PCI/proc: Warn on writes to kernel-exclusive config space regions

Currently, a driver can claim a region of a device's config space as
exclusive using pci_request_config_region_exclusive(), after which a write
to that region originating from user space is expected to emit a warning
and taint the kernel.  The check is advisory only, as the write itself is
still allowed to proceed.

Since commit 278294798a ("PCI: Allow drivers to request exclusive config
regions"), the sysfs config space attribute performs this check in
pci_write_config(), but the procfs interface was never updated.  A write
performed through /proc/bus/pci/BB/DD.F therefore bypasses the detection
entirely, even though both interfaces offer the same level of access.

Add the same resource_is_exclusive() check to proc_bus_pci_write().

Signed-off-by: Krzysztof Wilczyński <kwilczynski@kernel.org>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260729075413.1215821-1-kwilczynski@kernel.org
This commit is contained in:
Krzysztof Wilczyński 2026-07-29 07:54:13 +00:00 committed by Bjorn Helgaas
parent 4ff664a81d
commit 3359e044d5

View File

@ -14,6 +14,8 @@
#include <linux/capability.h>
#include <linux/uaccess.h>
#include <linux/security.h>
#include <linux/panic.h>
#include <linux/sched.h>
#include <asm/byteorder.h>
#include "pci.h"
@ -128,6 +130,12 @@ static ssize_t proc_bus_pci_write(struct file *file, const char __user *buf,
if (!nbytes)
return 0;
if (resource_is_exclusive(&dev->driver_exclusive_resource, pos, nbytes)) {
pci_warn_once(dev, "%s: Unexpected write to kernel-exclusive config offset %x",
current->comm, pos);
add_taint(TAINT_USER, LOCKDEP_STILL_OK);
}
if (pos >= size)
return 0;
if (nbytes >= size)