git: be6e357a3e51 - main - linuxkpi: Update `struct vm_area_struct` when an existing mapping is extended
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Mon, 07 Sep 2026 18:37:23 UTC
The branch main has been updated by dumbbell:
URL: https://cgit.FreeBSD.org/src/commit/?id=be6e357a3e51b7b24e205ef904f67333ca8e298c
commit be6e357a3e51b7b24e205ef904f67333ca8e298c
Author: Jean-Sébastien Pédron <dumbbell@FreeBSD.org>
AuthorDate: 2026-07-12 16:20:29 +0000
Commit: Jean-Sébastien Pédron <dumbbell@FreeBSD.org>
CommitDate: 2026-09-07 18:27:30 +0000
linuxkpi: Update `struct vm_area_struct` when an existing mapping is extended
With Mesa 26 and DRM drivers in Linux 6.13, userspace will try to extend
an existing mmap, at last push the end address further.
Before this change, the mapping was not updated, but userspace would try
to access a page after the initial end address, leading to a panic
triggered by the following assertion in `vm_fault_populate()`:
MPASS(fs->first_pindex <= pager_last);
Reviewed by: bz
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D58195
---
sys/compat/linuxkpi/common/src/linux_compat.c | 13 +++++++++++++
1 file changed, 13 insertions(+)
diff --git a/sys/compat/linuxkpi/common/src/linux_compat.c b/sys/compat/linuxkpi/common/src/linux_compat.c
index 4ac59bcfbb79..32f9ce8c1f5c 100644
--- a/sys/compat/linuxkpi/common/src/linux_compat.c
+++ b/sys/compat/linuxkpi/common/src/linux_compat.c
@@ -1404,6 +1404,19 @@ linux_file_mmap_single(struct file *fp, const struct file_operations *fop,
error = ESTALE;
vm_no_fault = 1;
} else {
+ if (ptr->vm_start == vmap->vm_start &&
+ ptr->vm_end <= vmap->vm_end) {
+ /*
+ * Userspace wants to grow an existing
+ * mapping. We already have a
+ * `vm_object_t' for this mapping. We
+ * just need to update the `struct
+ * vm_area_struct` to have the correct
+ * end address.
+ */
+ ptr->vm_end = vmap->vm_end;
+ }
+
error = EEXIST;
vm_no_fault = (ptr->vm_ops->fault == NULL);
}