Skip to content

[codex] Fix PSYS userptr allocation and attachment cleanup - #108

Open
AFOliveira wants to merge 2 commits into
intel:mainfrom
AFOliveira:fix/psys-userptr-and-attachment
Open

AFOliveira wants to merge 2 commits into
intel:mainfrom
AFOliveira:fix/psys-userptr-and-attachment

Conversation

@AFOliveira

Copy link
Copy Markdown

This PR proposes two focused fixes for PSYS userptr buffer handling, adapted from the downstream work in omacom/omarchy-pkgs#264.

The first commit validates the userptr address interval and page count before allocation, then uses kvcalloc() for the page-pointer array. The existing allocation narrows the byte count into an int; on x86-64, a request for 0x20000001 pages can allocate only eight bytes while passing the original page count to GUP.

The second commit clears attachment and mapping state on the shared map-failure path. A failed attachment otherwise leaves an error pointer, or a later mapping failure leaves a detached pointer, in an exported buffer that can survive until its dma-buf release callback dereferences that state.

The series changes only drivers/media/pci/intel/ipu7/psys/ipu-psys.c. It preserves the existing pinning flags, VMA checks, partial-pin cleanup, and imported-buffer ownership rules. It does not include Omarchy packaging changes, device permissions, or an additional byte-length cap.

The series is based on 495acc90feb09d8008c0a6228fb8bb4c6415ca62.

Both commits carry my DCO sign-off. These issues and the downstream fixes are already public in the linked PR; this submission is not an embargoed disclosure.

The userptr length reaches the page-array allocation without range checks. The pointer-array byte count is narrowed into an int, so a request for 0x20000001 pages on x86-64 allocates only eight bytes while GUP still receives the original count.

Validate the address interval before calculating its page count, reject counts that cannot be passed to GUP, and use kvcalloc to check the array-size multiplication. Preserve the existing pinning flags, VMA checks and partial-pin cleanup without adding an arbitrary byte-length cap.

Signed-off-by: Afonso Oliveira <afonso.oliveira707@gmail.com>
A failed dma_buf_attach leaves an error pointer in db_attach. A later map or vmap failure instead detaches the attachment but leaves the freed pointer in the surviving exported userptr buffer. The dma-buf release callback subsequently dereferences that pointer.

Clear the failed attachment and mapping state at the shared failure label, before dropping the local dma-buf reference. Preserve the existing detach, list removal and imported-buffer ownership rules.

Signed-off-by: Afonso Oliveira <afonso.oliveira707@gmail.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant