Re: [PATCH v2] staging: zsmalloc: Ensure handle is never 0 on success

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Thu, Nov 7, 2013 at 5:58 PM, Olav Haugan <ohaugan@xxxxxxxxxxxxxx> wrote:
> zsmalloc encodes a handle using the pfn and an object
> index. On hardware platforms with physical memory starting
> at 0x0 the pfn can be 0. This causes the encoded handle to be
> 0 and is incorrectly interpreted as an allocation failure.
>
> To prevent this false error we ensure that the encoded handle
> will not be 0 when allocation succeeds.
>
> Signed-off-by: Olav Haugan <ohaugan@xxxxxxxxxxxxxx>
> ---
>  drivers/staging/zsmalloc/zsmalloc-main.c | 17 +++++++++++++----
>  1 file changed, 13 insertions(+), 4 deletions(-)
>
> diff --git a/drivers/staging/zsmalloc/zsmalloc-main.c b/drivers/staging/zsmalloc/zsmalloc-main.c
> index 1a67537..3b950e5 100644
> --- a/drivers/staging/zsmalloc/zsmalloc-main.c
> +++ b/drivers/staging/zsmalloc/zsmalloc-main.c
> @@ -430,7 +430,12 @@ static struct page *get_next_page(struct page *page)
>         return next;
>  }
>
> -/* Encode <page, obj_idx> as a single handle value */
> +/*
> + * Encode <page, obj_idx> as a single handle value.
> + * On hardware platforms with physical memory starting at 0x0 the pfn
> + * could be 0 so we ensure that the handle will never be 0 by adjusting the
> + * encoded obj_idx value before encoding.
> + */
>  static void *obj_location_to_handle(struct page *page, unsigned long obj_idx)
>  {
>         unsigned long handle;
> @@ -441,17 +446,21 @@ static void *obj_location_to_handle(struct page *page, unsigned long obj_idx)
>         }
>
>         handle = page_to_pfn(page) << OBJ_INDEX_BITS;
> -       handle |= (obj_idx & OBJ_INDEX_MASK);
> +       handle |= ((obj_idx + 1) & OBJ_INDEX_MASK);
>
>         return (void *)handle;
>  }
>
> -/* Decode <page, obj_idx> pair from the given object handle */
> +/*
> + * Decode <page, obj_idx> pair from the given object handle. We adjust the
> + * decoded obj_idx back to its original value since it was adjusted in
> + * obj_location_to_handle().
> + */
>  static void obj_handle_to_location(unsigned long handle, struct page **page,
>                                 unsigned long *obj_idx)
>  {
>         *page = pfn_to_page(handle >> OBJ_INDEX_BITS);
> -       *obj_idx = handle & OBJ_INDEX_MASK;
> +       *obj_idx = (handle & OBJ_INDEX_MASK) - 1;
>  }
>
>  static unsigned long obj_idx_to_offset(struct page *page,

Acked-by: Nitin Gupta <ngupta@xxxxxxxxxx>

Thanks,
Nitin
--
To unsubscribe from this list: send the line "unsubscribe linux-arm-msm" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html




[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [Linux for Sparc]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]

  Powered by Linux