mirror of
https://github.com/torvalds/linux.git
synced 2026-09-22 20:54:03 +02:00
drm/vmwgfx: use check_add_overflow for shader size+offset bound
vmw_shader_define() validates the user-supplied shader window against
its backing buffer with
(u64)buffer->tbo.base.size < (u64)size + (u64)offset
drm_vmw_shader_create_arg::offset is __u64 in the uapi; when it is
near U64_MAX the unsigned addition wraps and the resulting tiny value
passes the check. The unbounded offset is then stored in
res->guest_memory_offset and forwarded to host SVGA shader-create
commands.
Use check_add_overflow() to detect the wrap and compare the resulting
endpoint against the buffer size.
Fixes: 668b206601 ("drm/vmwgfx: Stop using raw ttm_buffer_object's")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4.7
Signed-off-by: Zack Rusin <zack.rusin@broadcom.com>
Reviewed-by: Ian Forbes <ian.forbes@broadcom.com>
Link: https://patch.msgid.link/20260505222728.519626-12-zack.rusin@broadcom.com
This commit is contained in:
parent
e5c3e484e0
commit
54d56d5b42
|
|
@ -25,6 +25,8 @@
|
|||
*
|
||||
**************************************************************************/
|
||||
|
||||
#include <linux/overflow.h>
|
||||
|
||||
#include <drm/ttm/ttm_placement.h>
|
||||
|
||||
#include "vmwgfx_binding.h"
|
||||
|
|
@ -685,7 +687,7 @@ int vmw_shader_destroy_ioctl(struct drm_device *dev, void *data,
|
|||
static int vmw_user_shader_alloc(struct vmw_private *dev_priv,
|
||||
struct vmw_bo *buffer,
|
||||
size_t shader_size,
|
||||
size_t offset,
|
||||
u64 offset,
|
||||
SVGA3dShaderType shader_type,
|
||||
uint8_t num_input_sig,
|
||||
uint8_t num_output_sig,
|
||||
|
|
@ -739,7 +741,7 @@ static int vmw_user_shader_alloc(struct vmw_private *dev_priv,
|
|||
static struct vmw_resource *vmw_shader_alloc(struct vmw_private *dev_priv,
|
||||
struct vmw_bo *buffer,
|
||||
size_t shader_size,
|
||||
size_t offset,
|
||||
u64 offset,
|
||||
SVGA3dShaderType shader_type)
|
||||
{
|
||||
struct vmw_shader *shader;
|
||||
|
|
@ -768,7 +770,7 @@ static struct vmw_resource *vmw_shader_alloc(struct vmw_private *dev_priv,
|
|||
|
||||
static int vmw_shader_define(struct drm_device *dev, struct drm_file *file_priv,
|
||||
enum drm_vmw_shader_type shader_type_drm,
|
||||
u32 buffer_handle, size_t size, size_t offset,
|
||||
u32 buffer_handle, size_t size, u64 offset,
|
||||
uint8_t num_input_sig, uint8_t num_output_sig,
|
||||
uint32_t *shader_handle)
|
||||
{
|
||||
|
|
@ -779,13 +781,16 @@ static int vmw_shader_define(struct drm_device *dev, struct drm_file *file_priv,
|
|||
int ret;
|
||||
|
||||
if (buffer_handle != SVGA3D_INVALID_ID) {
|
||||
u64 end;
|
||||
|
||||
ret = vmw_user_bo_lookup(file_priv, buffer_handle, &buffer);
|
||||
if (unlikely(ret != 0)) {
|
||||
VMW_DEBUG_USER("Couldn't find buffer for shader creation.\n");
|
||||
return ret;
|
||||
}
|
||||
|
||||
if ((u64)buffer->tbo.base.size < (u64)size + (u64)offset) {
|
||||
if (check_add_overflow((u64)size, (u64)offset, &end) ||
|
||||
end > buffer->tbo.base.size) {
|
||||
VMW_DEBUG_USER("Illegal buffer- or shader size.\n");
|
||||
ret = -EINVAL;
|
||||
goto out_bad_arg;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user