All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Christian König" <christian.koenig@amd.com>
To: Dan Carpenter <dan.carpenter@oracle.com>,
	Alex Deucher <alexander.deucher@amd.com>
Cc: Sasha Levin <sasha.levin@oracle.com>, dri-devel@lists.freedesktop.org
Subject: Re: [patch] drm/radeon: integer underflow in radeon_cp_dispatch_texture()
Date: Mon, 29 Dec 2014 10:42:10 +0100	[thread overview]
Message-ID: <54A121F2.3040001@amd.com> (raw)
In-Reply-To: <20141223095649.GA21469@mwanda>

Am 23.12.2014 um 10:56 schrieb Dan Carpenter:
> The test:
>
> 	if (size > RADEON_MAX_TEXTURE_SIZE) {
>
> "size" is an integer and it's controled by the user so it can be
> negative and the test can underflow.  Later we use "size" in:
>
> 	dwords = size / 4;
> 	...
> 	RADEON_COPY_MT(buffer, data, (int)(dwords * sizeof(u32)));
>
> It causes memory corruption to copy a negative size buffer.
>
> Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>

This specific line of code is completely deprecated and the patch is 
just another coffin nail to finally remove it.

But since we can't be sure that it doesn't break any userspace still in 
use I'm generally ok to apply the patch and it is Reviewed-by: Christian 
König <christian.koenig@amd.com>

Regards,
Christian.

> ---
> Static checkers complain about the integer overflows here, and there are
> many real overflows but they appear harmless.
>
> diff --git a/drivers/gpu/drm/radeon/radeon_state.c b/drivers/gpu/drm/radeon/radeon_state.c
> index 535403e..15aee72 100644
> --- a/drivers/gpu/drm/radeon/radeon_state.c
> +++ b/drivers/gpu/drm/radeon/radeon_state.c
> @@ -1703,7 +1703,7 @@ static int radeon_cp_dispatch_texture(struct drm_device * dev,
>   	u32 format;
>   	u32 *buffer;
>   	const u8 __user *data;
> -	int size, dwords, tex_width, blit_width, spitch;
> +	unsigned int size, dwords, tex_width, blit_width, spitch;
>   	u32 height;
>   	int i;
>   	u32 texpitch, microtile;

_______________________________________________
dri-devel mailing list
dri-devel@lists.freedesktop.org
http://lists.freedesktop.org/mailman/listinfo/dri-devel

  reply	other threads:[~2014-12-29  9:42 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-12-23  9:56 [patch] drm/radeon: integer underflow in radeon_cp_dispatch_texture() Dan Carpenter
2014-12-29  9:42 ` Christian König [this message]
2015-01-05 17:10 ` Alex Deucher

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=54A121F2.3040001@amd.com \
    --to=christian.koenig@amd.com \
    --cc=alexander.deucher@amd.com \
    --cc=dan.carpenter@oracle.com \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=sasha.levin@oracle.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.