All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] PCI/proc: Warn on writes to kernel-exclusive config space regions
@ 2026-07-29  7:54 Krzysztof Wilczyński
  2026-07-29  8:13 ` sashiko-bot
  2026-08-01  4:06 ` Krzysztof Wilczyński
  0 siblings, 2 replies; 3+ messages in thread
From: Krzysztof Wilczyński @ 2026-07-29  7:54 UTC (permalink / raw)
  To: Bjorn Helgaas
  Cc: Bjorn Helgaas, Manivannan Sadhasivam, Lorenzo Pieralisi,
	Ira Weiny, Kees Cook, linux-pci

Currently, a driver can claim a region of a device's config space as
exclusive using pci_request_config_region_exclusive(), after which a
write to that region originating from user space is expected to emit a
warning and taint the kernel.  The check is advisory only, as the write
itself is still allowed to proceed.

Since commit 278294798ac9 ("PCI: Allow drivers to request exclusive
config regions"), the sysfs config space attribute performs this check
in pci_write_config(), but the procfs interface was never updated.  A
write performed through /proc/bus/pci/BB/DD.F therefore bypasses the
detection entirely, even though both interfaces offer the same level
of access.

Thus, add the same resource_is_exclusive() check to proc_bus_pci_write().

Signed-off-by: Krzysztof Wilczyński <kwilczynski@kernel.org>
---
 drivers/pci/proc.c | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/drivers/pci/proc.c b/drivers/pci/proc.c
index 71ad289fcb8e..12200979d3a8 100644
--- a/drivers/pci/proc.c
+++ b/drivers/pci/proc.c
@@ -14,6 +14,8 @@
 #include <linux/capability.h>
 #include <linux/uaccess.h>
 #include <linux/security.h>
+#include <linux/panic.h>
+#include <linux/sched.h>
 #include <asm/byteorder.h>
 #include "pci.h"
 
@@ -122,6 +124,12 @@ static ssize_t proc_bus_pci_write(struct file *file, const char __user *buf,
 	if (ret)
 		return ret;
 
+	if (resource_is_exclusive(&dev->driver_exclusive_resource, pos, nbytes)) {
+		pci_warn_once(dev, "%s: Unexpected write to kernel-exclusive config offset %x",
+			      current->comm, pos);
+		add_taint(TAINT_USER, LOCKDEP_STILL_OK);
+	}
+
 	if (pos >= size)
 		return 0;
 	if (nbytes >= size)
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-08-01  4:06 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-29  7:54 [PATCH] PCI/proc: Warn on writes to kernel-exclusive config space regions Krzysztof Wilczyński
2026-07-29  8:13 ` sashiko-bot
2026-08-01  4:06 ` Krzysztof Wilczyński

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.