All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] usbfront: do not assume sequentially mapped pages
@ 2009-03-30 15:02 Ian Jackson
  2009-04-01  6:05 ` Noboru Iwamatsu
  0 siblings, 1 reply; 6+ messages in thread
From: Ian Jackson @ 2009-03-30 15:02 UTC (permalink / raw)
  To: xen-devel

xenhcd_gnttab_map in usbfront-q.c looks up the mfn of the start of the
usb transfer buffer.  But the buffer may span several pages, and the
current code simply increments the obtained mfn.  Needless to say this
is an unwarranted assumption.  It causes large transfers to be
corrupted and/or to overwrite other parts of memory.

Signed-off-by: Ian Jackson <ian.jackson@eu.citrix.com>

diff -r 87c84f7dd850 drivers/xen/usbfront/usbfront-q.c
--- a/drivers/xen/usbfront/usbfront-q.c	Fri Mar 20 09:00:58 2009 +0000
+++ b/drivers/xen/usbfront/usbfront-q.c	Fri Mar 27 17:53:12 2009 +0100
@@ -106,12 +106,15 @@ static inline void xenhcd_gnttab_map(str
 	unsigned int bytes;
 	int i;
 
-	page = virt_to_page(addr);
-	buffer_pfn = page_to_phys(page) >> PAGE_SHIFT;
-	offset = offset_in_page(addr);
 	len = length;
 
 	for(i = 0;i < nr_pages;i++){
+		BUG_ON(!len);
+
+		page = virt_to_page(addr);
+		buffer_pfn = page_to_phys(page) >> PAGE_SHIFT;
+		offset = offset_in_page(addr);
+
 		bytes = PAGE_SIZE - offset;
 		if(bytes > len)
 			bytes = len;
@@ -123,9 +126,8 @@ static inline void xenhcd_gnttab_map(str
 		seg[i].offset = (uint16_t)offset;
 		seg[i].length = (uint16_t)bytes;
 
-		buffer_pfn++;
+		addr += bytes;
 		len -= bytes;
-		offset = 0;
 	}
 }

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2009-04-08  2:15 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-03-30 15:02 [PATCH] usbfront: do not assume sequentially mapped pages Ian Jackson
2009-04-01  6:05 ` Noboru Iwamatsu
2009-04-01 16:00   ` Ian Jackson
2009-04-06  9:03     ` Noboru Iwamatsu
2009-04-07 16:40       ` Ian Jackson
2009-04-08  2:15         ` Noboru Iwamatsu

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.