Intel-XE Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 1/2] drm/xe/ufence: Prefetch ufence addr to catch bogus address
@ 2024-10-11 11:57 Nirmoy Das
  2024-10-11 11:57 ` [PATCH 2/2] drm/xe/ufence: Warn if mmget_not_zero() fails Nirmoy Das
                   ` (8 more replies)
  0 siblings, 9 replies; 14+ messages in thread
From: Nirmoy Das @ 2024-10-11 11:57 UTC (permalink / raw)
  To: intel-xe; +Cc: Nirmoy Das, Matthew Brost

access_ok() only checks for addr overflow so also try to read the addr
to catch invalid addr sent from userspace.

Link: https://gitlab.freedesktop.org/drm/xe/kernel/-/issues/1630
Cc: Matthew Brost <matthew.brost@intel.com>
Signed-off-by: Nirmoy Das <nirmoy.das@intel.com>
---
 drivers/gpu/drm/xe/xe_sync.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/xe/xe_sync.c b/drivers/gpu/drm/xe/xe_sync.c
index bb3c2a830362..6a2e4dd41d56 100644
--- a/drivers/gpu/drm/xe/xe_sync.c
+++ b/drivers/gpu/drm/xe/xe_sync.c
@@ -54,8 +54,9 @@ static struct xe_user_fence *user_fence_create(struct xe_device *xe, u64 addr,
 {
 	struct xe_user_fence *ufence;
 	u64 __user *ptr = u64_to_user_ptr(addr);
+	u64 __maybe_unused prefetch_val;
 
-	if (!access_ok(ptr, sizeof(*ptr)))
+	if (get_user(prefetch_val, ptr))
 		return ERR_PTR(-EFAULT);
 
 	ufence = kmalloc(sizeof(*ufence), GFP_KERNEL);
-- 
2.46.0


^ permalink raw reply related	[flat|nested] 14+ messages in thread
* [PATCH 0/2]  Improve ufence addr validation and error handling
@ 2024-10-15  9:05 Nirmoy Das
  2024-10-15  9:05 ` [PATCH 1/2] drm/xe/ufence: Prefetch ufence addr to catch bogus address Nirmoy Das
  0 siblings, 1 reply; 14+ messages in thread
From: Nirmoy Das @ 2024-10-15  9:05 UTC (permalink / raw)
  To: intel-xe
  Cc: Nirmoy Das, Francois Dugast, Maarten Lankhorst, Matthew Auld,
	Matthew Brost

Resending https://patchwork.freedesktop.org/series/139887/ with 
Test-with tag to validate we catch bogus addr from userspace early.

Test-with: 20241014141839.1618518-1-nirmoy.das@intel.com
Cc: Francois Dugast <francois.dugast@intel.com>
Cc: Maarten Lankhorst <maarten.lankhorst@linux.intel.com>
Cc: Matthew Auld <matthew.auld@intel.com>
Cc: Matthew Brost <matthew.brost@intel.com>
Nirmoy Das (2):
  drm/xe/ufence: Prefetch ufence addr to catch bogus address
  drm/xe/ufence: Warn if mmget_not_zero() fails

 drivers/gpu/drm/xe/xe_sync.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

-- 
2.46.0


^ permalink raw reply	[flat|nested] 14+ messages in thread

end of thread, other threads:[~2024-10-15  9:47 UTC | newest]

Thread overview: 14+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-10-11 11:57 [PATCH 1/2] drm/xe/ufence: Prefetch ufence addr to catch bogus address Nirmoy Das
2024-10-11 11:57 ` [PATCH 2/2] drm/xe/ufence: Warn if mmget_not_zero() fails Nirmoy Das
2024-10-14  9:27   ` Francois Dugast
2024-10-14 10:58     ` Maarten Lankhorst
2024-10-14 11:37       ` Francois Dugast
2024-10-11 13:16 ` ✓ CI.Patch_applied: success for series starting with [1/2] drm/xe/ufence: Prefetch ufence addr to catch bogus address Patchwork
2024-10-11 13:17 ` ✓ CI.checkpatch: " Patchwork
2024-10-11 13:18 ` ✓ CI.KUnit: " Patchwork
2024-10-11 13:34 ` ✓ CI.Build: " Patchwork
2024-10-11 13:37 ` ✓ CI.Hooks: " Patchwork
2024-10-11 13:39 ` ✓ CI.checksparse: " Patchwork
2024-10-11 14:07 ` ✗ CI.BAT: failure " Patchwork
2024-10-11 16:01 ` ✗ CI.FULL: " Patchwork
  -- strict thread matches above, loose matches on Subject: below --
2024-10-15  9:05 [PATCH 0/2] Improve ufence addr validation and error handling Nirmoy Das
2024-10-15  9:05 ` [PATCH 1/2] drm/xe/ufence: Prefetch ufence addr to catch bogus address Nirmoy Das

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox