drm/tegra: Check syncpoint ID in the 'submit' IOCTL
authorDmitry Osipenko <digetx@gmail.com>
Wed, 14 Jun 2017 23:18:28 +0000 (02:18 +0300)
committerThierry Reding <treding@nvidia.com>
Thu, 15 Jun 2017 12:17:21 +0000 (14:17 +0200)
In case of invalid syncpoint ID, the host1x_syncpt_get() returns NULL and
none of its users perform a check of the returned pointer later. Let's bail
out until it's too late.

Signed-off-by: Dmitry Osipenko <digetx@gmail.com>
Reviewed-by: Mikko Perttunen <mperttunen@nvidia.com>
Signed-off-by: Thierry Reding <treding@nvidia.com>
drivers/gpu/drm/tegra/drm.c

index 0928f2bb420324f0fbe00582f12e2f495f4ac6b1..b44f1eddb570b9f4a8e0ba6205b1bfb59e36ba20 100644 (file)
@@ -393,6 +393,8 @@ int tegra_drm_submit(struct tegra_drm_context *context,
        struct drm_tegra_waitchk __user *waitchks =
                (void __user *)(uintptr_t)args->waitchks;
        struct drm_tegra_syncpt syncpt;
+       struct host1x *host1x = dev_get_drvdata(drm->dev->parent);
+       struct host1x_syncpt *sp;
        struct host1x_job *job;
        int err;
 
@@ -522,6 +524,13 @@ int tegra_drm_submit(struct tegra_drm_context *context,
                goto fail;
        }
 
+       /* check whether syncpoint ID is valid */
+       sp = host1x_syncpt_get(host1x, syncpt.id);
+       if (!sp) {
+               err = -ENOENT;
+               goto fail;
+       }
+
        job->is_addr_reg = context->client->ops->is_addr_reg;
        job->syncpt_incrs = syncpt.incrs;
        job->syncpt_id = syncpt.id;