On Sat, Aug 1, 2026 at 9:19 PM Pavel Begunkov <[email protected]> wrote: > @@ -841,7 +857,7 @@ static unsigned long iov_iter_alignment_bvec(const struct > iov_iter *i) > > unsigned long iov_iter_alignment(const struct iov_iter *i) > { > - if (likely(iter_is_ubuf(i))) { > + if (likely(iter_is_ubuf(i)) || iov_iter_is_dmabuf_map(i)) { > size_t size = i->count; > if (size) > return ((unsigned long)i->ubuf + i->iov_offset) | > size;
dmabuf_map shares the same union slot as ubuf, so this reads the map pointer as a user address. gap_alignment() below already returns 0 correctly for dmabuf - this should too. Checked the rest of this patch (advance/revert/restore) - none of them dereference the union pointer for dmabuf, so it's isolated to this one spot. Doesn't affect the current series, nothing reaches this with a dmabuf iter yet. > @@ -872,7 +888,7 @@ unsigned long iov_iter_gap_alignment(const struct > iov_iter *i) > size_t size = i->count; > unsigned k; > > - if (iter_is_ubuf(i)) > + if (iter_is_ubuf(i) || iov_iter_is_dmabuf_map(i)) > return 0;

