mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: "Lorenzo Stoakes (ARM)" <ljs@kernel.org>
To: Suren Baghdasaryan <surenb@google.com>
Cc: Andrew Morton <akpm@linux-foundation.org>,
	 "Liam R. Howlett" <liam@infradead.org>,
	Vlastimil Babka <vbabka@kernel.org>,
	 Jann Horn <jannh@google.com>, Pedro Falcato <pfalcato@suse.de>,
	 David Hildenbrand <david@kernel.org>,
	Mike Rapoport <rppt@kernel.org>, Michal Hocko <mhocko@suse.com>,
	 Jonathan Corbet <corbet@lwn.net>,
	Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
	 Dennis Dalessandro <dennis.dalessandro@cornelisnetworks.com>,
	Jason Gunthorpe <jgg@ziepe.ca>,
	 Leon Romanovsky <leon@kernel.org>,
	Paul Moore <paul@paul-moore.com>,
	 Stephen Smalley <stephen.smalley.work@gmail.com>,
	Jaroslav Kysela <perex@perex.cz>, Takashi Iwai <tiwai@suse.com>,
	 Alexei Starovoitov <ast@kernel.org>,
	Daniel Borkmann <daniel@iogearbox.net>,
	 Andrii Nakryiko <andrii@kernel.org>,
	Eduard Zingerman <eddyz87@gmail.com>,
	 Kumar Kartikeya Dwivedi <memxor@gmail.com>,
	Zi Yan <ziy@nvidia.com>,
	 Baolin Wang <baolin.wang@linux.alibaba.com>,
	Nico Pache <nico.pache@linux.dev>,
	 Ryan Roberts <ryan.roberts@arm.com>, Dev Jain <dev.jain@arm.com>,
	Barry Song <baohua@kernel.org>,
	 Lance Yang <lance.yang@linux.dev>,
	Usama Arif <usama.arif@linux.dev>,
	 Kiryl Shutsemau <kas@kernel.org>,
	Doug Gilbert <dgilbert@interlog.com>,
	 "James E.J. Bottomley" <James.Bottomley@hansenpartnership.com>,
	"Martin K. Petersen" <mkp@kernel.org>,
	 Jaya Kumar <jayalk@intworks.biz>,
	Simona Vetter <simona@ffwll.ch>, Helge Deller <deller@gmx.de>,
	 Sebastian Reichel <sre@kernel.org>,
	John Hubbard <jhubbard@nvidia.com>, Peter Xu <peterx@redhat.com>,
	 Masami Hiramatsu <mhiramat@kernel.org>,
	Oleg Nesterov <oleg@redhat.com>,
	 Peter Zijlstra <peterz@infradead.org>,
	Thomas Gleixner <tglx@kernel.org>,
	 Ingo Molnar <mingo@redhat.com>, Borislav Petkov <bp@alien8.de>,
	 Dave Hansen <dave.hansen@linux.intel.com>,
	x86@kernel.org, Arnaldo Carvalho de Melo <acme@kernel.org>,
	 Namhyung Kim <namhyung@kernel.org>,
	Mark Rutland <mark.rutland@arm.com>,
	 Rik van Riel <riel@surriel.com>, Harry Yoo <harry@kernel.org>,
	Juri Lelli <juri.lelli@redhat.com>,
	 Vincent Guittot <vincent.guittot@linaro.org>,
	Maarten Lankhorst <maarten.lankhorst@linux.intel.com>,
	 Maxime Ripard <mripard@kernel.org>,
	Thomas Zimmermann <tzimmermann@suse.de>,
	 David Airlie <airlied@gmail.com>, Will Deacon <will@kernel.org>,
	 "Aneesh Kumar K.V" <aneesh.kumar@kernel.org>,
	Nick Piggin <npiggin@gmail.com>, Arnd Bergmann <arnd@arndb.de>,
	 Muchun Song <muchun.song@linux.dev>,
	Oscar Salvador <osalvador@suse.de>,
	 "Matthew Wilcox (Oracle)" <willy@infradead.org>,
	Jan Kara <jack@suse.cz>, Marc Zyngier <maz@kernel.org>,
	 Oliver Upton <oupton@kernel.org>,
	Catalin Marinas <catalin.marinas@arm.com>,
	 Madhavan Srinivasan <maddy@linux.ibm.com>,
	Anup Patel <anup@brainfault.org>, Paul Walmsley <pjw@kernel.org>,
	 Palmer Dabbelt <palmer@dabbelt.com>,
	Albert Ou <aou@eecs.berkeley.edu>,
	 Christian Borntraeger <borntraeger@linux.ibm.com>,
	Janosch Frank <frankja@linux.ibm.com>,
	 Claudio Imbrenda <imbrenda@linux.ibm.com>,
	Alexander Gordeev <agordeev@linux.ibm.com>,
	 Gerald Schaefer <gerald.schaefer@linux.ibm.com>,
	Heiko Carstens <hca@linux.ibm.com>,
	 Vasily Gorbik <gor@linux.ibm.com>,
	"David S. Miller" <davem@davemloft.net>,
	 Andreas Larsson <andreas@gaisler.com>,
