mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v2] dma-buf: set SB_I_NOEXEC and SB_I_NODEV on the pseudo filesystem
@ 2026-05-23  1:11 John Hubbard
  2026-05-25  5:55 ` Christoph Hellwig
  0 siblings, 1 reply; 3+ messages in thread
From: John Hubbard @ 2026-05-23  1:11 UTC (permalink / raw)
  To: Sumit Semwal, Christian König
  Cc: Christian Brauner, Jens Axboe, linux-media, dri-devel,
	linaro-mm-sig, LKML, John Hubbard, stable

The dma-buf pseudo filesystem dispenses S_ANON_INODE inodes via
alloc_anon_inode() but never sets SB_I_NOEXEC on its superblock.
Since commit 1e7ab6f67824 ("anon_inode: rework assertions") in 6.17,
path_noexec() warns on exactly that combination, so an mmap() on any
dma-buf fd trips the warning:

  WARNING: CPU: 11 PID: 121813 at fs/exec.c:118 path_noexec+0x47/0x50
   do_mmap+0x2b5/0x680
   vm_mmap_pgoff+0x129/0x210
   ksys_mmap_pgoff+0x177/0x240
   __x64_sys_mmap+0x33/0x70

dma-bufs have no business being executable, which is the invariant
that the new assertion is enforcing. Set SB_I_NOEXEC. Also set
SB_I_NODEV, since the pseudo filesystem creates no device nodes.

Reproducer on a CONFIG_DEBUG_VFS=y kernel:

  make -C tools/testing/selftests/dmabuf-heaps
  sudo ./tools/testing/selftests/dmabuf-heaps/dmabuf-heap -t system

The selftest allocates from /dev/dma_heap/system and mmaps the
returned fd, which trips the warning without this patch.

Fixes: 1e7ab6f67824 ("anon_inode: rework assertions")
Cc: stable@vger.kernel.org
Reviewed-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: John Hubbard <jhubbard@nvidia.com>
---

Changes since v1:

   * Also set SB_I_NODEV (suggested by Christian Brauner).
   * Added Christian Brauner's Reviewed-by tag (thanks!)


 drivers/dma-buf/dma-buf.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/dma-buf/dma-buf.c b/drivers/dma-buf/dma-buf.c
index 71f37544a5c6..ea1ddd4293b2 100644
--- a/drivers/dma-buf/dma-buf.c
+++ b/drivers/dma-buf/dma-buf.c
@@ -216,6 +216,8 @@ static int dma_buf_fs_init_context(struct fs_context *fc)
 	if (!ctx)
 		return -ENOMEM;
 	ctx->dops = &dma_buf_dentry_ops;
+	fc->s_iflags |= SB_I_NOEXEC;
+	fc->s_iflags |= SB_I_NODEV;
 	return 0;
 }
 

base-commit: 6779b50faa562e6cca1aa6a4649a4d764c6c7e28
-- 
2.54.0


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH v2] dma-buf: set SB_I_NOEXEC and SB_I_NODEV on the pseudo filesystem
  2026-05-23  1:11 [PATCH v2] dma-buf: set SB_I_NOEXEC and SB_I_NODEV on the pseudo filesystem John Hubbard
@ 2026-05-25  5:55 ` Christoph Hellwig
  2026-05-28  2:39   ` John Hubbard
  0 siblings, 1 reply; 3+ messages in thread
From: Christoph Hellwig @ 2026-05-25  5:55 UTC (permalink / raw)
  To: John Hubbard
  Cc: Sumit Semwal, Christian König, Christian Brauner,
	Jens Axboe, linux-media, dri-devel, linaro-mm-sig, LKML, stable

On Fri, May 22, 2026 at 06:11:17PM -0700, John Hubbard wrote:
> The dma-buf pseudo filesystem dispenses S_ANON_INODE inodes via
> alloc_anon_inode() but never sets SB_I_NOEXEC on its superblock.
> Since commit 1e7ab6f67824 ("anon_inode: rework assertions") in 6.17,
> path_noexec() warns on exactly that combination, so an mmap() on any
> dma-buf fd trips the warning:

Just as last time this came up, we really should set this higher up.
There isn't really a reason why pseudofses should not set SB_I_NOEXEC
by default.


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH v2] dma-buf: set SB_I_NOEXEC and SB_I_NODEV on the pseudo filesystem
  2026-05-25  5:55 ` Christoph Hellwig
@ 2026-05-28  2:39   ` John Hubbard
  0 siblings, 0 replies; 3+ messages in thread
From: John Hubbard @ 2026-05-28  2:39 UTC (permalink / raw)
  To: Christoph Hellwig
  Cc: Sumit Semwal, Christian König, Christian Brauner,
	Jens Axboe, linux-media, dri-devel, linaro-mm-sig, LKML, stable

On 5/24/26 10:55 PM, Christoph Hellwig wrote:
> On Fri, May 22, 2026 at 06:11:17PM -0700, John Hubbard wrote:
>> The dma-buf pseudo filesystem dispenses S_ANON_INODE inodes via
>> alloc_anon_inode() but never sets SB_I_NOEXEC on its superblock.
>> Since commit 1e7ab6f67824 ("anon_inode: rework assertions") in 6.17,
>> path_noexec() warns on exactly that combination, so an mmap() on any
>> dma-buf fd trips the warning:
> 
> Just as last time this came up, we really should set this higher up.
> There isn't really a reason why pseudofses should not set SB_I_NOEXEC
> by default.
> 

Ha, I see now that there is some history to this.

After looking at the email history and the code, it does seem like
the time is right to do that. I'm testing out a tiny series to set
these flags in init_pseudo(), and then to *not* redundantly set them
elsewhere, I'll post it shortly.

thanks,
-- 
John Hubbard

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-05-28  2:39 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-05-23  1:11 [PATCH v2] dma-buf: set SB_I_NOEXEC and SB_I_NODEV on the pseudo filesystem John Hubbard
2026-05-25  5:55 ` Christoph Hellwig
2026-05-28  2:39   ` John Hubbard

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®