* [PATCH v3] media: rga: fix NULL pointer dereferences, use-after-free, memory leak
@ 2019-03-14 5:03 ` Kangjie Lu
0 siblings, 0 replies; 16+ messages in thread
From: Kangjie Lu @ 2019-03-14 5:03 UTC (permalink / raw)
To: kjlu
Cc: Heiko Stuebner, Jacob chen, linux-kernel, linux-rockchip,
pakki001, Mauro Carvalho Chehab, linux-arm-kernel, linux-media
1. dma_alloc_attrs, __get_free_pages can fail and return NULL.
Further uses of their return values lead to NULL pointer
dereferences
2. In the error-handling path, video_unregister_device uses
"rga->vfd" which has been freed by video_device_release
3. The error handling for v4l2_m2m_init and video_register_device
has memory-leak issues
The patch fixes the above issues.
Signed-off-by: Kangjie Lu <kjlu@umn.edu>
---
drivers/media/platform/rockchip/rga/rga.c | 26 ++++++++++++++++++++---
1 file changed, 23 insertions(+), 3 deletions(-)
diff --git a/drivers/media/platform/rockchip/rga/rga.c b/drivers/media/platform/rockchip/rga/rga.c
index 5c653287185f..468365ceb99d 100644
--- a/drivers/media/platform/rockchip/rga/rga.c
+++ b/drivers/media/platform/rockchip/rga/rga.c
@@ -889,11 +889,24 @@ static int rga_probe(struct platform_device *pdev)
rga->cmdbuf_virt = dma_alloc_attrs(rga->dev, RGA_CMDBUF_SIZE,
&rga->cmdbuf_phy, GFP_KERNEL,
DMA_ATTR_WRITE_COMBINE);
+ if (!rga->cmdbuf_virt) {
+ ret = -ENOMEM;
+ goto unreg_video_dev;
+ }
rga->src_mmu_pages =
(unsigned int *)__get_free_pages(GFP_KERNEL | __GFP_ZERO, 3);
+ if (!rga->src_mmu_pages) {
+ ret = -ENOMEM;
+ goto free_dma_attrs;
+ }
+
rga->dst_mmu_pages =
(unsigned int *)__get_free_pages(GFP_KERNEL | __GFP_ZERO, 3);
+ if (!rga->dst_mmu_pages) {
+ ret = -ENOMEM;
+ goto free_dst_pages;
+ }
def_frame.stride = (def_frame.width * def_frame.fmt->depth) >> 3;
def_frame.size = def_frame.stride * def_frame.height;
@@ -901,7 +914,7 @@ static int rga_probe(struct platform_device *pdev)
ret = video_register_device(vfd, VFL_TYPE_GRABBER, -1);
if (ret) {
v4l2_err(&rga->v4l2_dev, "Failed to register video device\n");
- goto rel_vdev;
+ goto free_pages;
}
v4l2_info(&rga->v4l2_dev, "Registered %s as /dev/%s\n",
@@ -909,10 +922,17 @@ static int rga_probe(struct platform_device *pdev)
return 0;
-rel_vdev:
- video_device_release(vfd);
+free_pages:
+ free_pages((unsigned long)rga->src_mmu_pages, 3);
+free_dst_pages:
+ free_pages((unsigned long)rga->dst_mmu_pages, 3);
+free_dma_attrs:
+ dma_free_attrs(rga->dev, RGA_CMDBUF_SIZE, rga->cmdbuf_virt,
+ rga->cmdbuf_phy,
+ DMA_ATTR_WRITE_COMBINE);
unreg_video_dev:
video_unregister_device(rga->vfd);
+ video_device_release(vfd);
unreg_v4l2_dev:
v4l2_device_unregister(&rga->v4l2_dev);
err_put_clk:
--
2.17.1
_______________________________________________
linux-arm-kernel mailing list
linux-arm-kernel@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-arm-kernel
^ permalink raw reply related [flat|nested] 16+ messages in thread
* Re: [PATCH v3] media: rga: fix NULL pointer dereferences, use-after-free, memory leak
2019-03-14 5:03 ` Kangjie Lu
@ 2019-03-14 10:30 ` Steven Price
-1 siblings, 0 replies; 16+ messages in thread
From: Steven Price @ 2019-03-14 10:30 UTC (permalink / raw)
To: Kangjie Lu
Cc: Heiko Stuebner, Jacob chen, linux-kernel, linux-rockchip,
pakki001, Mauro Carvalho Chehab, linux-arm-kernel, linux-media
On 14/03/2019 05:03, Kangjie Lu wrote:
> 1. dma_alloc_attrs, __get_free_pages can fail and return NULL.
> Further uses of their return values lead to NULL pointer
> dereferences
>
> 2. In the error-handling path, video_unregister_device uses
> "rga->vfd" which has been freed by video_device_release
>
> 3. The error handling for v4l2_m2m_init and video_register_device
> has memory-leak issues
>
> The patch fixes the above issues.
>
> Signed-off-by: Kangjie Lu <kjlu@umn.edu>
Reviewed-by: Steven Price <steven.price@arm.com>
Yes, that looks like it solves the issues with the clean up - thanks for
reworking it!
> ---
> drivers/media/platform/rockchip/rga/rga.c | 26 ++++++++++++++++++++---
> 1 file changed, 23 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/media/platform/rockchip/rga/rga.c b/drivers/media/platform/rockchip/rga/rga.c
> index 5c653287185f..468365ceb99d 100644
> --- a/drivers/media/platform/rockchip/rga/rga.c
> +++ b/drivers/media/platform/rockchip/rga/rga.c
> @@ -889,11 +889,24 @@ static int rga_probe(struct platform_device *pdev)
> rga->cmdbuf_virt = dma_alloc_attrs(rga->dev, RGA_CMDBUF_SIZE,
> &rga->cmdbuf_phy, GFP_KERNEL,
> DMA_ATTR_WRITE_COMBINE);
> + if (!rga->cmdbuf_virt) {
> + ret = -ENOMEM;
> + goto unreg_video_dev;
> + }
>
> rga->src_mmu_pages =
> (unsigned int *)__get_free_pages(GFP_KERNEL | __GFP_ZERO, 3);
> + if (!rga->src_mmu_pages) {
> + ret = -ENOMEM;
> + goto free_dma_attrs;
> + }
> +
> rga->dst_mmu_pages =
> (unsigned int *)__get_free_pages(GFP_KERNEL | __GFP_ZERO, 3);
> + if (!rga->dst_mmu_pages) {
> + ret = -ENOMEM;
> + goto free_dst_pages;
> + }
>
> def_frame.stride = (def_frame.width * def_frame.fmt->depth) >> 3;
> def_frame.size = def_frame.stride * def_frame.height;
> @@ -901,7 +914,7 @@ static int rga_probe(struct platform_device *pdev)
> ret = video_register_device(vfd, VFL_TYPE_GRABBER, -1);
> if (ret) {
> v4l2_err(&rga->v4l2_dev, "Failed to register video device\n");
> - goto rel_vdev;
> + goto free_pages;
> }
>
> v4l2_info(&rga->v4l2_dev, "Registered %s as /dev/%s\n",
> @@ -909,10 +922,17 @@ static int rga_probe(struct platform_device *pdev)
>
> return 0;
>
> -rel_vdev:
> - video_device_release(vfd);
> +free_pages:
> + free_pages((unsigned long)rga->src_mmu_pages, 3);
> +free_dst_pages:
> + free_pages((unsigned long)rga->dst_mmu_pages, 3);
Minor comment: free_pages accepts a NULL pointer (or more precisely 0,
since it takes an unsigned long), it just returns having done nothing.
So there isn't actually any harm in calling free_pages unconditionally
in the error path (since rga is initialised to all zeros). You can save
a couple of labels in the error path using that trick.
Thanks,
Steve
> +free_dma_attrs:
> + dma_free_attrs(rga->dev, RGA_CMDBUF_SIZE, rga->cmdbuf_virt,
> + rga->cmdbuf_phy,
> + DMA_ATTR_WRITE_COMBINE);
> unreg_video_dev:
> video_unregister_device(rga->vfd);
> + video_device_release(vfd);
> unreg_v4l2_dev:
> v4l2_device_unregister(&rga->v4l2_dev);
> err_put_clk:
>
^ permalink raw reply [flat|nested] 16+ messages in thread
* Re: [PATCH v3] media: rga: fix NULL pointer dereferences, use-after-free, memory leak
@ 2019-03-14 10:30 ` Steven Price
0 siblings, 0 replies; 16+ messages in thread
From: Steven Price @ 2019-03-14 10:30 UTC (permalink / raw)
To: Kangjie Lu
Cc: Heiko Stuebner, Jacob chen, linux-kernel, linux-rockchip,
pakki001, Mauro Carvalho Chehab, linux-arm-kernel, linux-media
On 14/03/2019 05:03, Kangjie Lu wrote:
> 1. dma_alloc_attrs, __get_free_pages can fail and return NULL.
> Further uses of their return values lead to NULL pointer
> dereferences
>
> 2. In the error-handling path, video_unregister_device uses
> "rga->vfd" which has been freed by video_device_release
>
> 3. The error handling for v4l2_m2m_init and video_register_device
> has memory-leak issues
>
> The patch fixes the above issues.
>
> Signed-off-by: Kangjie Lu <kjlu@umn.edu>
Reviewed-by: Steven Price <steven.price@arm.com>
Yes, that looks like it solves the issues with the clean up - thanks for
reworking it!
> ---
> drivers/media/platform/rockchip/rga/rga.c | 26 ++++++++++++++++++++---
> 1 file changed, 23 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/media/platform/rockchip/rga/rga.c b/drivers/media/platform/rockchip/rga/rga.c
> index 5c653287185f..468365ceb99d 100644
> --- a/drivers/media/platform/rockchip/rga/rga.c
> +++ b/drivers/media/platform/rockchip/rga/rga.c
> @@ -889,11 +889,24 @@ static int rga_probe(struct platform_device *pdev)
> rga->cmdbuf_virt = dma_alloc_attrs(rga->dev, RGA_CMDBUF_SIZE,
> &rga->cmdbuf_phy, GFP_KERNEL,
> DMA_ATTR_WRITE_COMBINE);
> + if (!rga->cmdbuf_virt) {
> + ret = -ENOMEM;
> + goto unreg_video_dev;
> + }
>
> rga->src_mmu_pages =
> (unsigned int *)__get_free_pages(GFP_KERNEL | __GFP_ZERO, 3);
> + if (!rga->src_mmu_pages) {
> + ret = -ENOMEM;
> + goto free_dma_attrs;
> + }
> +
> rga->dst_mmu_pages =
> (unsigned int *)__get_free_pages(GFP_KERNEL | __GFP_ZERO, 3);
> + if (!rga->dst_mmu_pages) {
> + ret = -ENOMEM;
> + goto free_dst_pages;
> + }
>
> def_frame.stride = (def_frame.width * def_frame.fmt->depth) >> 3;
> def_frame.size = def_frame.stride * def_frame.height;
> @@ -901,7 +914,7 @@ static int rga_probe(struct platform_device *pdev)
> ret = video_register_device(vfd, VFL_TYPE_GRABBER, -1);
> if (ret) {
> v4l2_err(&rga->v4l2_dev, "Failed to register video device\n");
> - goto rel_vdev;
> + goto free_pages;
> }
>
> v4l2_info(&rga->v4l2_dev, "Registered %s as /dev/%s\n",
> @@ -909,10 +922,17 @@ static int rga_probe(struct platform_device *pdev)
>
> return 0;
>
> -rel_vdev:
> - video_device_release(vfd);
> +free_pages:
> + free_pages((unsigned long)rga->src_mmu_pages, 3);
> +free_dst_pages:
> + free_pages((unsigned long)rga->dst_mmu_pages, 3);
Minor comment: free_pages accepts a NULL pointer (or more precisely 0,
since it takes an unsigned long), it just returns having done nothing.
So there isn't actually any harm in calling free_pages unconditionally
in the error path (since rga is initialised to all zeros). You can save
a couple of labels in the error path using that trick.
Thanks,
Steve
> +free_dma_attrs:
> + dma_free_attrs(rga->dev, RGA_CMDBUF_SIZE, rga->cmdbuf_virt,
> + rga->cmdbuf_phy,
> + DMA_ATTR_WRITE_COMBINE);
> unreg_video_dev:
> video_unregister_device(rga->vfd);
> + video_device_release(vfd);
> unreg_v4l2_dev:
> v4l2_device_unregister(&rga->v4l2_dev);
> err_put_clk:
>
_______________________________________________
linux-arm-kernel mailing list
linux-arm-kernel@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-arm-kernel
^ permalink raw reply [flat|nested] 16+ messages in thread
* Re: [PATCH v3] media: rga: fix NULL pointer dereferences, use-after-free, memory leak
2019-03-14 5:03 ` Kangjie Lu
@ 2019-03-28 14:47 ` Hans Verkuil
-1 siblings, 0 replies; 16+ messages in thread
From: Hans Verkuil @ 2019-03-28 14:47 UTC (permalink / raw)
To: Kangjie Lu
Cc: pakki001, Jacob chen, Mauro Carvalho Chehab, Heiko Stuebner,
linux-media, linux-arm-kernel, linux-rockchip, linux-kernel
Hi Kangjie,
Unfortunately there are more issues with the cleanup sequence in
this probe function:
On 3/14/19 6:03 AM, Kangjie Lu wrote:
> 1. dma_alloc_attrs, __get_free_pages can fail and return NULL.
> Further uses of their return values lead to NULL pointer
> dereferences
>
> 2. In the error-handling path, video_unregister_device uses
> "rga->vfd" which has been freed by video_device_release
>
> 3. The error handling for v4l2_m2m_init and video_register_device
> has memory-leak issues
>
> The patch fixes the above issues.
>
> Signed-off-by: Kangjie Lu <kjlu@umn.edu>
> ---
> drivers/media/platform/rockchip/rga/rga.c | 26 ++++++++++++++++++++---
> 1 file changed, 23 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/media/platform/rockchip/rga/rga.c b/drivers/media/platform/rockchip/rga/rga.c
> index 5c653287185f..468365ceb99d 100644
> --- a/drivers/media/platform/rockchip/rga/rga.c
> +++ b/drivers/media/platform/rockchip/rga/rga.c
> @@ -889,11 +889,24 @@ static int rga_probe(struct platform_device *pdev)
> rga->cmdbuf_virt = dma_alloc_attrs(rga->dev, RGA_CMDBUF_SIZE,
> &rga->cmdbuf_phy, GFP_KERNEL,
> DMA_ATTR_WRITE_COMBINE);
> + if (!rga->cmdbuf_virt) {
> + ret = -ENOMEM;
> + goto unreg_video_dev;
Actually, the unreg_video_dev label makes no sense: if the video device
is successfully registered, then probe() returns 0. So you never need to
unregister the video device again. You *do* need to release it with
video_device_release().
So this should be a goto rel_vdev.
And the cleanup sequence at the end also fails to call v4l2_m2m_release().
Can you make v4?
Thanks!
Hans
> + }
>
> rga->src_mmu_pages =
> (unsigned int *)__get_free_pages(GFP_KERNEL | __GFP_ZERO, 3);
> + if (!rga->src_mmu_pages) {
> + ret = -ENOMEM;
> + goto free_dma_attrs;
> + }
> +
> rga->dst_mmu_pages =
> (unsigned int *)__get_free_pages(GFP_KERNEL | __GFP_ZERO, 3);
> + if (!rga->dst_mmu_pages) {
> + ret = -ENOMEM;
> + goto free_dst_pages;
> + }
>
> def_frame.stride = (def_frame.width * def_frame.fmt->depth) >> 3;
> def_frame.size = def_frame.stride * def_frame.height;
> @@ -901,7 +914,7 @@ static int rga_probe(struct platform_device *pdev)
> ret = video_register_device(vfd, VFL_TYPE_GRABBER, -1);
> if (ret) {
> v4l2_err(&rga->v4l2_dev, "Failed to register video device\n");
> - goto rel_vdev;
> + goto free_pages;
> }
>
> v4l2_info(&rga->v4l2_dev, "Registered %s as /dev/%s\n",
> @@ -909,10 +922,17 @@ static int rga_probe(struct platform_device *pdev)
>
> return 0;
>
> -rel_vdev:
> - video_device_release(vfd);
> +free_pages:
> + free_pages((unsigned long)rga->src_mmu_pages, 3);
> +free_dst_pages:
> + free_pages((unsigned long)rga->dst_mmu_pages, 3);
> +free_dma_attrs:
> + dma_free_attrs(rga->dev, RGA_CMDBUF_SIZE, rga->cmdbuf_virt,
> + rga->cmdbuf_phy,
> + DMA_ATTR_WRITE_COMBINE);
> unreg_video_dev:
> video_unregister_device(rga->vfd);
> + video_device_release(vfd);
> unreg_v4l2_dev:
> v4l2_device_unregister(&rga->v4l2_dev);
> err_put_clk:
>
^ permalink raw reply [flat|nested] 16+ messages in thread
* Re: [PATCH v3] media: rga: fix NULL pointer dereferences, use-after-free, memory leak
@ 2019-03-28 14:47 ` Hans Verkuil
0 siblings, 0 replies; 16+ messages in thread
From: Hans Verkuil @ 2019-03-28 14:47 UTC (permalink / raw)
To: Kangjie Lu
Cc: Heiko Stuebner, Jacob chen, linux-kernel, linux-rockchip,
pakki001, Mauro Carvalho Chehab, linux-arm-kernel, linux-media
Hi Kangjie,
Unfortunately there are more issues with the cleanup sequence in
this probe function:
On 3/14/19 6:03 AM, Kangjie Lu wrote:
> 1. dma_alloc_attrs, __get_free_pages can fail and return NULL.
> Further uses of their return values lead to NULL pointer
> dereferences
>
> 2. In the error-handling path, video_unregister_device uses
> "rga->vfd" which has been freed by video_device_release
>
> 3. The error handling for v4l2_m2m_init and video_register_device
> has memory-leak issues
>
> The patch fixes the above issues.
>
> Signed-off-by: Kangjie Lu <kjlu@umn.edu>
> ---
> drivers/media/platform/rockchip/rga/rga.c | 26 ++++++++++++++++++++---
> 1 file changed, 23 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/media/platform/rockchip/rga/rga.c b/drivers/media/platform/rockchip/rga/rga.c
> index 5c653287185f..468365ceb99d 100644
> --- a/drivers/media/platform/rockchip/rga/rga.c
> +++ b/drivers/media/platform/rockchip/rga/rga.c
> @@ -889,11 +889,24 @@ static int rga_probe(struct platform_device *pdev)
> rga->cmdbuf_virt = dma_alloc_attrs(rga->dev, RGA_CMDBUF_SIZE,
> &rga->cmdbuf_phy, GFP_KERNEL,
> DMA_ATTR_WRITE_COMBINE);
> + if (!rga->cmdbuf_virt) {
> + ret = -ENOMEM;
> + goto unreg_video_dev;
Actually, the unreg_video_dev label makes no sense: if the video device
is successfully registered, then probe() returns 0. So you never need to
unregister the video device again. You *do* need to release it with
video_device_release().
So this should be a goto rel_vdev.
And the cleanup sequence at the end also fails to call v4l2_m2m_release().
Can you make v4?
Thanks!
Hans
> + }
>
> rga->src_mmu_pages =
> (unsigned int *)__get_free_pages(GFP_KERNEL | __GFP_ZERO, 3);
> + if (!rga->src_mmu_pages) {
> + ret = -ENOMEM;
> + goto free_dma_attrs;
> + }
> +
> rga->dst_mmu_pages =
> (unsigned int *)__get_free_pages(GFP_KERNEL | __GFP_ZERO, 3);
> + if (!rga->dst_mmu_pages) {
> + ret = -ENOMEM;
> + goto free_dst_pages;
> + }
>
> def_frame.stride = (def_frame.width * def_frame.fmt->depth) >> 3;
> def_frame.size = def_frame.stride * def_frame.height;
> @@ -901,7 +914,7 @@ static int rga_probe(struct platform_device *pdev)
> ret = video_register_device(vfd, VFL_TYPE_GRABBER, -1);
> if (ret) {
> v4l2_err(&rga->v4l2_dev, "Failed to register video device\n");
> - goto rel_vdev;
> + goto free_pages;
> }
>
> v4l2_info(&rga->v4l2_dev, "Registered %s as /dev/%s\n",
> @@ -909,10 +922,17 @@ static int rga_probe(struct platform_device *pdev)
>
> return 0;
>
> -rel_vdev:
> - video_device_release(vfd);
> +free_pages:
> + free_pages((unsigned long)rga->src_mmu_pages, 3);
> +free_dst_pages:
> + free_pages((unsigned long)rga->dst_mmu_pages, 3);
> +free_dma_attrs:
> + dma_free_attrs(rga->dev, RGA_CMDBUF_SIZE, rga->cmdbuf_virt,
> + rga->cmdbuf_phy,
> + DMA_ATTR_WRITE_COMBINE);
> unreg_video_dev:
> video_unregister_device(rga->vfd);
> + video_device_release(vfd);
> unreg_v4l2_dev:
> v4l2_device_unregister(&rga->v4l2_dev);
> err_put_clk:
>
_______________________________________________
linux-arm-kernel mailing list
linux-arm-kernel@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-arm-kernel
^ permalink raw reply [flat|nested] 16+ messages in thread
* Re: [PATCH v3] media: rga: fix NULL pointer dereferences, use-after-free, memory leak
2019-03-28 14:47 ` Hans Verkuil
@ 2019-03-28 15:00 ` Kangjie Lu
-1 siblings, 0 replies; 16+ messages in thread
From: Kangjie Lu @ 2019-03-28 15:00 UTC (permalink / raw)
To: Hans Verkuil
Cc: pakki001, Jacob chen, Mauro Carvalho Chehab, Heiko Stuebner,
linux-media, linux-arm-kernel, linux-rockchip, linux-kernel
On 3/28/19 9:47 AM, Hans Verkuil wrote:
> Hi Kangjie,
>
> Unfortunately there are more issues with the cleanup sequence in
> this probe function:
>
> On 3/14/19 6:03 AM, Kangjie Lu wrote:
>> 1. dma_alloc_attrs, __get_free_pages can fail and return NULL.
>> Further uses of their return values lead to NULL pointer
>> dereferences
>>
>> 2. In the error-handling path, video_unregister_device uses
>> "rga->vfd" which has been freed by video_device_release
>>
>> 3. The error handling for v4l2_m2m_init and video_register_device
>> has memory-leak issues
>>
>> The patch fixes the above issues.
>>
>> Signed-off-by: Kangjie Lu <kjlu@umn.edu>
>> ---
>> drivers/media/platform/rockchip/rga/rga.c | 26 ++++++++++++++++++++---
>> 1 file changed, 23 insertions(+), 3 deletions(-)
>>
>> diff --git a/drivers/media/platform/rockchip/rga/rga.c b/drivers/media/platform/rockchip/rga/rga.c
>> index 5c653287185f..468365ceb99d 100644
>> --- a/drivers/media/platform/rockchip/rga/rga.c
>> +++ b/drivers/media/platform/rockchip/rga/rga.c
>> @@ -889,11 +889,24 @@ static int rga_probe(struct platform_device *pdev)
>> rga->cmdbuf_virt = dma_alloc_attrs(rga->dev, RGA_CMDBUF_SIZE,
>> &rga->cmdbuf_phy, GFP_KERNEL,
>> DMA_ATTR_WRITE_COMBINE);
>> + if (!rga->cmdbuf_virt) {
>> + ret = -ENOMEM;
>> + goto unreg_video_dev;
> Actually, the unreg_video_dev label makes no sense: if the video device
> is successfully registered, then probe() returns 0. So you never need to
> unregister the video device again. You *do* need to release it with
> video_device_release().
>
> So this should be a goto rel_vdev.
>
> And the cleanup sequence at the end also fails to call v4l2_m2m_release().
>
> Can you make v4?
Thanks for the feedback. Will send a v4.
>
> Thanks!
>
> Hans
>
>> + }
>>
>> rga->src_mmu_pages =
>> (unsigned int *)__get_free_pages(GFP_KERNEL | __GFP_ZERO, 3);
>> + if (!rga->src_mmu_pages) {
>> + ret = -ENOMEM;
>> + goto free_dma_attrs;
>> + }
>> +
>> rga->dst_mmu_pages =
>> (unsigned int *)__get_free_pages(GFP_KERNEL | __GFP_ZERO, 3);
>> + if (!rga->dst_mmu_pages) {
>> + ret = -ENOMEM;
>> + goto free_dst_pages;
>> + }
>>
>> def_frame.stride = (def_frame.width * def_frame.fmt->depth) >> 3;
>> def_frame.size = def_frame.stride * def_frame.height;
>> @@ -901,7 +914,7 @@ static int rga_probe(struct platform_device *pdev)
>> ret = video_register_device(vfd, VFL_TYPE_GRABBER, -1);
>> if (ret) {
>> v4l2_err(&rga->v4l2_dev, "Failed to register video device\n");
>> - goto rel_vdev;
>> + goto free_pages;
>> }
>>
>> v4l2_info(&rga->v4l2_dev, "Registered %s as /dev/%s\n",
>> @@ -909,10 +922,17 @@ static int rga_probe(struct platform_device *pdev)
>>
>> return 0;
>>
>> -rel_vdev:
>> - video_device_release(vfd);
>> +free_pages:
>> + free_pages((unsigned long)rga->src_mmu_pages, 3);
>> +free_dst_pages:
>> + free_pages((unsigned long)rga->dst_mmu_pages, 3);
>> +free_dma_attrs:
>> + dma_free_attrs(rga->dev, RGA_CMDBUF_SIZE, rga->cmdbuf_virt,
>> + rga->cmdbuf_phy,
>> + DMA_ATTR_WRITE_COMBINE);
>> unreg_video_dev:
>> video_unregister_device(rga->vfd);
>> + video_device_release(vfd);
>> unreg_v4l2_dev:
>> v4l2_device_unregister(&rga->v4l2_dev);
>> err_put_clk:
>>
^ permalink raw reply [flat|nested] 16+ messages in thread
* Re: [PATCH v3] media: rga: fix NULL pointer dereferences, use-after-free, memory leak
@ 2019-03-28 15:00 ` Kangjie Lu
0 siblings, 0 replies; 16+ messages in thread
From: Kangjie Lu @ 2019-03-28 15:00 UTC (permalink / raw)
To: Hans Verkuil
Cc: Heiko Stuebner, Jacob chen, linux-kernel, linux-rockchip,
pakki001, Mauro Carvalho Chehab, linux-arm-kernel, linux-media
On 3/28/19 9:47 AM, Hans Verkuil wrote:
> Hi Kangjie,
>
> Unfortunately there are more issues with the cleanup sequence in
> this probe function:
>
> On 3/14/19 6:03 AM, Kangjie Lu wrote:
>> 1. dma_alloc_attrs, __get_free_pages can fail and return NULL.
>> Further uses of their return values lead to NULL pointer
>> dereferences
>>
>> 2. In the error-handling path, video_unregister_device uses
>> "rga->vfd" which has been freed by video_device_release
>>
>> 3. The error handling for v4l2_m2m_init and video_register_device
>> has memory-leak issues
>>
>> The patch fixes the above issues.
>>
>> Signed-off-by: Kangjie Lu <kjlu@umn.edu>
>> ---
>> drivers/media/platform/rockchip/rga/rga.c | 26 ++++++++++++++++++++---
>> 1 file changed, 23 insertions(+), 3 deletions(-)
>>
>> diff --git a/drivers/media/platform/rockchip/rga/rga.c b/drivers/media/platform/rockchip/rga/rga.c
>> index 5c653287185f..468365ceb99d 100644
>> --- a/drivers/media/platform/rockchip/rga/rga.c
>> +++ b/drivers/media/platform/rockchip/rga/rga.c
>> @@ -889,11 +889,24 @@ static int rga_probe(struct platform_device *pdev)
>> rga->cmdbuf_virt = dma_alloc_attrs(rga->dev, RGA_CMDBUF_SIZE,
>> &rga->cmdbuf_phy, GFP_KERNEL,
>> DMA_ATTR_WRITE_COMBINE);
>> + if (!rga->cmdbuf_virt) {
>> + ret = -ENOMEM;
>> + goto unreg_video_dev;
> Actually, the unreg_video_dev label makes no sense: if the video device
> is successfully registered, then probe() returns 0. So you never need to
> unregister the video device again. You *do* need to release it with
> video_device_release().
>
> So this should be a goto rel_vdev.
>
> And the cleanup sequence at the end also fails to call v4l2_m2m_release().
>
> Can you make v4?
Thanks for the feedback. Will send a v4.
>
> Thanks!
>
> Hans
>
>> + }
>>
>> rga->src_mmu_pages =
>> (unsigned int *)__get_free_pages(GFP_KERNEL | __GFP_ZERO, 3);
>> + if (!rga->src_mmu_pages) {
>> + ret = -ENOMEM;
>> + goto free_dma_attrs;
>> + }
>> +
>> rga->dst_mmu_pages =
>> (unsigned int *)__get_free_pages(GFP_KERNEL | __GFP_ZERO, 3);
>> + if (!rga->dst_mmu_pages) {
>> + ret = -ENOMEM;
>> + goto free_dst_pages;
>> + }
>>
>> def_frame.stride = (def_frame.width * def_frame.fmt->depth) >> 3;
>> def_frame.size = def_frame.stride * def_frame.height;
>> @@ -901,7 +914,7 @@ static int rga_probe(struct platform_device *pdev)
>> ret = video_register_device(vfd, VFL_TYPE_GRABBER, -1);
>> if (ret) {
>> v4l2_err(&rga->v4l2_dev, "Failed to register video device\n");
>> - goto rel_vdev;
>> + goto free_pages;
>> }
>>
>> v4l2_info(&rga->v4l2_dev, "Registered %s as /dev/%s\n",
>> @@ -909,10 +922,17 @@ static int rga_probe(struct platform_device *pdev)
>>
>> return 0;
>>
>> -rel_vdev:
>> - video_device_release(vfd);
>> +free_pages:
>> + free_pages((unsigned long)rga->src_mmu_pages, 3);
>> +free_dst_pages:
>> + free_pages((unsigned long)rga->dst_mmu_pages, 3);
>> +free_dma_attrs:
>> + dma_free_attrs(rga->dev, RGA_CMDBUF_SIZE, rga->cmdbuf_virt,
>> + rga->cmdbuf_phy,
>> + DMA_ATTR_WRITE_COMBINE);
>> unreg_video_dev:
>> video_unregister_device(rga->vfd);
>> + video_device_release(vfd);
>> unreg_v4l2_dev:
>> v4l2_device_unregister(&rga->v4l2_dev);
>> err_put_clk:
>>
_______________________________________________
linux-arm-kernel mailing list
linux-arm-kernel@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-arm-kernel
^ permalink raw reply [flat|nested] 16+ messages in thread