提交 cfe919b5 编写于 作者: C Chuansheng Liu 提交者: Felipe Balbi

usb: gadget: return the right length in ffs_epfile_io()

When the request length is aligned to maxpacketsize, sometimes
the return length ret > the user space requested len.

At that time, we will use min_t(size_t, ret, len) to limit the
size in case of user data buffer overflow.

But we need return the min_t(size_t, ret, len) to tell the user
space rightly also.

[ balbi@ti.com: also fix comment's indentation ]
Acked-by: NMichal Nazarewicz <mina86@mina86.com>
Reviewed-by: NDavid Cohen <david.a.cohen@linux.intel.com>
Signed-off-by: NChuansheng Liu <chuansheng.liu@intel.com>
Signed-off-by: NFelipe Balbi <balbi@ti.com>
上级 8bebbe8d
......@@ -838,19 +838,21 @@ static ssize_t ffs_epfile_io(struct file *file, struct ffs_io_data *io_data)
ret = -EINTR;
usb_ep_dequeue(ep->ep, req);
} else {
/*
* XXX We may end up silently droping data here.
* Since data_len (i.e. req->length) may be bigger
* than len (after being rounded up to maxpacketsize),
* we may end up with more data then user space has
* space for.
*/
ret = ep->status;
if (io_data->read && ret > 0 &&
unlikely(copy_to_user(io_data->buf, data,
min_t(size_t, ret,
io_data->len))))
ret = -EFAULT;
/*
* XXX We may end up silently droping data
* here. Since data_len (i.e. req->length) may
* be bigger than len (after being rounded up
* to maxpacketsize), we may end up with more
* data then user space has space for.
*/
ret = ep->status;
if (io_data->read && ret > 0) {
ret = min_t(size_t, ret, io_data->len);
if (unlikely(copy_to_user(io_data->buf,
data, ret)))
ret = -EFAULT;
}
}
kfree(data);
}
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册