All of lore.kernel.org
 help / color / mirror / Atom feed
From: Lance Yang <lance.yang@linux.dev>
To: ljs@kernel.org
Cc: akpm@linux-foundation.org, liam@infradead.org, vbabka@kernel.org,
	jannh@google.com, pfalcato@suse.de, david@kernel.org,
	rppt@kernel.org, surenb@google.com, mhocko@suse.com,
	arnd@arndb.de, gregkh@linuxfoundation.org, linux-mm@kvack.org,
	linux-kernel@vger.kernel.org, lance.yang@linux.dev,
	syzbot+c181d3198e98f8aef8b9@syzkaller.appspotmail.com
Subject: Re: [PATCH] drivers/char/mem: mmap readonly MAP_SHARED-/dev/zero correctly
Date: Wed,  7 Oct 2026 10:14:36 +0800	[thread overview]
Message-ID: <20261007021436.82381-1-lance.yang@linux.dev> (raw)
In-Reply-To: <20260924-fix-dev-zero-readonly-shared-v1-1-153c2111e323@kernel.org>


On Thu, Sep 24, 2026 at 03:48:24PM +0100, Lorenzo Stoakes (ARM) wrote:
>Rather surprisingly, opening /dev/zero read-only then mmap()'ing it
>MAP_SHARED gets you true anonymous memory (albeit in a VMA with
>non-NULL vma->vm_file).
>
>This is a by-product of MAP_PRIVATE-/dev/zero being how anonymous memory
>was mapped in Linux's distant past.
>
>It happens because mmap_zero_prepare() gates on VMA_SHARED_BIT and when
>mapping a read-only file MAP_SHARED, do_mmap() clears VMA_SHARED_BIT and
>VMA_MAYWRITE_BIT.
>
>The gating is incorrect - the (poorly named) VMA_MAYSHARE_BIT flag exists
>explicitly to tell you if something was originally mapped MAP_SHARED.
>
>So the fix is simple - gate on this instead.
>
>This isn't exactly a common use case, but it's unexpected behaviour which
>now causes an assert if CONFIG_DEBUG_VM is set.
>
>While this bug has existed since the dawn of time for linux (or at least
>since 2.6.12), it hasn't caused issues in the past, so while it's incorrect
>behaviour, it doesn't seem necessary to backport that far.
>
>The mapping is now accounted at mmap time and can fail with -ENOMEM under
>strict overcommit, and read faults allocate folios. However this is normal
>behaviour for a read-only shmem mapping.
>
>Commit 93c0c8dc87f6 ("mm/rmap: use anon pgoff to track MAP_PRIVATE
>file-backed anon folios") is the first patch at which the debug assert
>fires, so target that instead.
>
>Fixes: 93c0c8dc87f6 ("mm/rmap: use anon pgoff to track MAP_PRIVATE file-backed anon folios")
>Reported-by: syzbot+c181d3198e98f8aef8b9@syzkaller.appspotmail.com
>Closes: https://lore.kernel.org/linux-mm/6ab4ae75.80e1c6cc.1e8e5f.000d.GAE@google.com/
>Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
>---

Reviewed-by: Lance Yang <lance.yang@linux.dev>


      parent reply	other threads:[~2026-10-07  6:40 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-24 14:48 [PATCH] drivers/char/mem: mmap readonly MAP_SHARED-/dev/zero correctly Lorenzo Stoakes (ARM)
2026-09-24 15:08 ` Greg Kroah-Hartman
2026-09-24 15:29   ` Lorenzo Stoakes (ARM)
2026-09-24 15:42     ` Greg Kroah-Hartman
2026-09-24 15:37 ` David Hildenbrand (Arm)
2026-09-25  2:58   ` Andrew Morton
2026-09-25  7:29     ` David Hildenbrand (Arm)
2026-09-25  8:38       ` Lorenzo Stoakes (ARM)
2026-09-28 11:59         ` David Hildenbrand (Arm)
2026-09-28 15:08           ` Lorenzo Stoakes (ARM)
2026-09-29  0:26           ` Andrew Morton
2026-09-29  6:14             ` David Hildenbrand (Arm)
2026-10-07  2:14 ` Lance Yang [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261007021436.82381-1-lance.yang@linux.dev \
    --to=lance.yang@linux.dev \
    --cc=akpm@linux-foundation.org \
    --cc=arnd@arndb.de \
    --cc=david@kernel.org \
    --cc=gregkh@linuxfoundation.org \
    --cc=jannh@google.com \
    --cc=liam@infradead.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=ljs@kernel.org \
    --cc=mhocko@suse.com \
    --cc=pfalcato@suse.de \
    --cc=rppt@kernel.org \
    --cc=surenb@google.com \
    --cc=syzbot+c181d3198e98f8aef8b9@syzkaller.appspotmail.com \
    --cc=vbabka@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.