dri-devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 1/3] drm/vmwgfx: check master authentication in surface_ref ioctls
@ 2019-07-03 13:31 Emil Velikov
       [not found] ` <20190703133104.3211-1-emil.l.velikov-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org>
                   ` (2 more replies)
  0 siblings, 3 replies; 13+ messages in thread
From: Emil Velikov @ 2019-07-03 13:31 UTC (permalink / raw)
  To: dri-devel; +Cc: VMware Graphics, Thomas Hellstrom, emil.l.velikov

From: Emil Velikov <emil.velikov@collabora.com>

With later commit we'll rework DRM core authentication handling.

Namely unauthenticated master will be allowed with, DRM_AUTH ioctls.
Since vmwgfx does additional master locking and DRM_AUTH handling, this
will not matter almost all cases.

The only exception being using the legacy handle type in the family of
surface_reference iocts - all handled by vmw_surface_handle_reference().
Add the check to ensure such clients do not access more than they should

Cc: VMware Graphics <linux-graphics-maintainer@vmware.com>
Cc: Thomas Hellstrom <thellstrom@vmware.com>
Signed-off-by: Emil Velikov <emil.velikov@collabora.com>
---
I'd like to merge this through the drm-misc tree. Ack and rb are
appreciated.

Thanks
Emil

Unrelated: worth moving the is_render_client check alongside the
is_primary_client one.
---
 drivers/gpu/drm/vmwgfx/vmwgfx_surface.c | 7 +++++++
 1 file changed, 7 insertions(+)

diff --git a/drivers/gpu/drm/vmwgfx/vmwgfx_surface.c b/drivers/gpu/drm/vmwgfx/vmwgfx_surface.c
index 219471903bc1..1f5146c95785 100644
--- a/drivers/gpu/drm/vmwgfx/vmwgfx_surface.c
+++ b/drivers/gpu/drm/vmwgfx/vmwgfx_surface.c
@@ -940,6 +940,13 @@ vmw_surface_handle_reference(struct vmw_private *dev_priv,
 		user_srf = container_of(base, struct vmw_user_surface,
 					prime.base);
 
+		/* Error out if we are unauthenticated master */
+		if (drm_is_primary_client(file_priv) &&
+		    !file_priv->authenticated) {
+			ret = -EACCES;
+			goto out_bad_resource;
+		}
+
 		/*
 		 * Make sure the surface creator has the same
 		 * authenticating master, or is already registered with us.
-- 
2.21.0

_______________________________________________
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel

^ permalink raw reply related	[flat|nested] 13+ messages in thread
* Re: [PATCH 2/3] drm: introduce DRIVER_FORCE_AUTH
@ 2019-07-03 14:33 Koenig, Christian
       [not found] ` <744310ce-4546-4406-ad8d-49af0f06cd49-2ueSQiBKiTY7tOexoI0I+QC/G2K4zDHf@public.gmane.org>
  0 siblings, 1 reply; 13+ messages in thread
From: Koenig, Christian @ 2019-07-03 14:33 UTC (permalink / raw)
  To: Emil Velikov
  Cc: Deucher, Alexander, amd-gfx@lists.freedesktop.org,
	dri-devel@lists.freedesktop.org


[-- Attachment #1.1: Type: text/plain, Size: 943 bytes --]



Am 03.07.2019 16:00 schrieb Emil Velikov <emil.l.velikov@gmail.com>:
On Wed, 3 Jul 2019 at 14:48, Koenig, Christian <Christian.Koenig@amd.com> wrote:
>
> Well this is still a NAK.
>
> As stated previously please just don't remove DRM_AUTH and keep the functionality as it is.
>
AFAICT nobody was in favour of your suggestion to remove DRM_AUTH from
the handle to/from fd ioclts.
Thus this seems like the second best option.

Well just keep it. As I said please don't change anything here.

Dropping DRM_AUTH from the driver IOCTLs was sufficient to work around the problems at hand far as I know.

And stopping those two at least prevents userspace to abuse this even more.

On the other hand I haven't seen any NAK on dropping DRM_AUTH from them.

Christian.



Third route that I see is doing driver_name == "amdgpu" || driver_name
== "radeon" in core.
If you have alternative solution I'm all ears.

-Emil


[-- Attachment #1.2: Type: text/html, Size: 2110 bytes --]

[-- Attachment #2: Type: text/plain, Size: 159 bytes --]

_______________________________________________
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel

^ permalink raw reply	[flat|nested] 13+ messages in thread
* Re: [PATCH 2/3] drm: introduce DRIVER_FORCE_AUTH
@ 2019-07-03 14:58 Koenig, Christian
       [not found] ` <0bc184ea-bcc3-48cb-9b28-42e8fc037303-2ueSQiBKiTY7tOexoI0I+QC/G2K4zDHf@public.gmane.org>
  0 siblings, 1 reply; 13+ messages in thread
From: Koenig, Christian @ 2019-07-03 14:58 UTC (permalink / raw)
  To: Emil Velikov
  Cc: Deucher, Alexander, Daniel Vetter,
	amd-gfx-PD4FTy7X32lNgt0PjOBp9y5qC8QIuHrW@public.gmane.org,
	dri-devel-PD4FTy7X32lNgt0PjOBp9y5qC8QIuHrW@public.gmane.org


[-- Attachment #1.1: Type: text/plain, Size: 1358 bytes --]



Am 03.07.2019 16:51 schrieb Emil Velikov <emil.l.velikov@gmail.com>:
On Wed, 3 Jul 2019 at 15:33, Koenig, Christian <Christian.Koenig@amd.com> wrote:
> Am 03.07.2019 16:00 schrieb Emil Velikov <emil.l.velikov@gmail.com>:
>
> On Wed, 3 Jul 2019 at 14:48, Koenig, Christian <Christian.Koenig@amd.com> wrote:
> >
> > Well this is still a NAK.
> >
> > As stated previously please just don't remove DRM_AUTH and keep the functionality as it is.
> >
> AFAICT nobody was in favour of your suggestion to remove DRM_AUTH from
> the handle to/from fd ioclts.
> Thus this seems like the second best option.
>
>
> Well just keep it. As I said please don't change anything here.
>
> Dropping DRM_AUTH from the driver IOCTLs was sufficient to work around the problems at hand far as I know.
>
We also need the DRM_AUTH for handle to/from fd ones. Mesa drivers use
those ioctls.

