public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: "Ritesh Harjani (IBM)" <ritesh.list@gmail.com>
To: linuxppc-dev@lists.ozlabs.org, Haren Myneni <haren@linux.ibm.com>
Cc: Madhavan Srinivasan <maddy@linux.ibm.com>,
	Christophe Leroy <chleroy@kernel.org>,
	Venkat Rao Bagalkote <venkat88@linux.ibm.com>,
	Nicholas Piggin <npiggin@gmail.com>,
	linux-kernel@vger.kernel.org,
	"Ritesh Harjani (IBM)" <ritesh.list@gmail.com>
Subject: [RFC v1 0/6] pseries/papr-hvpipe: Fix and simplify papr-hvpipe
Date: Tue,  7 Apr 2026 20:01:34 +0530	[thread overview]
Message-ID: <cover.1775569027.git.ritesh.list@gmail.com> (raw)

Haren reported a UAF / null ptr deref issue here [1]. While reviewing that and
going over papr-hvpipe code, I found couple of more issues around the usage of
copy_to_user() and few refactoring which simplifies the code.

This patch series is an attempt to that. Note that this is only compile tested
on pseries for now.

Haren, I will kindly need your help in verifying this please. Let me know if we
have a selftests or any other test framework for this, which I can utilize too.

[1]: https://lore.kernel.org/linuxppc-dev/20260317040444.2785741-1-haren@linux.ibm.com/


Ritesh Harjani (IBM) (6):
  pseries/papr-hvpipe: Fix null ptr deref in papr_hvpipe_dev_create_handle
  pseries/papr-hvpipe: Fix the usage of copy_to_user()
  pseries/papr-hvpipe: Simplify spin_unlock() usage in papr_hvpipe_handle_release
  pseries/papr-hvpipe: Kill task_struct pointer from struct hvpipe_source_info
  pseries/papr-hvpipe: Refactor and simplify hvpipe_rtas_recv_msg()
  pseries/papr-hvpipe: Simplify error handling in papr_hvpipe_init()

 arch/powerpc/platforms/pseries/papr-hvpipe.c | 135 +++++++++----------
 arch/powerpc/platforms/pseries/papr-hvpipe.h |   1 -
 2 files changed, 66 insertions(+), 70 deletions(-)

--
2.39.5


             reply	other threads:[~2026-04-07 14:31 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-04-07 14:31 Ritesh Harjani (IBM) [this message]
2026-04-07 14:31 ` [RFC v1 1/6] pseries/papr-hvpipe: Fix null ptr deref in papr_hvpipe_dev_create_handle Ritesh Harjani (IBM)
2026-04-07 14:31 ` [RFC v1 2/6] pseries/papr-hvpipe: Fix the usage of copy_to_user() Ritesh Harjani (IBM)
2026-04-07 14:31 ` [RFC v1 3/6] pseries/papr-hvpipe: Simplify spin_unlock() usage in papr_hvpipe_handle_release Ritesh Harjani (IBM)
2026-04-07 14:31 ` [RFC v1 4/6] pseries/papr-hvpipe: Kill task_struct pointer from struct hvpipe_source_info Ritesh Harjani (IBM)
2026-04-07 14:31 ` [RFC v1 5/6] pseries/papr-hvpipe: Refactor and simplify hvpipe_rtas_recv_msg() Ritesh Harjani (IBM)
2026-04-07 14:31 ` [RFC v1 6/6] pseries/papr-hvpipe: Simplify error handling in papr_hvpipe_init() Ritesh Harjani (IBM)
2026-04-07 18:21 ` [RFC v1 0/6] pseries/papr-hvpipe: Fix and simplify papr-hvpipe Haren Myneni

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=cover.1775569027.git.ritesh.list@gmail.com \
    --to=ritesh.list@gmail.com \
    --cc=chleroy@kernel.org \
    --cc=haren@linux.ibm.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linuxppc-dev@lists.ozlabs.org \
    --cc=maddy@linux.ibm.com \
    --cc=npiggin@gmail.com \
    --cc=venkat88@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox