From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S965139AbcBBSqH (ORCPT ); Tue, 2 Feb 2016 13:46:07 -0500 Received: from mail-qk0-f193.google.com ([209.85.220.193]:35394 "EHLO mail-qk0-f193.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S964898AbcBBSqE (ORCPT ); Tue, 2 Feb 2016 13:46:04 -0500 Date: Tue, 2 Feb 2016 16:46:00 -0200 From: Gustavo Padovan To: Maarten Lankhorst Cc: Greg Kroah-Hartman , linux-kernel@vger.kernel.org, devel@driverdev.osuosl.org, dri-devel@lists.freedesktop.org, Daniel Stone , Arve =?iso-8859-1?B?SGr4bm5lduVn?= , Riley Andrews , Daniel Vetter , Rob Clark , Greg Hackmann , John Harrison , Gustavo Padovan Subject: Re: [PATCH v2 08/11] staging/android: make info->len return only the size of fence_infos Message-ID: <20160202184600.GB29160@joana> Mail-Followup-To: Gustavo Padovan , Maarten Lankhorst , Greg Kroah-Hartman , linux-kernel@vger.kernel.org, devel@driverdev.osuosl.org, dri-devel@lists.freedesktop.org, Daniel Stone , Arve =?iso-8859-1?B?SGr4bm5lduVn?= , Riley Andrews , Daniel Vetter , Rob Clark , Greg Hackmann , John Harrison , Gustavo Padovan References: <1454419402-10769-1-git-send-email-gustavo@padovan.org> <1454419402-10769-9-git-send-email-gustavo@padovan.org> <56B0BAC6.30506@linux.intel.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <56B0BAC6.30506@linux.intel.com> User-Agent: Mutt/1.5.24 (2015-08-30) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org 2016-02-02 Maarten Lankhorst : > Op 02-02-16 om 14:23 schreef Gustavo Padovan: > > From: Gustavo Padovan > > > > The len member of struct sync_file_info was returning the size of the whole > > buffer (struct sync_file_info + fence_infos at the of it). This commit > > change it to return only the size of the array of fence_infos. > > > > It also moves len to be right before the fences_infos struct. > > > > Signed-off-by: Gustavo Padovan > > --- > > drivers/staging/android/sync.c | 16 +++++++++++----- > > drivers/staging/android/uapi/sync.h | 7 +++---- > > 2 files changed, 14 insertions(+), 9 deletions(-) > > > > diff --git a/drivers/staging/android/sync.c b/drivers/staging/android/sync.c > > index ba7d461..e5fbf5a 100644 > > --- a/drivers/staging/android/sync.c > > +++ b/drivers/staging/android/sync.c > > @@ -502,14 +502,19 @@ static int sync_fill_fence_info(struct fence *fence, void *data, int size) > > static long sync_file_ioctl_fence_info(struct sync_file *sync_file, > > unsigned long arg) > > { > > - struct sync_file_info *info; > > + struct sync_file_info in, *info; > > __u32 size; > > - __u32 len = 0; > > + __u32 b_len, len = 0; > > int ret, i; > > > > - if (copy_from_user(&size, (void __user *)arg, sizeof(size))) > > + if (copy_from_user(&in, (void __user *)arg, sizeof(*info))) > > return -EFAULT; > > > > + if (in.name || in.status || in.num_fences || in.fence_info) > > + return -EFAULT; > > > Did you test this? I think in.name is always true.. Ugh, no! These checks were last change I made so I think I forgot to test them properly. Gustavo