* [char-misc-next] mei: hbm: fix client dma reply status
@ 2021-12-28 8:20 Tomas Winkler
2021-12-29 16:09 ` Grumbach, Emmanuel
0 siblings, 1 reply; 2+ messages in thread
From: Tomas Winkler @ 2021-12-28 8:20 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: Alexander Usyskin, Vitaly Lubart, linux-kernel,
Emmanuel Grumbach, stable, Tomas Winkler
From: Alexander Usyskin <alexander.usyskin@intel.com>
Don't blindly copy status value received from the firmware
into internal client status field,
It may be positive and ERR_PTR(ret) will translate it
into an invalid address and the caller will crash.
Put the error code into the client status on failure.
Fixes: 369aea845951 ("mei: implement client dma setup.")
Reported-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
Cc: <stable@vger.kernel.org> # v5.11+
Acked-by: Tomas Winkler <tomas.winkler@intel.com>
Signed-off-by: Alexander Usyskin <alexander.usyskin@intel.com>
Signed-off-by: Tomas Winkler <tomas.winkler@intel.com>
---
drivers/misc/mei/hbm.c | 20 ++++++++++++++------
1 file changed, 14 insertions(+), 6 deletions(-)
diff --git a/drivers/misc/mei/hbm.c b/drivers/misc/mei/hbm.c
index be41843df75b..cebcca6d6d3e 100644
--- a/drivers/misc/mei/hbm.c
+++ b/drivers/misc/mei/hbm.c
@@ -672,10 +672,14 @@ static void mei_hbm_cl_dma_map_res(struct mei_device *dev,
if (!cl)
return;
- dev_dbg(dev->dev, "cl dma map result = %d\n", res->status);
- cl->status = res->status;
- if (!cl->status)
+ if (res->status) {
+ dev_err(dev->dev, "cl dma map failed %d\n", res->status);
+ cl->status = -EFAULT;
+ } else {
+ dev_dbg(dev->dev, "cl dma map succeeded\n");
cl->dma_mapped = 1;
+ cl->status = 0;
+ }
wake_up(&cl->wait);
}
@@ -698,10 +702,14 @@ static void mei_hbm_cl_dma_unmap_res(struct mei_device *dev,
if (!cl)
return;
- dev_dbg(dev->dev, "cl dma unmap result = %d\n", res->status);
- cl->status = res->status;
- if (!cl->status)
+ if (res->status) {
+ dev_err(dev->dev, "cl dma unmap failed %d\n", res->status);
+ cl->status = -EFAULT;
+ } else {
+ dev_dbg(dev->dev, "cl dma unmap succeeded\n");
cl->dma_mapped = 0;
+ cl->status = 0;
+ }
wake_up(&cl->wait);
}
--
2.31.1
^ permalink raw reply [flat|nested] 2+ messages in thread
* RE: [char-misc-next] mei: hbm: fix client dma reply status
2021-12-28 8:20 [char-misc-next] mei: hbm: fix client dma reply status Tomas Winkler
@ 2021-12-29 16:09 ` Grumbach, Emmanuel
0 siblings, 0 replies; 2+ messages in thread
From: Grumbach, Emmanuel @ 2021-12-29 16:09 UTC (permalink / raw)
To: Winkler, Tomas, Greg Kroah-Hartman
Cc: Usyskin, Alexander, Lubart, Vitaly, linux-kernel, stable
>
> From: Alexander Usyskin <alexander.usyskin@intel.com>
>
> Don't blindly copy status value received from the firmware into internal client
> status field, It may be positive and ERR_PTR(ret) will translate it into an
> invalid address and the caller will crash.
>
> Put the error code into the client status on failure.
>
> Fixes: 369aea845951 ("mei: implement client dma setup.")
> Reported-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
> Cc: <stable@vger.kernel.org> # v5.11+
> Acked-by: Tomas Winkler <tomas.winkler@intel.com>
> Signed-off-by: Alexander Usyskin <alexander.usyskin@intel.com>
> Signed-off-by: Tomas Winkler <tomas.winkler@intel.com>
>
Tested-by: : Emmanuel Grumbach <emmanuel.grumbach@intel.com>
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2021-12-29 16:09 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-12-28 8:20 [char-misc-next] mei: hbm: fix client dma reply status Tomas Winkler
2021-12-29 16:09 ` Grumbach, Emmanuel
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®