#ifdef CONFIG_PPC_64S_HASH_MMU staticint realloc_context_ids(mm_context_t *ctx)
{ int i, id;
/* *id0(aka.ctx->id)isspecial,wealwaysallocateanewone,evenif *therewasn'toneallocatedpreviously(whichhappensintheexec *casewherectxisnewlyallocated). * *Wehavetobeabitcarefulhere.Wemustkeeptheexistingidsin *thearray,sothatwecantestifthey'renon-zerotodecideifwe *needtoallocateanewone.Howeverincaseoferrorwemustfreethe *idswe'veallocatedbut*not*anyoftheexistingones(orriska *UAF).That'swhywedecrementiatthestartoftheerrorhandling *loop,toskiptheidthatwejusttestedbutcouldn'treallocate.
*/ for (i = 0; i < ARRAY_SIZE(ctx->extended_id); i++) { if (i == 0 || ctx->extended_id[i]) {
id = hash__alloc_context_id(); if (id < 0) goto error;
ctx->extended_id[i] = id;
}
}
/* The caller expects us to return id */ return ctx->id;
error: for (i--; i >= 0; i--) { if (ctx->extended_id[i])
ida_free(&mmu_context_ida, ctx->extended_id[i]);
}
return id;
}
staticint hash__init_new_context(struct mm_struct *mm)
{ int index;
mm->context.hash_context = kmalloc(sizeof(struct hash_mm_context),
GFP_KERNEL); if (!mm->context.hash_context) return -ENOMEM;
/* *Theoldcodewouldre-promoteonfork,wedon'tdothatwhenusing *slicesasitcouldcauseproblempromotingslicesthathavebeen *forceddownto4K. * *Forbook3swehaveMMU_NO_CONTEXTsettobe~0.Hencecheck *explicitlyagainstcontext.id==0.Thisensuresthatweproperly *initializecontextslicedetailsfornewlyallocatedmm's(whichwill *haveid==0)anddon'taltercontextsliceinheritedviafork(which *willhaveid!=0). * *Weshouldnotbecallinginit_new_context()oninit_mm.Hencea *checkagainst0isOK.
*/ if (mm->context.id == 0) {
memset(mm->context.hash_context, 0, sizeof(struct hash_mm_context));
slice_init_new_context_exec(mm);
} else { /* This is fork. Copy hash_context details from current->mm */
memcpy(mm->context.hash_context, current->mm->context.hash_context, sizeof(struct hash_mm_context)); #ifdef CONFIG_PPC_SUBPAGE_PROT /* inherit subpage prot details if we have one. */ if (current->mm->context.hash_context->spt) {
mm->context.hash_context->spt = kmalloc(sizeof(struct subpage_prot_table),
GFP_KERNEL); if (!mm->context.hash_context->spt) {
kfree(mm->context.hash_context); return -ENOMEM;
}
} #endif
}
index = realloc_context_ids(&mm->context); if (index < 0) { #ifdef CONFIG_PPC_SUBPAGE_PROT
kfree(mm->context.hash_context->spt); #endif
kfree(mm->context.hash_context); return index;
}
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.