From 65088296870ba02a716e4fad785a1466f9682dcc Mon Sep 17 00:00:00 2001 From: Patrick Daly Date: Thu, 23 Sep 2021 15:24:42 -0700 Subject: [PATCH] dma-mapping-fast: Fix iova address leak with non-zero scatterlist offset The underlying arm-smmu hardware only supports mapping addresses aligned to PAGE_SIZE. Thus the actual mapped region may be larger than the range returned by iommu_map_sg(): [sg_dma_address(), sg_dma_address() + sg->length) When unmapping, ensure the same alignment requirements are applied in order to avoid leaking iova addresses. Change-Id: I1f5d5185d003cfe104b4a67efc1fe88f105f015f Signed-off-by: Patrick Daly --- drivers/iommu/dma-mapping-fast.c | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/drivers/iommu/dma-mapping-fast.c b/drivers/iommu/dma-mapping-fast.c index 8c7d6a5b78a8..3dbaef99d89c 100644 --- a/drivers/iommu/dma-mapping-fast.c +++ b/drivers/iommu/dma-mapping-fast.c @@ -1,6 +1,6 @@ // SPDX-License-Identifier: GPL-2.0-only /* - * Copyright (c) 2016-2020, The Linux Foundation. All rights reserved. + * Copyright (c) 2016-2021, The Linux Foundation. All rights reserved. */ #include @@ -364,7 +364,7 @@ static void fast_smmu_unmap_sg(struct device *dev, struct dma_fast_smmu_mapping *mapping = dev_get_mapping(dev); unsigned long flags; dma_addr_t start; - size_t len; + size_t len, offset; struct scatterlist *tmp; int i; @@ -376,12 +376,13 @@ static void fast_smmu_unmap_sg(struct device *dev, * contiguous IOVA allocation, so this is incredibly easy. */ start = sg_dma_address(sg); + offset = start & ~FAST_PAGE_MASK; for_each_sg(sg_next(sg), tmp, nelems - 1, i) { if (sg_dma_len(tmp) == 0) break; sg = tmp; } - len = ALIGN(sg_dma_address(sg) + sg_dma_len(sg) - start, + len = ALIGN(sg_dma_address(sg) + sg_dma_len(sg) - (start - offset), FAST_PAGE_SIZE); av8l_fast_unmap_public(mapping->pgtbl_ops, start, len);