Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1635575
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH 3.12 34/86] zram: do not use copy_page with non-page aligned address |
| Date | 2017-05-04 11:30 +0200 |
| Message-ID | <tDlfc-1wD-27@gated-at.bofh.it> (permalink) |
| References | <tDkVQ-1oS-3@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
From: Minchan Kim <minchan@kernel.org>
3.12-stable review patch. If anyone has any objections, please let me know.
===============
commit d72e9a7a93e4f8e9e52491921d99e0c8aa89eb4e upstream.
The copy_page is optimized memcpy for page-alinged address. If it is
used with non-page aligned address, it can corrupt memory which means
system corruption. With zram, it can happen with
1. 64K architecture
2. partial IO
3. slub debug
Partial IO need to allocate a page and zram allocates it via kmalloc.
With slub debug, kmalloc(PAGE_SIZE) doesn't return page-size aligned
address. And finally, copy_page(mem, cmem) corrupts memory.
So, this patch changes it to memcpy.
Actuaully, we don't need to change zram_bvec_write part because zsmalloc
returns page-aligned address in case of PAGE_SIZE class but it's not
good to rely on the internal of zsmalloc.
Note:
When this patch is merged to stable, clear_page should be fixed, too.
Unfortunately, recent zram removes it by "same page merge" feature so
it's hard to backport this patch to -stable tree.
I will handle it when I receive the mail from stable tree maintainer to
merge this patch to backport.
Fixes: 42e99bd ("zram: optimize memory operations with clear_page()/copy_page()")
Link: http://lkml.kernel.org/r/1492042622-12074-2-git-send-email-minchan@kernel.org
Signed-off-by: Minchan Kim <minchan@kernel.org>
Cc: Sergey Senozhatsky <sergey.senozhatsky@gmail.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
drivers/staging/zram/zram_drv.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/staging/zram/zram_drv.c b/drivers/staging/zram/zram_drv.c
index 162e01a27d40..f893a902a534 100644
--- a/drivers/staging/zram/zram_drv.c
+++ b/drivers/staging/zram/zram_drv.c
@@ -321,13 +321,13 @@ static int zram_decompress_page(struct zram *zram, char *mem, u32 index)
unsigned long handle = meta->table[index].handle;
if (!handle || zram_test_flag(meta, index, ZRAM_ZERO)) {
- clear_page(mem);
+ memset(mem, 0, PAGE_SIZE);
return 0;
}
cmem = zs_map_object(meta->mem_pool, handle, ZS_MM_RO);
if (meta->table[index].size == PAGE_SIZE)
- copy_page(mem, cmem);
+ memcpy(mem, cmem, PAGE_SIZE);
else
ret = lzo1x_decompress_safe(cmem, meta->table[index].size,
mem, &clen);
@@ -482,7 +482,7 @@ static int zram_bvec_write(struct zram *zram, struct bio_vec *bvec, u32 index,
if ((clen == PAGE_SIZE) && !is_partial_io(bvec)) {
src = kmap_atomic(page);
- copy_page(cmem, src);
+ memcpy(cmem, src, PAGE_SIZE);
kunmap_atomic(src);
} else {
memcpy(cmem, src, clen);
--
2.12.2
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH 3.12 00/86] 3.12.74-stable review Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 01/86] drm/vmwgfx: NULL pointer dereference in vmw_surface_define_ioctl() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 04/86] drm/vmwgfx: fix integer overflow in vmw_surface_define_ioctl() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 81/86] ALSA: seq: Don't break snd_use_lock_sync() loop by timeout Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 25/86] perf/x86: Avoid exposing wrong/stale data in intel_pmu_lbr_read_32() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 03/86] drm/vmwgfx: Remove getparam error message Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 05/86] Reset TreeId to zero on SMB2 TREE_CONNECT Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 85/86] nfsd: check for oversized NFSv2/v3 arguments Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 59/86] kvm: arm/arm64: Fix locking for kvm_free_stage2_pgd Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 26/86] x86/vdso: Plug race between mapping and ELF header setup Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 82/86] MIPS: KGDB: Use kernel context for sleeping threads Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 31/86] xen, fbfront: fix connecting to backend Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 56/86] ACPI / power: Avoid maybe-uninitialized warning Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 78/86] MIPS: Fix crash registers on non-crashing CPUs Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 28/86] iscsi-target: Drop work-around for legacy GlobalSAN initiator Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 29/86] scsi: sr: Sanity check returned mode data Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 83/86] p9_client_readdir() fix Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 06/86] ptrace: fix PTRACE_LISTEN race corrupting task->state Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 80/86] xen/x86: don't lose event interrupts Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 55/86] Input: elantech - add Fujitsu Lifebook E547 to force crc_enabled Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:10 +0200
[PATCH 3.12 77/86] md:raid1: fix a dead loop when read from a WriteMostly disk Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 63/86] net/packet: fix overflow in check for tp_frame_nr Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 72/86] net: ipv4: fix multipath RTM_GETROUTE behavior when iif is given Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 61/86] powerpc: Reject binutils 2.24 when building little endian Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 75/86] ipv6: check raw payload size correctly in ioctl Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 60/86] block: fix del_gendisk() vs blkdev_ioctl crash Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 33/86] char: lack of bool string made CONFIG_DEVPORT always on Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 74/86] ip6mr: fix notification device destruction Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 66/86] tty: nozomi: avoid a harmless gcc warning Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 67/86] hostap: avoid uninitialized variable use in hfa384x_get_rid Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 64/86] net/packet: fix overflow in check for tp_reserve Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 76/86] ext4: check if in-inode xattr is corrupted in ext4_expand_extra_isize_ea() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 45/86] net: ipv6: check route protocol when deleting routes Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 46/86] KEYS: Disallow keyrings beginning with '.' to be joined as session keyrings Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 65/86] netfilter: arp_tables: fix invoking 32bit "iptable -P INPUT ACCEPT" failed in 64bit kernel Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 42/86] rtl8150: Use heap buffers for all register access Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 30/86] scsi: sd: Fix capacity calculation with 32-bit sector_t Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 39/86] mm: Tighten x86 /dev/mem with zeroing reads Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 43/86] catc: Combine failure cleanup code in catc_probe() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 51/86] cifs: Do not send echoes before Negotiate is complete Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 40/86] virtio-console: avoid DMA from stack Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 69/86] net: neigh: guard against NULL solicit() method Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 49/86] tracing: Allocate the snapshot buffer before enabling probe Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 50/86] ring-buffer: Have ring_buffer_iter_empty() return true when empty Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 53/86] Drivers: hv: don't leak memory in vmbus_establish_gpadl() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 62/86] ping: implement proper locking Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 79/86] RDS: Fix the atomicity for congestion map update Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 84/86] Input: i8042 - add Clevo P650RS to the i8042 reset list Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 52/86] CIFS: remove bad_network_name flag Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 54/86] Drivers: hv: get rid of timeout in vmbus_open() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 47/86] KEYS: Change the name of the dead type to ".dead" to prevent user access Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 41/86] pegasus: Use heap buffers for all register access Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 37/86] ext4: fix inode checksum calculation problem if i_extra_size is small Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 38/86] platform/x86: acer-wmi: setup accelerometer when machine has appropriate notify event Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 71/86] l2tp: take reference on sessions being dumped Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 68/86] gfs2: avoid uninitialized variable warning Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 70/86] net: phy: handle state correctly in phy_stop_machine Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 58/86] x86/mce/AMD: Give a name to MCA bank 3 when accessed with legacy MSRs Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 73/86] sctp: listen on the sock only when it's state is listening or closed Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:20 +0200
[PATCH 3.12 18/86] usb: dwc3: gadget: delay unmap of bounced requests Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 32/86] char: Drop bogus dependency of DEVPORT on !M68K Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 36/86] dvb-usb-v2: avoid use-after-free Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 14/86] metag/usercopy: Add missing fixups Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 10/86] metag/usercopy: Add early abort to copy_to_user Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 21/86] usb: hub: Wait for connection to be reestablished after port reset Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 13/86] metag/usercopy: Fix src fixup in from user rapf loops Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 23/86] net/mlx4_core: Fix racy CQ (Completion Queue) free Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 34/86] zram: do not use copy_page with non-page aligned address Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 19/86] mtd: bcm47xxpart: fix parsing first block after aligned TRX Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 16/86] s390/decompressor: fix initrd corruption caused by bss clear Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 08/86] metag/usercopy: Drop unused macros Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 24/86] Input: xpad - add support for Razer Wildcat gamepad Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 44/86] catc: Use heap buffer for memory size test Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 35/86] powerpc: Disable HFSCR[TM] if TM is not supported Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 15/86] powerpc: Don't try to fix up misaligned load-with-reservation instructions Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 07/86] ring-buffer: Fix return value check in test_ringbuffer() Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 17/86] mm/mempolicy.c: fix error handling in set_mempolicy and mbind. Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 09/86] metag/usercopy: Fix alignment error checking Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 22/86] net/mlx4_en: Fix bad WQE issue Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 20/86] net/packet: fix overflow in check for priv area size Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 12/86] metag/usercopy: Set flags before ADDZ Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
[PATCH 3.12 11/86] metag/usercopy: Zero rest of buffer from copy_from_user Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
Re: [PATCH 3.12 00/86] 3.12.74-stable review Jiri Slaby <jslaby@suse.cz> - 2017-05-04 11:30 +0200
Re: [PATCH 3.12 00/86] 3.12.74-stable review Guenter Roeck <linux@roeck-us.net> - 2017-05-04 18:00 +0200
Re: [PATCH 3.12 00/86] 3.12.74-stable review Jiri Slaby <jslaby@suse.cz> - 2017-05-09 21:00 +0200
Re: [PATCH 3.12 00/86] 3.12.74-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2017-05-04 21:00 +0200
csiph-web