Re: [PATCH] ublk: remove WARN_ON_ONCE() in ublk_unmap_io()

Ming Lei <[email protected]> Tue, 28 Jul 2026 20:56:38 -0500
Newsgroups org.kernel.vger.linux-block,org.kernel.vger.linux-kernel
Message-ID <amld1rIvn52o8bZ6@fedora-laptop>
On Tue, Jul 28, 2026 at 11:22:00AM -0700, Caleb Sander Mateos wrote:
> On Mon, Jul 27, 2026 at 7:47 PM Ming Lei <[email protected]> wrote:
> >
> > On Mon, Jul 27, 2026 at 11:24 AM Caleb Sander Mateos
> > <[email protected]> wrote:
> > >
> > > io->res is set from struct ublksrv_io_cmd's result field, which is
> > > controlled by the ublk server process, without any validation. It's thus
> > > possible for userspace to trigger the io->res > rq_bytes warning.
> > > ublk_copy_user_pages() already limits the copy length to the request
> > > data length, so drop the warning.
> > >
> > > Signed-off-by: Caleb Sander Mateos <[email protected]>
> > > ---
> > >  drivers/block/ublk_drv.c | 2 --
> > >  1 file changed, 2 deletions(-)
> > >
> > > diff --git a/drivers/block/ublk_drv.c b/drivers/block/ublk_drv.c
> > > index 4ca6ec738c93..4f30644756df 100644
> > > --- a/drivers/block/ublk_drv.c
> > > +++ b/drivers/block/ublk_drv.c
> > > @@ -1492,12 +1492,10 @@ static unsigned int ublk_unmap_io(bool need_map,
> > >
> > >         if (ublk_need_unmap_req(req)) {
> > >                 struct iov_iter iter;
> > >                 const int dir = ITER_SOURCE;
> > >
> > > -               WARN_ON_ONCE(io->res > rq_bytes);
> > > -
> > >                 import_ubuf(dir, u64_to_user_ptr(io->buf.addr), io->res, &iter);
> > >                 return ublk_copy_user_pages(req, 0, &iter, dir);
> > >         }
> > >         return rq_bytes;
> >
> > The change may be fine, however access_ok() still can fail from import_ubuf(),
> > so can we consolidate ublk_unmap_io() a bit?
> 
> Sorry, not quite sure what you mean by "consolidate". Are you saying
> there should be a check of the import_ubuf() return value in
> ublk_map_io() and ublk_unmap_io()?

Yeah.

Thanks,
Ming