Re: [PATCH v3 2/2] misc: fastrpc: don't publish fd before copy_to_user() succeeds
From: T.J. Mercier
Date: Wed Jul 15 2026 - 16:44:57 EST
On Tue, Jul 14, 2026 at 4:47 AM Baineng Shou <shoubaineng@xxxxxxxxx> wrote:
>
> fastrpc_ioctl_alloc_dmabuf() calls dma_buf_fd() which installs the fd
> into the caller's fd table before copy_to_user() copies the fd number
> back to userspace. If copy_to_user() fails, the fd is already visible
> to other threads in the same process but the ioctl returns -EFAULT.
> The existing comment in the code even acknowledges the problem:
>
> "The usercopy failed, but we can't do much about it, as dma_buf_fd()
> already called fd_install()..."
>
> Now that dma_buf_fd_install() is available (introduced to fix the same
> issue in dma-heap), apply the same pattern here: reserve the fd with
> get_unused_fd_flags(), attempt copy_to_user(), and only on success call
> dma_buf_fd_install() to publish it atomically with the tracepoint. On
> copy_to_user() failure, put_unused_fd() and dma_buf_put() cleanly
> unwind without any user-visible side effects.
>
> Fixes: 6cffd79504ce ("misc: fastrpc: Add support for dmabuf exporter")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Baineng Shou <shoubaineng@xxxxxxxxx>
Reviewed-by: T.J. Mercier <tjmercier@xxxxxxxxxx>