Revert "Staging: android: binder: More offset validation."
authorRiley Andrews <riandrews@google.com>
Sat, 10 Jan 2015 03:08:03 +0000 (19:08 -0800)
committerRiley Andrews <riandrews@google.com>
Tue, 13 Jan 2015 22:33:06 +0000 (22:33 +0000)
This reverts commit 3fac2c119f537d4d8fea3f0b9063d72f44857b82.

Change-Id: I8840b43eceff9ef52d9bae2079d22046488a4ec2

drivers/staging/android/binder.c

index 9c821f398cad6424c3e8ddb2dac21da61b06126d..e718c84372a67bf46b03a84c72c5177d4cd59ad3 100644 (file)
@@ -1307,7 +1307,6 @@ static void binder_transaction(struct binder_proc *proc,
        struct binder_transaction *t;
        struct binder_work *tcomplete;
        binder_size_t *offp, *off_end;
-       binder_size_t off_min;
        struct binder_proc *target_proc;
        struct binder_thread *target_thread = NULL;
        struct binder_node *target_node = NULL;
@@ -1506,23 +1505,17 @@ static void binder_transaction(struct binder_proc *proc,
                goto err_bad_offset;
        }
        off_end = (void *)offp + tr->offsets_size;
-       off_min = 0;
        for (; offp < off_end; offp++) {
                struct flat_binder_object *fp;
                if (*offp > t->buffer->data_size - sizeof(*fp) ||
-                   *offp < off_min ||
                    t->buffer->data_size < sizeof(*fp) ||
                    !IS_ALIGNED(*offp, sizeof(u32))) {
-                       binder_user_error("%d:%d got transaction with invalid offset, %lld (min %lld, max %lld)\n",
-                                         proc->pid, thread->pid, (u64)*offp,
-                                         (u64)off_min,
-                                         (u64)(t->buffer->data_size -
-                                         sizeof(*fp)));
+                       binder_user_error("%d:%d got transaction with invalid offset, %lld\n",
+                                         proc->pid, thread->pid, (u64)*offp);
                        return_error = BR_FAILED_REPLY;
                        goto err_bad_offset;
                }
                fp = (struct flat_binder_object *)(t->buffer->data + *offp);
-               off_min = *offp + sizeof(struct flat_binder_object);
                switch (fp->type) {
                case BINDER_TYPE_BINDER:
                case BINDER_TYPE_WEAK_BINDER: {