From nobody Tue Jun 23 21:06:17 2026 X-Original-To: dev-commits-src-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4glHfy1jlyz6j7L5 for ; Tue, 23 Jun 2026 21:06:18 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR1" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4glHfy12GBz3Lyl for ; Tue, 23 Jun 2026 21:06:18 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1782248778; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=+SDDoI9lQ34j4aoN5wPDKOzmfpawPirsgKVwhXyX/f4=; b=Gpc5EYOXsy/JMZHrlSoqdfNaQ7miX7pzXBKVKBNaRTtzNZdtFcxfcziq2BOTvzIxPrAoHU rPXY1I6tahV9kxJsrZnm+vo+TwzQoTey0psuPW8mVwCKWe5Fai89/7UM1VQyfQ81DxhJRd T/QDHLtXX5Wcefgg6EUtpIu7UiaL2lCz1tj4xd7fFNSkpU/4UBK54YNhb/cNVSKaAvMKkY Z6MbwcS3ONb2U0pbsLruF0PTob+zLC0yJ9zk10lLPKmp+KZCVvjc4wQqgXI805qFNPo2Jr HgHzw1UmQn84/d+28tXKySLNddkiLP/JR8Oj9ouVCJ/t+nGSdntphSdpAfZeyQ== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1782248778; a=rsa-sha256; cv=none; b=urgXkTtQz3HWps+o+G+HsrHO4OnaYn1qOMLQrrsJTamJ38mOZodWHS4Uqzania0txrG7po 73njs9gdUgdrjhPxyAWq9ZuykH3iL6JbXkca0JisVeFx1VqC3K4Omwaeokrnkpa/F3kRRL nig8aYF8dnibEDF9s/anfy6C9M/1Qewrbhm6k89/q8zEeyyx8KeiGL6mGXdvw6ClHtOBVc khKkh4Vcqyqff7f40HcmjhnOOugMw0h5pdrU+9JRK4zjTqRuHvATHh7U/+5I4PlVjgGUu+ r6ygFy/rQ8QML3HL7fKDCSvK95f2edr4if0YN7VfYMTzXPU4BbyIaSdz9wlQ4Q== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1782248778; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=+SDDoI9lQ34j4aoN5wPDKOzmfpawPirsgKVwhXyX/f4=; b=JqfgwecwRbXK6RBcBoyyEM+xPcxFhdBfqPEZoLz/m+zrfpkg7ZTmDOE4akfvUI8enY89hs 9eVetTo85yAHtg4HmJFVI81uTtPHE2bomCTeP6cmIqQRby6mHKaQG2vFfXq1dPI6BySAzE JP5jjO7ix2VyNYtmQrbD9NXfSY/JGvtWyXzJUekCP879awXO4HW0IKrfIXPhkS/MeGOXEs /XsGKd4TdgVxiVBO7Y3RY+ZFE0ZjHCQq4FbQm+PHDQIlXLuTCzJmYtYEcDuNHzrjj4tHRT fE3bHe2JVLPgl3ZiFgj3k/DKlwtdK1nhHYtecuF0qFqSVMXYLL+JTQOF4kdGRg== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4glHfx6DC3zr2D for ; Tue, 23 Jun 2026 21:06:17 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 1c67c by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Tue, 23 Jun 2026 21:06:17 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Konstantin Belousov Subject: git: 91413e8e6311 - main - linuxkpi ioctl handler: restore the user data pointer List-Id: Commit messages for the main branch of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-main@freebsd.org Sender: owner-dev-commits-src-main@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kib X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 91413e8e6311b4d4891dc2299d144feb31e04628 Auto-Submitted: auto-generated Date: Tue, 23 Jun 2026 21:06:17 +0000 Message-Id: <6a3af549.1c67c.7746ed4e@gitrepo.freebsd.org> The branch main has been updated by kib: URL: https://cgit.FreeBSD.org/src/commit/?id=91413e8e6311b4d4891dc2299d144feb31e04628 commit 91413e8e6311b4d4891dc2299d144feb31e04628 Author: Konstantin Belousov AuthorDate: 2026-06-16 22:12:01 +0000 Commit: Konstantin Belousov CommitDate: 2026-06-23 21:06:04 +0000 linuxkpi ioctl handler: restore the user data pointer instead of trying to hack around it with LINUX_IOCTL_MIN_PTR. Since linux file ioctl methods expect the user address in the data argument, this should work for all ioctls, including the variable-length cases like ibcore. Only do it for the FreeBSD ABI, where we know how to reliably access the original syscall arguments. Reviewed by: Ariel Ehrenberg , markj Discussed with: zishun.yi.dev@gmail.com Sponsored by: NVidia networking MFC after: 1 week Differential revision: https://reviews.freebsd.org/D57612 --- sys/compat/linuxkpi/common/src/linux_compat.c | 48 ++++++++++++++++++++++++--- 1 file changed, 44 insertions(+), 4 deletions(-) diff --git a/sys/compat/linuxkpi/common/src/linux_compat.c b/sys/compat/linuxkpi/common/src/linux_compat.c index 2fd502990eb3..e93963428195 100644 --- a/sys/compat/linuxkpi/common/src/linux_compat.c +++ b/sys/compat/linuxkpi/common/src/linux_compat.c @@ -51,6 +51,7 @@ #include #include #include +#include #include #include #include @@ -926,19 +927,39 @@ linux_file_ioctl_sub(struct file *fp, struct linux_file *filp, struct task_struct *task = current; unsigned size; int error; + bool direct; size = IOCPARM_LEN(cmd); /* refer to logic in sys_ioctl() */ + direct = false; if (size > 0) { /* * Setup hint for linux_copyin() and linux_copyout(). * - * Background: Linux code expects a user-space address - * while FreeBSD supplies a kernel-space address. + * Background: Linux kernel code expects to operate on + * userspace addresses, but FreeBSD's kern_ioctl() + * will generally provide a kernel address. For the + * native process ABI, where we know how to find the + * original address, we reach directly into the system + * call args to get it. Then, if the Linux driver + * copied out to that address, we copy the whole block + * back into the kernel buffer allocated by + * kern_ioctl() so that kern_ioctl() itself doesn't + * clobber the driver's data. + * + * Otherwise, fall back to the LINUX_IOCTL_MIN_PTR + * hack. */ task->bsd_ioctl_data = data; task->bsd_ioctl_len = size; - data = (void *)LINUX_IOCTL_MIN_PTR; + if ((td->td_pflags & TDP_KTHREAD) == 0 && + SV_PROC_ABI(td->td_proc) == SV_ABI_FREEBSD && + td->td_sa.code == SYS_ioctl) { + direct = true; + data = (void *)(uintptr_t)td->td_sa.args[2]; + } else { + data = (void *)LINUX_IOCTL_MIN_PTR; + } } else { /* fetch user-space pointer */ data = *(void **)data; @@ -968,11 +989,30 @@ linux_file_ioctl_sub(struct file *fp, struct linux_file *filp, error = ENOTTY; } } + if (error == 0 && size > 0 && (cmd & IOC_OUT) != 0 && direct) { + void *xdata; + int error1; + + /* + * Ensure that the copyout in sys_generic.c copies + * over the data which is possibly modified by the + * driver. A possible error from the copyin() is + * ignored since it is formally possible for the memory + * to become unaccessible in the meantime. Do the copying + * through the intermediate buffer instead of copying + * directly to bsd_ioctl_data, to ensure atomicity of + * the change with respect to the error. + */ + xdata = malloc(size, M_TEMP, M_WAITOK); + error1 = copyin(data, xdata, size); + if (error1 == 0) + memcpy(task->bsd_ioctl_data, xdata, size); + free(xdata, M_TEMP); + } if (size > 0) { task->bsd_ioctl_data = NULL; task->bsd_ioctl_len = 0; } - if (error == EWOULDBLOCK) { /* update kqfilter status, if any */ linux_file_kqfilter_poll(filp,