On Fri, May 21, 2021 at 06:07:05PM +0800, Yu Kuai wrote:
The length of array 'pts_reply' is 4, and the loop in set_protocol()
will access array element from 0 to num_bytes_read - 1. Thus if
io_read_num_rec_bytes() gets 'num_bytes_read' more than 4, it will
cause index out of bounds errors.
And how can num_bytes_read be greater than 4?
Ah, it is tested, but you might want to error out if that happens, as
obviously something went wrong.
Do you have this hardware to test these changes?
thanks,
greg k-h
.