Re: [PATCH v6 04/12] arm64/mm: Export set_direct_map_*_noflush() APIs
From: sashiko-bot@kernel.org
Date: 2026-09-04 11:13:36
Also in:
dri-devel, linux-devicetree, linux-s390
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider: - [High] Exporting `set_direct_map_*_noflush` APIs without exporting `can_set_direct_map` forces loadable modules to silently fail to protect memory on ARM64, breaking security guarantees. -- commit 6a5f6422ed6de263b9c669919e175cc7d1ac6c09 Author: Thierry Reding [off-list ref] arm64/mm: Export set_direct_map_*_noflush() APIs Drivers that use this may want to be built as a module, so export them.
quoted hunk ↗ jump to hunk
diff --git a/arch/arm64/mm/pageattr.c b/arch/arm64/mm/pageattr.c index 132938b32eb16..9253c529f8aa5 100644 --- a/arch/arm64/mm/pageattr.c +++ b/arch/arm64/mm/pageattr.c@@ -262,6 +262,7 @@ int set_direct_map_invalid_noflush(struct page *page, unsigned int numpages) return update_range_prot((unsigned long)page_address(page), PAGE_SIZE * numpages, set_mask, clear_mask); } +EXPORT_SYMBOL(set_direct_map_invalid_noflush);
[Severity: High]
Are loadable modules going to silently fail to protect memory when using this
exported API?
If the kernel boots with a configuration where can_set_direct_map() is false
(e.g., rodata_full and debug_pagealloc are disabled),
set_direct_map_invalid_noflush() returns 0 without modifying the page tables:
arch/arm64/mm/pageattr.c:set_direct_map_invalid_noflush() {
...
if (!can_set_direct_map())
return 0;
...
}
Because can_set_direct_map() is not exported, a module cannot check this
capability itself. The module will receive 0 (success) and mistakenly assume
the memory was successfully isolated.
For security features, this means content-protected memory remains accessible
in the kernel's linear mapping. This can break DRM guarantees by allowing the
CPU to read protected memory, or cause a kernel panic if the hardware enforces
protection but the CPU speculatively accesses the region via stale linear map
PTEs.
quoted hunk ↗ jump to hunk
int set_direct_map_default_noflush(struct page *page, unsigned int numpages) {@@ -274,6 +275,7 @@ int set_direct_map_default_noflush(struct page *page, unsigned int numpages) return update_range_prot((unsigned long)page_address(page), PAGE_SIZE * numpages, set_mask, clear_mask); } +EXPORT_SYMBOL(set_direct_map_default_noflush);
[Severity: High] Does this apply the same silent failure logic when a module attempts to restore the mapping? -- Sashiko AI review · https://sashiko.dev/#/patchset/20260904-tegra-vpr-v6-0-79042cfa8de5@nvidia.com?part=4