From owner-freebsd-wireless@freebsd.org Tue Dec 15 17:19:49 2015 Return-Path: Delivered-To: freebsd-wireless@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 2EB47A48577 for ; Tue, 15 Dec 2015 17:19:49 +0000 (UTC) (envelope-from adrian.chadd@gmail.com) Received: from mail-io0-x22d.google.com (mail-io0-x22d.google.com [IPv6:2607:f8b0:4001:c06::22d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 02F251133; Tue, 15 Dec 2015 17:19:49 +0000 (UTC) (envelope-from adrian.chadd@gmail.com) Received: by mail-io0-x22d.google.com with SMTP id e126so26892057ioa.1; Tue, 15 Dec 2015 09:19:48 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:sender:date:message-id:subject:from:to:content-type; bh=A05zV5TQVUnI+uj/LEpT1A746IAt2ZAT41bt8SDiwN0=; b=WjbIdxfAaM2uz+2rb/1pCD/DqCGm0kHFJ07hpIxFg1pFo9YBjD54HwLp11eJG9vyrx JubPis2inCNYxz2uvfniLKRQ5MMdqQuAvuHHxachaelmej/vrUUtodpf4wE3TJXjyr+/ lKHTMFAQdAcR7eNU71rW5yCo+haYdP6vEpykRnkloSGqgr3RZuN1Q8VPOZUiZf4Gvjs+ VI36+gU5N2TwZcuBZuhgcSnG5H9CLM01P5sYH/1tvs0KHcZLAJufxs134wF0JIPRdbXC mlRlhfkyIMw0ha9V/sC5od7Se2wRN4b1cAykfPBa/4Aog5tkvx6Z5tzfzYmuH5Nz7ZJ/ bmgA== MIME-Version: 1.0 X-Received: by 10.107.162.21 with SMTP id l21mr34238711ioe.123.1450199988418; Tue, 15 Dec 2015 09:19:48 -0800 (PST) Sender: adrian.chadd@gmail.com Received: by 10.36.121.202 with HTTP; Tue, 15 Dec 2015 09:19:48 -0800 (PST) Date: Tue, 15 Dec 2015 09:19:48 -0800 X-Google-Sender-Auth: iCNsTlbk-Ur2lGaHbaac6nNGOj0 Message-ID: Subject: coverity scan results for urtwn From: Adrian Chadd To: Andriy Voskoboinyk , Kevin Lo , "freebsd-wireless@freebsd.org" Content-Type: text/plain; charset=UTF-8 X-BeenThere: freebsd-wireless@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: "Discussions of 802.11 stack, tools device driver development." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 15 Dec 2015 17:19:49 -0000 hiya, this popped up from the freebsd.org coverity scan: ________________________________________________________________________________________________________ *** CID 1343338: Memory - illegal accesses (OVERRUN) /sys/dev/usb/wlan/if_urtwn.c: 4288 in urtwn_r88e_newassoc() 4282 4283 if (!isnew) 4284 return; 4285 4286 URTWN_NT_LOCK(sc); 4287 for (id = 0; id <= URTWN_MACID_MAX(sc); id++) { >>> CID 1343338: Memory - illegal accesses (OVERRUN) >>> Overrunning array "sc->node_list" of 63 8-byte elements at element index 63 (byte offset 504) using index "id" (which evaluates to 63). 4288 if (id != URTWN_MACID_BC && sc->node_list[id] == NULL) { 4289 un->id = id; 4290 sc->node_list[id] = ni; 4291 break; 4292 } 4293 } Would one of you figure it out? Thanks! -a