dri-devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Roman Demidov" <roman.demidov.nn@gmail.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH 5.15 1/2] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array
Date: Wed, 23 Sep 2026 15:07:52 +0000	[thread overview]
Message-ID: <20260923150753.170D11F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260923145453.76114-1-roman.demidov.nn@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Low] build: missing vmemdup_array_user helper
--

commit 4d70c808a81c22c8b9f6c03847fa45f071b2e967
Author: Tvrtko Ursulin <tvrtko.ursulin@igalia.com>

drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array

This commit replaces kvmalloc_array() + copy_from_user() with
vmemdup_array_user() on the fast path. This aims to shrink the source code
and improve separation between kernel and userspace slabs.

> diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
> index 15c45b2a39835..b364f3f5fb918 100644
> --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
> +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
> @@ -223,43 +223,36 @@ void amdgpu_bo_list_put(struct amdgpu_bo_list *list)
>  int amdgpu_bo_create_list_entry_array(struct drm_amdgpu_bo_list_in *in,
>  				      struct drm_amdgpu_bo_list_entry **info_param)
>  {
[ ... ]
>  	/* copy the handle array from userspace to a kernel buffer */
> -	r = -EFAULT;
> -	if (likely(info_size == in->bo_info_size)) {
> -		unsigned long bytes = in->bo_number *
> -			in->bo_info_size;
> -
> -		if (copy_from_user(info, uptr, bytes))
> -			goto error_free;
> -
> +	if (likely(info_size == bo_info_size)) {
> +		info = vmemdup_array_user(uptr, bo_number, info_size);

[Severity: Low]
Does this code call a function vmemdup_array_user() that does not exist in
this kernel tree?

When compiling drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c with
CONFIG_DRM_AMDGPU=y or m, this will result in a build failure due to an
implicit function declaration in amdgpu_bo_create_list_entry_array(). If the
compiler allows implicit declarations, it would assume a 32-bit int return
type, which truncates the pointer on 64-bit systems and can lead to an
invalid pointer dereference or use-after-free when IS_ERR(info) or
kvfree(info) is called later.

> +		if (IS_ERR(info))
> +			return PTR_ERR(info);

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260923145453.76114-1-roman.demidov.nn@gmail.com?part=1

  parent reply	other threads:[~2026-09-23 15:07 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-23 14:54 [PATCH 5.15 1/2] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array Roman Demidov
2026-09-23 14:54 ` [PATCH 5.15 2/2] drm/amdgpu: Limit BO list entry count to prevent resource exhaustion Roman Demidov
2026-09-23 15:07 ` sashiko-bot [this message]
2026-09-24  7:07   ` [PATCH 5.15 1/2] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array Roman

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260923150753.170D11F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=roman.demidov.nn@gmail.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox