[PATCH] drm: Don't overwrite user ioctl arg unless requested

2016-07-14 Thread Daniel Vetter
On Thu, Jul 14, 2016 at 09:46:24AM +0200, Christian König wrote: > Am 12.07.2016 um 16:59 schrieb Chris Wilson: > > Currently, we completely ignore the user when it comes to the in/out > > direction of the ioctl argument, as we simply cannot trust userspace. > > (For example, they might request a

[PATCH] drm: Don't overwrite user ioctl arg unless requested

2016-07-14 Thread Christian König
Am 12.07.2016 um 16:59 schrieb Chris Wilson: > Currently, we completely ignore the user when it comes to the in/out > direction of the ioctl argument, as we simply cannot trust userspace. > (For example, they might request a copy of the modified ioctl argument > when the driver is not expecting suc

[PATCH] drm: Don't overwrite user ioctl arg unless requested

2016-07-12 Thread Chris Wilson
Currently, we completely ignore the user when it comes to the in/out direction of the ioctl argument, as we simply cannot trust userspace. (For example, they might request a copy of the modified ioctl argument when the driver is not expecting such and so leak kernel stack.) However, blindly copying