mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v2 0/2] drm: A couple of fixes for drm_copy_field() helper function
@ 2022-07-05 10:02 Javier Martinez Canillas
  2022-07-05 10:02 ` [PATCH v2 1/2] drm: Use size_t type for len variable in drm_copy_field() Javier Martinez Canillas
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Javier Martinez Canillas @ 2022-07-05 10:02 UTC (permalink / raw)
  To: linux-kernel
  Cc: Ville Syrjälä,
	Peter Robinson, Thomas Zimmermann, Javier Martinez Canillas,
	Daniel Vetter, David Airlie, Maarten Lankhorst, Maxime Ripard,
	dri-devel

Hello,

Peter Robinson reported me a kernel bug in one of his aarch64 test boards
and even though I was not able to reproduce it, I think that figured out
what the problem was. It seems the cause is that a DRM driver doesn't set
some of the struct drm fields copied to userspace via DRM_IOCTL_VERSION.

Even though this is a driver bug, we can make drm_copy_field() more robust
and warn about it instead of leading to an attempt to copy a NULL pointer.

While looking at this, I also found that a variable in drm_copy_field() is
not using the correct type. So I included that change in the patch-set too.

Best regards,
Javier

Changes in v2:
- Add Peter Robinson Tested-by and Thomas Zimmermann Reviewed-by tags.
- Just warn if a value isn't set and report it as a string of length 0.
  (Thomas Zimmermann).

Javier Martinez Canillas (2):
  drm: Use size_t type for len variable in drm_copy_field()
  drm: Prevent drm_copy_field() to attempt copying a NULL pointer

 drivers/gpu/drm/drm_ioctl.c | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

-- 
2.36.1


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2022-07-15  8:47 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2022-07-05 10:02 [PATCH v2 0/2] drm: A couple of fixes for drm_copy_field() helper function Javier Martinez Canillas
2022-07-05 10:02 ` [PATCH v2 1/2] drm: Use size_t type for len variable in drm_copy_field() Javier Martinez Canillas
2022-07-05 10:02 ` [PATCH v2 2/2] drm: Prevent drm_copy_field() to attempt copying a NULL pointer Javier Martinez Canillas
2022-07-15  8:46 ` [PATCH v2 0/2] drm: A couple of fixes for drm_copy_field() helper function Javier Martinez Canillas

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®