rapidio: fix error handling path
authorSouptick Joarder <jrdr.linux@gmail.com>
Fri, 16 Oct 2020 03:13:15 +0000 (20:13 -0700)
committerLinus Torvalds <torvalds@linux-foundation.org>
Fri, 16 Oct 2020 18:11:22 +0000 (11:11 -0700)
rio_dma_transfer() attempts to clamp the return value of
pin_user_pages_fast() to be >= 0.  However, the attempt fails because
nr_pages is overridden a few lines later, and restored to the undesirable
-ERRNO value.

The return value is ultimately stored in nr_pages, which in turn is passed
to unpin_user_pages(), which expects nr_pages >= 0, else, disaster.

Fix this by fixing the nesting of the assignment to nr_pages: nr_pages
should be clamped to zero if pin_user_pages_fast() returns -ERRNO, or set
to the return value of pin_user_pages_fast(), otherwise.

[jhubbard@nvidia.com: new changelog]

Fixes: e8de370188d09 ("rapidio: add mport char device driver")
Signed-off-by: Souptick Joarder <jrdr.linux@gmail.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Reviewed-by: Ira Weiny <ira.weiny@intel.com>
Reviewed-by: John Hubbard <jhubbard@nvidia.com>
Cc: Matthew Wilcox <willy@infradead.org>
Cc: Matt Porter <mporter@kernel.crashing.org>
Cc: Alexandre Bounine <alex.bou9@gmail.com>
Cc: Gustavo A. R. Silva <gustavoars@kernel.org>
Cc: Madhuparna Bhowmik <madhuparnabhowmik10@gmail.com>
Cc: Dan Carpenter <dan.carpenter@oracle.com>
Link: https://lkml.kernel.org/r/1600227737-20785-1-git-send-email-jrdr.linux@gmail.com
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
drivers/rapidio/devices/rio_mport_cdev.c

index a30342942e26f996cab50a7ace832f6886f7dd7b..163b6c72501d6bb7f61636b09272b01e951a8565 100644 (file)
@@ -871,15 +871,16 @@ rio_dma_transfer(struct file *filp, u32 transfer_mode,
                                rmcd_error("pin_user_pages_fast err=%ld",
                                           pinned);
                                nr_pages = 0;
-                       } else
+                       } else {
                                rmcd_error("pinned %ld out of %ld pages",
                                           pinned, nr_pages);
+                               /*
+                                * Set nr_pages up to mean "how many pages to unpin, in
+                                * the error handler:
+                                */
+                               nr_pages = pinned;
+                       }
                        ret = -EFAULT;
-                       /*
-                        * Set nr_pages up to mean "how many pages to unpin, in
-                        * the error handler:
-                        */
-                       nr_pages = pinned;
                        goto err_pg;
                }