	Alexander Viro <viro@zeniv.linux.org.uk>,
	 Christian Brauner <brauner@kernel.org>,
	Matthew Brost <matthew.brost@intel.com>,
	 Joshua Hahn <joshua.hahnjy@gmail.com>,
	Rakie Kim <rakie.kim@sk.com>, Byungchul Park <byungchul@sk.com>,
	 Gregory Price <gourry@gourry.net>,
	Ying Huang <ying.huang@linux.alibaba.com>,
	 Alistair Popple <apopple@nvidia.com>,
	Chris Li <chrisl@kernel.org>, Kairui Song <kasong@tencent.com>,
	 Kemeng Shi <shikemeng@huaweicloud.com>,
	Nhat Pham <nphamcs@gmail.com>, Baoquan He <baoquan.he@linux.dev>,
	 Youngjun Park <youngjun.park@lge.com>,
	Johannes Weiner <hannes@cmpxchg.org>,
	 Qi Zheng <qi.zheng@linux.dev>,
	Shakeel Butt <shakeel.butt@linux.dev>,
	 Axel Rasmussen <axelrasmussen@google.com>,
	Yuanchu Xie <yuanchu@google.com>, Wei Xu <weixugc@google.com>,
	 Chengming Zhou <chengming.zhou@linux.dev>,
	Michal Hocko <mhocko@kernel.org>,
	 Miklos Szeredi <miklos@szeredi.hu>, Xu Xin <xu.xin@linux.dev>,
	linux-mm@kvack.org,  linux-kernel@vger.kernel.org,
	linux-doc@vger.kernel.org, linux-usb@vger.kernel.org,
	 linux-rdma@vger.kernel.org, selinux@vger.kernel.org,
	linux-sound@vger.kernel.org,  bpf@vger.kernel.org,
	linux-scsi@vger.kernel.org, linux-fbdev@vger.kernel.org,
	 dri-devel@lists.freedesktop.org,
	linux-trace-kernel@vger.kernel.org,
	 linux-perf-users@vger.kernel.org, linux-arch@vger.kernel.org,
	linux-fsdevel@vger.kernel.org,
	 linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev,
	linuxppc-dev@lists.ozlabs.org,  kvm@vger.kernel.org,
	kvm-riscv@lists.infradead.org, linux-riscv@lists.infradead.org,
	 linux-s390@vger.kernel.org, sparclinux@vger.kernel.org,
	fuse-devel@lists.linux.dev
Subject: Re: [PATCH v3 04/40] mm: consistently validate VMA state after mmap[_prepare] hooks
Date: Wed, 23 Sep 2026 18:00:41 +0100	[thread overview]
Message-ID: <arQFp_bwAHnmkp2V@gremlin> (raw)
In-Reply-To: <CAJuCfpELP9Ups5XeS3PNbF=VtrfkYbkwRj-LuEHd7bLsTw4LUw@mail.gmail.com>

On Wed, Sep 23, 2026 at 09:47:20AM -0700, Suren Baghdasaryan wrote:
> On Thu, Sep 17, 2026 at 9:25 AM Lorenzo Stoakes (ARM) <ljs@kernel.org> wrote:
> >
> > When the f_op->mmap_prepare or deprecated f_op->mmap hooks are invoked, the
> > driver might have done something crazy that is not permitted by the kernel.
> >
> > Currently we check for three such cases in __mmap_new_file_vma(), but only
> > if the legacy f_op->mmap hook is used:
> >
> > * Did sparc ADI result in invalid flags?
> >
> > * Did the driver alter vma->vm_start?
> >
> > * Did the driver make a file-backed mapping on a read-only file writable?
> >
> > Generalise these checks for both mmap_prepare and mmap and apply to all
> > invocations of mmap_file(), the f_op->mmap and f_op->mmap_prepare handling
> > in the core VMA code and the mmap_prepare compatibility layer.
> >
> > Also extend the vm_start check to vm_end also - drivers must not change the
> > VMA range at all.
> >
> > We also WARN_ON_ONCE() on these conditions as they are things that should
> > simply not occur in the kernel and it's important to call it out when it
> > does.
> >
> > We invoke mmap_prepare_validate() after mmap_action_prepare(), as mmap
> > actions often manipulate state in the descriptor thus providing the final
> > state the VMA will be derived from.
> >
> > Also call mmap_validate_vma_flags() in insert_vm_struct() to ensure that
> > special regions which are inserted (such as a VDSO or VVAR) also satisfy
> > the sanity checks.
