Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

media/v4l2-core: untag user pointers in videobuf_dma_contig_user_get

This patch is a part of a series that extends kernel ABI to allow to pass
tagged user pointers (with the top byte set to something else other than
0x00) as syscall arguments.

videobuf_dma_contig_user_get() uses provided user pointers for vma
lookups, which can only by done with untagged pointers.

Untag the pointers in this function.

Link: http://lkml.kernel.org/r/100436d5f8e4349a78f27b0bbb27e4801fcb946b.1563904656.git.andreyknvl@google.com
Signed-off-by: Andrey Konovalov <andreyknvl@google.com>
Reviewed-by: Khalid Aziz <khalid.aziz@oracle.com>
Reviewed-by: Kees Cook <keescook@chromium.org>
Acked-by: Mauro Carvalho Chehab <mchehab+samsung@kernel.org>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: Dave Hansen <dave.hansen@intel.com>
Cc: Eric Auger <eric.auger@redhat.com>
Cc: Felix Kuehling <Felix.Kuehling@amd.com>
Cc: Jens Wiklander <jens.wiklander@linaro.org>
Cc: Mike Rapoport <rppt@linux.ibm.com>
Cc: Vincenzo Frascino <vincenzo.frascino@arm.com>
Cc: Will Deacon <will@kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>

authored by

Andrey Konovalov and committed by
Linus Torvalds
e275faf3 4fdfae8d

+5 -4
+5 -4
drivers/media/v4l2-core/videobuf-dma-contig.c
··· 157 157 static int videobuf_dma_contig_user_get(struct videobuf_dma_contig_memory *mem, 158 158 struct videobuf_buffer *vb) 159 159 { 160 + unsigned long untagged_baddr = untagged_addr(vb->baddr); 160 161 struct mm_struct *mm = current->mm; 161 162 struct vm_area_struct *vma; 162 163 unsigned long prev_pfn, this_pfn; ··· 165 164 unsigned int offset; 166 165 int ret; 167 166 168 - offset = vb->baddr & ~PAGE_MASK; 167 + offset = untagged_baddr & ~PAGE_MASK; 169 168 mem->size = PAGE_ALIGN(vb->size + offset); 170 169 ret = -EINVAL; 171 170 172 171 down_read(&mm->mmap_sem); 173 172 174 - vma = find_vma(mm, vb->baddr); 173 + vma = find_vma(mm, untagged_baddr); 175 174 if (!vma) 176 175 goto out_up; 177 176 178 - if ((vb->baddr + mem->size) > vma->vm_end) 177 + if ((untagged_baddr + mem->size) > vma->vm_end) 179 178 goto out_up; 180 179 181 180 pages_done = 0; 182 181 prev_pfn = 0; /* kill warning */ 183 - user_address = vb->baddr; 182 + user_address = untagged_baddr; 184 183 185 184 while (pages_done < (mem->size >> PAGE_SHIFT)) { 186 185 ret = follow_pfn(vma, user_address, &this_pfn);