Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Lorenzo Stoakes (ARM)" <ljs@kernel.org>
Cc: linux-perf-users@vger.kernel.org, bpf@vger.kernel.org,
	linux-s390@vger.kernel.org, linux-scsi@vger.kernel.org,
	linux-trace-kernel@vger.kernel.org,
	"Heiko Carstens" <hca@linux.ibm.com>,
	"Oliver Upton" <oupton@kernel.org>,
	kvm@vger.kernel.org, dri-devel@lists.freedesktop.org,
	kvmarm@lists.linux.dev,
	"Alexander Gordeev" <agordeev@linux.ibm.com>,
	selinux@vger.kernel.org,
	"Christian Borntraeger" <borntraeger@linux.ibm.com>,
	"Marc Zyngier" <maz@kernel.org>,
	"Vasily Gorbik" <gor@linux.ibm.com>
Subject: Re: [PATCH 08/39] docs: filesystems: update mmap_prepare docs for discontig kernel pgs
Date: Tue, 08 Sep 2026 20:38:36 +0000	[thread overview]
Message-ID: <20260908203837.48C7C1F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260908-b4-mmap-prepare-vma-flag-sanify-v1-8-dacf19cce22b@kernel.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Insufficient Validation of nr_pages (Integer Overflow and Zero-Page Hang)
--

commit 0017a54bcba2043c3f552b308a32a39be664f463
Author: Lorenzo Stoakes (ARM) <ljs@kernel.org>

mm: add mmap action for discontiguous kernel page mapping

The existing kernel page mapping mmap actions allow for partial and full
mapping of an array of struct page pointers.

However some drivers require the mapping of discontiguous ranges. Permit
this by providing discontig_kernel_page_ops which allows a driver to
specify how the operation should begin and how batches of pages should be
retrieved.

> diff --git a/mm/memory.c b/mm/memory.c
> index dc38cad1dcb7e..8c9675451d4ba 100644
> --- a/mm/memory.c
> +++ b/mm/memory.c

[ ... ]

>  int map_kernel_pages_prepare(struct vm_area_desc *desc)
>  {
>  	const struct mmap_action *action = &desc->action;
>  	const unsigned long addr = action->map_kernel.start;
>  	unsigned long nr_pages, end;
>  
> -	if (!vma_desc_test(desc, VMA_MIXEDMAP_BIT)) {
> -		VM_WARN_ON_ONCE(mmap_read_trylock(desc->mm));
> -		VM_WARN_ON_ONCE(vma_desc_test(desc, VMA_PFNMAP_BIT));
> -		vma_desc_set_flags(desc, VMA_MIXEDMAP_BIT);
> -	}
> +	__map_kernel_pages_prepare(desc);
>  
>  	nr_pages = action->map_kernel.nr_pages;
>  	end = addr + PAGE_SIZE * nr_pages;
>  	if (!range_in_vma_desc(desc, addr, end))
>  		return -EFAULT;

[Severity: High]
Can the end calculation overflow here if nr_pages is exceptionally large?

If a driver supplies an overly large nr_pages, PAGE_SIZE * nr_pages
could wrap to a small value. Because range_is_subset() lacks an
inner_start <= inner_end validation, this wrapped end value would
incorrectly pass the range_in_vma_desc() bounds check.

This could lead to inserting PTEs far out of VMA bounds and corrupting page
tables.

[ ... ]

> +int map_discontig_kernel_pages_complete(struct vm_area_struct *vma,
> +					struct mmap_action *action)
> +{

[ ... ]

> +	do {
> +		unsigned long end, pgoff_end;
> +		unsigned long nr_pages;
> +
> +		/* Default to abort. */
> +		state.action = DISCONTIG_KERNEL_PAGE_ABORT;
> +		err = ops->get(&state);
> +		if (err || state.action == DISCONTIG_KERNEL_PAGE_ABORT)
> +			return err;
> +		nr_pages = state.__nr_pages;
> +
> +		end = state.addr + PAGE_SIZE * nr_pages;
> +		if (end > vma->vm_end)
> +			return -EINVAL;

[Severity: High]
Does this bounds check handle a huge nr_pages value correctly?

Similar to the check in map_kernel_pages_prepare(), if nr_pages is
huge, end will wrap to a small value. This bypasses the end > vma->vm_end
check, potentially allowing page table corruption.

> +		pgoff_end = state.pgoff + nr_pages;
> +
> +		err = apply_discontig_action(vma, &state);
> +		if (err)
> +			return err;
> +
> +		state.addr = end;
> +		state.pgoff = pgoff_end;
> +		state.nr_pages_mapped += nr_pages;
> +		state.nr_pages_remain -= nr_pages;
> +	} while (state.addr < vma->vm_end);

[Severity: High]
Could this result in an infinite loop if nr_pages is 0?

If a driver provides 0 pages (for instance, via
discontig_kernel_map_page_range(..., 0)), end will equal state.addr.

state.addr is then updated with a 0 increment, causing the
while (state.addr < vma->vm_end) loop to execute infinitely and hang
the kernel.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260908-b4-mmap-prepare-vma-flag-sanify-v1-0-dacf19cce22b@kernel.org?part=8

  reply	other threads:[~2026-09-08 20:38 UTC|newest]

Thread overview: 89+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-08 20:01 [PATCH 00/39] mm: make VMA flag semantics explicit, eliminate VM_SPECIAL Lorenzo Stoakes (ARM)
2026-09-08 20:01 ` [PATCH 01/39] mm/vma: predicate setting mmap_prepare VMA fields on new vma alloc Lorenzo Stoakes (ARM)
2026-09-08 20:42   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 02/39] mm/vma: introduce and use vma_[flags_]can_merge() Lorenzo Stoakes (ARM)
2026-09-08 20:27   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 03/39] mm: consistently validate VMA state after mmap[_prepare] hooks Lorenzo Stoakes (ARM)
2026-09-08 20:40   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 04/39] mm/vma: ensure mmap_prepare doesn't set actions on a mergeable vma Lorenzo Stoakes (ARM)
2026-09-08 20:36   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 05/39] mm: make map_kernel_pages_[prepare,complete] internal and unexported Lorenzo Stoakes (ARM)
2026-09-08 20:24   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 06/39] mm/vma: tidy up map kernel pages enum values Lorenzo Stoakes (ARM)
2026-09-08 20:27   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 07/39] mm: add mmap action for discontiguous kernel page mapping Lorenzo Stoakes (ARM)
2026-09-08 20:34   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 08/39] docs: filesystems: update mmap_prepare docs for discontig kernel pgs Lorenzo Stoakes (ARM)
2026-09-08 20:38   ` sashiko-bot [this message]
2026-09-08 20:01 ` [PATCH 09/39] drivers/usb/mon: update to use mmap_prepare + map kernel pages Lorenzo Stoakes (ARM)
2026-09-08 20:35   ` sashiko-bot
2026-09-09  7:37   ` Greg Kroah-Hartman
2026-09-08 20:01 ` [PATCH 10/39] infiniband: update hfi1 to use remap_vmalloc_range() Lorenzo Stoakes (ARM)
2026-09-08 20:42   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 11/39] selinux: reject writable opens of policy file, drop mmap shared/write check Lorenzo Stoakes (ARM)
2026-09-08 20:22   ` Jann Horn
2026-09-08 20:36   ` sashiko-bot
2026-09-10 18:11   ` Stephen Smalley
2026-09-08 20:01 ` [PATCH 12/39] ALSA: pcm: use vm_insert_page() to map PCM status page Lorenzo Stoakes (ARM)
2026-09-08 20:45   ` sashiko-bot
2026-09-10 16:15   ` Takashi Iwai
2026-09-08 20:01 ` [PATCH 13/39] bpf: arena: mark arena_map_mmap() mappings VM_MIXEDMAP Lorenzo Stoakes (ARM)
2026-09-08 20:34   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 14/39] mm/vma: add vma[_flags]_is_kernel_owned() predicates Lorenzo Stoakes (ARM)
2026-09-08 20:28   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 15/39] mm/vma: only allow mmap to clear VMA_MAYWRITE_BIT if kernel-owned Lorenzo Stoakes (ARM)
2026-09-08 20:42   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 16/39] mm/vma: add and use vma_[flags]_is_fixed_mapping Lorenzo Stoakes (ARM)
2026-09-08 20:42   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 17/39] scsi: sg: convert mmap hook to mmap_prepare and rework Lorenzo Stoakes (ARM)
2026-09-08 20:37   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 18/39] fbdev: defio: assert FBINFO_VIRTFB, drop VM_IO, add VM_MIXEDMAP Lorenzo Stoakes (ARM)
2026-09-08 20:39   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 19/39] HSI: cmt_speech: convert mmap hook to mmap_prepare, refactor Lorenzo Stoakes (ARM)
