From: sashiko-bot@kernel.org
To: "Krzysztof Wilczyński" <kwilczynski@kernel.org>
Cc: linux-pci@vger.kernel.org
Subject: Re: [PATCH] PCI/sysfs: Add lockdown checks to legacy I/O and memory handlers
Date: Mon, 20 Jul 2026 21:25:22 +0000 [thread overview]
Message-ID: <20260720212523.425EC1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260720211541.1509744-1-kwilczynski@kernel.org>
> Currently, the legacy I/O and memory sysfs handlers do not
> check security_locked_down(LOCKDOWN_PCI_ACCESS), leaving the
> legacy_io and legacy_mem files unprotected when the kernel is
> locked down.
>
> Commit eb627e17727e ("PCI: Lock down BAR access when the
> kernel is locked down") added the check to pci_write_config(),
> pci_mmap_resource(), and pci_write_resource_io() to prevent
> userspace from programming DMA-capable hardware that could be
> used to modify kernel code, but did not cover the legacy
> handlers.
>
> As a result, root can still write arbitrary I/O ports and map
> the legacy I/O and memory spaces while the kernel is locked
> down, which is the same capability the lockdown is meant to
> remove.
>
> Thus, add the same check to pci_write_legacy_io(),
> pci_mmap_legacy_mem(), and pci_mmap_legacy_io().
>
> These generic handlers cover both architectures that
> define HAVE_PCI_LEGACY (such as Alpha and PowerPC).
>
> Fixes: eb627e17727e ("PCI: Lock down BAR access when the kernel is locked down")
> Signed-off-by: Krzysztof Wilczyński <kwilczynski@kernel.org>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260720211541.1509744-1-kwilczynski@kernel.org?part=1
prev parent reply other threads:[~2026-07-20 21:25 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-20 21:15 [PATCH] PCI/sysfs: Add lockdown checks to legacy I/O and memory handlers Krzysztof Wilczyński
2026-07-20 21:25 ` sashiko-bot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260720212523.425EC1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=kwilczynski@kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.