qxl_process_single_command() maps the page containing the current
release slot and copies the userspace command into it at the
release_offset within the page:

    fb_cmd = qxl_bo_kmap_atomic_page(qdev, cmd_bo,
                (release->release_offset & PAGE_MASK));
    copy_from_user(fb_cmd + sizeof(union qxl_release_info) +
                   (release->release_offset & ~PAGE_MASK), ...);

However, the subsequent mm_time stamp casts the page-start pointer
directly:

    struct qxl_drawable *draw = fb_cmd;
    draw->mm_time = qdev->rom->mm_clock;

This writes mm_time into the release_info header or whatever sits
at the page start rather than into the drawable that was just
copied. Apply the same offset so mm_time lands in the right place.

Fixes: f64122c1f6ad ("drm: add new QXL driver. (v1.4)")
Cc: [email protected]
Reported-by: Sashiko <[email protected]>
Signed-off-by: Aldo Ariel Panzardo <[email protected]>
---
diff --git a/drivers/gpu/drm/qxl/qxl_ioctl.c b/drivers/gpu/drm/qxl/qxl_ioctl.c
index 591b026..e7594d1 100644
--- a/drivers/gpu/drm/qxl/qxl_ioctl.c
+++ b/drivers/gpu/drm/qxl/qxl_ioctl.c
@@ -188,7 +188,9 @@ static int qxl_process_single_command(struct qxl_device 
*qdev,
                 u64_to_user_ptr(cmd->command), cmd->command_size);
 
        {
-               struct qxl_drawable *draw = fb_cmd;
+               struct qxl_drawable *draw = fb_cmd +
+                       sizeof(union qxl_release_info) +
+                       (release->release_offset & ~PAGE_MASK);
 
                draw->mm_time = qdev->rom->mm_clock;
        }
-- 
2.43.0

Reply via email to