From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pg1-f169.google.com (mail-pg1-f169.google.com [209.85.215.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 39C3E70 for ; Mon, 24 May 2021 17:26:28 +0000 (UTC) Received: by mail-pg1-f169.google.com with SMTP id q15so20579135pgg.12 for ; Mon, 24 May 2021 10:26:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=subject:to:cc:references:from:message-id:date:user-agent :mime-version:in-reply-to:content-language:content-transfer-encoding; bh=Kc0+FMTh1fPx01D55Spy3LcqXmB7S09x8WY0Dxu365k=; b=fVTQMabckqboIr0/IMEVPxBxbF/HEtsovdQRtkXQiqkQOqTNwm/ID92EtPEYT2H6mg SqbYfSzv882VpyKwCoqaA73Eui7m/pXDku0QSpXoSkMuRnvYAASMG+8WRBna3VYsnVVi L1e8PRnRcoXF9TOvo5YuQ1H2x66VegH60wjEcUHtXFMqt+JQFwjUan+hCT7kW52DU2TC +q5aV/Li2YAeFmdKrBsykqJMSiCQ7HtkkpFGhIfLF7jx6ZordI5EAYh+akXgBcfIyChX a5DpY3PvYwZYz37rxG+g5THKVaNCdi7Y8uv1EnRIcdzlMzrF8wAF4uKey1CzScXHkryP GykQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:cc:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=Kc0+FMTh1fPx01D55Spy3LcqXmB7S09x8WY0Dxu365k=; b=i+XHFgXp8c/o0yCY4PhRulETgVjFG0+9cGbrB3WA03SiNqWrjoXZCPRmMbs3CfFkvb X2Pn2+mHIz4h1ug3RC9vzf7+yYKq7/wC2KrDd3nQAYavNj6DMPR8Wo3fgQBQhKqkpgMt U2GQiiierN5GWhTJW+h2pl1VgaHlpKjhgSgMFq38T87x8xgZKY9ldwAUwFcrtcxbkzGM A3fu+RJ+73GF74iZlY2T3+DdsZ8Eexpr7JatxcH3Z2m8idxaQwBhRzdPzJF0vTH/dG92 LgYuXU9RuiuwBDuB+zJbRNNhcgwu7eULpxk15IZgSVVEcLdpTOWNZdy3MKkGXPXZVZFq ujPA== X-Gm-Message-State: AOAM533PVoOAKNVhkNu0vBPwnnYJ/V7i0rwHjgKMaZbSjCr9GhjrZPmp lJv7PiM7pS76oJ5LYzmAZIQ= X-Google-Smtp-Source: ABdhPJzBL7dL+K4AaWffSd8Hhot68UFvNRF8DXg4o7RNb8LfCBNLbMB7ygs96g4hHsXIBRcg3JzZ8w== X-Received: by 2002:a63:7107:: with SMTP id m7mr14927390pgc.287.1621877187748; Mon, 24 May 2021 10:26:27 -0700 (PDT) Received: from [192.168.93.106] ([118.200.63.8]) by smtp.gmail.com with ESMTPSA id c16sm11392439pfd.206.2021.05.24.10.26.24 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 24 May 2021 10:26:27 -0700 (PDT) Subject: Re: [PATCH] staging: vchiq_arm: Using copy_from_user() to copy data from userspace address To: Al Viro Cc: nsaenz@kernel.org, gregkh@linuxfoundation.org, stefan.wahren@i2se.com, arnd@arndb.de, dan.carpenter@oracle.com, phil@raspberrypi.com, amarjargal16@gmail.com, bcm-kernel-feedback-list@broadcom.com, linux-rpi-kernel@lists.infradead.org, linux-arm-kernel@lists.infradead.org, linux-staging@lists.linux.dev, linux-kernel@vger.kernel.org References: <20210522053429.82710-1-phind.uet@gmail.com> From: Phi Nguyen Message-ID: <51eaace6-e464-147f-85be-ec8188e0e2ef@gmail.com> Date: Tue, 25 May 2021 01:26:23 +0800 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Thunderbird/78.8.1 X-Mailing-List: linux-staging@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8; format=flowed Content-Language: en-US Content-Transfer-Encoding: 7bit On 22/5/21 2:33 pm, Al Viro wrote: > On Sat, May 22, 2021 at 01:34:29PM +0800, Nguyen Dinh Phi wrote: >> This commit to fix the following sparse warning: >> incorrect type in assignment (different address spaces) >> expected void *[assigned] userdata >> got void [noderef] __user *userdata >> >> Signed-off-by: Nguyen Dinh Phi >> --- >> .../staging/vc04_services/interface/vchiq_arm/vchiq_arm.c | 5 ++++- >> 1 file changed, 4 insertions(+), 1 deletion(-) >> >> diff --git a/drivers/staging/vc04_services/interface/vchiq_arm/vchiq_arm.c b/drivers/staging/vc04_services/interface/vchiq_arm/vchiq_arm.c >> index afbf01b7364c..2a4fc599f977 100644 >> --- a/drivers/staging/vc04_services/interface/vchiq_arm/vchiq_arm.c >> +++ b/drivers/staging/vc04_services/interface/vchiq_arm/vchiq_arm.c >> @@ -960,7 +960,10 @@ static int vchiq_irq_queue_bulk_tx_rx(struct vchiq_instance *instance, >> current->pid); >> userdata = &waiter->bulk_waiter; >> } else { >> - userdata = args->userdata; >> + if (copy_from_user(userdata, args->userdata, sizeof(args->userdata))) { > > The contents of userdata (local variable of type void *) is uninitialized at that > point. Sorry, That was my mistake. > Just what do you think that call of copy_from_user() would do? Because according to the definition of struct vchiq_queue_bulk_transfer, the args->userdata pointer is userspace address. From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-12.2 required=3.0 tests=BAYES_00, DKIM_ADSP_CUSTOM_MED,DKIM_SIGNED,DKIM_VALID,FREEMAIL_FORGED_FROMDOMAIN, FREEMAIL_FROM,HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_CR_TRAILER, INCLUDES_PATCH,MAILING_LIST_MULTI,NICE_REPLY_A,SPF_HELO_NONE,SPF_PASS, URIBL_BLOCKED,USER_AGENT_SANE_1 autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 99E37C2B9F7 for ; Tue, 25 May 2021 00:38:07 +0000 (UTC) Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id 55B0A6135F for ; Tue, 25 May 2021 00:38:07 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org 55B0A6135F Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=gmail.com Authentication-Results: mail.kernel.org; spf=none smtp.mailfrom=linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:Content-Type: Content-Transfer-Encoding:List-Subscribe:List-Help:List-Post:List-Archive: List-Unsubscribe:List-Id:In-Reply-To:MIME-Version:Date:Message-ID:From: References:Cc:To:Subject:Reply-To:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=HgFMvy5r1Y2/24QqjDyFW3JiuJPN4RHqdX0fB+oILlY=; b=kuWkNqYJL3nS4ro3AYQ8fy1GT 0B5O81TY3BZMx+8xXpv34RtFObU6nLfzGR0yqtGlpg/ghRQbWcibEKfA3/CR2FhoGtNVcGxg5Xd3s MwmS6CgB7iwiAQuzMBqVFWWp5YFegmBHG9XmUYN2T42ZXl0raiUSySHDWEMcPIks5EOGevz0HRJ97 FvuqjVAS83D6Y8t6PBCZlAiRCC0n3cO3q1M7b/3sBnxwON/rbB5SOgQJ8wiQuz7cX70kCaV7KHi22 TQyXmA2nk90KCURW6HesOkCI8zkGrYlVYQwJJs3r6Re6VlzGu2iyydt9QUtbEBUTuGAZM45TcenC/ g+FT3M0qA==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.94 #2 (Red Hat Linux)) id 1llL3L-002aVA-Bl; Tue, 25 May 2021 00:36:11 +0000 Received: from mail-pg1-x530.google.com ([2607:f8b0:4864:20::530]) by bombadil.infradead.org with esmtps (Exim 4.94 #2 (Red Hat Linux)) id 1llELV-001GmN-Mj; Mon, 24 May 2021 17:26:31 +0000 Received: by mail-pg1-x530.google.com with SMTP id r1so5736848pgk.8; Mon, 24 May 2021 10:26:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=subject:to:cc:references:from:message-id:date:user-agent :mime-version:in-reply-to:content-language:content-transfer-encoding; bh=Kc0+FMTh1fPx01D55Spy3LcqXmB7S09x8WY0Dxu365k=; b=fVTQMabckqboIr0/IMEVPxBxbF/HEtsovdQRtkXQiqkQOqTNwm/ID92EtPEYT2H6mg SqbYfSzv882VpyKwCoqaA73Eui7m/pXDku0QSpXoSkMuRnvYAASMG+8WRBna3VYsnVVi L1e8PRnRcoXF9TOvo5YuQ1H2x66VegH60wjEcUHtXFMqt+JQFwjUan+hCT7kW52DU2TC +q5aV/Li2YAeFmdKrBsykqJMSiCQ7HtkkpFGhIfLF7jx6ZordI5EAYh+akXgBcfIyChX a5DpY3PvYwZYz37rxG+g5THKVaNCdi7Y8uv1EnRIcdzlMzrF8wAF4uKey1CzScXHkryP GykQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:cc:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=Kc0+FMTh1fPx01D55Spy3LcqXmB7S09x8WY0Dxu365k=; b=OrAD/JqnzzeUKm8pd5ofhxrb0ipPz10DBeVB8/h50FxNWjFIqyQgkREyQJGBia8GlY