]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
blk-integrity: remove seed for user mapped buffers
authorKeith Busch <kbusch@kernel.org>
Wed, 16 Oct 2024 20:13:09 +0000 (13:13 -0700)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Mon, 1 Jun 2026 15:46:28 +0000 (17:46 +0200)
[ Upstream commit 133008e84b99e4f5f8cf3d8b768c995732df9406 ]

The seed is only used for kernel generation and verification. That
doesn't happen for user buffers, so passing the seed around doesn't
accomplish anything.

Signed-off-by: Keith Busch <kbusch@kernel.org>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Anuj Gupta <anuj20.g@samsung.com>
Reviewed-by: Kanchan Joshi <joshi.k@samsung.com>
Link: https://lore.kernel.org/r/20241016201309.1090320-1-kbusch@meta.com
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Stable-dep-of: 637ad3a56a3b ("block: don't overwrite bip_vcnt in bio_integrity_copy_user()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
block/bio-integrity.c
block/blk-integrity.c
drivers/nvme/host/ioctl.c
include/linux/bio-integrity.h
include/linux/blk-integrity.h

index 6641ecbf69678258f3552de831fe4fee085e4380..ab58f44058e96e69e838171b09a3b8c1bc801fa7 100644 (file)
@@ -197,7 +197,7 @@ EXPORT_SYMBOL(bio_integrity_add_page);
 
 static int bio_integrity_copy_user(struct bio *bio, struct bio_vec *bvec,
                                   int nr_vecs, unsigned int len,
-                                  unsigned int direction, u32 seed)
+                                  unsigned int direction)
 {
        bool write = direction == ITER_SOURCE;
        struct bio_integrity_payload *bip;
@@ -245,7 +245,6 @@ static int bio_integrity_copy_user(struct bio *bio, struct bio_vec *bvec,
        }
 
        bip->bip_flags |= BIP_COPY_USER;
-       bip->bip_iter.bi_sector = seed;
        bip->bip_vcnt = nr_vecs;
        return 0;
 free_bip:
@@ -256,7 +255,7 @@ free_buf:
 }
 
 static int bio_integrity_init_user(struct bio *bio, struct bio_vec *bvec,
-                                  int nr_vecs, unsigned int len, u32 seed)
+                                  int nr_vecs, unsigned int len)
 {
        struct bio_integrity_payload *bip;
 
@@ -265,7 +264,6 @@ static int bio_integrity_init_user(struct bio *bio, struct bio_vec *bvec,
                return PTR_ERR(bip);
 
        memcpy(bip->bip_vec, bvec, nr_vecs * sizeof(*bvec));
-       bip->bip_iter.bi_sector = seed;
        bip->bip_iter.bi_size = len;
        bip->bip_vcnt = nr_vecs;
        return 0;
@@ -301,8 +299,7 @@ static unsigned int bvec_from_pages(struct bio_vec *bvec, struct page **pages,
        return nr_bvecs;
 }
 
-int bio_integrity_map_user(struct bio *bio, void __user *ubuf, ssize_t bytes,
-                          u32 seed)
+int bio_integrity_map_user(struct bio *bio, void __user *ubuf, ssize_t bytes)
 {
        struct request_queue *q = bdev_get_queue(bio->bi_bdev);
        unsigned int align = blk_lim_dma_alignment_and_pad(&q->limits);
@@ -348,9 +345,9 @@ int bio_integrity_map_user(struct bio *bio, void __user *ubuf, ssize_t bytes,
 
        if (copy)
                ret = bio_integrity_copy_user(bio, bvec, nr_bvecs, bytes,
-                                             direction, seed);
+                                             direction);
        else
-               ret = bio_integrity_init_user(bio, bvec, nr_bvecs, bytes, seed);
+               ret = bio_integrity_init_user(bio, bvec, nr_bvecs, bytes);
        if (ret)
                goto release_pages;
        if (bvec != stack_vec)
index 3fe0681399f6e5a403b116e6ad1ea15f15ecc290..013469faa5e7c4e2592d22882a91a09bccd252eb 100644 (file)
@@ -113,9 +113,9 @@ new_segment:
 EXPORT_SYMBOL(blk_rq_map_integrity_sg);
 
 int blk_rq_integrity_map_user(struct request *rq, void __user *ubuf,
-                             ssize_t bytes, u32 seed)
+                             ssize_t bytes)
 {
-       int ret = bio_integrity_map_user(rq->bio, ubuf, bytes, seed);
+       int ret = bio_integrity_map_user(rq->bio, ubuf, bytes);
 
        if (ret)
                return ret;
index 64ae8af01d9a47f17be2f7a9e80a91d52d3485b5..930521c633d231a7511f40b7be4dffeef294c09a 100644 (file)
@@ -114,7 +114,7 @@ static struct request *nvme_alloc_user_request(struct request_queue *q,
 
 static int nvme_map_user_request(struct request *req, u64 ubuffer,
                unsigned bufflen, void __user *meta_buffer, unsigned meta_len,
-               u32 meta_seed, struct io_uring_cmd *ioucmd, unsigned int flags)
+               struct io_uring_cmd *ioucmd, unsigned int flags)
 {
        struct request_queue *q = req->q;
        struct nvme_ns *ns = q->queuedata;
@@ -164,8 +164,7 @@ static int nvme_map_user_request(struct request *req, u64 ubuffer,
                bio_set_dev(bio, bdev);
 
