OSDN Git Service

drm: protect drm_master pointers in drm_lease.c
authorDesmond Cheong Zhi Xi <desmondcheongzx@gmail.com>
Mon, 12 Jul 2021 04:35:08 +0000 (12:35 +0800)
committerDaniel Vetter <daniel.vetter@ffwll.ch>
Tue, 20 Jul 2021 18:22:19 +0000 (20:22 +0200)
commit56f0729a510f92151682ff6c89f69724d5595d6e
tree79227994f4b4c0df44486cdaa3e6edfec9cc02f8
parent0b0860a3cf5eccf183760b1177a1dcdb821b0b66
drm: protect drm_master pointers in drm_lease.c

drm_file->master pointers should be protected by
drm_device.master_mutex or drm_file.master_lookup_lock when being
dereferenced.

However, in drm_lease.c, there are multiple instances where
drm_file->master is accessed and dereferenced while neither lock is
held. This makes drm_lease.c vulnerable to use-after-free bugs.

We address this issue in 2 ways:

1. Add a new drm_file_get_master() function that calls drm_master_get
on drm_file->master while holding on to
drm_file.master_lookup_lock. Since drm_master_get increments the
reference count of master, this prevents master from being freed until
we unreference it with drm_master_put.

2. In each case where drm_file->master is directly accessed and
eventually dereferenced in drm_lease.c, we wrap the access in a call
to the new drm_file_get_master function, then unreference the master
pointer once we are done using it.

Reported-by: Daniel Vetter <daniel.vetter@ffwll.ch>
Signed-off-by: Desmond Cheong Zhi Xi <desmondcheongzx@gmail.com>
Reviewed-by: Emil Velikov <emil.l.velikov@gmail.com>
Signed-off-by: Daniel Vetter <daniel.vetter@ffwll.ch>
Link: https://patchwork.freedesktop.org/patch/msgid/20210712043508.11584-6-desmondcheongzx@gmail.com
drivers/gpu/drm/drm_auth.c
drivers/gpu/drm/drm_lease.c
include/drm/drm_auth.h
include/drm/drm_file.h