oJZtLanDdhaBXOo4UTe1k0wH05f+2Y1wCa6ENDOPQzV8pEbrH+V0UPugVstR39M5e+Ee p5buaZCHvhF2IJVB4n7OaucwkhCC+DS48sdYCmS1Vqc+aqA0tva2FZJk3YQYJzFuZE5m e2wAV1/YGC49MADSirCSwRJlDfimAMSqViAcHt9ErExBlVe/uVbFU5LKRZrNu/tE9NKT y77qtGtX7gRhlGDd4MIgPP+wpCQr0L9QEjVl2CVnonY5NI90pVN9gmXEWR8RTMU0L7mv lXgw== X-Gm-Message-State: AOAM533Y6feGtF0wl+syaEBxlDV/OZViUmzNvFLkik93mlEjdLbXuQlQ xUQvFjlwqO9RlO2YAtZsc2A= X-Google-Smtp-Source: ABdhPJzBL7dL+K4AaWffSd8Hhot68UFvNRF8DXg4o7RNb8LfCBNLbMB7ygs96g4hHsXIBRcg3JzZ8w== X-Received: by 2002:a63:7107:: with SMTP id m7mr14927390pgc.287.1621877187748; Mon, 24 May 2021 10:26:27 -0700 (PDT) Received: from [192.168.93.106] ([118.200.63.8]) by smtp.gmail.com with ESMTPSA id c16sm11392439pfd.206.2021.05.24.10.26.24 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 24 May 2021 10:26:27 -0700 (PDT) Subject: Re: [PATCH] staging: vchiq_arm: Using copy_from_user() to copy data from userspace address To: Al Viro Cc: nsaenz@kernel.org, gregkh@linuxfoundation.org, stefan.wahren@i2se.com, arnd@arndb.de, dan.carpenter@oracle.com, phil@raspberrypi.com, amarjargal16@gmail.com, bcm-kernel-feedback-list@broadcom.com, linux-rpi-kernel@lists.infradead.org, linux-arm-kernel@lists.infradead.org, linux-staging@lists.linux.dev, linux-kernel@vger.kernel.org References: <20210522053429.82710-1-phind.uet@gmail.com> From: Phi Nguyen Message-ID: <51eaace6-e464-147f-85be-ec8188e0e2ef@gmail.com> Date: Tue, 25 May 2021 01:26:23 +0800 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Thunderbird/78.8.1 MIME-Version: 1.0 In-Reply-To: Content-Language: en-US X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20210524_102629_846286_75C1406B X-CRM114-Status: GOOD ( 18.61 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Transfer-Encoding: 7bit Content-Type: text/plain; charset="us-ascii"; Format="flowed" Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org On 22/5/21 2:33 pm, Al Viro wrote: > On Sat, May 22, 2021 at 01:34:29PM +0800, Nguyen Dinh Phi wrote: >> This commit to fix the following sparse warning: >> incorrect type in assignment (different address spaces) >> expected void *[assigned] userdata >> got void [noderef] __user *userdata >> >> Signed-off-by: Nguyen Dinh Phi >> --- >> .../staging/vc04_services/interface/vchiq_arm/vchiq_arm.c | 5 ++++- >> 1 file changed, 4 insertions(+), 1 deletion(-) >> >> diff --git a/drivers/staging/vc04_services/interface/vchiq_arm/vchiq_arm.c b/drivers/staging/vc04_services/interface/vchiq_arm/vchiq_arm.c >> index afbf01b7364c..2a4fc599f977 100644 >> --- a/drivers/staging/vc04_services/interface/vchiq_arm/vchiq_arm.c >> +++ b/drivers/staging/vc04_services/interface/vchiq_arm/vchiq_arm.c >> @@ -960,7 +960,10 @@ static int vchiq_irq_queue_bulk_tx_rx(struct vchiq_instance *instance, >> current->pid); >> userdata = &waiter->bulk_waiter; >> } else { >> - userdata = args->userdata; >> + if (copy_from_user(userdata, args->userdata, sizeof(args->userdata))) { > > The contents of userdata (local variable of type void *) is uninitialized at that > point. Sorry, That was my mistake. > Just what do you think that call of copy_from_user() would do? Because according to the definition of struct vchiq_queue_bulk_transfer, the args->userdata pointer is userspace address. _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel