summaryrefslogtreecommitdiff
path: root/common/cmd_jffs2.c
diff options
context:
space:
mode:
authorPeter Tyser <ptyser@xes-inc.com>2010-12-30 15:47:56 -0600
committerWolfgang Denk <wd@denx.de>2011-01-19 00:04:43 +0100
commit141053d60ac459bc3859c06fe7cf16160077f937 (patch)
tree6b40cda4be9cb7bfb132bed3e02ca26cfa2ff59c /common/cmd_jffs2.c
parenteddf52b593c6c5dfa1c0ce51a6656e3635175feb (diff)
downloadu-boot-imx-141053d60ac459bc3859c06fe7cf16160077f937.zip
u-boot-imx-141053d60ac459bc3859c06fe7cf16160077f937.tar.gz
u-boot-imx-141053d60ac459bc3859c06fe7cf16160077f937.tar.bz2
cmd_jffs2: Fix get_part_sector_size_nor() overflow bug
When a flash partition was positioned at the very top of a 32-bit memory map (eg located at 0xf8000000 with a size of 0x8000000) get_part_sector_size_nor() would incorrectly calculate the partition's ending address to 0x0 due to overflow. When the overflow occurred get_part_sector_size_nor() would falsely return a sector size of 0. A sector size of 0 results in subsequent jffs2 operations failing. To workaround the overflow subtract 1 from calculated address of the partition endpoint. Signed-off-by: Peter Tyser <ptyser@xes-inc.com>
Diffstat (limited to 'common/cmd_jffs2.c')
-rw-r--r--common/cmd_jffs2.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/common/cmd_jffs2.c b/common/cmd_jffs2.c
index 0e7a6b0..27296dd 100644
--- a/common/cmd_jffs2.c
+++ b/common/cmd_jffs2.c
@@ -281,7 +281,7 @@ static inline u32 get_part_sector_size_nor(struct mtdids *id, struct part_info *
flash = &flash_info[id->num];
start_phys = flash->start[0] + part->offset;
- end_phys = start_phys + part->size;
+ end_phys = start_phys + part->size - 1;
for (i = 0; i < flash->sector_count; i++) {
if (flash->start[i] >= end_phys)