Thread (26 messages) flat view 26 messages, 3 authors, 1d ago

Re: [PATCH v6 04/12] arm64/mm: Export set_direct_map_*_noflush() APIs

From: sashiko-bot@kernel.org
Date: 2026-09-04 11:13:36
Also in: dri-devel, linux-devicetree, linux-s390

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Exporting `set_direct_map_*_noflush` APIs without exporting `can_set_direct_map` forces loadable modules to silently fail to protect memory on ARM64, breaking security guarantees.
--

commit 6a5f6422ed6de263b9c669919e175cc7d1ac6c09
Author: Thierry Reding [off-list ref]

arm64/mm: Export set_direct_map_*_noflush() APIs

Drivers that use this may want to be built as a module, so export them.
quoted hunk ↗ jump to hunk
diff --git a/arch/arm64/mm/pageattr.c b/arch/arm64/mm/pageattr.c
index 132938b32eb16..9253c529f8aa5 100644
--- a/arch/arm64/mm/pageattr.c
+++ b/arch/arm64/mm/pageattr.c
@@ -262,6 +262,7 @@ int set_direct_map_invalid_noflush(struct page *page, unsigned int numpages)
 	return update_range_prot((unsigned long)page_address(page),
 				 PAGE_SIZE * numpages, set_mask, clear_mask);
 }
+EXPORT_SYMBOL(set_direct_map_invalid_noflush);
[Severity: High]
Are loadable modules going to silently fail to protect memory when using this
exported API?

If the kernel boots with a configuration where can_set_direct_map() is false
(e.g., rodata_full and debug_pagealloc are disabled), 
set_direct_map_invalid_noflush() returns 0 without modifying the page tables:

arch/arm64/mm/pageattr.c:set_direct_map_invalid_noflush() {
	...
	if (!can_set_direct_map())
		return 0;
	...
}

Because can_set_direct_map() is not exported, a module cannot check this
capability itself. The module will receive 0 (success) and mistakenly assume
the memory was successfully isolated.

For security features, this means content-protected memory remains accessible
in the kernel's linear mapping. This can break DRM guarantees by allowing the
CPU to read protected memory, or cause a kernel panic if the hardware enforces
protection but the CPU speculatively accesses the region via stale linear map
PTEs.
quoted hunk ↗ jump to hunk
 
 int set_direct_map_default_noflush(struct page *page, unsigned int numpages)
 {
@@ -274,6 +275,7 @@ int set_direct_map_default_noflush(struct page *page, unsigned int numpages)
 	return update_range_prot((unsigned long)page_address(page),
 				 PAGE_SIZE * numpages, set_mask, clear_mask);
 }
+EXPORT_SYMBOL(set_direct_map_default_noflush);
[Severity: High]
Does this apply the same silent failure logic when a module attempts to
restore the mapping?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260904-tegra-vpr-v6-0-79042cfa8de5@nvidia.com?part=4
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help