From mboxrd@z Thu Jan 1 00:00:00 1970 From: =?UTF-8?Q?Christian_K=c3=b6nig?= Subject: Re: [PATCH 1/2] drm/radeon: forbid mapping of userptr bo through radeon device file Date: Wed, 20 Apr 2016 15:26:19 +0200 Message-ID: <5717837B.3050407@vodafone.de> References: <1461071271-16072-1-git-send-email-jglisse@redhat.com> Mime-Version: 1.0 Content-Type: text/plain; charset="utf-8"; Format="flowed" Content-Transfer-Encoding: base64 Return-path: Received: from pegasos-out.vodafone.de (pegasos-out.vodafone.de [80.84.1.38]) by gabe.freedesktop.org (Postfix) with ESMTP id 6C1CE6E9CB for ; Wed, 20 Apr 2016 13:26:25 +0000 (UTC) In-Reply-To: <1461071271-16072-1-git-send-email-jglisse@redhat.com> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: dri-devel-bounces@lists.freedesktop.org Sender: "dri-devel" To: =?UTF-8?B?SsOpcsO0bWUgR2xpc3Nl?= , dri-devel@lists.freedesktop.org Cc: stable@vger.kernel.org List-Id: dri-devel@lists.freedesktop.org VGhlcmUgYXJlIGFsc28gY2hlY2tzIGluIChhbWRncHV8cmFkZW9uKV9nZW1fbW1hcF9pb2N0bCgp IHRvIHByZXZlbnQgCnRoaXMgYXMgd2VsbC4KCkJ1dCBpdCBzaG91bGRuJ3QgaHVydCB1cyB0byBj aGVjayB0aGF0IGhlcmUgYXMgd2VsbC4gU28gYm90aCBwYXRjaGVzIGFyZSAKUmV2aWV3ZWQtYnk6 IENocmlzdGlhbiBLw7ZuaWcgPGNocmlzdGlhbi5rb2VuaWdAYW1kLmNvbT4KClJlZ2FyZHMsCkNo cmlzdGlhbi4KCkFtIDE5LjA0LjIwMTYgdW0gMTU6MDcgc2NocmllYiBKw6lyw7RtZSBHbGlzc2U6 Cj4gQWxsb3dpbmcgdXNlcnB0ciBibyB3aGljaCBhcmUgYmFzaWNseSBhIGxpc3Qgb2YgcGFnZSBm cm9tIHNvbWUgdm1hCj4gKHNvIGVpdGhlciBhbm9ueW1vdXMgcGFnZSBvciBmaWxlIGJhY2tlZCBw YWdlKSB3b3VsZCBsZWFkIHRvIHNlcmlvdXMKPiBjb3JydXB0aW9uIG9mIGtlcm5lbCBzdHJ1Y3R1 cmVzIGFuZCBjb3VudGVycyAoYmVjYXVzZSB3ZSBvdmVyd3JpdGUKPiB0aGUgcGFnZS0+bWFwcGlu ZyBmaWVsZCB3aGVuIG1hcHBpbmcgYnVmZmVyKS4KPgo+IFRoaXMgd2lsbCBhbHJlYWR5IGJsb2Nr IGlmIHRoZSBidWZmZXIgd2FzIHBvcHVsYXRlZCBiZWZvcmUgYW55b25lIGRvZXMKPiB0cnkgdG8g bW1hcCBpdCBiZWNhdXNlIHRoZW4gVFRNX1BBR0VfRkxBR19TRyB3b3VsZCBiZSBzZXQgaW4gaW4g dGhlCj4gdHRtX3R0IGZsYWdzLiBCdXQgdGhhdCBmbGFnIGlzIGNoZWNrIGJlZm9yZSB0dG1fdHRf cG9wdWxhdGUgaW4gdGhlIHR0bQo+IHZtIGZhdWx0IGhhbmRsZXIuCj4KPiBTbyB0byBiZSBzYWZl IGp1c3QgYWRkIGEgY2hlY2sgdG8gdmVyaWZ5X2FjY2VzcygpIGNhbGxiYWNrLgo+Cj4gU2lnbmVk LW9mZi1ieTogSsOpcsO0bWUgR2xpc3NlIDxqZ2xpc3NlQHJlZGhhdC5jb20+Cj4gQ2M6IDxzdGFi bGVAdmdlci5rZXJuZWwub3JnPgo+IC0tLQo+ICAgZHJpdmVycy9ncHUvZHJtL3JhZGVvbi9yYWRl b25fdHRtLmMgfCAyICsrCj4gICAxIGZpbGUgY2hhbmdlZCwgMiBpbnNlcnRpb25zKCspCj4KPiBk aWZmIC0tZ2l0IGEvZHJpdmVycy9ncHUvZHJtL3JhZGVvbi9yYWRlb25fdHRtLmMgYi9kcml2ZXJz L2dwdS9kcm0vcmFkZW9uL3JhZGVvbl90dG0uYwo+IGluZGV4IDdkZGRmZGMuLjkwZjczOTQgMTAw NjQ0Cj4gLS0tIGEvZHJpdmVycy9ncHUvZHJtL3JhZGVvbi9yYWRlb25fdHRtLmMKPiArKysgYi9k cml2ZXJzL2dwdS9kcm0vcmFkZW9uL3JhZGVvbl90dG0uYwo+IEBAIC0yMzUsNiArMjM1LDggQEAg c3RhdGljIGludCByYWRlb25fdmVyaWZ5X2FjY2VzcyhzdHJ1Y3QgdHRtX2J1ZmZlcl9vYmplY3Qg KmJvLCBzdHJ1Y3QgZmlsZSAqZmlscCkKPiAgIHsKPiAgIAlzdHJ1Y3QgcmFkZW9uX2JvICpyYm8g PSBjb250YWluZXJfb2YoYm8sIHN0cnVjdCByYWRlb25fYm8sIHRibyk7Cj4gICAKPiArCWlmIChy YWRlb25fdHRtX3R0X2hhc191c2VycHRyKGJvLT50dG0pKQo+ICsJCXJldHVybiAtRVBFUk07Cj4g ICAJcmV0dXJuIGRybV92bWFfbm9kZV92ZXJpZnlfYWNjZXNzKCZyYm8tPmdlbV9iYXNlLnZtYV9u b2RlLCBmaWxwKTsKPiAgIH0KPiAgIAoKX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f X19fX19fX19fX19fX18KZHJpLWRldmVsIG1haWxpbmcgbGlzdApkcmktZGV2ZWxAbGlzdHMuZnJl ZWRlc2t0b3Aub3JnCmh0dHBzOi8vbGlzdHMuZnJlZWRlc2t0b3Aub3JnL21haWxtYW4vbGlzdGlu Zm8vZHJpLWRldmVsCg== From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from pegasos-out.vodafone.de ([80.84.1.38]:43542 "EHLO pegasos-out.vodafone.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752908AbcDTNc4 (ORCPT ); Wed, 20 Apr 2016 09:32:56 -0400 Received: from localhost (localhost.localdomain [127.0.0.1]) by pegasos-out.vodafone.de (Rohrpostix1 Daemon) with ESMTP id BD6F3261984 for ; Wed, 20 Apr 2016 15:26:23 +0200 (CEST) Received: from pegasos-out.vodafone.de ([127.0.0.1]) by localhost (rohrpostix1.prod.vfnet.de [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pJ8jn++v9YnY for ; Wed, 20 Apr 2016 15:26:21 +0200 (CEST) Subject: Re: [PATCH 1/2] drm/radeon: forbid mapping of userptr bo through radeon device file To: =?UTF-8?B?SsOpcsO0bWUgR2xpc3Nl?= , dri-devel@lists.freedesktop.org References: <1461071271-16072-1-git-send-email-jglisse@redhat.com> Cc: stable@vger.kernel.org From: =?UTF-8?Q?Christian_K=c3=b6nig?= Message-ID: <5717837B.3050407@vodafone.de> Date: Wed, 20 Apr 2016 15:26:19 +0200 MIME-Version: 1.0 In-Reply-To: <1461071271-16072-1-git-send-email-jglisse@redhat.com> Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 8bit Sender: stable-owner@vger.kernel.org List-ID: There are also checks in (amdgpu|radeon)_gem_mmap_ioctl() to prevent this as well. But it shouldn't hurt us to check that here as well. So both patches are Reviewed-by: Christian König Regards, Christian. Am 19.04.2016 um 15:07 schrieb Jérôme Glisse: > Allowing userptr bo which are basicly a list of page from some vma > (so either anonymous page or file backed page) would lead to serious > corruption of kernel structures and counters (because we overwrite > the page->mapping field when mapping buffer). > > This will already block if the buffer was populated before anyone does > try to mmap it because then TTM_PAGE_FLAG_SG would be set in in the > ttm_tt flags. But that flag is check before ttm_tt_populate in the ttm > vm fault handler. > > So to be safe just add a check to verify_access() callback. > > Signed-off-by: Jérôme Glisse > Cc: > --- > drivers/gpu/drm/radeon/radeon_ttm.c | 2 ++ > 1 file changed, 2 insertions(+) > > diff --git a/drivers/gpu/drm/radeon/radeon_ttm.c b/drivers/gpu/drm/radeon/radeon_ttm.c > index 7dddfdc..90f7394 100644 > --- a/drivers/gpu/drm/radeon/radeon_ttm.c > +++ b/drivers/gpu/drm/radeon/radeon_ttm.c > @@ -235,6 +235,8 @@ static int radeon_verify_access(struct ttm_buffer_object *bo, struct file *filp) > { > struct radeon_bo *rbo = container_of(bo, struct radeon_bo, tbo); > > + if (radeon_ttm_tt_has_userptr(bo->ttm)) > + return -EPERM; > return drm_vma_node_verify_access(&rbo->gem_base.vma_node, filp); > } >