From: sashiko-bot@kernel.org
To: "Honglei Huang" <honghuan@amd.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v8 3/4] drm/virtio: implement userptr support for zero-copy memory access
Date: Fri, 18 Sep 2026 06:16:14 +0000 [thread overview]
Message-ID: <20260918061614.EC2581F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260918055917.2133574-4-honghuan@amd.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] drm/virtio: privilege escalation via HINT_USERPTR_RDONLY
--
commit 20ea6ca5af258a43b1dc12cab535283738613d35
Author: Honglei Huang <honghuan@amd.com>
Subject: drm/virtio: implement userptr support for zero-copy memory access
This commit adds userptr blob object support to virtio-gpu, allowing the
guest kernel to pin existing userspace mappings and use them as CREATE_BLOB
backing entries. It handles page pinning, DMA mapping if required, and
syncing the scatterlist for the device.
> diff --git a/drivers/gpu/drm/virtio/virtgpu_userptr.c b/drivers/gpu/drm/virtio/virtgpu_userptr.c
> new file mode 100644
> --- /dev/null
> +++ b/drivers/gpu/drm/virtio/virtgpu_userptr.c
[ ... ]
> +static int
> +virtio_gpu_userptr_get_pages(struct virtio_gpu_object_userptr *userptr)
> +{
> + unsigned int flag = FOLL_LONGTERM;
> + unsigned int num_pages, pinned = 0;
> + int ret = 0;
[ ... ]
> + if (!(userptr->flags & DRM_VIRTGPU_BLOB_FLAG_HINT_USERPTR_RDONLY))
> + flag |= FOLL_WRITE;
> +
> + do {
> + num_pages = userptr->npages - pinned;
> +
> + ret = pin_user_pages_fast(userptr->start + pinned * PAGE_SIZE,
> + num_pages, flag,
> + userptr->pages + pinned);
[Severity: Critical]
Does this allow unprivileged userspace to bypass guest page protections?
If a malicious guest userspace maps read-only memory (such as executable
pages like libc.so) and passes it with
DRM_VIRTGPU_BLOB_FLAG_HINT_USERPTR_RDONLY, the code omits FOLL_WRITE when
calling pin_user_pages_fast.
The pinned physical addresses are then sent to the host. If the guest has no
vIOMMU (where virtio_gpu_use_dma_api() is false), these addresses are passed
directly to the host without DMA_TO_DEVICE IOMMU protection. The userspace
process could then submit a command stream via VIRTGPU_EXECBUFFER instructing
the host GPU to write to this resource, causing the host hypervisor to write
directly into the guest's read-only physical memory.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260918055917.2133574-1-honghuan@amd.com?part=3
next prev parent reply other threads:[~2026-09-18 6:16 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-18 5:59 [PATCH v8 0/4] virtio-gpu: Add userptr support for compute workloads Honglei Huang
2026-09-18 5:59 ` [PATCH v8 1/4] drm/virtio-gpu: Add VIRTIO_GPU_CAPSET_ROCM capability Honglei Huang
2026-09-18 6:07 ` sashiko-bot
2026-09-18 5:59 ` [PATCH v8 2/4] drm/virtgpu api: add blob userptr resource Honglei Huang
2026-09-18 5:59 ` [PATCH v8 3/4] drm/virtio: implement userptr support for zero-copy memory access Honglei Huang
2026-09-18 6:16 ` sashiko-bot [this message]
2026-09-18 5:59 ` [PATCH v8 4/4] drm/virtio: wire blob ioctl creation to userptr objects Honglei Huang
2026-09-18 6:12 ` sashiko-bot
-- strict thread matches above, loose matches on Subject: below --
2026-09-18 6:56 [PATCH v8 0/4] virtio-gpu: Add userptr support for compute workloads Honglei Huang
2026-09-18 6:56 ` [PATCH v8 3/4] drm/virtio: implement userptr support for zero-copy memory access Honglei Huang
2026-09-18 7:55 [PATCH v8 0/4] virtio-gpu: Add userptr support for compute workloads Honglei Huang
2026-09-18 7:55 ` [PATCH v8 3/4] drm/virtio: implement userptr support for zero-copy memory access Honglei Huang
2026-09-18 8:17 ` sashiko-bot
2026-09-18 8:23 [PATCH v8 0/4] virtio-gpu: Add userptr support for compute workloads Honglei Huang
2026-09-18 8:23 ` [PATCH v8 3/4] drm/virtio: implement userptr support for zero-copy memory access Honglei Huang
2026-09-18 9:59 [PATCH v8 0/4] virtio-gpu: Add userptr support for compute workloads Honglei Huang
2026-09-18 9:59 ` [PATCH v8 3/4] drm/virtio: implement userptr support for zero-copy memory access Honglei Huang
2026-09-18 10:21 ` sashiko-bot
2026-09-19 8:59 ` Akihiko Odaki
2026-09-24 9:25 ` Huang, Honglei
2026-09-26 10:17 ` Akihiko Odaki
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260918061614.EC2581F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=honghuan@amd.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.