All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Kiryl Shutsemau" <kirill@shutemov.name>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH v5 14/18] mm/pagemap: add PAGE_IS_ACCESSED for RWP tracking
Date: Tue, 26 May 2026 14:37:01 +0000	[thread overview]
Message-ID: <20260526143701.893741F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260526130509.2748441-15-kirill@shutemov.name>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] Bypass of explicit PM_SCAN_CHECK_WPASYNC abort request for RWP VMAs.
--

commit ad3030249d2003121c666af3030236ae064a1680
Author: Kiryl Shutsemau (Meta) <kas@kernel.org>

mm/pagemap: add PAGE_IS_ACCESSED for RWP tracking

This commit introduces PAGE_IS_ACCESSED to the PAGEMAP_SCAN UAPI for
differentiating read-write protection (RWP) from write protection (WP) in
userfaultfd. It narrows PAGE_IS_WRITTEN to VM_UFFD_WP VMAs and restricts
the new flag to VM_UFFD_RWP VMAs, providing distinct semantics.

> diff --git a/fs/proc/task_mmu.c b/fs/proc/task_mmu.c
> index 974c5f4aa5331..0db29c3a8639f 100644
> --- a/fs/proc/task_mmu.c
> +++ b/fs/proc/task_mmu.c

[ ... ]

> @@ -2677,6 +2702,18 @@ static int pagemap_scan_test_walk(unsigned long start, unsigned long end,
>  	bool wp_allowed = userfaultfd_wp_async(vma) &&
>  	    userfaultfd_wp_use_markers(vma);
>  
> +	/*
> +	 * PM_SCAN_WP_MATCHING is the atomic read-and-reset flavour of the
> +	 * scan and is implemented for the WP marker only. Silently skip
> +	 * VM_UFFD_RWP VMAs, matching the convention used below for VMAs
> +	 * that lack the WP-async capability. Returning -EINVAL here would
> +	 * abort the walk after preceding VMAs had already been mutated,
> +	 * destroying the atomic read-and-reset guarantee. Re-arming RWP
> +	 * is done with UFFDIO_RWPROTECT(MODE_RWP).
> +	 */
> +	if (userfaultfd_rwp(vma) && (p->arg.flags & PM_SCAN_WP_MATCHING))
> +		return 1;
> +

[Severity: Medium]
Does this early return bypass the user's explicit request to abort via
PM_SCAN_CHECK_WPASYNC?

If a VMA is registered for RWP, it lacks WP-async capability, meaning
wp_allowed is false. By returning 1 here, we skip the VMA instead of reaching
the PM_SCAN_CHECK_WPASYNC check immediately below, which would normally return
-EPERM to honor the user's UAPI request to abort the scan.

>  	if (!wp_allowed) {
>  		/* User requested explicit failure over wp-async capability */
>  		if (p->arg.flags & PM_SCAN_CHECK_WPASYNC)

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260526130509.2748441-1-kirill@shutemov.name?part=14

  reply	other threads:[~2026-05-26 14:37 UTC|newest]

Thread overview: 43+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-05-26 13:04 [PATCH v5 00/18] userfaultfd: working set tracking for VM guest memory Kiryl Shutsemau
2026-05-26 13:04 ` [PATCH v5 01/18] fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race Kiryl Shutsemau
2026-05-26 13:46   ` sashiko-bot
2026-05-26 13:04 ` [PATCH v5 02/18] mm/huge_memory: preserve pmd_swp_uffd_wp on device-private PMD downgrade Kiryl Shutsemau
2026-05-26 13:43   ` sashiko-bot
2026-05-26 13:04 ` [PATCH v5 03/18] userfaultfd: gate must_wait writability check on pte_present() Kiryl Shutsemau
2026-05-26 13:44   ` sashiko-bot
2026-05-26 13:04 ` [PATCH v5 04/18] mm: skip out-of-range bits in mk_vma_flags() Kiryl Shutsemau
2026-05-29 14:00   ` Lorenzo Stoakes
2026-05-29 16:09     ` Kiryl Shutsemau
2026-06-01  9:37       ` Lorenzo Stoakes
2026-05-30 16:52     ` Mike Rapoport
2026-06-01  7:42       ` Lorenzo Stoakes
2026-06-01 14:08       ` Kiryl Shutsemau
2026-06-01 14:28         ` Mike Rapoport
2026-05-26 13:04 ` [PATCH v5 05/18] mm: decouple protnone helpers from CONFIG_NUMA_BALANCING Kiryl Shutsemau
2026-05-26 13:04 ` [PATCH v5 06/18] mm: rename uffd-wp PTE bit macros to uffd Kiryl Shutsemau
2026-05-26 13:04 ` [PATCH v5 07/18] mm: rename uffd-wp PTE accessors " Kiryl Shutsemau
2026-05-26 13:29   ` sashiko-bot
2026-05-26 13:04 ` [PATCH v5 08/18] mm: add VM_UFFD_RWP VMA flag Kiryl Shutsemau
2026-05-26 14:37   ` sashiko-bot
2026-05-29  7:24   ` Lorenzo Stoakes
2026-05-29 13:07     ` Kiryl Shutsemau
2026-05-29 14:00       ` Lorenzo Stoakes
2026-05-26 13:04 ` [PATCH v5 09/18] mm: add MM_CP_UFFD_RWP change_protection() flag Kiryl Shutsemau
2026-05-26 14:07   ` sashiko-bot
2026-05-29  1:19   ` SeongJae Park
2026-05-26 13:04 ` [PATCH v5 10/18] mm: preserve RWP marker across PTE rewrites Kiryl Shutsemau
2026-05-26 14:15   ` sashiko-bot
2026-05-26 13:04 ` [PATCH v5 11/18] mm: handle VM_UFFD_RWP in khugepaged, rmap, and GUP Kiryl Shutsemau
2026-05-26 15:04   ` sashiko-bot
2026-05-26 13:05 ` [PATCH v5 12/18] userfaultfd: add UFFDIO_REGISTER_MODE_RWP and UFFDIO_RWPROTECT plumbing Kiryl Shutsemau
2026-05-26 14:45   ` sashiko-bot
2026-05-26 13:05 ` [PATCH v5 13/18] mm/userfaultfd: add RWP fault delivery and expose UFFDIO_REGISTER_MODE_RWP Kiryl Shutsemau
2026-05-26 14:33   ` sashiko-bot
2026-05-26 13:05 ` [PATCH v5 14/18] mm/pagemap: add PAGE_IS_ACCESSED for RWP tracking Kiryl Shutsemau
2026-05-26 14:37   ` sashiko-bot [this message]
2026-05-26 13:05 ` [PATCH v5 15/18] userfaultfd: add UFFD_FEATURE_RWP_ASYNC for async fault resolution Kiryl Shutsemau
2026-05-26 13:05 ` [PATCH v5 16/18] userfaultfd: add UFFDIO_SET_MODE for runtime sync/async toggle Kiryl Shutsemau
2026-05-26 15:07   ` sashiko-bot
2026-05-26 13:05 ` [PATCH v5 17/18] selftests/mm: add userfaultfd RWP tests Kiryl Shutsemau
2026-05-26 13:05 ` [PATCH v5 18/18] Documentation/userfaultfd: document RWP working set tracking Kiryl Shutsemau
2026-05-26 14:51   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260526143701.893741F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=kirill@shutemov.name \
    --cc=kvm@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.