mirror of
https://github.com/torvalds/linux.git
synced 2026-09-23 13:14:02 +02:00
PCI/proc: Warn on writes to kernel-exclusive config space regions
Currently, a driver can claim a region of a device's config space as
exclusive using pci_request_config_region_exclusive(), after which a write
to that region originating from user space is expected to emit a warning
and taint the kernel. The check is advisory only, as the write itself is
still allowed to proceed.
Since commit 278294798a ("PCI: Allow drivers to request exclusive config
regions"), the sysfs config space attribute performs this check in
pci_write_config(), but the procfs interface was never updated. A write
performed through /proc/bus/pci/BB/DD.F therefore bypasses the detection
entirely, even though both interfaces offer the same level of access.
Add the same resource_is_exclusive() check to proc_bus_pci_write().
Signed-off-by: Krzysztof Wilczyński <kwilczynski@kernel.org>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260729075413.1215821-1-kwilczynski@kernel.org
This commit is contained in:
parent
4ff664a81d
commit
3359e044d5
|
|
@ -14,6 +14,8 @@
|
|||
#include <linux/capability.h>
|
||||
#include <linux/uaccess.h>
|
||||
#include <linux/security.h>
|
||||
#include <linux/panic.h>
|
||||
#include <linux/sched.h>
|
||||
#include <asm/byteorder.h>
|
||||
#include "pci.h"
|
||||
|
||||
|
|
@ -128,6 +130,12 @@ static ssize_t proc_bus_pci_write(struct file *file, const char __user *buf,
|
|||
if (!nbytes)
|
||||
return 0;
|
||||
|
||||
if (resource_is_exclusive(&dev->driver_exclusive_resource, pos, nbytes)) {
|
||||
pci_warn_once(dev, "%s: Unexpected write to kernel-exclusive config offset %x",
|
||||
current->comm, pos);
|
||||
add_taint(TAINT_USER, LOCKDEP_STILL_OK);
|
||||
}
|
||||
|
||||
if (pos >= size)
|
||||
return 0;
|
||||
if (nbytes >= size)
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user