* [PATCH] mm/page-writeback: document folio_mark_dirty() locking more explicitly
@ 2026-08-10 16:02 Jann Horn
2026-08-10 17:36 ` Christoph Hellwig
0 siblings, 1 reply; 3+ messages in thread
From: Jann Horn @ 2026-08-10 16:02 UTC (permalink / raw)
To: Matthew Wilcox (Oracle), Jan Kara, Andrew Morton
Cc: linux-fsdevel, linux-mm, linux-kernel, Jann Horn
I have found two out-of-tree driver bugs in the past where set_page_dirty()
was used on a page from GUP without appropriate locking, leading to UAF:
- https://project-zero.issues.chromium.org/42450908 (in Qualcomm's Adreno
GPU driver)
- https://project-zero.issues.chromium.org/494546491 (in Google Pixel's
GXP driver)
Today I found another instance of this in mainline:
https://lore.kernel.org/r/20260810-x86-kvm-setpagedirty-v1-1-85f180892d4f@google.com
I think this shows that set_page_dirty() and folio_mark_dirty() at least
need more explicit documentation; so add a comment on top of
set_page_dirty() and make the comment above folio_mark_dirty() more
explicit.
Signed-off-by: Jann Horn <jannh@google.com>
---
mm/folio-compat.c | 1 +
mm/page-writeback.c | 5 +++++
2 files changed, 6 insertions(+)
diff --git a/mm/folio-compat.c b/mm/folio-compat.c
index a02179a0bded..6212fdd6761a 100644
--- a/mm/folio-compat.c
+++ b/mm/folio-compat.c
@@ -41,6 +41,7 @@ void set_page_writeback(struct page *page)
}
EXPORT_SYMBOL(set_page_writeback);
+/* Read the comment above folio_mark_dirty() regarding required locks! */
bool set_page_dirty(struct page *page)
{
return folio_mark_dirty(page_folio(page));
diff --git a/mm/page-writeback.c b/mm/page-writeback.c
index e98748112d1e..b0ab687c83be 100644
--- a/mm/page-writeback.c
+++ b/mm/page-writeback.c
@@ -2773,6 +2773,11 @@ EXPORT_SYMBOL(folio_redirty_for_writepage);
* in this folio. Truncation will block on the page table lock as it
* unmaps pages before removing the folio from its mapping.
*
+ * .. DANGER::
+ * Do not use this on a folio obtained from a function like
+ * get_user_pages_fast() without holding appropriate locks; you might want to
+ * use set_page_dirty_lock() or folio_mark_dirty_lock() instead.
+ *
* Return: True if the folio was newly dirtied, false if it was already dirty.
*/
bool folio_mark_dirty(struct folio *folio)
---
base-commit: db2ddb87143519e20a95aa36c60b36107b736a58
change-id: 20260810-set-page-dirty-warnings-4000f0015394
Best regards,
--
Jann Horn <jannh@google.com>
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH] mm/page-writeback: document folio_mark_dirty() locking more explicitly
2026-08-10 16:02 [PATCH] mm/page-writeback: document folio_mark_dirty() locking more explicitly Jann Horn
@ 2026-08-10 17:36 ` Christoph Hellwig
2026-08-10 18:29 ` Jann Horn
0 siblings, 1 reply; 3+ messages in thread
From: Christoph Hellwig @ 2026-08-10 17:36 UTC (permalink / raw)
To: Jann Horn
Cc: Matthew Wilcox (Oracle), Jan Kara, Andrew Morton, linux-fsdevel,
linux-mm, linux-kernel
On Mon, Aug 10, 2026 at 06:02:36PM +0200, Jann Horn wrote:
> I have found two out-of-tree driver bugs in the past where set_page_dirty()
> was used on a page from GUP without appropriate locking, leading to UAF:
More documentation is always good, but out of tree drivers are totally
irrelevant for upstream, so please reword your commit message to be
relevant for the kernel itself and drop these references.
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] mm/page-writeback: document folio_mark_dirty() locking more explicitly
2026-08-10 17:36 ` Christoph Hellwig
@ 2026-08-10 18:29 ` Jann Horn
0 siblings, 0 replies; 3+ messages in thread
From: Jann Horn @ 2026-08-10 18:29 UTC (permalink / raw)
To: Christoph Hellwig
Cc: Matthew Wilcox (Oracle), Jan Kara, Andrew Morton, linux-fsdevel,
linux-mm, linux-kernel
On Mon, Aug 10, 2026 at 7:36 PM Christoph Hellwig <hch@infradead.org> wrote:
> On Mon, Aug 10, 2026 at 06:02:36PM +0200, Jann Horn wrote:
> > I have found two out-of-tree driver bugs in the past where set_page_dirty()
> > was used on a page from GUP without appropriate locking, leading to UAF:
>
> More documentation is always good, but out of tree drivers are totally
> irrelevant for upstream, so please reword your commit message to be
> relevant for the kernel itself and drop these references.
Ack, I've reworded the commit message and added some more examples I
found in mainline history.
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-08-10 18:29 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-10 16:02 [PATCH] mm/page-writeback: document folio_mark_dirty() locking more explicitly Jann Horn
2026-08-10 17:36 ` Christoph Hellwig
2026-08-10 18:29 ` Jann Horn
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox