vmemdup_array_user() is already available in 5.15.y via commit 24b17d530c42
(string.h: add array-wrappers for (v)memdup_user()). So there is no
implicit declaration or pointer truncation, and the described build failure
does not apply to the target stable tree.


ср, 23 сент. 2026 г. в 18:07, <[email protected]>:

> Thank you for your contribution! Sashiko AI review found 1 potential
> issue(s) to consider:
> - [Low] build: missing vmemdup_array_user helper
> --
>
> commit 4d70c808a81c22c8b9f6c03847fa45f071b2e967
> Author: Tvrtko Ursulin <[email protected]>
>
> drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array
>
> This commit replaces kvmalloc_array() + copy_from_user() with
> vmemdup_array_user() on the fast path. This aims to shrink the source code
> and improve separation between kernel and userspace slabs.
>
> > diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
> b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
> > index 15c45b2a39835..b364f3f5fb918 100644
> > --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
> > +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
> > @@ -223,43 +223,36 @@ void amdgpu_bo_list_put(struct amdgpu_bo_list
> *list)
> >  int amdgpu_bo_create_list_entry_array(struct drm_amdgpu_bo_list_in *in,
> >                                     struct drm_amdgpu_bo_list_entry
> **info_param)
> >  {
> [ ... ]
> >       /* copy the handle array from userspace to a kernel buffer */
> > -     r = -EFAULT;
> > -     if (likely(info_size == in->bo_info_size)) {
> > -             unsigned long bytes = in->bo_number *
> > -                     in->bo_info_size;
> > -
> > -             if (copy_from_user(info, uptr, bytes))
> > -                     goto error_free;
> > -
> > +     if (likely(info_size == bo_info_size)) {
> > +             info = vmemdup_array_user(uptr, bo_number, info_size);
>
> [Severity: Low]
> Does this code call a function vmemdup_array_user() that does not exist in
> this kernel tree?
>
> When compiling drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c with
> CONFIG_DRM_AMDGPU=y or m, this will result in a build failure due to an
> implicit function declaration in amdgpu_bo_create_list_entry_array(). If
> the
> compiler allows implicit declarations, it would assume a 32-bit int return
> type, which truncates the pointer on 64-bit systems and can lead to an
> invalid pointer dereference or use-after-free when IS_ERR(info) or
> kvfree(info) is called later.
>
> > +             if (IS_ERR(info))
> > +                     return PTR_ERR(info);
>
> --
> Sashiko AI review ·
> https://sashiko.dev/#/patchset/[email protected]?part=1
>

Reply via email to