| From 6b991ad8dc3abfe5720fc2e9ee96be63ae43e362 Mon Sep 17 00:00:00 2001 |
| From: Alessio Belle <alessio.belle@imgtec.com> |
| Date: Mon, 8 Dec 2025 09:11:00 +0000 |
| Subject: drm/imagination: Disallow exporting of PM/FW protected objects |
| |
| From: Alessio Belle <alessio.belle@imgtec.com> |
| |
| commit 6b991ad8dc3abfe5720fc2e9ee96be63ae43e362 upstream. |
| |
| These objects are meant to be used by the GPU firmware or by the PM unit |
| within the GPU, in which case they may contain physical addresses. |
| |
| This adds a layer of protection against exposing potentially exploitable |
| information outside of the driver. |
| |
| Fixes: ff5f643de0bf ("drm/imagination: Add GEM and VM related code") |
| Signed-off-by: Alessio Belle <alessio.belle@imgtec.com> |
| Cc: stable@vger.kernel.org |
| Link: https://patch.msgid.link/20251208-no-export-pm-fw-obj-v1-1-83ab12c61693@imgtec.com |
| Signed-off-by: Matt Coster <matt.coster@imgtec.com> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| --- |
| drivers/gpu/drm/imagination/pvr_gem.c | 11 +++++++++++ |
| 1 file changed, 11 insertions(+) |
| |
| --- a/drivers/gpu/drm/imagination/pvr_gem.c |
| +++ b/drivers/gpu/drm/imagination/pvr_gem.c |
| @@ -27,6 +27,16 @@ static void pvr_gem_object_free(struct d |
| drm_gem_shmem_object_free(obj); |
| } |
| |
| +static struct dma_buf *pvr_gem_export(struct drm_gem_object *obj, int flags) |
| +{ |
| + struct pvr_gem_object *pvr_obj = gem_to_pvr_gem(obj); |
| + |
| + if (pvr_obj->flags & DRM_PVR_BO_PM_FW_PROTECT) |
| + return ERR_PTR(-EPERM); |
| + |
| + return drm_gem_prime_export(obj, flags); |
| +} |
| + |
| static int pvr_gem_mmap(struct drm_gem_object *gem_obj, struct vm_area_struct *vma) |
| { |
| struct pvr_gem_object *pvr_obj = gem_to_pvr_gem(gem_obj); |
| @@ -41,6 +51,7 @@ static int pvr_gem_mmap(struct drm_gem_o |
| static const struct drm_gem_object_funcs pvr_gem_object_funcs = { |
| .free = pvr_gem_object_free, |
| .print_info = drm_gem_shmem_object_print_info, |
| + .export = pvr_gem_export, |
| .pin = drm_gem_shmem_object_pin, |
| .unpin = drm_gem_shmem_object_unpin, |
| .get_sg_table = drm_gem_shmem_object_get_sg_table, |