• Nicholas Bellinger's avatar
    vhost/scsi: Fix incorrect usage of get_user_pages_fast write parameter · 722b78bc
    Nicholas Bellinger authored
    commit 60a01f558af9c48b0bb31f303c479e32721add3f upstream.
    
    This patch addresses a long-standing bug where the get_user_pages_fast()
    write parameter used for setting the underlying page table entry permission
    bits was incorrectly set to write=1 for data_direction=DMA_TO_DEVICE, and
    passed into get_user_pages_fast() via vhost_scsi_map_iov_to_sgl().
    
    However, this parameter is intended to signal WRITEs to pinned userspace
    PTEs for the virtio-scsi DMA_FROM_DEVICE -> READ payload case, and *not*
    for the virtio-scsi DMA_TO_DEVICE -> WRITE payload case.
    
    This bug would manifest itself as random process segmentation faults on
    KVM host after repeated vhost starts + stops and/or with lots of vhost
    endpoints + LUNs.
    
    Cc: Stefan Hajnoczi <stefanha@redhat.com>
    Cc: Michael S. Tsirkin <mst@redhat.com>
    Cc: Asias He <asias@redhat.com>
    Signed-off-by: 's avatarNicholas Bellinger <nab@linux-iscsi.org>
    Signed-off-by: 's avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
    722b78bc
Name
Last commit
Last update
..
Kconfig Loading commit data...
Makefile Loading commit data...
net.c Loading commit data...
scsi.c Loading commit data...
test.c Loading commit data...
test.h Loading commit data...
vhost.c Loading commit data...
vhost.h Loading commit data...
vringh.c Loading commit data...