        if (has_metadata) {
-               ret = blk_rq_integrity_map_user(req, meta_buffer, meta_len,
-                                               meta_seed);
+               ret = blk_rq_integrity_map_user(req, meta_buffer, meta_len);
                if (ret)
                        goto out_unmap;
        }
@@ -182,7 +181,7 @@ out:
 
 static int nvme_submit_user_cmd(struct request_queue *q,
                struct nvme_command *cmd, u64 ubuffer, unsigned bufflen,
-               void __user *meta_buffer, unsigned meta_len, u32 meta_seed,
+               void __user *meta_buffer, unsigned meta_len,
                u64 *result, unsigned timeout, unsigned int flags)
 {
        struct nvme_ns *ns = q->queuedata;
@@ -199,7 +198,7 @@ static int nvme_submit_user_cmd(struct request_queue *q,
        req->timeout = timeout;
        if (ubuffer && bufflen) {
                ret = nvme_map_user_request(req, ubuffer, bufflen, meta_buffer,
-                               meta_len, meta_seed, NULL, flags);
+                               meta_len, NULL, flags);
                if (ret)
                        return ret;
        }
@@ -280,7 +279,7 @@ static int nvme_submit_io(struct nvme_ns *ns, struct nvme_user_io __user *uio)
        c.rw.lbatm = cpu_to_le16(io.appmask);
 
        return nvme_submit_user_cmd(ns->queue, &c, io.addr, length, metadata,
-                       meta_len, lower_32_bits(io.slba), NULL, 0, 0);
+                       meta_len, NULL, 0, 0);
 }
 
 static bool nvme_validate_passthru_nsid(struct nvme_ctrl *ctrl,
@@ -334,7 +333,7 @@ static int nvme_user_cmd(struct nvme_ctrl *ctrl, struct nvme_ns *ns,
 
        status = nvme_submit_user_cmd(ns ? ns->queue : ctrl->admin_q, &c,
                        cmd.addr, cmd.data_len, nvme_to_user_ptr(cmd.metadata),
-                       cmd.metadata_len, 0, &result, timeout, 0);
+                       cmd.metadata_len, &result, timeout, 0);
 
        if (status >= 0) {
                if (put_user(result, &ucmd->result))
@@ -381,7 +380,7 @@ static int nvme_user_cmd64(struct nvme_ctrl *ctrl, struct nvme_ns *ns,
 
        status = nvme_submit_user_cmd(ns ? ns->queue : ctrl->admin_q, &c,
                        cmd.addr, cmd.data_len, nvme_to_user_ptr(cmd.metadata),
-                       cmd.metadata_len, 0, &cmd.result, timeout, flags);
+                       cmd.metadata_len, &cmd.result, timeout, flags);
 
        if (status >= 0) {
                if (put_user(cmd.result, &ucmd->result))
@@ -511,7 +510,7 @@ static int nvme_uring_cmd_io(struct nvme_ctrl *ctrl, struct nvme_ns *ns,
        if (d.addr && d.data_len) {
                ret = nvme_map_user_request(req, d.addr,
                        d.data_len, nvme_to_user_ptr(d.metadata),
-                       d.metadata_len, 0, ioucmd, vec);
+                       d.metadata_len, ioucmd, vec);
                if (ret)
                        return ret;
        }
index dd831c269e9948a32ec96741f2c4fc7836fc1c99..dbf0f74c15291327c11af3c393386ec13cc3906f 100644 (file)
@@ -72,7 +72,7 @@ struct bio_integrity_payload *bio_integrity_alloc(struct bio *bio, gfp_t gfp,
                unsigned int nr);
 int bio_integrity_add_page(struct bio *bio, struct page *page, unsigned int len,
                unsigned int offset);
-int bio_integrity_map_user(struct bio *bio, void __user *ubuf, ssize_t len, u32 seed);
+int bio_integrity_map_user(struct bio *bio, void __user *ubuf, ssize_t len);
 void bio_integrity_unmap_user(struct bio *bio);
 bool bio_integrity_prep(struct bio *bio);
 void bio_integrity_advance(struct bio *bio, unsigned int bytes_done);
@@ -99,7 +99,7 @@ static inline void bioset_integrity_free(struct bio_set *bs)
 }
 
 static inline int bio_integrity_map_user(struct bio *bio, void __user *ubuf,
-                                        ssize_t len, u32 seed)
+                                        ssize_t len)
 {
        return -EINVAL;
 }
index 676f8f860c4748660aa1bda0f809f982b527f61a..c7eae0bfb013f171eadb34e7b107cf451e356287 100644 (file)
@@ -28,7 +28,7 @@ static inline bool queue_limits_stack_integrity_bdev(struct queue_limits *t,
 int blk_rq_map_integrity_sg(struct request *, struct scatterlist *);
 int blk_rq_count_integrity_sg(struct request_queue *, struct bio *);
 int blk_rq_integrity_map_user(struct request *rq, void __user *ubuf,
-                             ssize_t bytes, u32 seed);
+                             ssize_t bytes);
 
 static inline bool
 blk_integrity_queue_supports_integrity(struct request_queue *q)
@@ -104,8 +104,7 @@ static inline int blk_rq_map_integrity_sg(struct request *q,
 }
 static inline int blk_rq_integrity_map_user(struct request *rq,
                                            void __user *ubuf,
-                                           ssize_t bytes,
-                                           u32 seed)
+                                           ssize_t bytes)
 {
        return -EINVAL;
 }