Intel-GFX Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] iommu/dma: Catch scatterlist length overflows
@ 2026-10-02  5:33 Krzysztof Karas
  2026-10-02  7:01 ` ✗ i915.CI.BAT: failure for " Patchwork
                   ` (2 more replies)
  0 siblings, 3 replies; 5+ messages in thread
From: Krzysztof Karas @ 2026-10-02  5:33 UTC (permalink / raw)
  To: intel-gfx, iommu, dri-devel
  Cc: Robin Murphy, Joerg Roedel, Will Deacon, Andi Shyti,
	Michał Grzelak, Janusz Krzysztofik, Sebastian Brzezinka,
	Krzysztof Niemiec, Krzysztof Karas, stable

It is possible, when a very large mapping uses only one
scatterlist, that padding overflows scatterlist's length field.
This results in:
 1) silently wrapping the value
 2) smaller than desired mappings produced by iommu_map_sg
 3) leaving mapped bytes in memory (no iommu_unmap)

Address this issue by adding overflow detection for scatterlist
length field.

Fixes: 809eac54cdd6 ("iommu/dma: Implement scatterlist segment merging")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Krzysztof Karas <krzysztof.karas@intel.com>
Reviewed-by: Robin Murphy <robin.murphy@arm.com>
---
This patch was previously part of "drivers: Improve memory
management for large object allocations when i915/shmem is used
with iommu" series, but was extracted and posted separately on
request of one of the reviewers (Andi Shyti). There have been no
functional changes since last version.

this version:
 * Added separating blank lines (Andi);
 * Added IOMMU maintainers suggested by get_maintainer.pl
   script to CC (Andi);

 drivers/iommu/dma-iommu.c | 20 +++++++++++++++++++-
 1 file changed, 19 insertions(+), 1 deletion(-)

diff --git a/drivers/iommu/dma-iommu.c b/drivers/iommu/dma-iommu.c
index 58c624513cd43..06edb4056dc1b 100644
--- a/drivers/iommu/dma-iommu.c
+++ b/drivers/iommu/dma-iommu.c
@@ -1477,6 +1477,11 @@ int iommu_dma_map_sg(struct device *dev, struct scatterlist *sg, int nents,
 		sg_dma_len(s) = s_length;
 		s->offset -= s_iova_off;
 		s_length = iova_align(iovad, s_length + s_iova_off);
+		if (overflows_type(s_length, s->length)) {
+			ret = -EOVERFLOW;
+
+			goto out_restore_sg;
+		}
 		s->length = s_length;
 
 		/*
@@ -1493,7 +1498,20 @@ int iommu_dma_map_sg(struct device *dev, struct scatterlist *sg, int nents,
 		 *   time through here (i.e. before it has a meaningful value).
 		 */
 		if (pad_len && pad_len < s_length - 1) {
-			prev->length += pad_len;
+			unsigned int new_prev_len;
+
+			/*
+			 * For large mappings spanning multiple GBs we
+			 * may not be able to fit all needed padding into
+			 * sg->length.
+			 */
+			if (check_add_overflow(prev->length, pad_len, &new_prev_len)) {
+				ret = -EOVERFLOW;
+
+				goto out_restore_sg;
+			}
+
+			prev->length = new_prev_len;
 			iova_len += pad_len;
 		}
 
-- 
2.34.1


^ permalink raw reply related	[flat|nested] 5+ messages in thread

* ✗ i915.CI.BAT: failure for iommu/dma: Catch scatterlist length overflows
  2026-10-02  5:33 [PATCH] iommu/dma: Catch scatterlist length overflows Krzysztof Karas
@ 2026-10-02  7:01 ` Patchwork
  2026-10-05  7:35   ` Krzysztof Karas
  2026-10-02  9:14 ` [PATCH] " sashiko-bot
  2026-10-06  9:56 ` Sebastian Brzezinka
  2 siblings, 1 reply; 5+ messages in thread
From: Patchwork @ 2026-10-02  7:01 UTC (permalink / raw)
  To: Krzysztof Karas; +Cc: intel-gfx

[-- Attachment #1: Type: text/plain, Size: 3383 bytes --]

== Series Details ==

Series: iommu/dma: Catch scatterlist length overflows
URL   : https://patchwork.freedesktop.org/series/175398/
State : failure

== Summary ==

CI Bug Log - changes from CI_DRM_19266 -> Patchwork_175398v1
====================================================

Summary
-------

  **FAILURE**

  Serious unknown changes coming with Patchwork_175398v1 absolutely need to be
  verified manually.
  
  If you think the reported changes have nothing to do with the changes
  introduced in Patchwork_175398v1, please notify your bug team (I915-ci-infra@lists.freedesktop.org) to allow them
  to document this new failure mode, which will reduce false positives in CI.

