diff options
| author | Jens Axboe <axboe@kernel.dk> | 2026-05-04 05:42:51 -0600 |
|---|---|---|
| committer | Jens Axboe <axboe@kernel.dk> | 2026-05-14 08:12:29 -0600 |
| commit | b4e41050b212ca33c82fb0598a7b323d5b18f1bb (patch) | |
| tree | 024f03fec13856f8ba140535d863d00a1a118d9d /io_uring | |
| parent | ca76b56a2a2acf9875e5cad68612085f25b463bb (diff) | |
| download | linux-next-b4e41050b212ca33c82fb0598a7b323d5b18f1bb.tar.gz linux-next-b4e41050b212ca33c82fb0598a7b323d5b18f1bb.zip | |
io_uring/rsrc: raise registered buffer 1GB limit
There's no real reason to have a limit, as the memory is accounted by
the lockmem limits anyway, if any exist. io_pin_pages() will still
restrict the maximum allowed limit per buffer, which is INT_MAX
number of pages. Cap it a bit lower than that, at 1TB for a 64-bit
system. Surely that should be enough for everyone. For now.
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Diffstat (limited to 'io_uring')
| -rw-r--r-- | io_uring/rsrc.c | 9 |
1 files changed, 7 insertions, 2 deletions
diff --git a/io_uring/rsrc.c b/io_uring/rsrc.c index be7c5bf4e161..7f553d115e36 100644 --- a/io_uring/rsrc.c +++ b/io_uring/rsrc.c @@ -133,9 +133,14 @@ int io_validate_user_buf_range(u64 uaddr, u64 ulen) unsigned long tmp, base = (unsigned long)uaddr; unsigned long acct_len = (unsigned long)PAGE_ALIGN(ulen); - /* arbitrary limit, but we need something */ - if (ulen > SZ_1G || !ulen) + if (!ulen) return -EFAULT; + /* 32-bit sanity checking */ + if (ulen > ULONG_MAX || uaddr > ULONG_MAX) + return -EFAULT; + /* cap to 1TB for 64-bit */ + if (ulen > SZ_1T) + return -EINVAL; if (check_add_overflow(base, acct_len, &tmp)) return -EOVERFLOW; return 0; |
