From: Jérôme Glisse Date: Tue, 19 Apr 2016 13:07:50 +0000 (-0400) Subject: drm/radeon: forbid mapping of userptr bo through radeon device file X-Git-Tag: v4.1.12-92~15^2~178 X-Git-Url: https://www.infradead.org/git/?a=commitdiff_plain;h=6d83cc7613d0ad31b506ab503d1c2c87274aed0e;p=users%2Fjedix%2Flinux-maple.git drm/radeon: forbid mapping of userptr bo through radeon device file Orabug: 25227133 [ Upstream commit b5dcec693f87cb8475f2291c0075b2422addd3d6 ] Allowing userptr bo which are basicly a list of page from some vma (so either anonymous page or file backed page) would lead to serious corruption of kernel structures and counters (because we overwrite the page->mapping field when mapping buffer). This will already block if the buffer was populated before anyone does try to mmap it because then TTM_PAGE_FLAG_SG would be set in in the ttm_tt flags. But that flag is check before ttm_tt_populate in the ttm vm fault handler. So to be safe just add a check to verify_access() callback. Reviewed-by: Christian König Signed-off-by: Jérôme Glisse Cc: Signed-off-by: Alex Deucher Signed-off-by: Sasha Levin (cherry picked from commit 2719d3c05d4c93054e7c5838cc5b1906f72b465e) Signed-off-by: Dhaval Giani --- diff --git a/drivers/gpu/drm/radeon/radeon_ttm.c b/drivers/gpu/drm/radeon/radeon_ttm.c index edafd3c2b1702..205b6dbdcc1af 100644 --- a/drivers/gpu/drm/radeon/radeon_ttm.c +++ b/drivers/gpu/drm/radeon/radeon_ttm.c @@ -235,6 +235,8 @@ static int radeon_verify_access(struct ttm_buffer_object *bo, struct file *filp) { struct radeon_bo *rbo = container_of(bo, struct radeon_bo, tbo); + if (radeon_ttm_tt_has_userptr(bo->ttm)) + return -EPERM; return drm_vma_node_verify_access(&rbo->gem_base.vma_node, filp); }