git: 8ffe2419e4e7 - main - linuxkpi: Fix assertion in `lkpi_vmf_insert_pfn_prot_locked()`

From: Jean-Sébastien Pédron <dumbbell_at_FreeBSD.org>
Date: Mon, 07 Sep 2026 19:41:58 UTC
The branch main has been updated by dumbbell:

URL: https://cgit.FreeBSD.org/src/commit/?id=8ffe2419e4e74e05e8042ccc3c0445a13b41a02f

commit 8ffe2419e4e74e05e8042ccc3c0445a13b41a02f
Author:     Jean-Sébastien Pédron <dumbbell@FreeBSD.org>
AuthorDate: 2026-06-25 23:07:11 +0000
Commit:     Jean-Sébastien Pédron <dumbbell@FreeBSD.org>
CommitDate: 2026-09-07 19:40:44 +0000

    linuxkpi: Fix assertion in `lkpi_vmf_insert_pfn_prot_locked()`
    
    Before this change, the assertion would not catch a page index matching
    the end address, even though the end address of a mapping is outside of
    that mapping.
    
    While here, add another assertion to catch page indexes outside of the
    expected range earlier.
    
    Also, pagefaulting an address outside of the mapping range should return
    `VM_FAULT_SIGBUS` instead of panicing.
    
    Reviewed by:    bz
    Sponsored by:   The FreeBSD Foundation
    Differential Revision: https://reviews.freebsd.org/D58194
---
 sys/compat/linuxkpi/common/src/linux_compat.c | 2 ++
 sys/compat/linuxkpi/common/src/linux_page.c   | 5 ++++-
 2 files changed, 6 insertions(+), 1 deletion(-)

diff --git a/sys/compat/linuxkpi/common/src/linux_compat.c b/sys/compat/linuxkpi/common/src/linux_compat.c
index 32f9ce8c1f5c..12e5852c8dc9 100644
--- a/sys/compat/linuxkpi/common/src/linux_compat.c
+++ b/sys/compat/linuxkpi/common/src/linux_compat.c
@@ -560,6 +560,8 @@ linux_cdev_pager_populate(vm_object_t vm_obj, vm_pindex_t pidx, int fault_type,
 		 */
 		*first = vmap->vm_pfn_first;
 		*last = *first + vmap->vm_pfn_count - 1;
+		MPASS(pidx >= *first);
+		MPASS(pidx <= *last);
 		err = VM_PAGER_OK;
 		break;
 	default:
diff --git a/sys/compat/linuxkpi/common/src/linux_page.c b/sys/compat/linuxkpi/common/src/linux_page.c
index e0385bf2d40a..14abc3376a1c 100644
--- a/sys/compat/linuxkpi/common/src/linux_page.c
+++ b/sys/compat/linuxkpi/common/src/linux_page.c
@@ -515,12 +515,15 @@ lkpi_vmf_insert_pfn_prot_locked(struct vm_area_struct *vma, unsigned long addr,
 	vm_page_t page;
 	vm_pindex_t pindex;
 
+	if (addr < vma->vm_start || addr >= vma->vm_end)
+		return (VM_FAULT_SIGBUS);
+
 	VM_OBJECT_ASSERT_WLOCKED(vm_obj);
 	vm_page_iter_init(&pages, vm_obj);
 	pindex = OFF_TO_IDX(addr - vma->vm_start);
 	if (vma->vm_pfn_count == 0)
 		vma->vm_pfn_first = pindex;
-	MPASS(pindex <= OFF_TO_IDX(vma->vm_end));
+	MPASS(pindex < OFF_TO_IDX(vma->vm_end));
 
 retry:
 	page = vm_page_grab_iter(vm_obj, pindex, VM_ALLOC_NOCREAT, &pages);