> >
> > This way every VMA established through an mmap hook, whether via mmap() or
> > the compatibility layer, or inserted via insert_vm_struct(), has been
> > validated. brk() VMAs never pass through a driver hook and so need no such
> > check.
> >
> > While we're here, also fixup a couple disjoint blocks of #ifdef CONFIG_MMU.
> >
> > Finally, update the VMA userland tests to reflect the change.
> >
> > Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
>
> Reviewed-by: Suren Baghdasaryan <surenb@google.com>

Thanks!

>
> > ---
> >  mm/internal.h                   |  51 ++++++++++++--------
> >  mm/util.c                       |  19 ++++++--
> >  mm/vma.c                        | 100 ++++++++++++++++++++++++++++++++++------
> >  mm/vma.h                        |  25 ++++++++--
> >  tools/testing/vma/include/dup.h |  10 ++++
> >  5 files changed, 163 insertions(+), 42 deletions(-)
> >
> > diff --git a/mm/internal.h b/mm/internal.h
> > index fe576d468af4..970fb34898b2 100644
> > --- a/mm/internal.h
> > +++ b/mm/internal.h
> > @@ -213,6 +213,24 @@ static inline void *folio_raw_mapping(const struct folio *folio)
> >         return (void *)(mapping & ~FOLIO_MAPPING_FLAGS);
> >  }
> >
> > +/*
> > + * If the VMA has a close hook then close it, and since closing it might leave
> > + * it in an inconsistent state which makes the use of any hooks suspect, clear
> > + * them down by installing dummy empty hooks.
> > + */
> > +static inline void vma_close(struct vm_area_struct *vma)
> > +{
> > +       if (vma->vm_ops && vma->vm_ops->close) {
> > +               vma->vm_ops->close(vma);
> > +
> > +               /*
> > +                * The mapping is in an inconsistent state, and no further hooks
> > +                * may be invoked upon it.
> > +                */
> > +               vma->vm_ops = &vma_dummy_vm_ops;
> > +       }
> > +}
> > +
> >  /*
> >   * This is a file-backed mapping, and is about to be memory mapped - invoke its
> >   * mmap hook and safely handle error conditions. On error, VMA hooks will be
> > @@ -225,8 +243,12 @@ static inline void *folio_raw_mapping(const struct folio *folio)
> >   */
> >  static inline int mmap_file(struct file *file, struct vm_area_struct *vma)
> >  {
> > -       int err = vfs_mmap(file, vma);
> > +       const unsigned long prev_start = vma->vm_start;
> > +       const unsigned long prev_end = vma->vm_end;
> > +       const vma_flags_t prev_flags = vma->flags;
>
> nit: Might be just me but when I see prev_XXX in VMA-related code I
> picture previous VMA in the address space. Maybe call these orig_XXX?

Sure, will change.

>
> > +       int err;
> >
> > +       err = vfs_mmap(file, vma);
> >         /*
> >          * Either we tried to call the file hook for mmap() and an error arose
> >          * or a driver set vma->vm_ops = NULL intending there to be no VMA
> > @@ -239,26 +261,17 @@ static inline int mmap_file(struct file *file, struct vm_area_struct *vma)
> >          */
> >         if (unlikely(err || !vma->vm_ops))
> >                 vma->vm_ops = &vma_dummy_vm_ops;
> > +       if (unlikely(err))
> > +               return err;
> >
> > -       return err;
> > -}
> > -
> > -/*
> > - * If the VMA has a close hook then close it, and since closing it might leave
> > - * it in an inconsistent state which makes the use of any hooks suspect, clear
> > - * them down by installing dummy empty hooks.
> > - */
> > -static inline void vma_close(struct vm_area_struct *vma)
> > -{
> > -       if (vma->vm_ops && vma->vm_ops->close) {
> > -               vma->vm_ops->close(vma);
> > -
> > -               /*
> > -                * The mapping is in an inconsistent state, and no further hooks
> > -                * may be invoked upon it.
> > -                */
> > -               vma->vm_ops = &vma_dummy_vm_ops;
> > +       err = mmap_hook_validate(prev_start, prev_end, &prev_flags, vma);
> > +       if (unlikely(err)) {
> > +               vma->vm_start = prev_start;
> > +               vma->vm_end = prev_end;
> > +               vma_close(vma);
> >         }
> > +
> > +       return err;
> >  }
> >
> >  /* unmap_vmas is in mm/memory.c */
> > diff --git a/mm/util.c b/mm/util.c
> > index 016932780925..bdd5923eebc7 100644
> > --- a/mm/util.c
> > +++ b/mm/util.c
> > @@ -1224,19 +1224,28 @@ EXPORT_SYMBOL(compat_set_desc_from_vma);
> >  int __compat_vma_mmap(struct vm_area_desc *desc,
> >                       struct vm_area_struct *vma)
> >  {
> > +       struct vm_area_desc prev_desc;
> >         int err;
> >
> > +       /* Derive state prior to mmap_prepare hook. */
> > +       compat_set_desc_from_vma(&prev_desc, desc->file, vma);
> >         /* Perform any preparatory tasks for mmap action. */
> >         err = mmap_action_prepare(desc);
> > -       if (err) {
> > -               if (desc->vm_file != vma->vm_file)
> > -                       fput(desc->vm_file);
> > -               return err;
> > -       }
> > +       if (err)
> > +               goto err_put;
> > +       /* Check the caller did nothing crazy. */
> > +       err = mmap_prepare_validate(&prev_desc, desc);
> > +       if (err)
> > +               goto err_put;
> >         /* Update the VMA from the descriptor. */
> >         compat_set_vma_from_desc(vma, desc);
> >         /* Complete any specified mmap actions. */
> >         return mmap_action_complete(vma, &desc->action, /*is_compat=*/true);
> > +
> > +err_put:
> > +       if (desc->vm_file != vma->vm_file)
> > +               fput(desc->vm_file);
> > +       return err;
> >  }
> >  EXPORT_SYMBOL(__compat_vma_mmap);
> >
> > diff --git a/mm/vma.c b/mm/vma.c
> > index 05d2c676672e..d6ed10cefc8f 100644
> > --- a/mm/vma.c
> > +++ b/mm/vma.c
> > @@ -2623,16 +2623,6 @@ static int __mmap_new_file_vma(struct mmap_state *map,
> >                 return error;
> >         }
> >
> > -       /* Drivers cannot alter the address of the VMA. */
> > -       WARN_ON_ONCE(map->addr != vma->vm_start);
> > -       /*
> > -        * Drivers should not permit writability when previously it was
> > -        * disallowed.
> > -        */
> > -       VM_WARN_ON_ONCE(!vma_flags_same_pair(&map->vma_flags, &vma->flags) &&
> > -                       !vma_flags_test(&map->vma_flags, VMA_MAYWRITE_BIT) &&
> > -                       vma_test(vma, VMA_MAYWRITE_BIT));
> > -
> >         map->vma_flags = vma->flags;
> >
> >         return 0;
> > @@ -2710,11 +2700,6 @@ static int __mmap_new_vma(struct mmap_state *map, struct vm_area_struct **vmap,
> >                 vma->flags = map->vma_flags;
> >         }
> >
> > -#ifdef CONFIG_SPARC64
> > -       /* TODO: Fix SPARC ADI! */
> > -       WARN_ON_ONCE(!arch_validate_flags(map->vm_flags));
> > -#endif
> > -
> >         /* Lock the VMA since it is modified after insertion into VMA tree */
> >         vma_start_write(vma);
> >         vma_iter_store_new(vmi, vma);
> > @@ -2777,6 +2762,80 @@ static void __mmap_complete(struct mmap_state *map, struct vm_area_struct *vma)
> >         vma_set_page_prot(vma);
> >  }
> >
> > +/* Check to ensure that the VMA flags of a newly mapped VMA are sane. */
> > +static int mmap_validate_vma_flags(const vma_flags_t *flags)
> > +{
> > +#ifdef CONFIG_SPARC64
> > +       const vm_flags_t legacy_flags = vma_flags_to_legacy(*flags);
> > +
> > +       /* TODO: Fix SPARC ADI! */
> > +       if (WARN_ON_ONCE(!arch_validate_flags(legacy_flags)))
> > +               return -EINVAL;
> > +#endif
> > +
> > +       return 0;
> > +}
> > +
> > +/* Check to ensure a driver hasn't done something crazy. */
> > +static int mmap_validate(unsigned long prev_start, unsigned long prev_end,
> > +                        unsigned long curr_start, unsigned long curr_end,
> > +                        const vma_flags_t *prev_flags,
> > +                        const vma_flags_t *curr_flags)
> > +{
> > +       bool was_maywrite, is_maywrite;
> > +
> > +       /* Drivers cannot alter the range of the VMA. */
> > +       if (WARN_ON_ONCE(prev_start != curr_start || prev_end != curr_end))
> > +               return -EINVAL;
> > +
> > +       was_maywrite = vma_flags_test(prev_flags, VMA_MAYWRITE_BIT);
> > +       is_maywrite = vma_flags_test(curr_flags, VMA_MAYWRITE_BIT);
> > +
> > +       /* A driver may not make a previously unwritable mapping writable. */
> > +       if (WARN_ON_ONCE(!was_maywrite && is_maywrite))
> > +               return -EINVAL;
> > +
> > +       return mmap_validate_vma_flags(curr_flags);
> > +}
> > +
> > +/**
> > + * mmap_prepare_validate() - Ensure the driver hasn't violated invariants in its
> > + * f_op->mmap_prepare hook.
> > + * @prev_desc: The VMA descriptor prior to the mmap_prepare hook being called.
> > + * @desc: The VMA descriptor after the mmap_prepare hook has been called.
> > + *
> > + * Returns: 0 on success, otherwise an error.
> > + */
> > +int mmap_prepare_validate(const struct vm_area_desc *prev_desc,
> > +                         const struct vm_area_desc *desc)
> > +{
> > +       return mmap_validate(prev_desc->start, prev_desc->end,
> > +                            desc->start, desc->end,
> > +                            &prev_desc->vma_flags, &desc->vma_flags);
> > +}
> > +
> > +/**
> > + * mmap_hook_validate() - Ensure the driver hasn't violated invariants in
> > + * its f_op->mmap hook.
> > + * @prev_start: The start of the mapping prior to the mmap hook.
> > + * @prev_end: The end of the mapping prior to the mmap hook.
> > + * @prev_flags: The VMA flags set for the VMA prior to the mmap hook.
> > + * @vma: The VMA after the hook has been applied.
> > + *
> > + * Returns: 0 on success, otherwise an error.
> > + */
> > +int mmap_hook_validate(unsigned long prev_start, unsigned long prev_end,
> > +                      const vma_flags_t *prev_flags,
> > +                      const struct vm_area_struct *vma)
> > +{
> > +       const unsigned long start = vma->vm_start;
> > +       const unsigned long end = vma->vm_end;
> > +       const vma_flags_t *flags = &vma->flags;
> > +
> > +       return mmap_validate(prev_start, prev_end, start, end, prev_flags,
> > +                            flags);
> > +}
> > +
> >  static int call_action_prepare(struct mmap_state *map,
> >                                struct vm_area_desc *desc)
> >  {
> > @@ -2803,6 +2862,7 @@ static int call_action_prepare(struct mmap_state *map,
> >  static int call_mmap_prepare(struct mmap_state *map,
> >                 struct vm_area_desc *desc)
> >  {
> > +       const struct vm_area_desc prev_desc = *desc;
> >         int err;
> >
> >         /* Invoke the hook. */
> > @@ -2822,6 +2882,11 @@ static int call_mmap_prepare(struct mmap_state *map,
> >         if (err)
> >                 return err;
> >
> > +       /* Check the caller did nothing crazy. */
> > +       err = mmap_prepare_validate(&prev_desc, desc);
> > +       if (err)
> > +               return err;
> > +
> >         /* Update fields permitted to be changed. */
> >         map->pgoff = desc->pgoff;
> >         map->vma_flags = desc->vma_flags;
> > @@ -3457,10 +3522,15 @@ int __vm_munmap(unsigned long start, size_t len, bool unlock)
> >  int insert_vm_struct(struct mm_struct *mm, struct vm_area_struct *vma)
> >  {
> >         unsigned long charged = vma_pages(vma);
> > +       int err;
> >
> >         if (find_vma_intersection(mm, vma->vm_start, vma->vm_end))
> >                 return -ENOMEM;
> >
> > +       err = mmap_validate_vma_flags(&vma->flags);
> > +       if (err)
> > +               return err;
> > +
> >         if (vma_test(vma, VMA_ACCOUNT_BIT) &&
> >              security_vm_enough_memory_mm(mm, charged))
> >                 return -ENOMEM;
> > diff --git a/mm/vma.h b/mm/vma.h
> > index f15faa83f3d6..b2c3bc832a48 100644
> > --- a/mm/vma.h
> > +++ b/mm/vma.h
> > @@ -782,14 +782,19 @@ struct vm_area_struct *vm_area_alloc(struct mm_struct *mm);
> >  struct vm_area_struct *vm_area_dup(struct vm_area_struct *orig);
> >  void vm_area_free(struct vm_area_struct *vma);
> >
> > -/* vma_exec.c */
> >  #ifdef CONFIG_MMU
> > +int mmap_prepare_validate(const struct vm_area_desc *prev_desc,
> > +                         const struct vm_area_desc *desc);
> > +
> > +int mmap_hook_validate(unsigned long prev_start, unsigned long prev_end,
> > +                      const vma_flags_t *prev_flags,
> > +                      const struct vm_area_struct *vma);
> > +
> > +/* vma_exec.c */
> >  int create_init_stack_vma(struct mm_struct *mm, struct vm_area_struct **vmap,
> >                           unsigned long *top_mem_p);
> >  int relocate_vma_down(struct vm_area_struct *vma, unsigned long shift);
> > -#endif
> >
> > -#ifdef CONFIG_MMU
> >  /*
> >   * Denies creating a writable executable mapping or gaining executable permissions.
> >   *
> > @@ -838,6 +843,20 @@ static inline bool map_deny_write_exec(const vma_flags_t *old,
> >
> >         return false;
> >  }
> > +#else
> > +static inline int mmap_prepare_validate(const struct vm_area_desc *prev_desc,
> > +                                       const struct vm_area_desc *desc)
> > +{
> > +       return 0;
> > +}
> > +
> > +static inline int mmap_hook_validate(unsigned long prev_start,
> > +                                    unsigned long prev_end,
> > +                                    const vma_flags_t *prev_flags,
> > +                                    const struct vm_area_struct *vma)
> > +{
> > +       return 0;
> > +}
> >  #endif
> >
> >  struct vm_area_struct *__install_special_mapping(struct mm_struct *mm,
> > diff --git a/tools/testing/vma/include/dup.h b/tools/testing/vma/include/dup.h
> > index 2fd422789717..2986ae6ca1e5 100644
> > --- a/tools/testing/vma/include/dup.h
> > +++ b/tools/testing/vma/include/dup.h
> > @@ -1359,13 +1359,23 @@ static inline int vfs_mmap_prepare(struct file *file, struct vm_area_desc *desc)
> >         return file->f_op->mmap_prepare(desc);
> >  }
> >
> > +int mmap_prepare_validate(const struct vm_area_desc *prev_desc,
> > +                         const struct vm_area_desc *desc);
> > +
> >  static inline int __compat_vma_mmap(struct vm_area_desc *desc,
> >                 struct vm_area_struct *vma)
> >  {
> > +       struct vm_area_desc prev_desc;
> >         int err;
> >
> > +       /* Derive state prior to mmap_prepare hook. */
> > +       compat_set_desc_from_vma(&prev_desc, desc->file, vma);
> >         /* Perform any preparatory tasks for mmap action. */
> >         err = mmap_action_prepare(desc);
> > +       if (err)
> > +               return err;
> > +       /* Check the caller did nothing crazy. */
> > +       err = mmap_prepare_validate(&prev_desc, desc);
> >         if (err)
> >                 return err;
> >         /* Update the VMA from the descriptor. */
> >
> > --
> > 2.55.0
> >

--
Cheers, Lorenzo

  reply	other threads:[~2026-09-23 17:01 UTC|newest]

Thread overview: 74+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-17 16:22 [PATCH v3 00/40] mm: make VMA flag semantics explicit, eliminate VM_SPECIAL Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 01/40] mm/vma: fix mmap_prepare file handling, remove file_doesnt_need_get Lorenzo Stoakes (ARM)
2026-09-23 15:21   ` Suren Baghdasaryan
2026-09-23 15:46     ` Lorenzo Stoakes (ARM)
2026-09-23 15:59       ` Suren Baghdasaryan
2026-09-24  2:20   ` Zi Yan
2026-09-24 10:03     ` Lorenzo Stoakes (ARM)
2026-09-24 16:28   ` Gregory Price
2026-09-24 19:00   ` Liam R. Howlett
2026-09-17 16:22 ` [PATCH v3 02/40] mm/vma: predicate setting mmap_prepare VMA fields on new vma alloc Lorenzo Stoakes (ARM)
2026-09-23 15:32   ` Suren Baghdasaryan
2026-09-23 15:53     ` Lorenzo Stoakes (ARM)
2026-09-23 16:09       ` Suren Baghdasaryan
2026-09-23 17:07         ` Lorenzo Stoakes (ARM)
2026-09-23 17:33   ` Lorenzo Stoakes (ARM)
2026-09-24  2:25   ` Zi Yan
2026-09-17 16:22 ` [PATCH v3 03/40] mm/vma: introduce and use vma_[flags_]can_merge() Lorenzo Stoakes (ARM)
2026-09-23 16:23   ` Suren Baghdasaryan
2026-09-24  2:27   ` Zi Yan
2026-09-24 16:38   ` Gregory Price
2026-09-17 16:22 ` [PATCH v3 04/40] mm: consistently validate VMA state after mmap[_prepare] hooks Lorenzo Stoakes (ARM)
2026-09-23 16:47   ` Suren Baghdasaryan
2026-09-23 17:00     ` Lorenzo Stoakes (ARM) [this message]
2026-09-24  2:52   ` Zi Yan
2026-09-24 10:06     ` Lorenzo Stoakes (ARM)
2026-09-24 17:17   ` Gregory Price
2026-09-17 16:22 ` [PATCH v3 05/40] mm/vma: ensure mmap_prepare doesn't set actions on a mergeable vma Lorenzo Stoakes (ARM)
2026-09-24 18:00   ` Gregory Price
2026-09-24 19:28   ` Zi Yan
2026-09-25  7:28   ` Suren Baghdasaryan
2026-09-17 16:22 ` [PATCH v3 06/40] mm: make map_kernel_pages_[prepare,complete] internal and unexported Lorenzo Stoakes (ARM)
2026-09-24 19:30   ` Zi Yan
2026-09-25  7:35     ` Suren Baghdasaryan
2026-09-17 16:22 ` [PATCH v3 07/40] mm/vma: tidy up map kernel pages enum values Lorenzo Stoakes (ARM)
2026-09-24 19:30   ` Zi Yan
2026-09-25  7:37     ` Suren Baghdasaryan
2026-09-17 16:22 ` [PATCH v3 08/40] mm: add mmap action for discontiguous kernel page mapping Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 09/40] docs: filesystems: update mmap_prepare docs for discontig kernel pgs Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 10/40] drivers/usb/mon: update to use mmap_prepare + map kernel pages Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 11/40] infiniband: update hfi1 to use remap_vmalloc_range() Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 12/40] selinux: reject writable opens of policy file, drop mmap shared/write check Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 13/40] ALSA: pcm: use vm_insert_page() to map PCM status page Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 14/40] bpf: arena: mark arena_map_mmap() mappings VM_MIXEDMAP Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 15/40] mm/vma: add vma[_flags]_is_kernel_owned() predicates Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 16/40] mm/vma: only allow mmap to clear VMA_MAYWRITE_BIT if kernel-owned Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 17/40] mm/vma: add and use vma_[flags]_is_fixed_mapping Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 18/40] scsi: sg: convert mmap hook to mmap_prepare and rework Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 19/40] fbdev: defio: assert FBINFO_VIRTFB, drop VM_IO, add VM_MIXEDMAP Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 20/40] HSI: cmt_speech: convert mmap hook to mmap_prepare, refactor Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 21/40] mm/gup: error out early on !VMA_MAYREAD_BIT VMAs Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 22/40] uprobes: remove VM_IO, set VM_MIXEDMAP for mapped kernel pages Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 23/40] mm/mlock: clear VMA_LOCKED_MASK over mmap callback Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 24/40] mm/mlock: eliminate weird VMA_IO_BIT abuse and simplify Lorenzo Stoakes (ARM)
2026-09-23 20:06   ` Zi Yan
2026-09-24 10:21     ` Lorenzo Stoakes (ARM)
2026-09-24 15:50       ` Zi Yan
2026-09-17 16:22 ` [PATCH v3 25/40] mm/vma: enforce that only kernel-owned mappings may set VMA_IO_BIT Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 26/40] mm: remove VMA_IO_BIT check in vma[_flags]_is_kernel_owned() Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 27/40] mm: remove hugetlb_inline.h Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 28/40] mm: rename is_vm_hugetlb_page() to vma_is_hugetlb() Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 29/40] mm: drop some redundant checks around hugetlb VMAs Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 30/40] mm/madvise: update is_valid_guard_vma() to use vma_can_merge() Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 31/40] mm/vma: introduce vma[_flags]_is_persistent() Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 32/40] mm/uffd: use predicates for userfaultfd checks Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 33/40] mm/madvise: use predicates for madvise(..., MADV_DOFORK) Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 34/40] mm: eliminate VMA_SPECIAL_FLAGS usage when hugetlb explicitly tested Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 35/40] mm: eliminate VMA_SPECIAL_FLAGS check in lru_gen_look_around() Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 36/40] mm: avoid use of VMA_SPECIAL_FLAGS in migrate_vma_setup() Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 37/40] mm: eliminate VM_SPECIAL, VMA_SPECIAL_FLAGS Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 38/40] fuse: dax: do not set VM_MIXEDMAP Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 39/40] mm/huge_memory: remove vma_is_special_huge() Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 40/40] mm/vma: introduce and use vma[_flags]_can_gup() Lorenzo Stoakes (ARM)
2026-09-17 21:23 ` [PATCH v3 00/40] mm: make VMA flag semantics explicit, eliminate VM_SPECIAL Andrew Morton
2026-09-23  8:57 ` Lorenzo Stoakes (ARM)

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=arQFp_bwAHnmkp2V@gremlin \
    --to=ljs@kernel.org \
    --cc=James.Bottomley@hansenpartnership.com \
    --cc=acme@kernel.org \
    --cc=agordeev@linux.ibm.com \
    --cc=airlied@gmail.com \
    --cc=akpm@linux-foundation.org \
    --cc=andreas@gaisler.com \
    --cc=andrii@kernel.org \
    --cc=aneesh.kumar@kernel.org \
    --cc=anup@brainfault.org \
    --cc=aou@eecs.berkeley.edu \
    --cc=apopple@nvidia.com \
    --cc=arnd@arndb.de \
    --cc=ast@kernel.org \
    --cc=axelrasmussen@google.com \
    --cc=baohua@kernel.org \
    --cc=baolin.wang@linux.alibaba.com \
    --cc=baoquan.he@linux.dev \
    --cc=borntraeger@linux.ibm.com \
    --cc=bp@alien8.de \
    --cc=bpf@vger.kernel.org \
    --cc=brauner@kernel.org \
    --cc=byungchul@sk.com \
    --cc=catalin.marinas@arm.com \
    --cc=chengming.zhou@linux.dev \
    --cc=chrisl@kernel.org \
    --cc=corbet@lwn.net \
    --cc=daniel@iogearbox.net \
    --cc=dave.hansen@linux.intel.com \
    --cc=davem@davemloft.net \
    --cc=david@kernel.org \
    --cc=deller@gmx.de \
    --cc=dennis.dalessandro@cornelisnetworks.com \
    --cc=dev.jain@arm.com \
    --cc=dgilbert@interlog.com \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=eddyz87@gmail.com \
    --cc=frankja@linux.ibm.com \
    --cc=fuse-devel@lists.linux.dev \
    --cc=gerald.schaefer@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=gourry@gourry.net \
    --cc=gregkh@linuxfoundation.org \
    --cc=hannes@cmpxchg.org \
    --cc=harry@kernel.org \
    --cc=hca@linux.ibm.com \
    --cc=imbrenda@linux.ibm.com \
    --cc=jack@suse.cz \
    --cc=jannh@google.com \
    --cc=jayalk@intworks.biz \
    --cc=jgg@ziepe.ca \
    --cc=jhubbard@nvidia.com \
    --cc=joshua.hahnjy@gmail.com \
    --cc=juri.lelli@redhat.com \
    --cc=kas@kernel.org \
    --cc=kasong@tencent.com \
    --cc=kvm-riscv@lists.infradead.org \
    --cc=kvm@vger.kernel.org \
    --cc=kvmarm@lists.linux.dev \
    --cc=lance.yang@linux.dev \
    --cc=leon@kernel.org \
    --cc=liam@infradead.org \
    --cc=linux-arch@vger.kernel.org \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-doc@vger.kernel.org \
    --cc=linux-fbdev@vger.kernel.org \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=linux-rdma@vger.kernel.org \
    --cc=linux-riscv@lists.infradead.org \
    --cc=linux-s390@vger.kernel.org \
    --cc=linux-scsi@vger.kernel.org \
    --cc=linux-sound@vger.kernel.org \
    --cc=linux-trace-kernel@vger.kernel.org \
    --cc=linux-usb@vger.kernel.org \
    --cc=linuxppc-dev@lists.ozlabs.org \
    --cc=maarten.lankhorst@linux.intel.com \
    --cc=maddy@linux.ibm.com \
    --cc=mark.rutland@arm.com \
    --cc=matthew.brost@intel.com \
    --cc=maz@kernel.org \
    --cc=memxor@gmail.com \
    --cc=mhiramat@kernel.org \
    --cc=mhocko@kernel.org \
    --cc=mhocko@suse.com \
    --cc=miklos@szeredi.hu \
    --cc=mingo@redhat.com \
    --cc=mkp@kernel.org \
    --cc=mripard@kernel.org \
    --cc=muchun.song@linux.dev \
    --cc=namhyung@kernel.org \
    --cc=nico.pache@linux.dev \
    --cc=nphamcs@gmail.com \
    --cc=npiggin@gmail.com \
    --cc=oleg@redhat.com \
    --cc=osalvador@suse.de \
    --cc=oupton@kernel.org \
    --cc=palmer@dabbelt.com \
    --cc=paul@paul-moore.com \
    --cc=perex@perex.cz \
    --cc=peterx@redhat.com \
    --cc=peterz@infradead.org \
    --cc=pfalcato@suse.de \
    --cc=pjw@kernel.org \
    --cc=qi.zheng@linux.dev \
    --cc=rakie.kim@sk.com \
    --cc=riel@surriel.com \
    --cc=rppt@kernel.org \
    --cc=ryan.roberts@arm.com \
    --cc=selinux@vger.kernel.org \
    --cc=shakeel.butt@linux.dev \
    --cc=shikemeng@huaweicloud.com \
    --cc=simona@ffwll.ch \
    --cc=sparclinux@vger.kernel.org \
    --cc=sre@kernel.org \
    --cc=stephen.smalley.work@gmail.com \
    --cc=surenb@google.com \
    --cc=tglx@kernel.org \
    --cc=tiwai@suse.com \
    --cc=tzimmermann@suse.de \
    --cc=usama.arif@linux.dev \
    --cc=vbabka@kernel.org \
    --cc=vincent.guittot@linaro.org \
    --cc=viro@zeniv.linux.org.uk \
    --cc=weixugc@google.com \
    --cc=will@kernel.org \
    --cc=willy@infradead.org \
    --cc=x86@kernel.org \
    --cc=xu.xin@linux.dev \
    --cc=ying.huang@linux.alibaba.com \
    --cc=youngjun.park@lge.com \
    --cc=yuanchu@google.com \
    --cc=ziy@nvidia.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®