summaryrefslogtreecommitdiff
path: root/io_uring
diff options
context:
space:
mode:
authorJens Axboe <axboe@kernel.dk>2026-05-04 05:42:51 -0600
committerJens Axboe <axboe@kernel.dk>2026-05-14 08:12:29 -0600
commitb4e41050b212ca33c82fb0598a7b323d5b18f1bb (patch)
tree024f03fec13856f8ba140535d863d00a1a118d9d /io_uring
parentca76b56a2a2acf9875e5cad68612085f25b463bb (diff)
downloadlinux-next-b4e41050b212ca33c82fb0598a7b323d5b18f1bb.tar.gz
linux-next-b4e41050b212ca33c82fb0598a7b323d5b18f1bb.zip
io_uring/rsrc: raise registered buffer 1GB limit
There's no real reason to have a limit, as the memory is accounted by the lockmem limits anyway, if any exist. io_pin_pages() will still restrict the maximum allowed limit per buffer, which is INT_MAX number of pages. Cap it a bit lower than that, at 1TB for a 64-bit system. Surely that should be enough for everyone. For now. Signed-off-by: Jens Axboe <axboe@kernel.dk>
Diffstat (limited to 'io_uring')
-rw-r--r--io_uring/rsrc.c9
1 files changed, 7 insertions, 2 deletions
diff --git a/io_uring/rsrc.c b/io_uring/rsrc.c
index be7c5bf4e161..7f553d115e36 100644
--- a/io_uring/rsrc.c
+++ b/io_uring/rsrc.c
@@ -133,9 +133,14 @@ int io_validate_user_buf_range(u64 uaddr, u64 ulen)
unsigned long tmp, base = (unsigned long)uaddr;
unsigned long acct_len = (unsigned long)PAGE_ALIGN(ulen);
- /* arbitrary limit, but we need something */
- if (ulen > SZ_1G || !ulen)
+ if (!ulen)
return -EFAULT;
+ /* 32-bit sanity checking */
+ if (ulen > ULONG_MAX || uaddr > ULONG_MAX)
+ return -EFAULT;
+ /* cap to 1TB for 64-bit */
+ if (ulen > SZ_1T)
+ return -EINVAL;
if (check_add_overflow(base, acct_len, &tmp))
return -EOVERFLOW;
return 0;