public inbox for stable@vger.kernel.org
 help / color / mirror / Atom feed
* [PATCH] vTPM: Fix missing NULL check
@ 2017-03-06 22:21 Hon Ching(Vicky) Lo
  0 siblings, 0 replies; 5+ messages in thread
From: Hon Ching(Vicky) Lo @ 2017-03-06 22:21 UTC (permalink / raw)
  To: lo1; +Cc: Vicky Lo, Hon Ching(Vicky) Lo, stable

The current code passes the address of tpm_chip as the argument to
dev_get_drvdata() without prior NULL check in
tpm_ibmvtpm_get_desired_dma.  This resulted an oops during kernel
boot when vTPM is enabled in Power partition configured in active
memory sharing mode.

The vio_driver's get_desired_dma() is called before the probe(), which
for vtpm is tpm_ibmvtpm_probe, and it's this latter function that
initializes the driver and set data.  Attempting to get data before
the probe() caused the problem.

This patch adds a NULL check to the tpm_ibmvtpm_get_desired_dma.

fixes: 9e0d39d8a6a0 ("tpm: Remove useless priv field in struct tpm_vendor_specific")
Cc: <stable@vger.kernel.org>
Signed-off-by: Hon Ching(Vicky) Lo <honclo@linux.vnet.ibm.com>
---
 drivers/char/tpm/tpm_ibmvtpm.c |    5 ++++-
 1 files changed, 4 insertions(+), 1 deletions(-)

diff --git a/drivers/char/tpm/tpm_ibmvtpm.c b/drivers/char/tpm/tpm_ibmvtpm.c
index 1b9d61f..a88ee25 100644
--- a/drivers/char/tpm/tpm_ibmvtpm.c
+++ b/drivers/char/tpm/tpm_ibmvtpm.c
@@ -313,7 +313,10 @@ static int tpm_ibmvtpm_remove(struct vio_dev *vdev)
 static unsigned long tpm_ibmvtpm_get_desired_dma(struct vio_dev *vdev)
 {
 	struct tpm_chip *chip = dev_get_drvdata(&vdev->dev);
-	struct ibmvtpm_dev *ibmvtpm = dev_get_drvdata(&chip->dev);
+	struct ibmvtpm_dev *ibmvtpm = NULL;
+
+	if (chip)
+		ibmvtpm = dev_get_drvdata(&chip->dev);
 
 	/*
 	 * ibmvtpm initializes at probe time, so the data we are
-- 
1.7.1

^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [PATCH] vTPM: Fix missing NULL check
@ 2017-03-06 22:32 Hon Ching(Vicky) Lo
  0 siblings, 0 replies; 5+ messages in thread
From: Hon Ching(Vicky) Lo @ 2017-03-06 22:32 UTC (permalink / raw)
  To: tpmdd-devel
  Cc: Jarkko Sakkinen, Peter Huewe, Ashley Lai, Vicky Lo, linux-kernel,
	Hon Ching(Vicky) Lo, stable

The current code passes the address of tpm_chip as the argument to
dev_get_drvdata() without prior NULL check in
tpm_ibmvtpm_get_desired_dma.  This resulted an oops during kernel
boot when vTPM is enabled in Power partition configured in active
memory sharing mode.

The vio_driver's get_desired_dma() is called before the probe(), which
for vtpm is tpm_ibmvtpm_probe, and it's this latter function that
initializes the driver and set data.  Attempting to get data before
the probe() caused the problem.

This patch adds a NULL check to the tpm_ibmvtpm_get_desired_dma.

fixes: 9e0d39d8a6a0 ("tpm: Remove useless priv field in struct tpm_vendor_specific")
Cc: <stable@vger.kernel.org>
Signed-off-by: Hon Ching(Vicky) Lo <honclo@linux.vnet.ibm.com>
---
 drivers/char/tpm/tpm_ibmvtpm.c |    5 ++++-
 1 files changed, 4 insertions(+), 1 deletions(-)

diff --git a/drivers/char/tpm/tpm_ibmvtpm.c b/drivers/char/tpm/tpm_ibmvtpm.c
index 1b9d61f..a88ee25 100644
--- a/drivers/char/tpm/tpm_ibmvtpm.c
+++ b/drivers/char/tpm/tpm_ibmvtpm.c
@@ -313,7 +313,10 @@ static int tpm_ibmvtpm_remove(struct vio_dev *vdev)
 static unsigned long tpm_ibmvtpm_get_desired_dma(struct vio_dev *vdev)
 {
 	struct tpm_chip *chip = dev_get_drvdata(&vdev->dev);
-	struct ibmvtpm_dev *ibmvtpm = dev_get_drvdata(&chip->dev);
+	struct ibmvtpm_dev *ibmvtpm = NULL;
+
+	if (chip)
+		ibmvtpm = dev_get_drvdata(&chip->dev);
 
 	/*
 	 * ibmvtpm initializes at probe time, so the data we are
-- 
1.7.1

^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [PATCH] vTPM: Fix missing NULL check
@ 2017-06-18 23:43 Jarkko Sakkinen
  2017-06-19  1:11 ` Greg KH
  0 siblings, 1 reply; 5+ messages in thread
From: Jarkko Sakkinen @ 2017-06-18 23:43 UTC (permalink / raw)
  To: stable; +Cc: honclo, Jarkko Sakkinen

From: "Hon Ching \\(Vicky\\) Lo" <honclo@linux.vnet.ibm.com>

The current code passes the address of tpm_chip as the argument to
dev_get_drvdata() without prior NULL check in
tpm_ibmvtpm_get_desired_dma.  This resulted an oops during kernel
boot when vTPM is enabled in Power partition configured in active
memory sharing mode.

The vio_driver's get_desired_dma() is called before the probe(), which
for vtpm is tpm_ibmvtpm_probe, and it's this latter function that
initializes the driver and set data.  Attempting to get data before
the probe() caused the problem.

This patch adds a NULL check to the tpm_ibmvtpm_get_desired_dma.

fixes: 9e0d39d8a6a0 ("tpm: Remove useless priv field in struct tpm_vendor_specific")
Cc: <stable@vger.kernel.org>
Signed-off-by: Hon Ching(Vicky) Lo <honclo@linux.vnet.ibm.com>
Reviewed-by: Jarkko Sakkine <jarkko.sakkinen@linux.intel.com>
Signed-off-by: Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
---
Backport for v4.9. I asked to Vicky to test my backport so this should be OK.
 drivers/char/tpm/tpm_ibmvtpm.c | 17 +++++++++++------
 1 file changed, 11 insertions(+), 6 deletions(-)

diff --git a/drivers/char/tpm/tpm_ibmvtpm.c b/drivers/char/tpm/tpm_ibmvtpm.c
index 946025a7413b..84eca4f93b82 100644
--- a/drivers/char/tpm/tpm_ibmvtpm.c
+++ b/drivers/char/tpm/tpm_ibmvtpm.c
@@ -295,6 +295,8 @@ static int tpm_ibmvtpm_remove(struct vio_dev *vdev)
 	}
 
 	kfree(ibmvtpm);
+	/* For tpm_ibmvtpm_get_desired_dma */
+	dev_set_drvdata(&vdev->dev, NULL);
 
 	return 0;
 }
@@ -309,13 +311,16 @@ static int tpm_ibmvtpm_remove(struct vio_dev *vdev)
 static unsigned long tpm_ibmvtpm_get_desired_dma(struct vio_dev *vdev)
 {
 	struct tpm_chip *chip = dev_get_drvdata(&vdev->dev);
-	struct ibmvtpm_dev *ibmvtpm = dev_get_drvdata(&chip->dev);
+	struct ibmvtpm_dev *ibmvtpm;
 
-	/* ibmvtpm initializes at probe time, so the data we are
-	* asking for may not be set yet. Estimate that 4K required
-	* for TCE-mapped buffer in addition to CRQ.
-	*/
-	if (!ibmvtpm)
+	/*
+	 * ibmvtpm initializes at probe time, so the data we are
+	 * asking for may not be set yet. Estimate that 4K required
+	 * for TCE-mapped buffer in addition to CRQ.
+	 */
+	if (chip)
+		ibmvtpm = dev_get_drvdata(&chip->dev);
+	else
 		return CRQ_RES_BUF_SIZE + PAGE_SIZE;
 
 	return CRQ_RES_BUF_SIZE + ibmvtpm->rtce_size;
-- 
2.11.0

^ permalink raw reply related	[flat|nested] 5+ messages in thread

* Re: [PATCH] vTPM: Fix missing NULL check
  2017-06-18 23:43 [PATCH] vTPM: Fix missing NULL check Jarkko Sakkinen
@ 2017-06-19  1:11 ` Greg KH
  2017-06-19 14:37   ` Jarkko Sakkinen
  0 siblings, 1 reply; 5+ messages in thread
From: Greg KH @ 2017-06-19  1:11 UTC (permalink / raw)
  To: Jarkko Sakkinen; +Cc: stable, honclo

On Mon, Jun 19, 2017 at 01:43:21AM +0200, Jarkko Sakkinen wrote:
> From: "Hon Ching \\(Vicky\\) Lo" <honclo@linux.vnet.ibm.com>
> 
> The current code passes the address of tpm_chip as the argument to
> dev_get_drvdata() without prior NULL check in
> tpm_ibmvtpm_get_desired_dma.  This resulted an oops during kernel
> boot when vTPM is enabled in Power partition configured in active
> memory sharing mode.
> 
> The vio_driver's get_desired_dma() is called before the probe(), which
> for vtpm is tpm_ibmvtpm_probe, and it's this latter function that
> initializes the driver and set data.  Attempting to get data before
> the probe() caused the problem.
> 
> This patch adds a NULL check to the tpm_ibmvtpm_get_desired_dma.
> 
> fixes: 9e0d39d8a6a0 ("tpm: Remove useless priv field in struct tpm_vendor_specific")
> Cc: <stable@vger.kernel.org>
> Signed-off-by: Hon Ching(Vicky) Lo <honclo@linux.vnet.ibm.com>
> Reviewed-by: Jarkko Sakkine <jarkko.sakkinen@linux.intel.com>
> Signed-off-by: Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
> ---
> Backport for v4.9. I asked to Vicky to test my backport so this should be OK.

Thanks for this, but next time can you give me a hint of what the git
commit id is for the patch in Linus's tree?  I had to go dig it out by
hand :(

greg k-h

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH] vTPM: Fix missing NULL check
  2017-06-19  1:11 ` Greg KH
@ 2017-06-19 14:37   ` Jarkko Sakkinen
  0 siblings, 0 replies; 5+ messages in thread
From: Jarkko Sakkinen @ 2017-06-19 14:37 UTC (permalink / raw)
  To: Greg KH; +Cc: stable, honclo

On Mon, Jun 19, 2017 at 09:11:17AM +0800, Greg KH wrote:
> On Mon, Jun 19, 2017 at 01:43:21AM +0200, Jarkko Sakkinen wrote:
> > From: "Hon Ching \\(Vicky\\) Lo" <honclo@linux.vnet.ibm.com>
> > 
> > The current code passes the address of tpm_chip as the argument to
> > dev_get_drvdata() without prior NULL check in
> > tpm_ibmvtpm_get_desired_dma.  This resulted an oops during kernel
> > boot when vTPM is enabled in Power partition configured in active
> > memory sharing mode.
> > 
> > The vio_driver's get_desired_dma() is called before the probe(), which
> > for vtpm is tpm_ibmvtpm_probe, and it's this latter function that
> > initializes the driver and set data.  Attempting to get data before
> > the probe() caused the problem.
> > 
> > This patch adds a NULL check to the tpm_ibmvtpm_get_desired_dma.
> > 
> > fixes: 9e0d39d8a6a0 ("tpm: Remove useless priv field in struct tpm_vendor_specific")
> > Cc: <stable@vger.kernel.org>
> > Signed-off-by: Hon Ching(Vicky) Lo <honclo@linux.vnet.ibm.com>
> > Reviewed-by: Jarkko Sakkine <jarkko.sakkinen@linux.intel.com>
> > Signed-off-by: Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com>
> > ---
> > Backport for v4.9. I asked to Vicky to test my backport so this should be OK.
> 
> Thanks for this, but next time can you give me a hint of what the git
> commit id is for the patch in Linus's tree?  I had to go dig it out by
> hand :(
> 
> greg k-h

I forgot it. I'm sorry. Has been in my previous backports and will be
in my future backports!

/Jarkko

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2017-06-19 14:37 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-06-18 23:43 [PATCH] vTPM: Fix missing NULL check Jarkko Sakkinen
2017-06-19  1:11 ` Greg KH
2017-06-19 14:37   ` Jarkko Sakkinen
  -- strict thread matches above, loose matches on Subject: below --
2017-03-06 22:32 Hon Ching(Vicky) Lo
2017-03-06 22:21 Hon Ching(Vicky) Lo

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox