All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Baineng Shou" <shoubaineng@gmail.com>
Cc: media-ci@linuxtv.org, dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v7 3/4] drm/prime: use dma_buf_fd_install() to preserve export tracing
Date: Mon, 17 Aug 2026 05:14:39 +0000	[thread overview]
Message-ID: <20260817051439.CF6BE1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260817050457.1005285-4-shoubaineng@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] The file descriptor is published to userspace before copy_to_user() succeeds, violating the dma_buf_fd_install() API contract and causing a resource leak on error.
--

--- Patch [3]: [PATCH v7 3/4] drm/prime: use dma_buf_fd_install() to preserve export tracing ---
commit edfa3fdf8153dcc15c693c10359892f042189a1c
Author: Baineng Shou <shoubaineng@gmail.com>

drm/prime: use dma_buf_fd_install() to preserve export tracing
    
This commit replaces fd_install() with dma_buf_fd_install() in
drm_gem_prime_handle_to_fd() to restore tracepoint coverage for DRM PRIME
exports. It asserts that the file descriptor lifecycle is already correct.

Link: https://lore.kernel.org/dri-devel/20260714114654.3885457-2-shoubaineng@gmail.com/

> No functional change; the fd lifecycle (get_unused_fd_flags
> -> work -> install) is already correct.

[Severity: High]
This isn't a bug introduced by this patch, but is this claim about the fd
lifecycle being correct accurate?

The new dma_buf_fd_install() API requires that it must only be called after
all fallible work (such as copy_to_user) has succeeded.

> diff --git a/drivers/gpu/drm/drm_prime.c b/drivers/gpu/drm/drm_prime.c
> index 9b44c78cd77fc..fe3436d1235db 100644
> --- a/drivers/gpu/drm/drm_prime.c
> +++ b/drivers/gpu/drm/drm_prime.c
[ ... ]
> @@ -524,7 +524,7 @@ int drm_gem_prime_handle_to_fd(struct drm_device *dev,
>  		return PTR_ERR(dmabuf);
>  	}
>  
> -	fd_install(fd, dmabuf->file);
> +	dma_buf_fd_install(dmabuf, fd);

[Severity: High]
This is a pre-existing issue, but by adopting the new dma_buf_fd_install()
API, doesn't this code path violate its documented contract?

Can this lead to a file descriptor leak if a userspace application calls the
DRM_IOCTL_PRIME_HANDLE_TO_FD ioctl with an invalid userspace pointer?

If drm_gem_prime_handle_to_fd() publishes the file descriptor to the
userspace fdtable here:

dma_buf_fd_install(dmabuf, fd);
*prime_fd = fd;
return 0;

Then the DRM core ioctl dispatcher attempts to copy the result to userspace
after the handler returns, which can fail:

drivers/gpu/drm/drm_ioctl.c:drm_ioctl() {
    ...
    retcode = func(dev, kdata, file_priv);
    ...
    if (copy_to_user((void __user *)arg, kdata, out_size) != 0)
        retcode = -EFAULT;
    ...
}

Wouldn't the failed copy_to_user() return -EFAULT and leave the already
installed fd orphaned in the process's fdtable, without the application
ever receiving the fd number to close it?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260817050457.1005285-1-shoubaineng@gmail.com?part=3

  reply	other threads:[~2026-08-17  5:14 UTC|newest]

Thread overview: 58+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-03  8:09 [PATCH] dma-buf: dma-heap: close installed fd when copy_to_user() fails Baineng Shou
2026-07-03  8:17 ` sashiko-bot
2026-07-03  8:26 ` Christian König
2026-07-10 10:57 ` [PATCH v2] dma-buf: dma-heap: don't publish fd before copy_to_user() succeeds Baineng Shou
2026-07-10 11:06   ` sashiko-bot
2026-07-10 20:20     ` T.J. Mercier
2026-07-11  4:18       ` 寿柏能
2026-07-13 23:33         ` T.J. Mercier
2026-07-14 11:46           ` [PATCH v3 0/2] dma-buf: fix fd leak when copy_to_user() fails after fd_install() Baineng Shou
2026-07-14 11:46             ` [PATCH v3 1/2] dma-buf: dma-heap: don't publish fd before copy_to_user() succeeds Baineng Shou
2026-07-14 13:13               ` David Laight
2026-07-14 13:38                 ` 寿柏能
2026-07-14 14:33                   ` David Laight
2026-07-15  2:04                     ` 寿柏能
     [not found]                       ` <CAGCp47zxaZsoBKeXz2YdyxbX8QOy_g8dGwnC9gVpJ-Sqng48Qg@mail.gmail.com>
2026-07-28  6:35                         ` Sumit Semwal
2026-07-30  6:25                           ` [PATCH v5 0/4] dma-buf: fix fd leak when copy_to_user() fails after fd_install() Baineng Shou
2026-07-30  6:25                             ` [PATCH v5 1/4] dma-buf: dma-heap: don't publish fd before copy_to_user() succeeds Baineng Shou
2026-07-30  6:25                             ` [PATCH v5 2/4] misc: fastrpc: " Baineng Shou
2026-07-30  6:26                           ` [PATCH v5 0/4] dma-buf: fix fd leak when copy_to_user() fails after fd_install() Baineng Shou
2026-07-30  6:26                             ` [PATCH v5 1/4] dma-buf: dma-heap: don't publish fd before copy_to_user() succeeds Baineng Shou
2026-07-30  6:26                             ` [PATCH v5 2/4] misc: fastrpc: " Baineng Shou
2026-07-30  6:26                             ` [PATCH v5 3/4] drm/prime: use dma_buf_fd_install() to preserve export tracing Baineng Shou
2026-07-30  6:40                               ` sashiko-bot
2026-07-31 17:14                               ` T.J. Mercier
2026-08-07 10:09                                 ` [PATCH v6 0/4] dma-buf: fix fd leak when copy_to_user() fails after fd_install() Baineng Shou
2026-08-07 10:10                                 ` Baineng Shou
2026-08-07 10:10                                   ` [PATCH v6 1/4] dma-buf: dma-heap: don't publish fd before copy_to_user() succeeds Baineng Shou
2026-08-07 10:10                                 ` [PATCH v6 0/4] dma-buf: fix fd leak when copy_to_user() fails after fd_install() Baineng Shou
2026-08-07 10:11                                 ` Baineng Shou
2026-08-07 10:11                                 ` Baineng Shou
2026-08-07 10:11                                   ` [PATCH v6 1/4] dma-buf: dma-heap: don't publish fd before copy_to_user() succeeds Baineng Shou
2026-08-07 10:11                                   ` [PATCH v6 2/4] misc: fastrpc: " Baineng Shou
2026-08-07 10:11                                   ` [PATCH v6 3/4] drm/prime: use dma_buf_fd_install() to preserve export tracing Baineng Shou
2026-08-07 10:22                                     ` sashiko-bot
2026-08-07 10:11                                   ` [PATCH v6 4/4] selftests: dmabuf-heaps: add fd-leak-on-EFAULT regression test Baineng Shou
2026-08-07 10:20                                     ` sashiko-bot
2026-08-07 21:49                                     ` T.J. Mercier
2026-08-12 15:27                                   ` [PATCH v6 0/4] dma-buf: fix fd leak when copy_to_user() fails after fd_install() Sumit Semwal
2026-08-17  5:04                                 ` [PATCH v7 " Baineng Shou
2026-08-17  5:04                                   ` [PATCH v7 1/4] dma-buf: dma-heap: don't publish fd before copy_to_user() succeeds Baineng Shou
2026-08-17  5:04                                   ` [PATCH v7 2/4] misc: fastrpc: " Baineng Shou
2026-08-17  5:20                                     ` sashiko-bot
2026-08-17  5:04                                   ` [PATCH v7 3/4] drm/prime: use dma_buf_fd_install() to preserve export tracing Baineng Shou
2026-08-17  5:14                                     ` sashiko-bot [this message]
2026-08-17  5:04                                   ` [PATCH v7 4/4] selftests: dmabuf-heaps: add fd-leak-on-EFAULT regression test Baineng Shou
2026-08-17  5:14                                     ` sashiko-bot
2026-07-30  6:26                             ` [PATCH v5 " Baineng Shou
2026-07-30  6:38                               ` sashiko-bot
2026-07-31 17:09                               ` T.J. Mercier
2026-07-14 11:46             ` [PATCH v3 2/2] misc: fastrpc: don't publish fd before copy_to_user() succeeds Baineng Shou
2026-07-14 12:08               ` sashiko-bot
2026-07-15 20:44               ` T.J. Mercier
2026-07-14 12:24             ` [PATCH v3 0/2] dma-buf: fix fd leak when copy_to_user() fails after fd_install() Christian König
2026-07-14 13:27               ` [PATCH v3] drm/prime: use dma_buf_fd_install() to preserve export tracing Baineng Shou
2026-07-14 13:45                 ` sashiko-bot
2026-07-10 12:33   ` [PATCH v2] dma-buf: dma-heap: don't publish fd before copy_to_user() succeeds Christian König
2026-07-11  4:14 ` Baineng Shou
2026-07-11  4:29   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260817051439.CF6BE1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=media-ci@linuxtv.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=shoubaineng@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.