]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
vhost: vringh: Modify the return value check
authorzhang jiao <zhangjiao2@cmss.chinamobile.com>
Wed, 10 Sep 2025 09:17:38 +0000 (17:17 +0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 15 Oct 2025 09:56:39 +0000 (11:56 +0200)
[ Upstream commit 82a8d0fda55b35361ee7f35b54fa2b66d7847d2b ]

The return value of copy_from_iter and copy_to_iter can't be negative,
check whether the copied lengths are equal.

Fixes: 309bba39c945 ("vringh: iterate on iotlb_translate to handle large translations")
Cc: "Stefano Garzarella" <sgarzare@redhat.com>
Signed-off-by: zhang jiao <zhangjiao2@cmss.chinamobile.com>
Message-Id: <20250910091739.2999-1-zhangjiao2@cmss.chinamobile.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/vhost/vringh.c

index c570d214d5b68b16fb703e00d145c4b3b6927884..d89c2bce94cbf9e30722cd3be7868537638b77dd 100644 (file)
@@ -1162,6 +1162,7 @@ static inline int copy_from_iotlb(const struct vringh *vrh, void *dst,
                struct iov_iter iter;
                u64 translated;
                int ret;
+               size_t size;
 
                ret = iotlb_translate(vrh, (u64)(uintptr_t)src,
                                      len - total_translated, &translated,
@@ -1173,9 +1174,9 @@ static inline int copy_from_iotlb(const struct vringh *vrh, void *dst,
 
                iov_iter_bvec(&iter, ITER_SOURCE, iov, ret, translated);
 
-               ret = copy_from_iter(dst, translated, &iter);
-               if (ret < 0)
-                       return ret;
+               size = copy_from_iter(dst, translated, &iter);
+               if (size != translated)
+                       return -EFAULT;
 
                src += translated;
                dst += translated;