diff options
author | Jiang Liu <jiang.liu@linux.intel.com> | 2014-04-09 10:20:39 +0800 |
---|---|---|
committer | David Woodhouse <David.Woodhouse@intel.com> | 2014-04-13 13:07:56 +0100 |
commit | adeb25905c644350baf1f446bcd856517e58060e (patch) | |
tree | 1ce3d39a0761c3cf12c562128c605af7bb3cbb8f | |
parent | 7713ec066ae8adc49dd8daa02a73e6b60af6ee5f (diff) | |
download | op-kernel-dev-adeb25905c644350baf1f446bcd856517e58060e.zip op-kernel-dev-adeb25905c644350baf1f446bcd856517e58060e.tar.gz |
iommu/vt-d: fix memory leakage caused by commit ea8ea46
Commit ea8ea46 "iommu/vt-d: Clean up and fix page table clear/free
behaviour" introduces possible leakage of DMA page tables due to:
for (pte = page_address(pg); !first_pte_in_page(pte); pte++) {
if (dma_pte_present(pte) && !dma_pte_superpage(pte))
freelist = dma_pte_list_pagetables(domain, level - 1,
pte, freelist);
}
For the first pte in a page, first_pte_in_page(pte) will always be true,
thus dma_pte_list_pagetables() will never be called and leak DMA page
tables if level is bigger than 1.
Signed-off-by: Jiang Liu <jiang.liu@linux.intel.com>
Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
-rw-r--r-- | drivers/iommu/intel-iommu.c | 6 |
1 files changed, 4 insertions, 2 deletions
diff --git a/drivers/iommu/intel-iommu.c b/drivers/iommu/intel-iommu.c index 69fa7da..13dc231 100644 --- a/drivers/iommu/intel-iommu.c +++ b/drivers/iommu/intel-iommu.c @@ -1009,11 +1009,13 @@ static struct page *dma_pte_list_pagetables(struct dmar_domain *domain, if (level == 1) return freelist; - for (pte = page_address(pg); !first_pte_in_page(pte); pte++) { + pte = page_address(pg); + do { if (dma_pte_present(pte) && !dma_pte_superpage(pte)) freelist = dma_pte_list_pagetables(domain, level - 1, pte, freelist); - } + pte++; + } while (!first_pte_in_page(pte)); return freelist; } |