Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider: - [Low] build: missing vmemdup_array_user helper --
commit 4d70c808a81c22c8b9f6c03847fa45f071b2e967 Author: Tvrtko Ursulin <[email protected]> drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array This commit replaces kvmalloc_array() + copy_from_user() with vmemdup_array_user() on the fast path. This aims to shrink the source code and improve separation between kernel and userspace slabs. > diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c > b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c > index 15c45b2a39835..b364f3f5fb918 100644 > --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c > +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c > @@ -223,43 +223,36 @@ void amdgpu_bo_list_put(struct amdgpu_bo_list *list) > int amdgpu_bo_create_list_entry_array(struct drm_amdgpu_bo_list_in *in, > struct drm_amdgpu_bo_list_entry > **info_param) > { [ ... ] > /* copy the handle array from userspace to a kernel buffer */ > - r = -EFAULT; > - if (likely(info_size == in->bo_info_size)) { > - unsigned long bytes = in->bo_number * > - in->bo_info_size; > - > - if (copy_from_user(info, uptr, bytes)) > - goto error_free; > - > + if (likely(info_size == bo_info_size)) { > + info = vmemdup_array_user(uptr, bo_number, info_size); [Severity: Low] Does this code call a function vmemdup_array_user() that does not exist in this kernel tree? When compiling drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c with CONFIG_DRM_AMDGPU=y or m, this will result in a build failure due to an implicit function declaration in amdgpu_bo_create_list_entry_array(). If the compiler allows implicit declarations, it would assume a 32-bit int return type, which truncates the pointer on 64-bit systems and can lead to an invalid pointer dereference or use-after-free when IS_ERR(info) or kvfree(info) is called later. > + if (IS_ERR(info)) > + return PTR_ERR(info); -- Sashiko AI review ยท https://sashiko.dev/#/patchset/[email protected]?part=1