  External URL: https://intel-gfx-ci.01.org/tree/drm-tip/Patchwork_175398v1/index.html

Participating hosts (39 -> 37)
------------------------------

  Missing    (2): bat-dg2-13 fi-glk-j4005 

Possible new issues
-------------------

  Here are the unknown changes that may have been introduced in Patchwork_175398v1:

### IGT changes ###

#### Possible regressions ####

  * igt@core_hotunplug@unbind-rebind:
    - bat-arlh-2:         [PASS][1] -> [INCOMPLETE][2]
   [1]: https://intel-gfx-ci.01.org/tree/drm-tip/CI_DRM_19266/bat-arlh-2/igt@core_hotunplug@unbind-rebind.html
   [2]: https://intel-gfx-ci.01.org/tree/drm-tip/Patchwork_175398v1/bat-arlh-2/igt@core_hotunplug@unbind-rebind.html

  
Known issues
------------

  Here are the changes found in Patchwork_175398v1 that come from known issues:

### IGT changes ###

#### Possible fixes ####

  * igt@i915_selftest@live@sanitycheck:
    - fi-kbl-7567u:       [DMESG-WARN][3] ([i915#13735]) -> [PASS][4] +79 other tests pass
   [3]: https://intel-gfx-ci.01.org/tree/drm-tip/CI_DRM_19266/fi-kbl-7567u/igt@i915_selftest@live@sanitycheck.html
   [4]: https://intel-gfx-ci.01.org/tree/drm-tip/Patchwork_175398v1/fi-kbl-7567u/igt@i915_selftest@live@sanitycheck.html

  * igt@kms_busy@basic@flip:
    - fi-kbl-7567u:       [DMESG-WARN][5] ([i915#13735] / [i915#180]) -> [PASS][6]
   [5]: https://intel-gfx-ci.01.org/tree/drm-tip/CI_DRM_19266/fi-kbl-7567u/igt@kms_busy@basic@flip.html
   [6]: https://intel-gfx-ci.01.org/tree/drm-tip/Patchwork_175398v1/fi-kbl-7567u/igt@kms_busy@basic@flip.html

  * igt@kms_pm_rpm@basic-pci-d3-state:
    - fi-kbl-7567u:       [DMESG-WARN][7] ([i915#13735] / [i915#15673] / [i915#180]) -> [PASS][8] +52 other tests pass
   [7]: https://intel-gfx-ci.01.org/tree/drm-tip/CI_DRM_19266/fi-kbl-7567u/igt@kms_pm_rpm@basic-pci-d3-state.html
   [8]: https://intel-gfx-ci.01.org/tree/drm-tip/Patchwork_175398v1/fi-kbl-7567u/igt@kms_pm_rpm@basic-pci-d3-state.html

  
  [i915#13735]: https://gitlab.freedesktop.org/drm/i915/kernel/-/issues/13735
  [i915#15673]: https://gitlab.freedesktop.org/drm/i915/kernel/-/issues/15673
  [i915#180]: https://gitlab.freedesktop.org/drm/i915/kernel/-/issues/180


Build changes
-------------

  * Linux: CI_DRM_19266 -> Patchwork_175398v1

  CI-20190529: 20190529
  CI_DRM_19266: fc5f5579dbfab13003fd4d6c1c9214a558f58c9d @ git://anongit.freedesktop.org/gfx-ci/linux
  IGT_9123: afd8cfb7aa15906974dd979b6dc739ed17ab9e33 @ https://gitlab.freedesktop.org/drm/igt-gpu-tools.git
  Patchwork_175398v1: fc5f5579dbfab13003fd4d6c1c9214a558f58c9d @ git://anongit.freedesktop.org/gfx-ci/linux

== Logs ==

For more details see: https://intel-gfx-ci.01.org/tree/drm-tip/Patchwork_175398v1/index.html

[-- Attachment #2: Type: text/html, Size: 4296 bytes --]

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH] iommu/dma: Catch scatterlist length overflows
  2026-10-02  5:33 [PATCH] iommu/dma: Catch scatterlist length overflows Krzysztof Karas
  2026-10-02  7:01 ` ✗ i915.CI.BAT: failure for " Patchwork
@ 2026-10-02  9:14 ` sashiko-bot
  2026-10-06  9:56 ` Sebastian Brzezinka
  2 siblings, 0 replies; 5+ messages in thread
From: sashiko-bot @ 2026-10-02  9:14 UTC (permalink / raw)
  To: Krzysztof Karas; +Cc: dri-devel, intel-gfx

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] iommu/dma: missed scatterlist length overflow on 32-bit architectures
--

commit c8808dcafa857db06b75cf791820b2414095b3cc
Author: Krzysztof Karas <krzysztof.karas@intel.com>

iommu/dma: Catch scatterlist length overflows

It is possible, when a very large mapping uses only one scatterlist, that
padding overflows scatterlist's length field. Address this issue by adding
overflow detection for scatterlist length field.

