dri-devel.lists.freedesktop.org archive mirror
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Karl Mehltretter" <kmehltretter@gmail.com>
Cc: dmitry.torokhov@gmail.com, linux-input@vger.kernel.org,
	media-ci@linuxtv.org, dri-devel@lists.freedesktop.org,
	linux-usb@vger.kernel.org
Subject: Re: [RFT PATCH] Input: sur40 - fix DMA handling in video capture
Date: Wed, 07 Oct 2026 05:58:41 +0000	[thread overview]
Message-ID: <sashiko-outbox-162655@kernel.org> (raw)
In-Reply-To: <20261007054430.40155-1-kmehltretter@gmail.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] media: use-after-free of sur40 state on disconnect when V4L2 fd is open
- [Medium] usb: invalid GFP flags (0) passed to usb_sg_init in sleepable context
--

commit f65bffa4ada0f7963abf3d4813cdc5924218586d
Author: Karl Mehltretter <kmehltretter@gmail.com>

Input: sur40 - fix DMA handling in video capture

This commit fixes video capture failures by transitioning from vb2_dma_sg to
vb2_vmalloc. It receives each frame into a driver-owned, page-backed
scatterlist and copies it through the vb2 mapping, while synchronizing
CPU writes to imported dma-bufs.

> diff --git a/drivers/input/touchscreen/sur40.c b/drivers/input/touchscreen/sur40.c
> index 09d8c5f8d09fc..72e3f0fa1f4cb 100644
> --- a/drivers/input/touchscreen/sur40.c
> +++ b/drivers/input/touchscreen/sur40.c
[ ... ]
> @@ -579,11 +584,17 @@ static void sur40_process_video(struct sur40_state *sur40)
>  
>  	dev_dbg(sur40->dev, "header acquired\n");
>  
> -	sgt = vb2_dma_sg_plane_desc(&new_buf->vb.vb2_buf, 0);
> +	vaddr = vb2_plane_vaddr(&new_buf->vb.vb2_buf, 0);
> +	if (!vaddr)
> +		goto err_poll;
>  
> +	/*
> +	 * vb2_plane_vaddr() may return a vmalloc or vmap address. Receive
> +	 * into page-backed memory so the USB core can map it for DMA.
> +	 */
>  	result = usb_sg_init(&sgr, sur40->usbdev,
>  		usb_rcvbulkpipe(sur40->usbdev, VIDEO_ENDPOINT), 0,
> -		sgt->sgl, sgt->nents, sur40->pix_fmt.sizeimage, 0);
> +		sur40->video_sgl, sur40->video_nents, size, 0);

[Severity: Medium]
Is it correct to pass 0 as the mem_flags argument to usb_sg_init() here?

Passing 0 implies no reclaim and no wait (equivalent to GFP_NOWAIT), which
restricts usb_alloc_urb() and internal kmalloc operations. This can increase
the probability of spurious -ENOMEM failures under memory pressure.

Since sur40_process_video() executes inside the input poller worker thread
(sur40_poll) which runs in process context and is allowed to sleep (it already
calls usb_bulk_msg() and usb_sg_wait()), shouldn't this use GFP_KERNEL instead?

[ ... ]
> @@ -831,6 +883,7 @@ static void sur40_disconnect(struct usb_interface *interface)
>  	video_unregister_device(&sur40->vdev);
>  	v4l2_device_unregister(&sur40->v4l2);
>  
> +	sgl_free(sur40->video_sgl);
>  	kfree(sur40->bulk_in_buffer);
>  	kfree(sur40);

[Severity: High]
Could freeing the sur40 structure unconditionally here lead to a use-after-free
if userspace holds the V4L2 file descriptor open during device unplug?

When the application later closes the file, the V4L2 core invokes
vb2_fop_release(), which dereferences vdev->queue and attempts to acquire
vdev->queue->lock. Because vdev is embedded in the freed sur40 structure,
this results in a direct use-after-free.

While the commit message acknowledges this bug and defers to a pending patch
series for the disconnect fixes, the current patch adds new cleanup to this
vulnerable path. The referenced series is absent from the provided tree,
leaving the vulnerability exposed.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261007054430.40155-1-kmehltretter@gmail.com?part=1

  reply	other threads:[~2026-10-07  5:58 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-07  5:44 [RFT PATCH] Input: sur40 - fix DMA handling in video capture Karl Mehltretter
2026-10-07  5:58 ` sashiko-bot [this message]
2026-10-08  4:16 ` kernel test robot
2026-10-09 10:35 ` kernel test robot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=sashiko-outbox-162655@kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dmitry.torokhov@gmail.com \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=kmehltretter@gmail.com \
    --cc=linux-input@vger.kernel.org \
    --cc=linux-usb@vger.kernel.org \
    --cc=media-ci@linuxtv.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).