kbd = kzalloc_obj(struct kbd_data);
        if (!kbd)
                goto out;
-       kbd->key_maps = kzalloc(sizeof(ebc_key_maps), GFP_KERNEL);
+       kbd->key_maps = kcalloc(ARRAY_SIZE(ebc_key_maps),
+                               sizeof(*kbd->key_maps), GFP_KERNEL);
        if (!kbd->key_maps)
                goto out_kbd;
        for (i = 0; i < ARRAY_SIZE(ebc_key_maps); i++) {
@@ -93,7 +94,8 @@ kbd_alloc(void) {
                                goto out_maps;
                }
        }
-       kbd->func_table = kzalloc(sizeof(ebc_func_table), GFP_KERNEL);
+       kbd->func_table = kcalloc(ARRAY_SIZE(ebc_func_table),
+                                 sizeof(*kbd->func_table), GFP_KERNEL);
        if (!kbd->func_table)
                goto out_maps;
        for (i = 0; i < ARRAY_SIZE(ebc_func_table); i++) {
-- 
2.34.1


Reply via email to