git: be6e357a3e51 - main - linuxkpi: Update `struct vm_area_struct` when an existing mapping is extended

From: Jean-Sébastien Pédron <dumbbell_at_FreeBSD.org>
Date: Mon, 07 Sep 2026 18:37:23 UTC
The branch main has been updated by dumbbell:

URL: https://cgit.FreeBSD.org/src/commit/?id=be6e357a3e51b7b24e205ef904f67333ca8e298c

commit be6e357a3e51b7b24e205ef904f67333ca8e298c
Author:     Jean-Sébastien Pédron <dumbbell@FreeBSD.org>
AuthorDate: 2026-07-12 16:20:29 +0000
Commit:     Jean-Sébastien Pédron <dumbbell@FreeBSD.org>
CommitDate: 2026-09-07 18:27:30 +0000

    linuxkpi: Update `struct vm_area_struct` when an existing mapping is extended
    
    With Mesa 26 and DRM drivers in Linux 6.13, userspace will try to extend
    an existing mmap, at last push the end address further.
    
    Before this change, the mapping was not updated, but userspace would try
    to access a page after the initial end address, leading to a panic
    triggered by the following assertion in `vm_fault_populate()`:
    
        MPASS(fs->first_pindex <= pager_last);
    
    Reviewed by:    bz
    Sponsored by:   The FreeBSD Foundation
    Differential Revision: https://reviews.freebsd.org/D58195
---
 sys/compat/linuxkpi/common/src/linux_compat.c | 13 +++++++++++++
 1 file changed, 13 insertions(+)

diff --git a/sys/compat/linuxkpi/common/src/linux_compat.c b/sys/compat/linuxkpi/common/src/linux_compat.c
index 4ac59bcfbb79..32f9ce8c1f5c 100644
--- a/sys/compat/linuxkpi/common/src/linux_compat.c
+++ b/sys/compat/linuxkpi/common/src/linux_compat.c
@@ -1404,6 +1404,19 @@ linux_file_mmap_single(struct file *fp, const struct file_operations *fop,
 				error = ESTALE;
 				vm_no_fault = 1;
 			} else {
+				if (ptr->vm_start == vmap->vm_start &&
+				    ptr->vm_end <= vmap->vm_end) {
+					/*
+					 * Userspace wants to grow an existing
+					 * mapping. We already have a
+					 * `vm_object_t' for this mapping. We
+					 * just need to update the `struct
+					 * vm_area_struct` to have the correct
+					 * end address.
+					 */
+					ptr->vm_end = vmap->vm_end;
+				}
+
 				error = EEXIST;
 				vm_no_fault = (ptr->vm_ops->fault == NULL);
 			}