From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f178.google.com (mail-pf1-f178.google.com [209.85.210.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1650238F25D for ; Wed, 8 Apr 2026 12:02:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.178 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1775649728; cv=none; b=gnpR+VL0XBeT4dePtLtU2YfS4tp08aVMuiQwJdy9rdwv0uOJoRfEY3b/NIjtTlTfEW4ahp0GVLAOHgr7iZmJyVAtaQSR/nF6/bxLv264nmLQTHibqr3Ii95J0eIxFXcG8m4wiyN3uUpxN+rcIhGGd5m7GUZxRomnoCsN5Gs6mQY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1775649728; c=relaxed/simple; bh=ClRhNRwxPLJnSZeAFoT+Im+tz9UAH8Wr+KY9oPbAxZg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=GdvgDWcvey46ZUdD9JaBLLf8Z+LSvu8MB/y4+XlsqJAaICx2ZNz8tUoIejqFF27b9QJsPet/EeGV7rRmoYOBMvPRzyAyDVVBxTzKLDCyKWTB0A9DsUEFXLfsgL8la8vS9TIZUuTc29jzxCQx+sB07wDXXKEgQTsl5cljUrnyXVY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=kWinODTd; arc=none smtp.client-ip=209.85.210.178 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="kWinODTd" Received: by mail-pf1-f178.google.com with SMTP id d2e1a72fcca58-82c28f0a4ecso4542295b3a.3 for ; Wed, 08 Apr 2026 05:02:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1775649726; x=1776254526; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=yT/imSl5xO1+XIbW+YZh2He2MwMtKgkLKK3cHIqMkqk=; b=kWinODTdxSVKhFMJPUtPQE8XmJdI6oEACLtzxdpwcxDwq7yCU3N7B39EMBubJ7QUAR 3sHLE2JYrpGWJZL5j8jF6JI8osUZ4Do7g6LeTT8Cw85Fswr/lqlmV7w4C41S9yDerm2j hasOrBWlaYWmwGkrJLZWH6NPiwEp7kL4thUUwp2czzj9To7dG4pFYrgn30VRjknN7EwX 4LkZf1fElT4xf4x/r0tvanDHHmOkxN1+RueOyfxTdYjJx/Qn3ztpXz1MADigRIYKYwUZ fMTb9JFQnQ5pcsV5oz+pzK210iDyo8BcjnMJYp8pAopySa0A8HbW7fiz1J3g/XrXKvOE /sRg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1775649726; x=1776254526; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=yT/imSl5xO1+XIbW+YZh2He2MwMtKgkLKK3cHIqMkqk=; b=Pzg+/SPHAHscipiLxmh5rjkLqExpt8/49c8tGOmFYory+/PuMrL19WLDLELWp3+LsO oLqbPHRtD4/XiSF4pKa0fZ30H7DvHcQtq2YAfzE0BXFhW7husNo8iAYt9/PdCHecGEYz xktIWMvT1Io6zF4Ivrc3sYR4u4N11JYbpTtjZVv5t1TUqXxuvMMzWkkDWEmm28P0ohQa YSAqirIWYxSyF8lVRYgyWAtM8XECVInY4RTPgXGdfx8ZyEOQIaIFEz5Hed3m8u95gJB/ xG/Tm3XBknbag0vDqqRiIsW4alvhhCafE6NvTJSy7w41JgCj6D3EiuJQZKz5uskzyqKF 7ZMw== X-Forwarded-Encrypted: i=1; AJvYcCWAy537SS5EVIGMRqRuxeCRvfqoyInHCsZYLFUHFK1LinmLcPfaan4AiZfxPXylviwvzMHxSP2bqvxgHg4=@vger.kernel.org X-Gm-Message-State: AOJu0Yw5v5kJr3zwFhTYaqFCN3vCGcR37wdzYUfz3j0Vrgzw7SnzWlPN ckEHsoKAo4oEqjz7elT6N7Jb5AwsY58eoIljdOgabBJteOxj6HkcS2PA X-Gm-Gg: AeBDieuSZu/hQ+7CQzT8lQKoPDKqmOiagsGgeTU47m68gRhXTcIp/blzFK3fS37Rqjv y8ZEkXcM+QOvDpPDjvchvQhF6tRhUxZjYWvNZQN+50KlmF/JISm7cD+1EW2qvMUO3CKvpToJJBH YLUGaxOg2Fxfp54r7T0Ern60Ow3yIZzFcsJcOyknYJZfEge6QTw2ZaUb67f8LAecKz//ee6LbA3 SlEy6MgIMtKe5TwGYAikBHcpl5gNVBnVQIGo6i+vpsoyYDtg2ol7AVexmpCEmIUeSs1f4CV1jRD OFX/jS4vvqJ6AeqwAjdwifHSoJvxqrKnrwH5GUd3a7XdI++bPOL7AJzDKUnFjItspcdTngcx4lW VOXAgkjlzf8KIyCqcdh0kfTv4y4KUELMcNzAtCH0982I6CUh4fPFxe7yMvPeouX8wozuXmCT+nV DVf13mOEaSRuH/SuxqI+yYLV/1hfdISn7yz5uq0QtQRwEb X-Received: by 2002:a05:6a00:4613:b0:81e:e09d:2687 with SMTP id d2e1a72fcca58-82d0da27ab5mr20793609b3a.1.1775649725987; Wed, 08 Apr 2026 05:02:05 -0700 (PDT) Received: from Mac.localdomain ([49.205.216.49]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-82cf9b3e169sm21209322b3a.18.2026.04.08.05.02.02 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 08 Apr 2026 05:02:05 -0700 (PDT) From: "Ritesh Harjani (IBM)" To: linuxppc-dev@lists.ozlabs.org, Haren Myneni Cc: Madhavan Srinivasan , Christophe Leroy , Venkat Rao Bagalkote , Nicholas Piggin , linux-kernel@vger.kernel.org, "Ritesh Harjani (IBM)" Subject: [RFC v2 03/10] pseries/papr-hvpipe: Fix null ptr deref in papr_hvpipe_dev_create_handle() Date: Wed, 8 Apr 2026 17:31:33 +0530 Message-ID: <0843d293fa00a345f156977534e5cb666f1d8bcd.1775648406.git.ritesh.list@gmail.