aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorColin Cross <ccross@android.com>2013-11-13 14:46:06 -0800
committerColin Cross <ccross@android.com>2013-12-11 17:52:17 -0800
commite8f7f42cdcbe3ae4c4bf719847369ddac44219a9 (patch)
tree21cbe05dd46c5af5b89b5249b2a7d1caf3ddbfcf
parentda3b36172d546200a851f165bf574d6090f4ff4a (diff)
ion: check invalid values in ion_system_heap
ion_system_heap can only satisfy page alignment, and ion_system_contig_heap can only satisify alignment to the allocation size. Neither can support faulting user mappings because they use slab pages. Change-Id: I895c2d4184c672f647f83a17aeb862985dc92f2c Signed-off-by: Colin Cross <ccross@android.com>
-rw-r--r--drivers/staging/android/ion/ion_system_heap.c14
1 files changed, 14 insertions, 0 deletions
diff --git a/drivers/staging/android/ion/ion_system_heap.c b/drivers/staging/android/ion/ion_system_heap.c
index ecae16f2109..4eb0ae8c675 100644
--- a/drivers/staging/android/ion/ion_system_heap.c
+++ b/drivers/staging/android/ion/ion_system_heap.c
@@ -150,6 +150,12 @@ static int ion_system_heap_allocate(struct ion_heap *heap,
long size_remaining = PAGE_ALIGN(size);
unsigned int max_order = orders[0];
+ if (align > PAGE_SIZE)
+ return -EINVAL;
+
+ if (ion_buffer_fault_user_mappings(buffer))
+ return -EINVAL;
+
INIT_LIST_HEAD(&pages);
while (size_remaining > 0) {
info = alloc_largest_available(sys_heap, buffer, size_remaining, max_order);
@@ -362,6 +368,14 @@ static int ion_system_contig_heap_allocate(struct ion_heap *heap,
unsigned long align,
unsigned long flags)
{
+ int order = get_order(len);
+
+ if (align > (PAGE_SIZE << order))
+ return -EINVAL;
+
+ if (ion_buffer_fault_user_mappings(buffer))
+ return -EINVAL;
+
buffer->priv_virt = kzalloc(len, GFP_KERNEL);
if (!buffer->priv_virt)
return -ENOMEM;