Netdev List
 help / color / mirror / Atom feed
From: Bjorn Helgaas <helgaas@kernel.org>
To: Gary Guo <gary@garyguo.net>
Cc: Bjorn Helgaas <bhelgaas@google.com>,
	Zhenzhong Duan <zhenzhong.duan@gmail.com>,
	Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
	"Rafael J. Wysocki" <rafael@kernel.org>,
	Danilo Krummrich <dakr@kernel.org>,
	Damien Le Moal <dlemoal@kernel.org>,
	Niklas Cassel <cassel@kernel.org>,
	GOTO Masanori <gotom@debian.or.jp>,
	YOKOTA Hiroshi <yokota@netlab.is.tsukuba.ac.jp>,
	"James E.J. Bottomley" <James.Bottomley@hansenpartnership.com>,
	"Martin K. Petersen" <martin.petersen@oracle.com>,
	Vaibhav Gupta <vaibhavgupta40@gmail.com>,
	Jens Taprogge <jens.taprogge@taprogge.org>,
	Ido Schimmel <idosch@nvidia.com>, Petr Machata <petrm@nvidia.com>,
	Andrew Lunn <andrew+netdev@lunn.ch>,
	"David S. Miller" <davem@davemloft.net>,
	Eric Dumazet <edumazet@google.com>,
	Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
	David Airlie <airlied@redhat.com>,
	linux-pci@vger.kernel.org, driver-core@lists.linux.dev,
	linux-kernel@vger.kernel.org, linux-ide@vger.kernel.org,
	linux-scsi@vger.kernel.org,
	industrypack-devel@lists.sourceforge.net, netdev@vger.kernel.org,
	dri-devel@lists.freedesktop.org, Sashiko <sashiko-bot@kernel.org>
Subject: Re: [PATCH v4 0/9] PCI: Fix UAF and TOCTOU related to dynamic ID
Date: Tue, 28 Jul 2026 11:25:38 -0500	[thread overview]
Message-ID: <20260728162538.GA1325438@bhelgaas> (raw)
In-Reply-To: <20260723-pci_id_fix-v4-0-3580726844e1@garyguo.net>

On Thu, Jul 23, 2026 at 11:00:39PM +0100, Gary Guo wrote:
> While working on improving the Rust abstractions [1], Sashiko reported that
> an existing UAF issue related to dynamic ID, which I find to be genuine.
> When taking a look at the code I also find a TOCTOU issue where the
> existence check of dynamic ID happens in a separate critical section as the
> actual insertion. This series fix both issues.
> 
> There are two exported functions pci_match_id() and pci_add_dynid() which I
> have to tweak to implement this cleanly; I created separate "do_xxx"
> functions to keep the existing APIs because they all have multiple users.
> 
> There're a few existing users which stores their pci_device_id argument in
> probe callback. This is a bad pattern because nothing except driver_data
> inside pci_device_id is what they want; actual ID information can be
> retrieved from pci_dev instead.
> 
> There are two users that performs pointer arithmetic on the pci_device_id;
> these are also problematic with dynamic ID and driver_override, so fix them
> as well.
> 
> I've used the following coccinelle script to flag all cases where the
> pci_device_id is used other than reading its fields.
> 
> @usage@
> identifier fn, id;
> position p;
> @@
>   fn(..., struct pci_device_id *id, ...)
>   {
>     ...
>     id@p
>     ...
>   }
> 
> // Due to cocci isomorphism this needs to be explicit
> @bad@
> identifier fn, id;
> type T;
> position usage.p;
> @@
>   fn(..., struct pci_device_id *id, ...)
>   {
>     ...
>     (T*)id@p
>     ...
>   }
> 
> // Good use cases
> @good@
> identifier fn, id, fld;
> expression E;
> position usage.p;
> @@
>   fn(..., struct pci_device_id *id, ...)
>   {
>     ...
> (
>     id@p->fld
> |
>     E(..., id@p, ...)
> |
> // Redundant checks, but ignore
>     !id@p
> |
> // Redundant checks, but ignore
>     id ? ... : ...
> )
>     ...
>   }
> 
> @script:python depends on usage && (bad || !good)@
> p << usage.p;
> @@
> coccilib.report.print_report(p[0], "suspicious use of pci_device_id")
> 
> Link: https://lore.kernel.org/all/20260618-id_info-v1-0-96af1e559ef9@garyguo.net/ [1]
> Link: https://lore.kernel.org/all/20260619170503.518F61F00A3A@smtp.kernel.org/ [2]
> 
> ---
> Changes in v4:
> - Code and commit message style fixes (Bjorn)
> - Link to v3: https://patch.msgid.link/20260706-pci_id_fix-v3-0-2d48fc025acc@garyguo.net
> 
> Changes in v3:
> - Fix users which uses pci_device_id for pointer arithmetic. (Sashiko)
> - Convert to scoped_guard. (Danilo)
> - For static IDs, still give out static pointers and avoid making a copy.
> - Link to v2: https://patch.msgid.link/20260630-pci_id_fix-v2-0-b834a98c0af2@garyguo.net
> 
> Changes in v2:
> - Fix users which store pci_device_id.
> - Clarify in probe documentation about the lifetime of pci_device_id
>   parameter.
> - Dynamic ID conflict check now ignores override_only. (Sashiko)
> - Link to v1: https://patch.msgid.link/20260626-pci_id_fix-v1-0-a35c803f1b95@garyguo.net
> 
> ---
> Gary Guo (9):
>       ata: ata_generic: don't store pci_device_id
>       scsi: nsp32: don't store pci_device_id
>       ipack: tpci200: don't store pci_device_id
>       mlxsw: pci: don't store pci_device_id
>       agp/via: Don't rely on address of pci_device_id
>       agp/amd-k7: Don't rely on address of pci_device_id
>       PCI: Make pci_match_one_device() match on ID instead of device
>       PCI: Fix dyn_id add TOCTOU
>       PCI: Fix UAF when probe runs concurrent to dyn ID removal
> 
>  drivers/ata/ata_generic.c                 |   6 +-
>  drivers/char/agp/amd-k7-agp.c             |  26 +--
>  drivers/char/agp/via-agp.c                | 308 +++++++-----------------------
>  drivers/ipack/carriers/tpci200.c          |   1 -
>  drivers/ipack/carriers/tpci200.h          |   1 -
>  drivers/net/ethernet/mellanox/mlxsw/pci.c |  11 +-
>  drivers/pci/pci-driver.c                  | 194 ++++++++++---------
>  drivers/pci/pci.h                         |  43 +++--
>  drivers/pci/search.c                      |   8 +-
>  drivers/scsi/nsp32.c                      |   8 +-
>  drivers/scsi/nsp32.h                      |   8 +-
>  include/linux/pci.h                       |   1 +
>  12 files changed, 237 insertions(+), 378 deletions(-)

I put this on pci/enumeration and plan it for v7.3, hopefully with
acks from the AGP, tpci200, and nsp32 folks.

      parent reply	other threads:[~2026-07-28 16:25 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-23 22:00 [PATCH v4 0/9] PCI: Fix UAF and TOCTOU related to dynamic ID Gary Guo
2026-07-23 22:00 ` [PATCH v4 1/9] ata: ata_generic: don't store pci_device_id Gary Guo
2026-07-23 22:00 ` [PATCH v4 2/9] scsi: nsp32: " Gary Guo
2026-07-23 22:00 ` [PATCH v4 3/9] ipack: tpci200: " Gary Guo
2026-07-23 22:00 ` [PATCH v4 4/9] mlxsw: pci: " Gary Guo
2026-07-23 22:00 ` [PATCH v4 5/9] agp/via: Don't rely on address of pci_device_id Gary Guo
2026-07-23 22:00 ` [PATCH v4 6/9] agp/amd-k7: " Gary Guo
2026-07-23 22:00 ` [PATCH v4 7/9] PCI: Make pci_match_one_device() match on ID instead of device Gary Guo
2026-07-24 22:29   ` Bjorn Helgaas
2026-07-25 12:17     ` Gary Guo
2026-07-25 15:40       ` Danilo Krummrich
2026-07-28 16:24       ` Bjorn Helgaas
2026-07-23 22:00 ` [PATCH v4 8/9] PCI: Fix dyn_id add TOCTOU Gary Guo
2026-07-24 22:29   ` Bjorn Helgaas
2026-07-23 22:00 ` [PATCH v4 9/9] PCI: Fix UAF when probe runs concurrent to dyn ID removal Gary Guo
2026-07-24 22:30   ` Bjorn Helgaas
2026-07-28 16:25 ` Bjorn Helgaas [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260728162538.GA1325438@bhelgaas \
    --to=helgaas@kernel.org \
    --cc=James.Bottomley@hansenpartnership.com \
    --cc=airlied@redhat.com \
    --cc=andrew+netdev@lunn.ch \
    --cc=bhelgaas@google.com \
    --cc=cassel@kernel.org \
    --cc=dakr@kernel.org \
    --cc=davem@davemloft.net \
    --cc=dlemoal@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=driver-core@lists.linux.dev \
    --cc=edumazet@google.com \
    --cc=gary@garyguo.net \
    --cc=gotom@debian.or.jp \
    --cc=gregkh@linuxfoundation.org \
    --cc=idosch@nvidia.com \
    --cc=industrypack-devel@lists.sourceforge.net \
    --cc=jens.taprogge@taprogge.org \
    --cc=kuba@kernel.org \
    --cc=linux-ide@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-pci@vger.kernel.org \
    --cc=linux-scsi@vger.kernel.org \
    --cc=martin.petersen@oracle.com \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=petrm@nvidia.com \
    --cc=rafael@kernel.org \
    --cc=sashiko-bot@kernel.org \
    --cc=vaibhavgupta40@gmail.com \
    --cc=yokota@netlab.is.tsukuba.ac.jp \
    --cc=zhenzhong.duan@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox