Re: [PATCH v5 02/16] iov_iter: add iterator type for dmabuf maps
Pavel Begunkov <[email protected]> Tue, 4 Aug 2026 09:39:31 +0100
| Newsgroups | org.kernel.vger.linux-media,dev.linux.lists.dm-devel,dev.linux.lists.nvdimm,org.freedesktop.lists.dri-devel,org.infradead.lists.linux-nvme,org.kernel.vger.ceph-devel,org.kernel.vger.io-uring,org.kernel.vger.linux-block,org.kernel.vger.linux-btrfs,org.kernel.vger.linux-fsdevel,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
On 8/3/26 14:20, Anuj gupta wrote: > On Sat, Aug 1, 2026 at 9:19 PM Pavel Begunkov <[email protected]> wrote: >> @@ -841,7 +857,7 @@ static unsigned long iov_iter_alignment_bvec(const struct iov_iter *i) >> >> unsigned long iov_iter_alignment(const struct iov_iter *i) >> { >> - if (likely(iter_is_ubuf(i))) { >> + if (likely(iter_is_ubuf(i)) || iov_iter_is_dmabuf_map(i)) { >> size_t size = i->count; >> if (size) >> return ((unsigned long)i->ubuf + i->iov_offset) | size; > > dmabuf_map shares the same union slot as ubuf, so this reads the map > pointer as a user address. gap_alignment() below already returns 0 > correctly for dmabuf - this should too. Checked the rest of this patch > (advance/revert/restore) - none of them dereference the union pointer > for dmabuf, so it's isolated to this one spot. Doesn't affect the > current series, nothing reaches this with a dmabuf iter yet. Ah yes, that's nonsense, it should've checked iov_offset instead. Thanks -- Pavel Begunkov