mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Sasha Levin <sashal@kernel.org>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: "Philipp Stanner" <pstanner@redhat.com>,
	"Christian König" <christian.koenig@amd.com>,
	"Sasha Levin" <sashal@kernel.org>,
	ltuikov89@gmail.com, matthew.brost@intel.com, dakr@kernel.org,
	maarten.lankhorst@linux.intel.com, mripard@kernel.org,
	tzimmermann@suse.de, airlied@gmail.com, simona@ffwll.ch,
	dri-devel@lists.freedesktop.org
Subject: [PATCH AUTOSEL 6.1 26/48] drm/sched: memset() 'job' in drm_sched_job_init()
Date: Sun, 24 Nov 2024 08:48:49 -0500	[thread overview]
Message-ID: <20241124134950.3348099-26-sashal@kernel.org> (raw)
In-Reply-To: <20241124134950.3348099-1-sashal@kernel.org>

From: Philipp Stanner <pstanner@redhat.com>

[ Upstream commit 2320c9e6a768d135c7b0039995182bb1a4e4fd22 ]

drm_sched_job_init() has no control over how users allocate struct
drm_sched_job. Unfortunately, the function can also not set some struct
members such as job->sched.

This could theoretically lead to UB by users dereferencing the struct's
pointer members too early.

It is easier to debug such issues if these pointers are initialized to
NULL, so dereferencing them causes a NULL pointer exception.
Accordingly, drm_sched_entity_init() does precisely that and initializes
its struct with memset().

Initialize parameter "job" to 0 in drm_sched_job_init().

Signed-off-by: Philipp Stanner <pstanner@redhat.com>
Link: https://patchwork.freedesktop.org/patch/msgid/20241021105028.19794-2-pstanner@redhat.com
Reviewed-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 drivers/gpu/drm/scheduler/sched_main.c | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/drivers/gpu/drm/scheduler/sched_main.c b/drivers/gpu/drm/scheduler/sched_main.c
index f138b3be1646f..dbdd00c61315b 100644
--- a/drivers/gpu/drm/scheduler/sched_main.c
+++ b/drivers/gpu/drm/scheduler/sched_main.c
@@ -595,6 +595,14 @@ int drm_sched_job_init(struct drm_sched_job *job,
 	if (!entity->rq)
 		return -ENOENT;
 
+	/*
+	 * We don't know for sure how the user has allocated. Thus, zero the
+	 * struct so that unallowed (i.e., too early) usage of pointers that
+	 * this function does not set is guaranteed to lead to a NULL pointer
+	 * exception instead of UB.
+	 */
+	memset(job, 0, sizeof(*job));
+
 	job->entity = entity;
 	job->s_fence = drm_sched_fence_alloc(entity, owner);
 	if (!job->s_fence)
-- 
2.43.0


  parent reply	other threads:[~2024-11-24 13:50 UTC|newest]

