[codex] Fix PSYS userptr allocation and attachment cleanup - #108
Open
AFOliveira wants to merge 2 commits into
Open
AFOliveira wants to merge 2 commits into
AFOliveira wants to merge 2 commits into
Conversation
The userptr length reaches the page-array allocation without range checks. The pointer-array byte count is narrowed into an int, so a request for 0x20000001 pages on x86-64 allocates only eight bytes while GUP still receives the original count. Validate the address interval before calculating its page count, reject counts that cannot be passed to GUP, and use kvcalloc to check the array-size multiplication. Preserve the existing pinning flags, VMA checks and partial-pin cleanup without adding an arbitrary byte-length cap. Signed-off-by: Afonso Oliveira <afonso.oliveira707@gmail.com>
A failed dma_buf_attach leaves an error pointer in db_attach. A later map or vmap failure instead detaches the attachment but leaves the freed pointer in the surviving exported userptr buffer. The dma-buf release callback subsequently dereferences that pointer. Clear the failed attachment and mapping state at the shared failure label, before dropping the local dma-buf reference. Preserve the existing detach, list removal and imported-buffer ownership rules. Signed-off-by: Afonso Oliveira <afonso.oliveira707@gmail.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR proposes two focused fixes for PSYS userptr buffer handling, adapted from the downstream work in omacom/omarchy-pkgs#264.
The first commit validates the userptr address interval and page count before allocation, then uses
kvcalloc()for the page-pointer array. The existing allocation narrows the byte count into anint; on x86-64, a request for0x20000001pages can allocate only eight bytes while passing the original page count to GUP.The second commit clears attachment and mapping state on the shared map-failure path. A failed attachment otherwise leaves an error pointer, or a later mapping failure leaves a detached pointer, in an exported buffer that can survive until its dma-buf release callback dereferences that state.
The series changes only
drivers/media/pci/intel/ipu7/psys/ipu-psys.c. It preserves the existing pinning flags, VMA checks, partial-pin cleanup, and imported-buffer ownership rules. It does not include Omarchy packaging changes, device permissions, or an additional byte-length cap.The series is based on
495acc90feb09d8008c0a6228fb8bb4c6415ca62.Both commits carry my DCO sign-off. These issues and the downstream fixes are already public in the linked PR; this submission is not an embargoed disclosure.