From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 67A6A3793D0; Mon, 30 Mar 2026 16:28:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1774888139; cv=none; b=ad3UZ87Atc+Dl/pvWDK+z/lXRL8Ov7hrVab+QiNPu5ZlVC9MX0oCq9ri5wrtS0jczBclwSiJ+d1TNskvmxR7WXe4adgM7n72sImtpUZWe1aNyZtSKF9h93oGVwroBSalNi0LSLRCJdNeSTgEcbBbs39Tx1s6dzmR7f6ckh6qt9I= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1774888139; c=relaxed/simple; bh=HnR3T8HyhR5zh3UidQc9tY5GP+iCNJ+9G4eesNsn66c=; h=Mime-Version:Content-Type:Date:Message-Id:Subject:Cc:To:From: References:In-Reply-To; b=SUDhd07PBiVBhnoqnSir44k5vwicaFjFvBEUZlOJFdDDaR8IErB8Rf9InZ6cehUx0Jd/MF34n0qqEwAsLtPANDZ6s449VHBmdImlyZ8HxHR5H3TvmMHhGk+t90Wr+vTzN8AAnX1qU4OVjpW2aSW50YKaddGsKtKhItNVDp4X2Dc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=P/3XWocf; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="P/3XWocf" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 2732FC4CEF7; Mon, 30 Mar 2026 16:28:49 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1774888138; bh=HnR3T8HyhR5zh3UidQc9tY5GP+iCNJ+9G4eesNsn66c=; h=Date:Subject:Cc:To:From:References:In-Reply-To:From; b=P/3XWocfTvHDzL/TvgnY90VGL4nSlLd5QBe5hsYLKubBK3nWHOJaPjPq5JQAaRhM8 iAGk5KjaD3ik9GNqL6YSdRdGeXxBgLs24zJtsj3e6fxOpDbi7ZZd8I/d1cyMypX8NE 2XOL2YHA8im3TC/6MZc4CKSvIWYdWZeBHcvNBDXSWRJJuejsAH9jaZzQRbryV+m5kG lnPI2WxSgVXB97c4laa/t/vZgU3QAb4tmja9ypMEFSoxTNm4EFRWFco06IOLdeGzNC AdWvpkXe36xoTq6sFQYDIMUXUgS6vorYizdKVDGjM2rmv+ZiFnuwAzo46ijHVV7DUf PA+6jJae0BAbA== Precedence: bulk X-Mailing-List: kvm@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=UTF-8 Date: Mon, 30 Mar 2026 18:28:48 +0200 Message-Id: Subject: Re: [PATCH 05/12] PCI: use generic driver_override infrastructure Cc: "Russell King" , "Greg Kroah-Hartman" , "Rafael J. Wysocki" , "Ioana Ciornei" , "Nipun Gupta" , "Nikhil Agarwal" , "K. Y. Srinivasan" , "Haiyang Zhang" , "Wei Liu" , "Dexuan Cui" , "Long Li" , "Bjorn Helgaas" , "Armin Wolf" , "Bjorn Andersson" , "Mathieu Poirier" , "Vineeth Vijayan" , "Peter Oberparleiter" , "Heiko Carstens" , "Vasily Gorbik" , "Alexander Gordeev" , "Christian Borntraeger" , "Sven Schnelle" , "Harald Freudenberger" , "Holger Dengler" , "Mark Brown" , "Michael S. Tsirkin" , "Jason Wang" , "Xuan Zhuo" , =?utf-8?q?Eugenio_P=C3=A9rez?= , "Alex Williamson" , "Juergen Gross" , "Stefano Stabellini" , "Oleksandr Tyshchenko" , "Christophe Leroy (CS GROUP)" , , , , , , , , , , , , , , , "Gui-Dong Han" To: "Bjorn Helgaas" From: "Danilo Krummrich" References: <20260324005919.2408620-6-dakr@kernel.org> <20260326180825.GA1330769@bhelgaas> In-Reply-To: <20260326180825.GA1330769@bhelgaas> On Thu Mar 26, 2026 at 7:08 PM CET, Bjorn Helgaas wrote: > On Tue, Mar 24, 2026 at 01:59:09AM +0100, Danilo Krummrich wrote: >> When a driver is probed through __driver_attach(), the bus' match() >> callback is called without the device lock held, thus accessing the >> driver_override field without a lock, which can cause a UAF. >>=20 >> Fix this by using the driver-core driver_override infrastructure taking >> care of proper locking internally. >>=20 >> Note that calling match() from __driver_attach() without the device lock >> held is intentional. [1] >>=20 >> Link: https://lore.kernel.org/driver-core/DGRGTIRHA62X.3RY09D9SOK77P@ker= nel.org/ [1] >> Reported-by: Gui-Dong Han >> Closes: https://bugzilla.kernel.org/show_bug.cgi?id=3D220789 >> Fixes: 782a985d7af2 ("PCI: Introduce new device binding path using pci_d= ev.driver_override") >> Signed-off-by: Danilo Krummrich >> --- >> drivers/pci/pci-driver.c | 11 +++++++---- >> drivers/pci/pci-sysfs.c | 28 ---------------------------- >> drivers/pci/probe.c | 1 - >> include/linux/pci.h | 6 ------ > > For the above: > > Acked-by: Bjorn Helgaas > > "driver_override" is mentioned several places in > Documentation/ABI/testing/sysfs-bus-*. I assume this series doesn't > change the behavior documented there? Correct, none of this is altered.