Skip to content

Commit

Permalink
iommu/amd: Do proper access checking before calling handle_mm_fault()
Browse files Browse the repository at this point in the history
The handle_mm_fault function expects the caller to do the
access checks. Not doing so and calling the function with
wrong permissions is a bug (catched by a BUG_ON).
So fix this bug by adding proper access checking to the io
page-fault code in the AMD IOMMUv2 driver.

Reviewed-by: Jesse Barnes <jbarnes@virtuousgeek.org>
Acked-By: David Woodhouse <David.Woodhouse@intel.com>
Signed-off-by: Joerg Roedel <jroedel@suse.de>
  • Loading branch information
Joerg Roedel committed Dec 14, 2015
1 parent 9f9499a commit 7b5cc1a
Showing 1 changed file with 18 additions and 2 deletions.
20 changes: 18 additions & 2 deletions drivers/iommu/amd_iommu_v2.c
Original file line number Diff line number Diff line change
Expand Up @@ -494,6 +494,22 @@ static void handle_fault_error(struct fault *fault)
}
}

static bool access_error(struct vm_area_struct *vma, struct fault *fault)
{
unsigned long requested = 0;

if (fault->flags & PPR_FAULT_EXEC)
requested |= VM_EXEC;

if (fault->flags & PPR_FAULT_READ)
requested |= VM_READ;

if (fault->flags & PPR_FAULT_WRITE)
requested |= VM_WRITE;

return (requested & ~vma->vm_flags) != 0;
}

static void do_fault(struct work_struct *work)
{
struct fault *fault = container_of(work, struct fault, work);
Expand All @@ -516,8 +532,8 @@ static void do_fault(struct work_struct *work)
goto out;
}

if (!(vma->vm_flags & (VM_READ | VM_EXEC | VM_WRITE))) {
/* handle_mm_fault would BUG_ON() */
/* Check if we have the right permissions on the vma */
if (access_error(vma, fault)) {
up_read(&mm->mmap_sem);
handle_fault_error(fault);
goto out;
Expand Down

0 comments on commit 7b5cc1a

Please sign in to comment.