On Wed, Jun 24, 2020 at 08:41:21AM +0000, Suravee Suthikulpanit wrote:
Currently, an integer is used to specify the size in unmap_sg(). With 2GB worth of pages (512k 4k pages), it requires 31 bits (i.e. (1 << 19) << 12), which overflows the integer, and ends up unmapping more pages than intended. Subsequently, this results in IO_PAGE_FAULT.
Uses size_t instead of int to pass parameter to __unmap_single().
Please note that this patch is only for the stable-kernels tree because the commit be62dbf554c5 ("iommu/amd: Convert AMD iommu driver to the dma-iommu api"), which removes the function unmap_sg() was introduced in v5.5. This patch is not applicable in subsequent kernel versions.
Cc: stable@vger.kernel.org Cc: iommu@lists.linux-foundation.org Reported-by: Robert Lippert rlippert@google.com Signed-off-by: Suravee Suthikulpanit suravee.suthikulpanit@amd.com
Acked-by: Joerg Roedel jroedel@suse.de