On 9/21/26 14:53, [email protected] wrote:
...>> +void iov_iter_dmabuf_map(struct iov_iter *i, unsigned int direction,
+ struct dma_buf_io_map *map,
+ loff_t off, size_t count)
+{
+ WARN_ON(direction & ~(READ | WRITE));
+ *i = (struct iov_iter){
+ .iter_type = ITER_DMABUF_MAP,
+ .data_source = direction,
+ .dmabuf_map = map,
+ .count = count,
+ .iov_offset = off,
+ };
+}
[Severity: Medium]
Since iov_offset is initialized here to the absolute starting offset (off)
rather than a relative zero, does this cause an issue with the tracking
logic in iov_iter_revert()?
It is relative to the buffer. No clue why it thinks it's absolute,
but this unroll looks fine.
In iov_iter_revert(), the unroll size is checked against i->iov_offset
like this:
if (unroll <= i->iov_offset) {
i->iov_offset -= unroll;
return;
}
Because iov_offset starts at the absolute offset rather than 0, couldn't a
caller successfully revert an ITER_DMABUF_MAP iterator beyond its initial
starting offset? This would bypass the BUG() safety net intended to catch
invalid unrolls, potentially leading to an out-of-bounds DMA access if the
reverted iterator is used again.
--
Pavel Begunkov