> diff --git a/drivers/iommu/dma-iommu.c b/drivers/iommu/dma-iommu.c
> index 58c624513cd43..06edb4056dc1b 100644
> --- a/drivers/iommu/dma-iommu.c
> +++ b/drivers/iommu/dma-iommu.c
> @@ -1477,6 +1477,11 @@ int iommu_dma_map_sg(struct device *dev, struct scatterlist *sg, int nents,
>  		sg_dma_len(s) = s_length;
>  		s->offset -= s_iova_off;
>  		s_length = iova_align(iovad, s_length + s_iova_off);
> +		if (overflows_type(s_length, s->length)) {
> +			ret = -EOVERFLOW;
> +
> +			goto out_restore_sg;
> +		}

[Severity: Medium]
Does this catch scatterlist length wrapping on 32-bit architectures?

If a caller provides a scatterlist segment with a length close to 4GB
on a 32-bit system, s_length and s_iova_off are both size_t. Their addition
and the subsequent iova_align() will silently wrap around in 32-bit
arithmetic before the overflows_type() check is reached.

Because s_length has already wrapped, overflows_type() will evaluate if the
wrapped 32-bit value fits inside a 32-bit unsigned int (s->length), which
always returns false.

In contrast, the subsequent pad_len check correctly uses
check_add_overflow(), avoiding this pitfall. Could a similar approach be
used here?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261002053320.3145901-1-krzysztof.karas@intel.com?part=1

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: ✗ i915.CI.BAT: failure for iommu/dma: Catch scatterlist length overflows
  2026-10-02  7:01 ` ✗ i915.CI.BAT: failure for " Patchwork
@ 2026-10-05  7:35   ` Krzysztof Karas
  0 siblings, 0 replies; 5+ messages in thread
From: Krzysztof Karas @ 2026-10-05  7:35 UTC (permalink / raw)
  To: I915-ci-infra; +Cc: intel-gfx

Hi Ci Infra Team,

The below failure is unrelated to this patch.

On 2026-10-02 at 07:01:29 +0000, Patchwork wrote:
> == Series Details ==
> 
> Series: iommu/dma: Catch scatterlist length overflows
> URL   : https://patchwork.freedesktop.org/series/175398/
> State : failure
> 
> == Summary ==
> 
> CI Bug Log - changes from CI_DRM_19266 -> Patchwork_175398v1
> ====================================================
> 
> Summary
> -------
> 
>   **FAILURE**
> 
>   Serious unknown changes coming with Patchwork_175398v1 absolutely need to be
>   verified manually.
>   
>   If you think the reported changes have nothing to do with the changes
>   introduced in Patchwork_175398v1, please notify your bug team (I915-ci-infra@lists.freedesktop.org) to allow them
>   to document this new failure mode, which will reduce false positives in CI.
> 
>   External URL: https://intel-gfx-ci.01.org/tree/drm-tip/Patchwork_175398v1/index.html
> 
> Participating hosts (39 -> 37)
> ------------------------------
> 
>   Missing    (2): bat-dg2-13 fi-glk-j4005 
> 
> Possible new issues
> -------------------
> 
>   Here are the unknown changes that may have been introduced in Patchwork_175398v1:
> 
> ### IGT changes ###
> 
> #### Possible regressions ####
> 
>   * igt@core_hotunplug@unbind-rebind:
>     - bat-arlh-2:         [PASS][1] -> [INCOMPLETE][2]
>    [1]: https://intel-gfx-ci.01.org/tree/drm-tip/CI_DRM_19266/bat-arlh-2/igt@core_hotunplug@unbind-rebind.html
>    [2]: https://intel-gfx-ci.01.org/tree/drm-tip/Patchwork_175398v1/bat-arlh-2/igt@core_hotunplug@unbind-rebind.html
> 
>   
> Known issues
> ------------
> 
>   Here are the changes found in Patchwork_175398v1 that come from known issues:
> 
> ### IGT changes ###
> 
> #### Possible fixes ####
> 
>   * igt@i915_selftest@live@sanitycheck:
>     - fi-kbl-7567u:       [DMESG-WARN][3] ([i915#13735]) -> [PASS][4] +79 other tests pass
>    [3]: https://intel-gfx-ci.01.org/tree/drm-tip/CI_DRM_19266/fi-kbl-7567u/igt@i915_selftest@live@sanitycheck.html
>    [4]: https://intel-gfx-ci.01.org/tree/drm-tip/Patchwork_175398v1/fi-kbl-7567u/igt@i915_selftest@live@sanitycheck.html
> 
>   * igt@kms_busy@basic@flip:
>     - fi-kbl-7567u:       [DMESG-WARN][5] ([i915#13735] / [i915#180]) -> [PASS][6]
>    [5]: https://intel-gfx-ci.01.org/tree/drm-tip/CI_DRM_19266/fi-kbl-7567u/igt@kms_busy@basic@flip.html
>    [6]: https://intel-gfx-ci.01.org/tree/drm-tip/Patchwork_175398v1/fi-kbl-7567u/igt@kms_busy@basic@flip.html
> 
>   * igt@kms_pm_rpm@basic-pci-d3-state:
>     - fi-kbl-7567u:       [DMESG-WARN][7] ([i915#13735] / [i915#15673] / [i915#180]) -> [PASS][8] +52 other tests pass
>    [7]: https://intel-gfx-ci.01.org/tree/drm-tip/CI_DRM_19266/fi-kbl-7567u/igt@kms_pm_rpm@basic-pci-d3-state.html
>    [8]: https://intel-gfx-ci.01.org/tree/drm-tip/Patchwork_175398v1/fi-kbl-7567u/igt@kms_pm_rpm@basic-pci-d3-state.html
> 
>   
>   [i915#13735]: https://gitlab.freedesktop.org/drm/i915/kernel/-/issues/13735
>   [i915#15673]: https://gitlab.freedesktop.org/drm/i915/kernel/-/issues/15673
>   [i915#180]: https://gitlab.freedesktop.org/drm/i915/kernel/-/issues/180
> 
> 
> Build changes
> -------------
> 
>   * Linux: CI_DRM_19266 -> Patchwork_175398v1
> 
>   CI-20190529: 20190529
>   CI_DRM_19266: fc5f5579dbfab13003fd4d6c1c9214a558f58c9d @ git://anongit.freedesktop.org/gfx-ci/linux
>   IGT_9123: afd8cfb7aa15906974dd979b6dc739ed17ab9e33 @ https://gitlab.freedesktop.org/drm/igt-gpu-tools.git
>   Patchwork_175398v1: fc5f5579dbfab13003fd4d6c1c9214a558f58c9d @ git://anongit.freedesktop.org/gfx-ci/linux
> 
> == Logs ==
> 
> For more details see: https://intel-gfx-ci.01.org/tree/drm-tip/Patchwork_175398v1/index.html

-- 
Best Regards,
Krzysztof

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH] iommu/dma: Catch scatterlist length overflows
  2026-10-02  5:33 [PATCH] iommu/dma: Catch scatterlist length overflows Krzysztof Karas
  2026-10-02  7:01 ` ✗ i915.CI.BAT: failure for " Patchwork
  2026-10-02  9:14 ` [PATCH] " sashiko-bot
@ 2026-10-06  9:56 ` Sebastian Brzezinka
  2 siblings, 0 replies; 5+ messages in thread
From: Sebastian Brzezinka @ 2026-10-06  9:56 UTC (permalink / raw)
  To: Krzysztof Karas, intel-gfx, iommu, dri-devel
  Cc: Robin Murphy, Joerg Roedel, Will Deacon, Andi Shyti,
	Michał Grzelak, Janusz Krzysztofik, Sebastian Brzezinka,
	Krzysztof Niemiec, stable

Hi Krzysztof,

On Fri Oct 2, 2026 at 7:33 AM CEST, Krzysztof Karas wrote:
> It is possible, when a very large mapping uses only one
> scatterlist, that padding overflows scatterlist's length field.
> This results in:
>  1) silently wrapping the value
>  2) smaller than desired mappings produced by iommu_map_sg
>  3) leaving mapped bytes in memory (no iommu_unmap)
>
> Address this issue by adding overflow detection for scatterlist
> length field.
>
> Fixes: 809eac54cdd6 ("iommu/dma: Implement scatterlist segment merging")
> Cc: stable@vger.kernel.org
> Assisted-by: LLM
> Signed-off-by: Krzysztof Karas <krzysztof.karas@intel.com>
> Reviewed-by: Robin Murphy <robin.murphy@arm.com>
> ---
Reviewed-by: Sebastian Brzezinka <sebastian.brzezinka@intel.com>

-- 
Best regards,
Sebastian


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-10-06  9:57 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-02  5:33 [PATCH] iommu/dma: Catch scatterlist length overflows Krzysztof Karas
2026-10-02  7:01 ` ✗ i915.CI.BAT: failure for " Patchwork
2026-10-05  7:35   ` Krzysztof Karas
2026-10-02  9:14 ` [PATCH] " sashiko-bot
2026-10-06  9:56 ` Sebastian Brzezinka

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox