From: Michal Nazarewicz <mina86@mina86.com>
To: "Felipe F. Tonello" <eu@felipetonello.com>, linux-usb@vger.kernel.org
Cc: linux-kernel@vger.kernel.org, Felipe Balbi <balbi@kernel.org>,
Baolin Wang <baolin.wang@linaro.org>,
Andrzej Pietrasiewicz <andrzej.p@samsung.com>
Subject: Re: [PATCH 2/9] usb: gadget: align buffer size when allocating for OUT endpoint
Date: Wed, 27 Jul 2016 21:59:21 +0200 [thread overview]
Message-ID: <xa1t37mu3l9i.fsf@mina86.com> (raw)
In-Reply-To: <20160726191200.18943-3-eu@felipetonello.com>
On Tue, Jul 26 2016, Felipe F. Tonello wrote:
> Using usb_ep_align() makes sure that the buffer size for OUT endpoints is
> always aligned with wMaxPacketSize (512 usually). This makes sure
> that no buffer has the wrong size, which can cause nasty bugs.
>
> Signed-off-by: Felipe F. Tonello <eu@felipetonello.com>
> ---
> drivers/usb/gadget/u_f.c | 3 +++
> 1 file changed, 3 insertions(+)
>
> diff --git a/drivers/usb/gadget/u_f.c b/drivers/usb/gadget/u_f.c
> index 4bc7eea8bfc8..d1933b0b76c3 100644
> --- a/drivers/usb/gadget/u_f.c
> +++ b/drivers/usb/gadget/u_f.c
> @@ -12,6 +12,7 @@
> */
>
> #include "u_f.h"
> +#include <linux/usb/ch9.h>
>
> struct usb_request *alloc_ep_req(struct usb_ep *ep, int len, int default_len)
> {
> @@ -20,6 +21,8 @@ struct usb_request *alloc_ep_req(struct usb_ep *ep, int len, int default_len)
> req = usb_ep_alloc_request(ep, GFP_ATOMIC);
> if (req) {
> req->length = len ?: default_len;
> + if (usb_endpoint_dir_out(ep->desc))
> + req->length = usb_ep_align(ep, req->length);
> req->buf = kmalloc(req->length, GFP_ATOMIC);
> if (!req->buf) {
> usb_ep_free_request(ep, req);
I’m a bit scared of this change.
Drivers which call alloc_ep_req and then ignore req->length using the
same length they passed to the function will silently drop data.
Drivers which do not ignore req->length may end up overwriting some
other buffer, e.g.:
some_buffer = kmalloc(length, GFP_KERNEL);
req = alloc_ep_req(ep, length, 0);
… later …
memcpy(some_buffer, req->buf, req->length);
--
Best regards
ミハウ “𝓶𝓲𝓷𝓪86” ナザレヴイツ
«If at first you don’t succeed, give up skydiving»
next prev parent reply other threads:[~2016-07-27 19:59 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-07-26 19:11 [PATCH v2 0/9] Gadget endpoint request allocation and MIDI Felipe F. Tonello
2016-07-26 19:11 ` [PATCH 1/9] usb: gadget: fix usb_ep_align_maybe endianness and new usb_ep_align Felipe F. Tonello
2016-07-27 19:37 ` Michal Nazarewicz
2016-08-02 15:05 ` Felipe Ferreri Tonello
2016-07-26 19:11 ` [PATCH 2/9] usb: gadget: align buffer size when allocating for OUT endpoint Felipe F. Tonello
2016-07-27 19:59 ` Michal Nazarewicz [this message]
2016-08-02 15:15 ` Felipe Ferreri Tonello
2016-07-26 19:11 ` [PATCH 3/9] usb: gadget: f_midi: remove alignment code " Felipe F. Tonello
2016-07-26 19:11 ` [PATCH 4/9] usb: gadget: f_midi: defaults buflen sizes to 512 Felipe F. Tonello
2016-07-27 19:38 ` Michal Nazarewicz
2016-07-26 19:11 ` [PATCH 5/9] usb: gadget: f_midi: refactor state machine Felipe F. Tonello
2016-07-26 19:11 ` [PATCH 6/9] usb: gadget: f_midi: drop substreams when disabling endpoint Felipe F. Tonello
2016-07-26 19:11 ` [PATCH 7/9] usb: gadget: remove useless parameter in alloc_ep_req() Felipe F. Tonello
2016-07-26 19:18 ` [PATCH v2 " Felipe F. Tonello
2016-07-26 19:19 ` Felipe Ferreri Tonello
2016-07-27 20:02 ` [PATCH " Michal Nazarewicz
2016-08-02 15:08 ` Felipe Ferreri Tonello
2016-07-26 19:11 ` [PATCH 8/9] usb: gadget: f_hid: use free_ep_req() Felipe F. Tonello
2016-07-27 20:03 ` Michal Nazarewicz
2016-07-26 19:12 ` [PATCH 9/9] usb: gadget: f_hid: use alloc_ep_req() Felipe F. Tonello
2016-07-27 20:34 ` Michal Nazarewicz
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=xa1t37mu3l9i.fsf@mina86.com \
--to=mina86@mina86.com \
--cc=andrzej.p@samsung.com \
--cc=balbi@kernel.org \
--cc=baolin.wang@linaro.org \
--cc=eu@felipetonello.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-usb@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.