From mboxrd@z Thu Jan 1 00:00:00 1970 From: jeffy Subject: Re: drm: Add missing field copy in compat_drm_version Date: Thu, 13 Jul 2017 10:20:20 +0800 Message-ID: <5966D8E4.3050907@rock-chips.com> References: <1499840312-23418-1-git-send-email-jeffy.chen@rock-chips.com> Mime-Version: 1.0 Content-Type: text/plain; charset="utf-8"; Format="flowed" Content-Transfer-Encoding: base64 Return-path: Received: from regular1.263xmail.com (regular1.263xmail.com [211.150.99.131]) by gabe.freedesktop.org (Postfix) with ESMTPS id 6D4816E070 for ; Thu, 13 Jul 2017 02:20:51 +0000 (UTC) In-Reply-To: <1499840312-23418-1-git-send-email-jeffy.chen@rock-chips.com> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: dri-devel-bounces@lists.freedesktop.org Sender: "dri-devel" To: Jeffy Chen , linux-kernel@vger.kernel.org Cc: briannorris@chromium.org, dianders@chromium.org, dri-devel@lists.freedesktop.org, Daniel Vetter List-Id: dri-devel@lists.freedesktop.org SGkgZ3V5cywKCmkgd2FzIHRlc3RpbmcgdGhpcyBvbiBhcm02NCBiYXNlIGNocm9tZW9zKHdpdGgg YXJtMzIgdXNlcnNwYWNlKS4KCmFuZCB0aGUgbGliZHJtIGNyYXNoZWQ6CiAgICAgZHJtVmVyc2lv blB0ciBkcm1HZXRWZXJzaW9uKGludCBmZCkKICAgICB7CiAgICAgLi4uCiAgICAgICAgIG1lbWNs ZWFyKCp2ZXJzaW9uKTsKCiAgICAgICAgIGlmIChkcm1Jb2N0bChmZCwgRFJNX0lPQ1RMX1ZFUlNJ T04sIHZlcnNpb24pKSB7CiAgICAgLi4uCiAgICAgICAgIGlmICh2ZXJzaW9uLT5uYW1lX2xlbikK ICAgICAgICAgICAgIHZlcnNpb24tPm5hbWUgICAgPSBkcm1NYWxsb2ModmVyc2lvbi0+bmFtZV9s ZW4gKyAxKTsgPC0tIApyZWx5IG9uIHRoZSBsZW5ndGhzIHVwZGF0ZWQgYnkga2VybmVsCiAgICAg ICAgIGlmICh2ZXJzaW9uLT5kYXRlX2xlbikKICAgICAgICAgICAgIHZlcnNpb24tPmRhdGUgICAg PSBkcm1NYWxsb2ModmVyc2lvbi0+ZGF0ZV9sZW4gKyAxKTsKICAgICAgICAgaWYgKHZlcnNpb24t PmRlc2NfbGVuKQogICAgICAgICAgICAgdmVyc2lvbi0+ZGVzYyAgICA9IGRybU1hbGxvYyh2ZXJz aW9uLT5kZXNjX2xlbiArIDEpOwogICAgIC4uLgogICAgICAgICBpZiAodmVyc2lvbi0+bmFtZV9s ZW4pIHZlcnNpb24tPm5hbWVbdmVyc2lvbi0+bmFtZV9sZW5dID0gJ1wwJzsgCjwtLSBjcmFzaGVk IGhlcmUsIHNpbmNlIHRoZSBuYW1lX2xlbiB3b3VsZCBhbHdheXMgYmUgemVybywgc28gCnZlcnNp b24tPm5hbWUgd291bGQgYmUgbnVsbHB0ci4KCgpPbiAwNy8xMi8yMDE3IDAyOjE4IFBNLCBKZWZm eSBDaGVuIHdyb3RlOgo+IERSTV9JT0NUTF9WRVJTSU9OIGlzIHN1cHBvc2VkIHRvIHVwZGF0ZSB0 aGUgbmFtZV9sZW4vZGF0ZV9sZW4vZGVzY19sZW4KPiBmaWVsZHMgdG8gdXNlci4KPgo+IEZpeGVz OiAwMTJjNjc0MWM2YWEoInN3aXRjaCBjb21wYXRfZHJtX3ZlcnNpb24oKSB0byBkcm1faW9jdGxf a2VybmVsKCkiKQo+IFNpZ25lZC1vZmYtYnk6IEplZmZ5IENoZW4gPGplZmZ5LmNoZW5Acm9jay1j aGlwcy5jb20+Cj4gLS0tCj4KPiAgIGRyaXZlcnMvZ3B1L2RybS9kcm1faW9jMzIuYyB8IDMgKysr Cj4gICAxIGZpbGUgY2hhbmdlZCwgMyBpbnNlcnRpb25zKCspCj4KPiBkaWZmIC0tZ2l0IGEvZHJp dmVycy9ncHUvZHJtL2RybV9pb2MzMi5jIGIvZHJpdmVycy9ncHUvZHJtL2RybV9pb2MzMi5jCj4g aW5kZXggOTRhY2Y1MS4uMjc4OTM1NiAxMDA2NDQKPiAtLS0gYS9kcml2ZXJzL2dwdS9kcm0vZHJt X2lvYzMyLmMKPiArKysgYi9kcml2ZXJzL2dwdS9kcm0vZHJtX2lvYzMyLmMKPiBAQCAtMTEyLDYg KzExMiw5IEBAIHN0YXRpYyBpbnQgY29tcGF0X2RybV92ZXJzaW9uKHN0cnVjdCBmaWxlICpmaWxl LCB1bnNpZ25lZCBpbnQgY21kLAo+ICAgCXYzMi52ZXJzaW9uX21ham9yID0gdi52ZXJzaW9uX21h am9yOwo+ICAgCXYzMi52ZXJzaW9uX21pbm9yID0gdi52ZXJzaW9uX21pbm9yOwo+ICAgCXYzMi52 ZXJzaW9uX3BhdGNobGV2ZWwgPSB2LnZlcnNpb25fcGF0Y2hsZXZlbDsKPiArCXYzMi5uYW1lX2xl biA9IHYubmFtZV9sZW47Cj4gKwl2MzIuZGF0ZV9sZW4gPSB2LmRhdGVfbGVuOwo+ICsJdjMyLmRl c2NfbGVuID0gdi5kZXNjX2xlbjsKPiAgIAlpZiAoY29weV90b191c2VyKCh2b2lkIF9fdXNlciAq KWFyZywgJnYzMiwgc2l6ZW9mKHYzMikpKQo+ICAgCQlyZXR1cm4gLUVGQVVMVDsKPiAgIAlyZXR1 cm4gMDsKPgo+CgoKX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f X18KZHJpLWRldmVsIG1haWxpbmcgbGlzdApkcmktZGV2ZWxAbGlzdHMuZnJlZWRlc2t0b3Aub3Jn Cmh0dHBzOi8vbGlzdHMuZnJlZWRlc2t0b3Aub3JnL21haWxtYW4vbGlzdGluZm8vZHJpLWRldmVs Cg== From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751271AbdGMCU5 (ORCPT ); Wed, 12 Jul 2017 22:20:57 -0400 Received: from regular1.263xmail.com ([211.150.99.131]:49562 "EHLO regular1.263xmail.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751061AbdGMCUz (ORCPT ); Wed, 12 Jul 2017 22:20:55 -0400 X-263anti-spam: KSV:0; X-MAIL-GRAY: 0 X-MAIL-DELIVERY: 1 X-KSVirus-check: 0 X-ABS-CHECKED: 4 X-RL-SENDER: jeffy.chen@rock-chips.com X-FST-TO: jeffy.chen@rock-chips.com X-SENDER-IP: 103.29.142.67 X-LOGIN-NAME: jeffy.chen@rock-chips.com X-UNIQUE-TAG: <11f6c84818969ee4776fcef73a6bbe72> X-ATTACHMENT-NUM: 0 X-DNS-TYPE: 0 Message-ID: <5966D8E4.3050907@rock-chips.com> Date: Thu, 13 Jul 2017 10:20:20 +0800 From: jeffy User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:19.0) Gecko/20130126 Thunderbird/19.0 MIME-Version: 1.0 To: Jeffy Chen , linux-kernel@vger.kernel.org CC: briannorris@chromium.org, dianders@chromium.org, Daniel Vetter , Jani Nikula , dri-devel@lists.freedesktop.org, David Airlie , Sean Paul Subject: Re: drm: Add missing field copy in compat_drm_version References: <1499840312-23418-1-git-send-email-jeffy.chen@rock-chips.com> In-Reply-To: <1499840312-23418-1-git-send-email-jeffy.chen@rock-chips.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Hi guys, i was testing this on arm64 base chromeos(with arm32 userspace). and the libdrm crashed: drmVersionPtr drmGetVersion(int fd) { ... memclear(*version); if (drmIoctl(fd, DRM_IOCTL_VERSION, version)) { ... if (version->name_len) version->name = drmMalloc(version->name_len + 1); <-- rely on the lengths updated by kernel if (version->date_len) version->date = drmMalloc(version->date_len + 1); if (version->desc_len) version->desc = drmMalloc(version->desc_len + 1); ... if (version->name_len) version->name[version->name_len] = '\0'; <-- crashed here, since the name_len would always be zero, so version->name would be nullptr. On 07/12/2017 02:18 PM, Jeffy Chen wrote: > DRM_IOCTL_VERSION is supposed to update the name_len/date_len/desc_len > fields to user. > > Fixes: 012c6741c6aa("switch compat_drm_version() to drm_ioctl_kernel()") > Signed-off-by: Jeffy Chen > --- > > drivers/gpu/drm/drm_ioc32.c | 3 +++ > 1 file changed, 3 insertions(+) > > diff --git a/drivers/gpu/drm/drm_ioc32.c b/drivers/gpu/drm/drm_ioc32.c > index 94acf51..2789356 100644 > --- a/drivers/gpu/drm/drm_ioc32.c > +++ b/drivers/gpu/drm/drm_ioc32.c > @@ -112,6 +112,9 @@ static int compat_drm_version(struct file *file, unsigned int cmd, > v32.version_major = v.version_major; > v32.version_minor = v.version_minor; > v32.version_patchlevel = v.version_patchlevel; > + v32.name_len = v.name_len; > + v32.date_len = v.date_len; > + v32.desc_len = v.desc_len; > if (copy_to_user((void __user *)arg, &v32, sizeof(v32))) > return -EFAULT; > return 0; > >