|
|
|
|
|
|
|
|
|
|
xen-devel
[Xen-devel] [PATCH v2] xen-gntdev: prevent using UNMAP_NOTIFY_CLEAR_BYTE
Signed-off-by: Daniel De Graaf <dgdegra@xxxxxxxxxxxxx>
diff --git a/drivers/xen/gntdev.c b/drivers/xen/gntdev.c
index 4687cd5..00e4644 100644
--- a/drivers/xen/gntdev.c
+++ b/drivers/xen/gntdev.c
@@ -291,7 +291,7 @@ static int __unmap_grant_pages(struct grant_map *map, int
offset, int pages)
if (pgno >= offset && pgno < offset + pages && use_ptemod) {
void __user *tmp;
tmp = map->vma->vm_start + map->notify.addr;
- copy_to_user(tmp, &err, 1);
+ WARN_ON(copy_to_user(tmp, &err, 1));
map->notify.flags &= ~UNMAP_NOTIFY_CLEAR_BYTE;
} else if (pgno >= offset && pgno < offset + pages) {
uint8_t *tmp = kmap(map->pages[pgno]);
@@ -596,6 +596,12 @@ static long gntdev_ioctl_notify(struct gntdev_priv *priv,
void __user *u)
goto unlock_out;
found:
+ if ((op.action & UNMAP_NOTIFY_CLEAR_BYTE) &&
+ (map->flags & GNTMAP_readonly)) {
+ rc = -EINVAL;
+ goto unlock_out;
+ }
+
map->notify.flags = op.action;
map->notify.addr = op.index - (map->index << PAGE_SHIFT);
map->notify.event = op.event_channel_port;
_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-devel
|
|
|
|
|