Thread overview: 49+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-11-24 13:48 [PATCH AUTOSEL 6.1 01/48] drm/vc4: hdmi: Avoid log spam for audio start failure Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 02/48] drm/vc4: hvs: Set AXI panic modes for the HVS Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 03/48] drm: panel-orientation-quirks: Add quirk for AYA NEO 2 model Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 04/48] drm: panel-orientation-quirks: Add quirk for AYA NEO Founder edition Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 05/48] drm: panel-orientation-quirks: Add quirk for AYA NEO GEEK Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 06/48] drm/bridge: it6505: Enable module autoloading Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 07/48] drm/mcde: " Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 08/48] drm/radeon/r600_cs: Fix possible int overflow in r600_packet3_check() Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 09/48] drm/display: Fix building with GCC 15 Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 10/48] r8169: don't apply UDP padding quirk on RTL8126A Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 11/48] samples/bpf: Fix a resource leak Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 12/48] net: fec_mpc52xx_phy: Use %pa to format resource_size_t Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 13/48] net: ethernet: fs_enet: " Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 14/48] net/sched: cbs: Fix integer overflow in cbs_set_port_rate() Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 15/48] af_packet: avoid erroring out after sock_init_data() in packet_create() Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 16/48] Bluetooth: L2CAP: do not leave dangling sk pointer on error in l2cap_sock_create() Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 17/48] Bluetooth: RFCOMM: avoid leaving dangling sk pointer in rfcomm_sock_alloc() Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 18/48] net: af_can: do not leave a dangling sk pointer in can_create() Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 19/48] net: ieee802154: do not leave a dangling sk pointer in ieee802154_create() Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 20/48] net: inet: do not leave a dangling sk pointer in inet_create() Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 21/48] net: inet6: do not leave a dangling sk pointer in inet6_create() Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 22/48] wifi: ath5k: add PCI ID for SX76X Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 23/48] wifi: ath5k: add PCI ID for Arcadyan devices Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 24/48] drm/panel: simple: Add Microchip AC69T88A LVDS Display panel Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 25/48] net: sfp: change quirks for Alcatel Lucent G-010S-P Sasha Levin
2024-11-24 13:48 ` Sasha Levin [this message]
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 27/48] drm/amdgpu: clear RB_OVERFLOW bit when enabling interrupts for vega20_ih Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 28/48] drm/amdgpu: Dereference the ATCS ACPI buffer Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 29/48] drm/amdgpu: refine error handling in amdgpu_ttm_tt_pin_userptr Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 30/48] dma-debug: fix a possible deadlock on radix_lock Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 31/48] jfs: array-index-out-of-bounds fix in dtReadFirst Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 32/48] jfs: fix shift-out-of-bounds in dbSplit Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 33/48] jfs: fix array-index-out-of-bounds in jfs_readdir Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 34/48] jfs: add a check to prevent array-index-out-of-bounds in dbAdjTree Sasha Levin
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 35/48] net: enetc: remove ERR050089 workaround for i.MX95 Sasha Levin
2024-11-25  1:55   ` Wei Fang
2024-11-24 13:48 ` [PATCH AUTOSEL 6.1 36/48] net: enetc: add i.MX95 EMDIO support Sasha Levin
2024-11-24 13:49 ` [PATCH AUTOSEL 6.1 37/48] drm/amdgpu: skip amdgpu_device_cache_pci_state under sriov Sasha Levin
2024-11-24 13:49 ` [PATCH AUTOSEL 6.1 38/48] ALSA: usb-audio: Make mic volume workarounds globally applicable Sasha Levin
2024-11-24 13:49 ` [PATCH AUTOSEL 6.1 39/48] drm/amdgpu: set the right AMDGPU sg segment limitation Sasha Levin
2024-11-24 13:49 ` [PATCH AUTOSEL 6.1 40/48] wifi: ipw2x00: libipw_rx_any(): fix bad alignment Sasha Levin
2024-11-24 13:49 ` [PATCH AUTOSEL 6.1 41/48] wifi: brcmfmac: Fix oops due to NULL pointer dereference in brcmf_sdiod_sglist_rw() Sasha Levin
2024-11-24 13:49 ` [PATCH AUTOSEL 6.1 42/48] dsa: qca8k: Use nested lock to avoid splat Sasha Levin
2024-11-24 13:49 ` [PATCH AUTOSEL 6.1 43/48] Bluetooth: btusb: Add RTL8852BE device 0489:e123 to device tables Sasha Levin
2024-11-24 13:49 ` [PATCH AUTOSEL 6.1 44/48] Bluetooth: hci_core: Fix not checking skb length on hci_acldata_packet Sasha Levin
2024-11-24 13:49 ` [PATCH AUTOSEL 6.1 45/48] ASoC: hdmi-codec: reorder channel allocation list Sasha Levin
2024-11-24 13:49 ` [PATCH AUTOSEL 6.1 46/48] rocker: fix link status detection in rocker_carrier_init() Sasha Levin
2024-11-24 13:49 ` [PATCH AUTOSEL 6.1 47/48] net/neighbor: clear error in case strict check is not set Sasha Levin
2024-11-24 13:49 ` [PATCH AUTOSEL 6.1 48/48] netpoll: Use rcu_access_pointer() in __netpoll_setup Sasha Levin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20241124134950.3348099-26-sashal@kernel.org \
    --to=sashal@kernel.org \
    --cc=airlied@gmail.com \
    --cc=christian.koenig@amd.com \
    --cc=dakr@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=ltuikov89@gmail.com \
    --cc=maarten.lankhorst@linux.intel.com \
    --cc=matthew.brost@intel.com \
    --cc=mripard@kernel.org \
    --cc=pstanner@redhat.com \
    --cc=simona@ffwll.ch \
    --cc=stable@vger.kernel.org \
    --cc=tzimmermann@suse.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®