浏览代码

iommu/amd: Handle integer overflow in dma_ops_area_alloc

Handle this case to make sure boundary_size does not become
0 and trigger a BUG_ON later.

Signed-off-by: Joerg Roedel <jroedel@suse.de>
Joerg Roedel 10 年之前
父节点
当前提交
e6aabee05f
共有 1 个文件被更改,包括 5 次插入3 次删除
  1. 5 3
      drivers/iommu/amd_iommu.c

+ 5 - 3
drivers/iommu/amd_iommu.c

@@ -1699,14 +1699,16 @@ static unsigned long dma_ops_area_alloc(struct device *dev,
 	unsigned long next_bit = dom->next_address % APERTURE_RANGE_SIZE;
 	unsigned long next_bit = dom->next_address % APERTURE_RANGE_SIZE;
 	int max_index = dom->aperture_size >> APERTURE_RANGE_SHIFT;
 	int max_index = dom->aperture_size >> APERTURE_RANGE_SHIFT;
 	int i = start >> APERTURE_RANGE_SHIFT;
 	int i = start >> APERTURE_RANGE_SHIFT;
-	unsigned long boundary_size;
+	unsigned long boundary_size, mask;
 	unsigned long address = -1;
 	unsigned long address = -1;
 	unsigned long limit;
 	unsigned long limit;
 
 
 	next_bit >>= PAGE_SHIFT;
 	next_bit >>= PAGE_SHIFT;
 
 
-	boundary_size = ALIGN(dma_get_seg_boundary(dev) + 1,
-			PAGE_SIZE) >> PAGE_SHIFT;
+	mask = dma_get_seg_boundary(dev);
+
+	boundary_size = mask + 1 ? ALIGN(mask + 1, PAGE_SIZE) >> PAGE_SHIFT :
+				   1UL << (BITS_PER_LONG - PAGE_SHIFT);
 
 
 	for (;i < max_index; ++i) {
 	for (;i < max_index; ++i) {
 		unsigned long offset = dom->aperture[i]->offset >> PAGE_SHIFT;
 		unsigned long offset = dom->aperture[i]->offset >> PAGE_SHIFT;