2026-09-08 20:36   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 20/39] mm/gup: error out early on !VMA_MAYREAD_BIT VMAs Lorenzo Stoakes (ARM)
2026-09-08 20:36   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 21/39] uprobes: remove VM_IO, set VM_MIXEDMAP for mapped kernel pages Lorenzo Stoakes (ARM)
2026-09-08 20:36   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 22/39] mm/mlock: clear VMA_LOCKED_MASK over mmap callback Lorenzo Stoakes (ARM)
2026-09-08 20:38   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 23/39] mm/mlock: eliminate weird VMA_IO_BIT abuse and simplify Lorenzo Stoakes (ARM)
2026-09-08 20:47   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 24/39] mm/vma: enforce that only kernel-owned mappings may set VMA_IO_BIT Lorenzo Stoakes (ARM)
2026-09-08 20:47   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 25/39] mm: remove VMA_IO_BIT check in vma[_flags]_is_kernel_owned() Lorenzo Stoakes (ARM)
2026-09-08 20:37   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 26/39] mm: remove hugetlb_inline.h Lorenzo Stoakes (ARM)
2026-09-08 20:34   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 27/39] mm: rename is_vm_hugetlb_page() to vma_is_hugetlb() Lorenzo Stoakes (ARM)
2026-09-08 20:40   ` sashiko-bot
2026-09-09 11:09   ` Anup Patel
2026-09-09 11:22   ` Claudio Imbrenda
2026-09-09 11:30     ` Lorenzo Stoakes (ARM)
2026-09-09 13:20       ` Claudio Imbrenda
2026-09-09 12:07   ` Marc Zyngier
2026-09-08 20:01 ` [PATCH 28/39] mm: drop some redundant checks around hugetlb VMAs Lorenzo Stoakes (ARM)
2026-09-08 20:39   ` sashiko-bot
2026-09-09 12:08   ` Marc Zyngier
2026-09-08 20:01 ` [PATCH 29/39] mm/madvise: update is_valid_guard_vma() to use vma_can_merge() Lorenzo Stoakes (ARM)
2026-09-08 20:45   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 30/39] mm/vma: introduce vma[_flags]_is_persistent() Lorenzo Stoakes (ARM)
2026-09-08 20:47   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 31/39] mm/uffd: use predicates for userfaultfd checks Lorenzo Stoakes (ARM)
2026-09-08 20:45   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 32/39] mm/madvise: use predicates for madvise(..., MADV_DOFORK) Lorenzo Stoakes (ARM)
2026-09-08 20:48   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 33/39] mm: eliminate VMA_SPECIAL_FLAGS usage when hugetlb explicitly tested Lorenzo Stoakes (ARM)
2026-09-08 20:42   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 34/39] mm: eliminate VMA_SPECIAL_FLAGS check in lru_gen_look_around() Lorenzo Stoakes (ARM)
2026-09-08 20:45   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 35/39] mm: avoid use of VMA_SPECIAL_FLAGS in migrate_vma_setup() Lorenzo Stoakes (ARM)
2026-09-08 20:47   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 36/39] mm: eliminate VM_SPECIAL, VMA_SPECIAL_FLAGS Lorenzo Stoakes (ARM)
2026-09-08 20:41   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 37/39] fuse: dax: do not set VM_MIXEDMAP Lorenzo Stoakes (ARM)
2026-09-08 20:50   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 38/39] mm/huge_memory: remove vma_is_special_huge() Lorenzo Stoakes (ARM)
2026-09-08 20:45   ` sashiko-bot
2026-09-08 20:01 ` [PATCH 39/39] mm/vma: introduce and use vma[_flags]_can_gup() Lorenzo Stoakes (ARM)
2026-09-08 20:44   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260908203837.48C7C1F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=agordeev@linux.ibm.com \
    --cc=borntraeger@linux.ibm.com \
    --cc=bpf@vger.kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=gor@linux.ibm.com \
    --cc=hca@linux.ibm.com \
    --cc=kvm@vger.kernel.org \
    --cc=kvmarm@lists.linux.dev \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=linux-s390@vger.kernel.org \
    --cc=linux-scsi@vger.kernel.org \
    --cc=linux-trace-kernel@vger.kernel.org \
    --cc=ljs@kernel.org \
    --cc=maz@kernel.org \
    --cc=oupton@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=selinux@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox