From: sashiko-bot@kernel.org
To: "Honglei Huang" <honghuan@amd.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v8 4/4] drm/virtio: wire blob ioctl creation to userptr objects
Date: Fri, 18 Sep 2026 07:07:21 +0000 [thread overview]
Message-ID: <20260918070722.71B7E1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260918065653.2170828-5-honghuan@amd.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] drm/virtio: privilege escalation via unnegotiated VIRTGPU_BLOB_FLAG_USE_READONLY
--
commit b371f8bf32b2c925d61457787ca19851334b0963
Author: Honglei Huang <honghuan@amd.com>
drm/virtio: wire blob ioctl creation to userptr objects
This commit integrates userptr into the blob resource creation ioctl.
It selects virtio_gpu_userptr_create for non-zero userptrs and
accepts the VIRTGPU_BLOB_FLAG_USE_READONLY flag.
> diff --git a/drivers/gpu/drm/virtio/virtgpu_ioctl.c b/drivers/gpu/drm/virtio/virtgpu_ioctl.c
> index 3d8e4ccdb7c1f..d42ca3898d4ed 100644
> --- a/drivers/gpu/drm/virtio/virtgpu_ioctl.c
> +++ b/drivers/gpu/drm/virtio/virtgpu_ioctl.c
> @@ -36,7 +36,10 @@
>
> #define VIRTGPU_BLOB_FLAG_USE_MASK (VIRTGPU_BLOB_FLAG_USE_MAPPABLE | \
> VIRTGPU_BLOB_FLAG_USE_SHAREABLE | \
> - VIRTGPU_BLOB_FLAG_USE_CROSS_DEVICE)
> + VIRTGPU_BLOB_FLAG_USE_CROSS_DEVICE | \
> + VIRTGPU_BLOB_FLAG_USE_READONLY)
> +
> +#define VIRTGPU_BLOB_HINT_MASK DRM_VIRTGPU_BLOB_FLAG_HINT_DEFER_MAPPING
[ ... ]
> @@ -453,11 +459,18 @@ static int verify_blob(struct virtio_gpu_device *vgdev,
> if (rc_blob->blob_flags & ~VIRTGPU_BLOB_FLAG_USE_MASK)
> return -EINVAL;
[Severity: Critical]
Does verify_blob() unconditionally allow VIRTGPU_BLOB_FLAG_USE_READONLY
without verifying if the host emulator actually supports enforcing it?
Other flags, such as VIRTGPU_BLOB_FLAG_USE_CROSS_DEVICE, have explicit host
capability checks (such as vgdev->has_resource_assign_uuid) further down in
this function.
If a guest userspace calls DRM_IOCTL_VIRTGPU_RESOURCE_CREATE_BLOB with
VIRTGPU_BLOB_FLAG_USE_READONLY set and a user pointer to read-only memory,
the guest pins the memory without FOLL_WRITE. If the hypervisor does not
understand the READONLY flag, it might ignore it and map the memory as
read-write.
Could this allow unprivileged guest users to submit virtio-gpu rendering
commands that write to the buffer, bypassing the guest's page protections
and modifying arbitrary read-only memory in the guest?
> + if (rc_blob->blob_hints & ~VIRTGPU_BLOB_HINT_MASK)
> + return -EINVAL;
> +
> if (rc_blob->blob_flags & VIRTGPU_BLOB_FLAG_USE_CROSS_DEVICE) {
> if (!vgdev->has_resource_assign_uuid)
> return -EINVAL;
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260918065653.2170828-1-honghuan@amd.com?part=4
next prev parent reply other threads:[~2026-09-18 7:07 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-18 6:56 [PATCH v8 0/4] virtio-gpu: Add userptr support for compute workloads Honglei Huang
2026-09-18 6:56 ` [PATCH v8 1/4] drm/virtio-gpu: Add VIRTIO_GPU_CAPSET_ROCM capability Honglei Huang
2026-09-18 6:56 ` [PATCH v8 2/4] drm/virtgpu api: add blob userptr resource Honglei Huang
2026-09-18 6:56 ` [PATCH v8 3/4] drm/virtio: implement userptr support for zero-copy memory access Honglei Huang
2026-09-18 6:56 ` [PATCH v8 4/4] drm/virtio: wire blob ioctl creation to userptr objects Honglei Huang
2026-09-18 7:07 ` sashiko-bot [this message]
-- strict thread matches above, loose matches on Subject: below --
2026-09-18 9:59 [PATCH v8 0/4] virtio-gpu: Add userptr support for compute workloads Honglei Huang
2026-09-18 9:59 ` [PATCH v8 4/4] drm/virtio: wire blob ioctl creation to userptr objects Honglei Huang
2026-09-18 10:08 ` sashiko-bot
2026-09-19 14:28 ` Akihiko Odaki
2026-09-24 9:33 ` Huang, Honglei
2026-09-18 8:23 [PATCH v8 0/4] virtio-gpu: Add userptr support for compute workloads Honglei Huang
2026-09-18 8:23 ` [PATCH v8 4/4] drm/virtio: wire blob ioctl creation to userptr objects Honglei Huang
2026-09-18 7:55 [PATCH v8 0/4] virtio-gpu: Add userptr support for compute workloads Honglei Huang
2026-09-18 7:56 ` [PATCH v8 4/4] drm/virtio: wire blob ioctl creation to userptr objects Honglei Huang
2026-09-18 8:12 ` sashiko-bot
2026-09-18 5:59 [PATCH v8 0/4] virtio-gpu: Add userptr support for compute workloads Honglei Huang
2026-09-18 5:59 ` [PATCH v8 4/4] drm/virtio: wire blob ioctl creation to userptr objects Honglei Huang
2026-09-18 6:12 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260918070722.71B7E1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=honghuan@amd.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.