1. May 05, 2011
  2. May 04, 2011
    • Thomas Gleixner's avatar
      alarmtimer: Drop device refcount after rtc_open() · 179eb032
      Thomas Gleixner authored
      
      
      class_find_device() takes a refcount on the rtc device. rtc_open()
      takes another one, so we can drop it after the rtc_open() call.
      
      Signed-off-by: default avatarThomas Gleixner <tglx@linutronix.de>
      Cc: John Stultz <john.stultz@linaro.org>
      179eb032
    • Thomas Gleixner's avatar
      alarmtimer: Check return value of class_find_device() · ce788f93
      Thomas Gleixner authored
      
      
      alarmtimer_late_init() uses class_find_device() to find a alarm
      capable rtc device. The match callback stores a pointer to the name in
      the char pointer handed in from the call site. alarmtimer_late_init()
      checks the char pointer for NULL, but the pointer is on the stack and
      not initialized to NULL before the call. So it can have random content
      when the match function did not identify a device, which leads to
      random access in the following rtc_open() call where the pointer is
      dereferenced
      
      Instead of relying on the char pointer, check the return value of
      class_find_device. If a device is found then the name pointer is valid
      as well.
      
      Reported-by: default avatarIngo Molnar <mingo@elte.hu>
      Cc: John Stultz <john.stultz@linaro.org>
      Signed-off-by: default avatarThomas Gleixner <tglx@linutronix.de>
      ce788f93
  3. May 03, 2011
  4. May 02, 2011
  5. May 01, 2011
  6. Apr 30, 2011
  7. Apr 29, 2011