|
@@ -24,6 +24,7 @@
|
|
|
#include <linux/pci-ats.h>
|
|
|
#include <linux/dmar.h>
|
|
|
#include <linux/interrupt.h>
|
|
|
+#include <asm/page.h>
|
|
|
|
|
|
static irqreturn_t prq_event_thread(int irq, void *d);
|
|
|
|
|
@@ -555,6 +556,14 @@ static bool access_error(struct vm_area_struct *vma, struct page_req_dsc *req)
|
|
|
return (requested & ~vma->vm_flags) != 0;
|
|
|
}
|
|
|
|
|
|
+static bool is_canonical_address(u64 addr)
|
|
|
+{
|
|
|
+ int shift = 64 - (__VIRTUAL_MASK_SHIFT + 1);
|
|
|
+ long saddr = (long) addr;
|
|
|
+
|
|
|
+ return (((saddr << shift) >> shift) == saddr);
|
|
|
+}
|
|
|
+
|
|
|
static irqreturn_t prq_event_thread(int irq, void *d)
|
|
|
{
|
|
|
struct intel_iommu *iommu = d;
|
|
@@ -612,6 +621,11 @@ static irqreturn_t prq_event_thread(int irq, void *d)
|
|
|
/* If the mm is already defunct, don't handle faults. */
|
|
|
if (!mmget_not_zero(svm->mm))
|
|
|
goto bad_req;
|
|
|
+
|
|
|
+ /* If address is not canonical, return invalid response */
|
|
|
+ if (!is_canonical_address(address))
|
|
|
+ goto bad_req;
|
|
|
+
|
|
|
down_read(&svm->mm->mmap_sem);
|
|
|
vma = find_extend_vma(svm->mm, address);
|
|
|
if (!vma || address < vma->vm_start)
|