• Jens Axboe's avatar
    io_uring: don't allow discontig pages for IORING_SETUP_NO_MMAP · 820d070f
    Jens Axboe authored
    io_sqes_map() is used rather than io_mem_alloc(), if the application
    passes in memory for mapping rather than have the kernel allocate it and
    then mmap(2) the ranges. This then calls __io_uaddr_map() to perform the
    page mapping and pinning, which checks if we end up with the same pages,
    if more than one page is mapped. But this check is incorrect and only
    checks if the first and last pages are the same, where it really should
    be checking if the mapped pages are contigous. This allows mapping a
    single normal page, or a huge page range.
    
    Down the line we can add support for remapping pages to be virtually
    contigous, which is really all that io_uring cares about.
    
    Cc: stable@vger.kernel.org
    Fixes: 03d89a2d ("io_uring: support for user allocated memory for rings/sqes")
    Reported-by: default avatarJann Horn <jannh@google.com>
    Signed-off-by: default avatarJens Axboe <axboe@kernel.dk>
    820d070f
io_uring.c 123 KB