On 9/21/26 14:53, [email protected] wrote:
...>> +void iov_iter_dmabuf_map(struct iov_iter *i, unsigned int direction,
+                        struct dma_buf_io_map *map,
+                        loff_t off, size_t count)
+{
+       WARN_ON(direction & ~(READ | WRITE));
+       *i = (struct iov_iter){
+               .iter_type = ITER_DMABUF_MAP,
+               .data_source = direction,
+               .dmabuf_map = map,
+               .count = count,
+               .iov_offset = off,
+       };
+}

[Severity: Medium]
Since iov_offset is initialized here to the absolute starting offset (off)
rather than a relative zero, does this cause an issue with the tracking
logic in iov_iter_revert()?

It is relative to the buffer. No clue why it thinks it's absolute,
but this unroll looks fine.

In iov_iter_revert(), the unroll size is checked against i->iov_offset
like this:

        if (unroll <= i->iov_offset) {
                i->iov_offset -= unroll;
                return;
        }

Because iov_offset starts at the absolute offset rather than 0, couldn't a
caller successfully revert an ITER_DMABUF_MAP iterator beyond its initial
starting offset? This would bypass the BUG() safety net intended to catch
invalid unrolls, potentially leading to an out-of-bounds DMA access if the
reverted iterator is used again.


--
Pavel Begunkov

Reply via email to