mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [char-misc-next] mei: hbm: fix client dma reply status
@ 2021-12-28  8:20 Tomas Winkler
  2021-12-29 16:09 ` Grumbach, Emmanuel
  0 siblings, 1 reply; 2+ messages in thread
From: Tomas Winkler @ 2021-12-28  8:20 UTC (permalink / raw)
  To: Greg Kroah-Hartman
  Cc: Alexander Usyskin, Vitaly Lubart, linux-kernel,
	Emmanuel Grumbach, stable, Tomas Winkler

From: Alexander Usyskin <alexander.usyskin@intel.com>

Don't blindly copy status value received from the firmware
into internal client status field,
It may be positive and ERR_PTR(ret) will translate it
into an invalid address and the caller will crash.

Put the error code into the client status on failure.

Fixes: 369aea845951 ("mei: implement client dma setup.")
Reported-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
Cc: <stable@vger.kernel.org> # v5.11+
Acked-by: Tomas Winkler <tomas.winkler@intel.com>
Signed-off-by: Alexander Usyskin <alexander.usyskin@intel.com>
Signed-off-by: Tomas Winkler <tomas.winkler@intel.com>
---
 drivers/misc/mei/hbm.c | 20 ++++++++++++++------
 1 file changed, 14 insertions(+), 6 deletions(-)

diff --git a/drivers/misc/mei/hbm.c b/drivers/misc/mei/hbm.c
index be41843df75b..cebcca6d6d3e 100644
--- a/drivers/misc/mei/hbm.c
+++ b/drivers/misc/mei/hbm.c
@@ -672,10 +672,14 @@ static void mei_hbm_cl_dma_map_res(struct mei_device *dev,
 	if (!cl)
 		return;
 
-	dev_dbg(dev->dev, "cl dma map result = %d\n", res->status);
-	cl->status = res->status;
-	if (!cl->status)
+	if (res->status) {
+		dev_err(dev->dev, "cl dma map failed %d\n", res->status);
+		cl->status = -EFAULT;
+	} else {
+		dev_dbg(dev->dev, "cl dma map succeeded\n");
 		cl->dma_mapped = 1;
+		cl->status = 0;
+	}
 	wake_up(&cl->wait);
 }
 
@@ -698,10 +702,14 @@ static void mei_hbm_cl_dma_unmap_res(struct mei_device *dev,
 	if (!cl)
 		return;
 
-	dev_dbg(dev->dev, "cl dma unmap result = %d\n", res->status);
-	cl->status = res->status;
-	if (!cl->status)
+	if (res->status) {
+		dev_err(dev->dev, "cl dma unmap failed %d\n", res->status);
+		cl->status = -EFAULT;
+	} else {
+		dev_dbg(dev->dev, "cl dma unmap succeeded\n");
 		cl->dma_mapped = 0;
+		cl->status = 0;
+	}
 	wake_up(&cl->wait);
 }
 
-- 
2.31.1


^ permalink raw reply	[flat|nested] 2+ messages in thread

* RE: [char-misc-next] mei: hbm: fix client dma reply status
  2021-12-28  8:20 [char-misc-next] mei: hbm: fix client dma reply status Tomas Winkler
@ 2021-12-29 16:09 ` Grumbach, Emmanuel
  0 siblings, 0 replies; 2+ messages in thread
From: Grumbach, Emmanuel @ 2021-12-29 16:09 UTC (permalink / raw)
  To: Winkler, Tomas, Greg Kroah-Hartman
  Cc: Usyskin, Alexander, Lubart, Vitaly, linux-kernel, stable

> 
> From: Alexander Usyskin <alexander.usyskin@intel.com>
> 
> Don't blindly copy status value received from the firmware into internal client
> status field, It may be positive and ERR_PTR(ret) will translate it into an
> invalid address and the caller will crash.
> 
> Put the error code into the client status on failure.
> 
> Fixes: 369aea845951 ("mei: implement client dma setup.")
> Reported-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
> Cc: <stable@vger.kernel.org> # v5.11+
> Acked-by: Tomas Winkler <tomas.winkler@intel.com>
> Signed-off-by: Alexander Usyskin <alexander.usyskin@intel.com>
> Signed-off-by: Tomas Winkler <tomas.winkler@intel.com>
> 

Tested-by: : Emmanuel Grumbach <emmanuel.grumbach@intel.com>

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2021-12-29 16:09 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-12-28  8:20 [char-misc-next] mei: hbm: fix client dma reply status Tomas Winkler
2021-12-29 16:09 ` Grumbach, Emmanuel

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®