From a9cbc7f9c57bef912a99c602af169c58bbdead0b Mon Sep 17 00:00:00 2001 From: Prakash Gupta Date: Thu, 22 Aug 2019 17:14:32 +0530 Subject: [PATCH] iommu: iommu-debug: check valid pfn before performing ATOS ops ATOS operation can be fatal when performed on invalid pfn. Validate mapped entry pfn for validity before performing ATOS operation. Change-Id: Ie1b118d768c396f91618ee1eb101754cbee5318e Signed-off-by: Prakash Gupta [isaacm@codeaurora: Move PFN validity check prior to IOVA assignment] Signed-off-by: Isaac J. Manjarres --- drivers/iommu/iommu-debug.c | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/drivers/iommu/iommu-debug.c b/drivers/iommu/iommu-debug.c index 3714634a8d61..a66a52243918 100644 --- a/drivers/iommu/iommu-debug.c +++ b/drivers/iommu/iommu-debug.c @@ -1562,6 +1562,8 @@ static ssize_t iommu_debug_atos_write(struct file *file, { struct iommu_debug_device *ddev = file->private_data; dma_addr_t iova; + phys_addr_t phys; + unsigned long pfn; if (kstrtox_from_user(ubuf, count, 0, &iova)) { pr_err_ratelimited("Invalid format for iova\n"); @@ -1569,7 +1571,14 @@ static ssize_t iommu_debug_atos_write(struct file *file, return -EINVAL; } + phys = iommu_iova_to_phys(ddev->domain, ddev->iova); + pfn = __phys_to_pfn(phys); + if (!pfn_valid(pfn)) { + dev_err(ddev->dev, "Invalid ATOS operation page %pa\n", &phys); + return -EINVAL; + } ddev->iova = iova; + pr_err_ratelimited("Saved iova=%pa for future ATOS commands\n", &iova); return count; }