Yeah, but only for importing/exporting things.

And in those cases we either already gave render nodes or correctly authenticated primary nodes.

So no need to change anything here as far as I see.

I simply want to prevent that userspace gets the same functionality from the primary node they get from the render node. And that actually seems to be a good way to keep the restriction and still work around the userspace problems.

Christian.



-Emil


[-- Attachment #1.2: Type: text/html, Size: 2596 bytes --]

[-- Attachment #2: Type: text/plain, Size: 153 bytes --]

_______________________________________________
amd-gfx mailing list
amd-gfx@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/amd-gfx

^ permalink raw reply	[flat|nested] 13+ messages in thread
* Re: [PATCH 2/3] drm: introduce DRIVER_FORCE_AUTH
@ 2019-07-06  6:16 Koenig, Christian
  0 siblings, 0 replies; 13+ messages in thread
From: Koenig, Christian @ 2019-07-06  6:16 UTC (permalink / raw)
  To: Emil Velikov
  Cc: Deucher, Alexander, amd-gfx@lists.freedesktop.org,
	dri-devel@lists.freedesktop.org


[-- Attachment #1.1: Type: text/plain, Size: 1775 bytes --]



Am 03.07.2019 17:14 schrieb Emil Velikov <emil.l.velikov@gmail.com>:
On Wed, 3 Jul 2019 at 15:58, Koenig, Christian <Christian.Koenig@amd.com> wrote:
> Am 03.07.2019 16:51 schrieb Emil Velikov <emil.l.velikov@gmail.com>:
>
> On Wed, 3 Jul 2019 at 15:33, Koenig, Christian <Christian.Koenig@amd.com> wrote:
> > Am 03.07.2019 16:00 schrieb Emil Velikov <emil.l.velikov@gmail.com>:
> >
> > On Wed, 3 Jul 2019 at 14:48, Koenig, Christian <Christian.Koenig@amd.com> wrote:
> > >
> > > Well this is still a NAK.
> > >
> > > As stated previously please just don't remove DRM_AUTH and keep the functionality as it is.
> > >
> > AFAICT nobody was in favour of your suggestion to remove DRM_AUTH from
> > the handle to/from fd ioclts.
> > Thus this seems like the second best option.
> >
> >
> > Well just keep it. As I said please don't change anything here.
> >
> > Dropping DRM_AUTH from the driver IOCTLs was sufficient to work around the problems at hand far as I know.
> >
> We also need the DRM_AUTH for handle to/from fd ones. Mesa drivers use
> those ioctls.
>
>
> Yeah, but only for importing/exporting things.
>
> And in those cases we either already gave render nodes or correctly authenticated primary nodes.
>
> So no need to change anything here as far as I see.
>
Not quite. When working with the primary node we have the following scenarios:
 - handle to fd -> pass fd to other APIs - gbm, opencl, vdpau, etc
 - handle to fd -> fd to handle - use it internally

Yeah, I'm aware of that but hoped that this would be a rather rare case.

I need to take another closer look on this, but currently I am on vacation and won't have time next week either.

Trying to get back to this as soon as possible,
Christian.


-Emil


[-- Attachment #1.2: Type: text/html, Size: 3081 bytes --]

[-- Attachment #2: Type: text/plain, Size: 159 bytes --]

_______________________________________________
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel

^ permalink raw reply	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2019-07-17  8:26 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2019-07-03 13:31 [PATCH 1/3] drm/vmwgfx: check master authentication in surface_ref ioctls Emil Velikov
     [not found] ` <20190703133104.3211-1-emil.l.velikov-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org>
2019-07-03 13:31   ` [PATCH 2/3] drm: introduce DRIVER_FORCE_AUTH Emil Velikov
2019-07-03 13:48     ` Koenig, Christian
2019-07-03 14:00       ` Emil Velikov
2019-07-03 13:31 ` [PATCH 3/3] drm: allow render capable master with DRM_AUTH ioctls Emil Velikov
2019-07-03 17:10 ` [PATCH] " Emil Velikov
2019-07-04 10:56   ` Michel Dänzer
  -- strict thread matches above, loose matches on Subject: below --
2019-07-03 14:33 [PATCH 2/3] drm: introduce DRIVER_FORCE_AUTH Koenig, Christian
     [not found] ` <744310ce-4546-4406-ad8d-49af0f06cd49-2ueSQiBKiTY7tOexoI0I+QC/G2K4zDHf@public.gmane.org>
2019-07-03 14:51   ` Emil Velikov
2019-07-03 14:58 Koenig, Christian
     [not found] ` <0bc184ea-bcc3-48cb-9b28-42e8fc037303-2ueSQiBKiTY7tOexoI0I+QC/G2K4zDHf@public.gmane.org>
2019-07-03 15:14   ` Emil Velikov
     [not found]     ` <CACvgo52y50bV90+7JeABvKCNCwT_E7r7CXTw98bOgyiDDzG2Pg-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2019-07-17  8:26       ` Koenig, Christian
2019-07-06  6:16 Koenig, Christian

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox