Intel-GFX Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] iommu/dma: Catch scatterlist length overflows
@ 2026-10-02  5:33 Krzysztof Karas
  2026-10-02  7:01 ` ✗ i915.CI.BAT: failure for " Patchwork
                   ` (2 more replies)
  0 siblings, 3 replies; 5+ messages in thread
From: Krzysztof Karas @ 2026-10-02  5:33 UTC (permalink / raw)
  To: intel-gfx, iommu, dri-devel
  Cc: Robin Murphy, Joerg Roedel, Will Deacon, Andi Shyti,
	Michał Grzelak, Janusz Krzysztofik, Sebastian Brzezinka,
	Krzysztof Niemiec, Krzysztof Karas, stable

It is possible, when a very large mapping uses only one
scatterlist, that padding overflows scatterlist's length field.
This results in:
 1) silently wrapping the value
 2) smaller than desired mappings produced by iommu_map_sg
 3) leaving mapped bytes in memory (no iommu_unmap)

Address this issue by adding overflow detection for scatterlist
length field.

Fixes: 809eac54cdd6 ("iommu/dma: Implement scatterlist segment merging")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Krzysztof Karas <krzysztof.karas@intel.com>
Reviewed-by: Robin Murphy <robin.murphy@arm.com>
---
This patch was previously part of "drivers: Improve memory
management for large object allocations when i915/shmem is used
with iommu" series, but was extracted and posted separately on
request of one of the reviewers (Andi Shyti). There have been no
functional changes since last version.

this version:
 * Added separating blank lines (Andi);
 * Added IOMMU maintainers suggested by get_maintainer.pl
   script to CC (Andi);

 drivers/iommu/dma-iommu.c | 20 +++++++++++++++++++-
 1 file changed, 19 insertions(+), 1 deletion(-)

diff --git a/drivers/iommu/dma-iommu.c b/drivers/iommu/dma-iommu.c
index 58c624513cd43..06edb4056dc1b 100644
--- a/drivers/iommu/dma-iommu.c
+++ b/drivers/iommu/dma-iommu.c
@@ -1477,6 +1477,11 @@ int iommu_dma_map_sg(struct device *dev, struct scatterlist *sg, int nents,
 		sg_dma_len(s) = s_length;
 		s->offset -= s_iova_off;
 		s_length = iova_align(iovad, s_length + s_iova_off);
+		if (overflows_type(s_length, s->length)) {
+			ret = -EOVERFLOW;
+
+			goto out_restore_sg;
+		}
 		s->length = s_length;
 
 		/*
@@ -1493,7 +1498,20 @@ int iommu_dma_map_sg(struct device *dev, struct scatterlist *sg, int nents,
 		 *   time through here (i.e. before it has a meaningful value).
 		 */
 		if (pad_len && pad_len < s_length - 1) {
-			prev->length += pad_len;
+			unsigned int new_prev_len;
+
+			/*
+			 * For large mappings spanning multiple GBs we
+			 * may not be able to fit all needed padding into
+			 * sg->length.
+			 */
+			if (check_add_overflow(prev->length, pad_len, &new_prev_len)) {
+				ret = -EOVERFLOW;
+
+				goto out_restore_sg;
+			}
+
+			prev->length = new_prev_len;
 			iova_len += pad_len;
 		}
 
-- 
2.34.1


^ permalink raw reply related	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-10-06  9:57 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-02  5:33 [PATCH] iommu/dma: Catch scatterlist length overflows Krzysztof Karas
2026-10-02  7:01 ` ✗ i915.CI.BAT: failure for " Patchwork
2026-10-05  7:35   ` Krzysztof Karas
2026-10-02  9:14 ` [PATCH] " sashiko-bot
2026-10-06  9:56 ` Sebastian Brzezinka

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox