vhost: vringh: Modify the return value check

[ Upstream commit 82a8d0fda55b35361ee7f35b54fa2b66d7847d2b ]

The return value of copy_from_iter and copy_to_iter can't be negative,
check whether the copied lengths are equal.

Fixes: 309bba39c9 ("vringh: iterate on iotlb_translate to handle large translations")
Cc: "Stefano Garzarella" <sgarzare@redhat.com>
Signed-off-by: zhang jiao <zhangjiao2@cmss.chinamobile.com>
Message-Id: <20250910091739.2999-1-zhangjiao2@cmss.chinamobile.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
zhang jiao 2025-09-10 17:17:38 +08:00 committed by Greg Kroah-Hartman
parent aa57822ade
commit 78dc736266

View File

@ -1191,6 +1191,7 @@ static inline int copy_from_iotlb(const struct vringh *vrh, void *dst,
struct iov_iter iter; struct iov_iter iter;
u64 translated; u64 translated;
int ret; int ret;
size_t size;
ret = iotlb_translate(vrh, (u64)(uintptr_t)src, ret = iotlb_translate(vrh, (u64)(uintptr_t)src,
len - total_translated, &translated, len - total_translated, &translated,
@ -1208,9 +1209,9 @@ static inline int copy_from_iotlb(const struct vringh *vrh, void *dst,
translated); translated);
} }
ret = copy_from_iter(dst, translated, &iter); size = copy_from_iter(dst, translated, &iter);
if (ret < 0) if (size != translated)
return ret; return -EFAULT;
src += translated; src += translated;
dst += translated; dst += translated;