OSDN Git Service

drm: add a locked version of drm_is_current_master
authorDesmond Cheong Zhi Xi <desmondcheongzx@gmail.com>
Sun, 20 Jun 2021 11:03:26 +0000 (19:03 +0800)
committerDaniel Vetter <daniel.vetter@ffwll.ch>
Mon, 21 Jun 2021 15:42:28 +0000 (17:42 +0200)
commit1815d9c86e3090477fbde066ff314a7e9721ee0f
treeb8b020baa41abd8fe9f046745ed84fbeaeb26984
parente541845ae0858616c52dd97df4bf91568c7a7a1b
drm: add a locked version of drm_is_current_master

While checking the master status of the DRM file in
drm_is_current_master(), the device's master mutex should be
held. Without the mutex, the pointer fpriv->master may be freed
concurrently by another process calling drm_setmaster_ioctl(). This
could lead to use-after-free errors when the pointer is subsequently
dereferenced in drm_lease_owner().

The callers of drm_is_current_master() from drm_auth.c hold the
device's master mutex, but external callers do not. Hence, we implement
drm_is_current_master_locked() to be used within drm_auth.c, and
modify drm_is_current_master() to grab the device's master mutex
before checking the master status.

Reported-by: Daniel Vetter <daniel.vetter@ffwll.ch>
Signed-off-by: Desmond Cheong Zhi Xi <desmondcheongzx@gmail.com>
Reviewed-by: Emil Velikov <emil.l.velikov@gmail.com>
Cc: stable@vger.kernel.org
Signed-off-by: Daniel Vetter <daniel.vetter@ffwll.ch>
Link: https://patchwork.freedesktop.org/patch/msgid/20210620110327.4964-2-desmondcheongzx@gmail.com
drivers/gpu/drm/drm_auth.c