public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* [RFC v1 0/6] pseries/papr-hvpipe: Fix and simplify papr-hvpipe
@ 2026-04-07 14:31 Ritesh Harjani (IBM)
  2026-04-07 14:31 ` [RFC v1 1/6] pseries/papr-hvpipe: Fix null ptr deref in papr_hvpipe_dev_create_handle Ritesh Harjani (IBM)
                   ` (6 more replies)
  0 siblings, 7 replies; 8+ messages in thread
From: Ritesh Harjani (IBM) @ 2026-04-07 14:31 UTC (permalink / raw)
  To: linuxppc-dev, Haren Myneni
  Cc: Madhavan Srinivasan, Christophe Leroy, Venkat Rao Bagalkote,
	Nicholas Piggin, linux-kernel, Ritesh Harjani (IBM)

Haren reported a UAF / null ptr deref issue here [1]. While reviewing that and
going over papr-hvpipe code, I found couple of more issues around the usage of
copy_to_user() and few refactoring which simplifies the code.

This patch series is an attempt to that. Note that this is only compile tested
on pseries for now.

Haren, I will kindly need your help in verifying this please. Let me know if we
have a selftests or any other test framework for this, which I can utilize too.

[1]: https://lore.kernel.org/linuxppc-dev/20260317040444.2785741-1-haren@linux.ibm.com/


Ritesh Harjani (IBM) (6):
  pseries/papr-hvpipe: Fix null ptr deref in papr_hvpipe_dev_create_handle
  pseries/papr-hvpipe: Fix the usage of copy_to_user()
  pseries/papr-hvpipe: Simplify spin_unlock() usage in papr_hvpipe_handle_release
  pseries/papr-hvpipe: Kill task_struct pointer from struct hvpipe_source_info
  pseries/papr-hvpipe: Refactor and simplify hvpipe_rtas_recv_msg()
  pseries/papr-hvpipe: Simplify error handling in papr_hvpipe_init()

 arch/powerpc/platforms/pseries/papr-hvpipe.c | 135 +++++++++----------
 arch/powerpc/platforms/pseries/papr-hvpipe.h |   1 -
 2 files changed, 66 insertions(+), 70 deletions(-)

--
2.39.5


^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2026-04-07 18:21 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-04-07 14:31 [RFC v1 0/6] pseries/papr-hvpipe: Fix and simplify papr-hvpipe Ritesh Harjani (IBM)
2026-04-07 14:31 ` [RFC v1 1/6] pseries/papr-hvpipe: Fix null ptr deref in papr_hvpipe_dev_create_handle Ritesh Harjani (IBM)
2026-04-07 14:31 ` [RFC v1 2/6] pseries/papr-hvpipe: Fix the usage of copy_to_user() Ritesh Harjani (IBM)
2026-04-07 14:31 ` [RFC v1 3/6] pseries/papr-hvpipe: Simplify spin_unlock() usage in papr_hvpipe_handle_release Ritesh Harjani (IBM)
2026-04-07 14:31 ` [RFC v1 4/6] pseries/papr-hvpipe: Kill task_struct pointer from struct hvpipe_source_info Ritesh Harjani (IBM)
2026-04-07 14:31 ` [RFC v1 5/6] pseries/papr-hvpipe: Refactor and simplify hvpipe_rtas_recv_msg() Ritesh Harjani (IBM)
2026-04-07 14:31 ` [RFC v1 6/6] pseries/papr-hvpipe: Simplify error handling in papr_hvpipe_init() Ritesh Harjani (IBM)
2026-04-07 18:21 ` [RFC v1 0/6] pseries/papr-hvpipe: Fix and simplify papr-hvpipe Haren Myneni

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox