diff options
| author | zhang jiao <zhangjiao2@cmss.chinamobile.com> | 2025-09-10 17:17:38 +0800 |
|---|---|---|
| committer | Greg Kroah-Hartman <gregkh@linuxfoundation.org> | 2025-10-15 11:56:39 +0200 |
| commit | db042925a5ab7a550b710addeadbf6f72e3a8a4b (patch) | |
| tree | 3f75298a78331016499bfe775e756c3c31c9d38f | |
| parent | f8648cb41842bc88a362e3f8c6162826161b22c3 (diff) | |
| download | linux-db042925a5ab7a550b710addeadbf6f72e3a8a4b.tar.gz linux-db042925a5ab7a550b710addeadbf6f72e3a8a4b.tar.bz2 linux-db042925a5ab7a550b710addeadbf6f72e3a8a4b.zip | |
vhost: vringh: Modify the return value check
[ Upstream commit 82a8d0fda55b35361ee7f35b54fa2b66d7847d2b ]
The return value of copy_from_iter and copy_to_iter can't be negative,
check whether the copied lengths are equal.
Fixes: 309bba39c945 ("vringh: iterate on iotlb_translate to handle large translations")
Cc: "Stefano Garzarella" <sgarzare@redhat.com>
Signed-off-by: zhang jiao <zhangjiao2@cmss.chinamobile.com>
Message-Id: <20250910091739.2999-1-zhangjiao2@cmss.chinamobile.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
| -rw-r--r-- | drivers/vhost/vringh.c | 7 |
1 files changed, 4 insertions, 3 deletions
diff --git a/drivers/vhost/vringh.c b/drivers/vhost/vringh.c index c570d214d5b6..d89c2bce94cb 100644 --- a/drivers/vhost/vringh.c +++ b/drivers/vhost/vringh.c @@ -1162,6 +1162,7 @@ static inline int copy_from_iotlb(const struct vringh *vrh, void *dst, struct iov_iter iter; u64 translated; int ret; + size_t size; ret = iotlb_translate(vrh, (u64)(uintptr_t)src, len - total_translated, &translated, @@ -1173,9 +1174,9 @@ static inline int copy_from_iotlb(const struct vringh *vrh, void *dst, iov_iter_bvec(&iter, ITER_SOURCE, iov, ret, translated); - ret = copy_from_iter(dst, translated, &iter); - if (ret < 0) - return ret; + size = copy_from_iter(dst, translated, &iter); + if (size != translated) + return -EFAULT; src += translated; dst += translated; |
