* [PATCH] PCI/proc: Use file_ns_capable() when checking config space read access
@ 2026-07-20 20:41 Krzysztof Wilczyński
2026-07-20 20:59 ` sashiko-bot
0 siblings, 1 reply; 2+ messages in thread
From: Krzysztof Wilczyński @ 2026-07-20 20:41 UTC (permalink / raw)
To: Bjorn Helgaas
Cc: Bjorn Helgaas, Manivannan Sadhasivam, Lorenzo Pieralisi,
Kees Cook, linux-pci
proc_bus_pci_read() decides how much of the config space is readable
based on capable(CAP_SYS_ADMIN), which checks the credentials of the
task calling read(), not the credentials of the process that opened
the file.
The sysfs equivalent, pci_read_config(), has checked the credentials
of the opening process since commit de139a339395 ("pci: check caps
from sysfs file open to read device dependent config space"), so a
privileged process can open the config space file and pass the file
descriptor to an unprivileged process (for example, a process running
a KVM guest with an assigned device), which can then read the entire
config space. The check was subsequently routed through the LSM
framework in commit 47970b1b2aa6 ("pci: use security_capable() when
checking capablities during config space read") and converted to the
dedicated helper in commit ab0fa82b2df9 ("pci-sysfs: use proper file
capability helper function").
Thus, the two interfaces check the same capability against different
credentials. Checking the credentials of the task calling read()
makes the outcome depend on who reads rather than who opened, so the
restriction is bypassed whenever a more privileged process reads
through the descriptor. Checking the credentials recorded in
file->f_cred settles the decision at open() time and ties it to the
file, where it cannot change with the caller.
Therefore, use file_ns_capable() to check CAP_SYS_ADMIN against the
credentials in effect when the file was opened, bringing the procfs
interface in line with the sysfs behaviour.
As a result, a file descriptor opened by a privileged process and
passed to an unprivileged one now allows the entire config space to
be read through procfs, matching sysfs.
Signed-off-by: Krzysztof Wilczyński <kwilczynski@kernel.org>
---
drivers/pci/proc.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/pci/proc.c b/drivers/pci/proc.c
index 71ad289fcb8e..690a5625fcb4 100644
--- a/drivers/pci/proc.c
+++ b/drivers/pci/proc.c
@@ -39,7 +39,7 @@ static ssize_t proc_bus_pci_read(struct file *file, char __user *buf,
* undefined locations (think of Intel PIIX4 as a typical example).
*/
- if (capable(CAP_SYS_ADMIN))
+ if (file_ns_capable(file, &init_user_ns, CAP_SYS_ADMIN))
size = dev->cfg_size;
else if (dev->hdr_type == PCI_HEADER_TYPE_CARDBUS)
size = 128;
--
2.55.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH] PCI/proc: Use file_ns_capable() when checking config space read access
2026-07-20 20:41 [PATCH] PCI/proc: Use file_ns_capable() when checking config space read access Krzysztof Wilczyński
@ 2026-07-20 20:59 ` sashiko-bot
0 siblings, 0 replies; 2+ messages in thread
From: sashiko-bot @ 2026-07-20 20:59 UTC (permalink / raw)
To: Krzysztof Wilczyński; +Cc: linux-pci
> proc_bus_pci_read() decides how much of the config space is readable
> based on capable(CAP_SYS_ADMIN), which checks the credentials of the
> task calling read(), not the credentials of the process that opened
> the file.
>
> The sysfs equivalent, pci_read_config(), has checked the credentials
> of the opening process since commit de139a339395 ("pci: check caps
> from sysfs file open to read device dependent config space"), so a
> privileged process can open the config space file and pass the file
> descriptor to an unprivileged process (for example, a process running
> a KVM guest with an assigned device), which can then read the entire
> config space. The check was subsequently routed through the LSM
> framework in commit 47970b1b2aa6 ("pci: use security_capable() when
> checking capablities during config space read") and converted to the
> dedicated helper in commit ab0fa82b2df9 ("pci-sysfs: use proper file
> [ ... ]
> As a result, a file descriptor opened by a privileged process and
> passed to an unprivileged one now allows the entire config space to
> be read through procfs, matching sysfs.
>
> Signed-off-by: Krzysztof Wilczyński <kwilczynski@kernel.org>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260720204145.1500105-1-kwilczynski@kernel.org?part=1
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-07-20 20:59 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-20 20:41 [PATCH] PCI/proc: Use file_ns_capable() when checking config space read access Krzysztof Wilczyński
2026-07-20 20:59 ` sashiko-bot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox