[PATCH v2 2/3] accel/rocket: Use an unsigned index to copy the job's tasks
From: Sidong Yang
Date: Sun Oct 04 2026 - 12:48:18 EST
task_count is a u32 from userspace, but rocket_copy_tasks() walks it
with an int index, which would overflow for counts above INT_MAX. That
is not reachable today, since kvmalloc_objs() rejects any count above
INT_MAX / 16, but use an unsigned index to match the type.
Reported-by: Sashiko <sashiko-bot@xxxxxxxxxx>
Closes: https://lore.kernel.org/all/20260711063638.61B411F000E9@xxxxxxxxxxxxxxx/
Signed-off-by: Sidong Yang <sidong.yang@xxxxxxxxxx>
---
drivers/accel/rocket/rocket_job.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/accel/rocket/rocket_job.c b/drivers/accel/rocket/rocket_job.c
index 319365ad7976..428de5a7cb03 100644
--- a/drivers/accel/rocket/rocket_job.c
+++ b/drivers/accel/rocket/rocket_job.c
@@ -78,7 +78,7 @@ rocket_copy_tasks(struct drm_device *dev,
return -ENOMEM;
}
- for (int i = 0; i < rjob->task_count; i++) {
+ for (unsigned int i = 0; i < rjob->task_count; i++) {
struct drm_rocket_task task = {0};
if (copy_from_user(&task,
--
2.53.0