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit commit 6d3789d347a7 ("papr-hvpipe: convert papr_hvpipe_dev_create_handle() to FD_PREPARE()"), changed the create handle to FD_PREPARE(), but it caused kernel null-ptr-deref because after call to retain_and_null_ptr(src_info), src_info is re-used for adding it to the global list. Getting the following kernel panic in papr_hvpipe_dev_create_handle() when trying to add src_info to the list. Kernel attempted to write user page (0) - exploit attempt? (uid: 0) BUG: Kernel NULL pointer dereference on write at 0x00000000 Faulting instruction address: 0xc0000000001b44a0 Oops: Kernel access of bad area, sig: 11 [#1] ... Call Trace: papr_hvpipe_dev_ioctl+0x1f4/0x48c (unreliable) sys_ioctl+0x528/0x1064 system_call_exception+0x128/0x360 system_call_vectored_common+0x15c/0x2ec Now, the error handling with FD_PREPARE's file cleanup and __free(kfree) auto cleanup is getting too convoluted. This is mainly because we need to ensure only 1 user get the srcID handle. To simplify this, we allocate prepare the src_info in the beginning and add it to the global list under a spinlock after checking that no duplicates exist. This simplify the error handling where if the FD_ADD fails, we can simply remove the src_info from the list and consume any pending msg in hvpipe to be cleared, after src_info became visible in the global list. Fixes: 6d3789d347a7 ("papr-hvpipe: convert papr_hvpipe_dev_create_handle() to FD_PREPARE()") Reported-by: Haren Myneni Signed-off-by: Ritesh Harjani (IBM) --- arch/powerpc/platforms/pseries/papr-hvpipe.c | 57 ++++++++++---------- 1 file changed, 30 insertions(+), 27 deletions(-) diff --git a/arch/powerpc/platforms/pseries/papr-hvpipe.c b/arch/powerpc/platforms/pseries/papr-hvpipe.c index 3392874ebdf6..402781299497 100644 --- a/arch/powerpc/platforms/pseries/papr-hvpipe.c +++ b/arch/powerpc/platforms/pseries/papr-hvpipe.c @@ -480,23 +480,10 @@ static const struct file_operations papr_hvpipe_handle_ops = { static int papr_hvpipe_dev_create_handle(u32 srcID) { - struct hvpipe_source_info *src_info __free(kfree) = NULL; + struct hvpipe_source_info *src_info; + int fd; unsigned long flags; - spin_lock_irqsave(&hvpipe_src_list_lock, flags); - /* - * Do not allow more than one process communicates with - * each source. - */ - src_info = hvpipe_find_source(srcID); - if (src_info) { - spin_unlock_irqrestore(&hvpipe_src_list_lock, flags); - pr_err("pid(%d) is already using the source(%d)\n", - src_info->tsk->pid, srcID); - return -EALREADY; - } - spin_unlock_irqrestore(&hvpipe_src_list_lock, flags); - src_info = kzalloc_obj(*src_info, GFP_KERNEL_ACCOUNT); if (!src_info) return -ENOMEM; @@ -505,26 +492,42 @@ static int papr_hvpipe_dev_create_handle(u32 srcID) src_info->tsk = current; init_waitqueue_head(&src_info->recv_wqh); - FD_PREPARE(fdf, O_RDONLY | O_CLOEXEC, - anon_inode_getfile("[papr-hvpipe]", &papr_hvpipe_handle_ops, - (void *)src_info, O_RDWR)); - if (fdf.err) - return fdf.err; - - retain_and_null_ptr(src_info); - spin_lock_irqsave(&hvpipe_src_list_lock, flags); /* - * If two processes are executing ioctl() for the same - * source ID concurrently, prevent the second process to - * acquire FD. + * Do not allow more than one process communicates with + * each source. */ + spin_lock_irqsave(&hvpipe_src_list_lock, flags); if (hvpipe_find_source(srcID)) { spin_unlock_irqrestore(&hvpipe_src_list_lock, flags); + pr_err("pid(%d) could not get the source(%d)\n", + src_info->tsk->pid, srcID); + kfree(src_info); return -EALREADY; } list_add(&src_info->list, &hvpipe_src_list); spin_unlock_irqrestore(&hvpipe_src_list_lock, flags); - return fd_publish(fdf); + + fd = FD_ADD(O_RDONLY | O_CLOEXEC, + anon_inode_getfile("[papr-hvpipe]", &papr_hvpipe_handle_ops, + (void *)src_info, O_RDWR)); + if (fd < 0) { + spin_lock_irqsave(&hvpipe_src_list_lock, flags); + list_del(&src_info->list); + spin_unlock_irqrestore(&hvpipe_src_list_lock, flags); + /* + * if we fail to add FD, that means no userspace program is + * polling. In that case if there is a msg pending because the + * interrupt was fired after the src_info was added to the + * global list, then let's consume it here, to unblock the + * hvpipe + */ + if (src_info->hvpipe_status & HVPIPE_MSG_AVAILABLE) + hvpipe_rtas_recv_msg(NULL, 0); + kfree(src_info); + return fd; + } + + return fd; } /* -- 2.39.5