From: "Lorenzo Stoakes (ARM)" <ljs@kernel.org>
To: Suren Baghdasaryan <surenb@google.com>
Cc: Andrew Morton <akpm@linux-foundation.org>,
"Liam R. Howlett" <liam@infradead.org>,
Vlastimil Babka <vbabka@kernel.org>,
Jann Horn <jannh@google.com>, Pedro Falcato <pfalcato@suse.de>,
David Hildenbrand <david@kernel.org>,
Mike Rapoport <rppt@kernel.org>, Michal Hocko <mhocko@suse.com>,
Jonathan Corbet <corbet@lwn.net>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
Dennis Dalessandro <dennis.dalessandro@cornelisnetworks.com>,
Jason Gunthorpe <jgg@ziepe.ca>,
Leon Romanovsky <leon@kernel.org>,
Paul Moore <paul@paul-moore.com>,
Stephen Smalley <stephen.smalley.work@gmail.com>,
Jaroslav Kysela <perex@perex.cz>, Takashi Iwai <tiwai@suse.com>,
Alexei Starovoitov <ast@kernel.org>,
Daniel Borkmann <daniel@iogearbox.net>,
Andrii Nakryiko <andrii@kernel.org>,
Eduard Zingerman <eddyz87@gmail.com>,
Kumar Kartikeya Dwivedi <memxor@gmail.com>,
Zi Yan <ziy@nvidia.com>,
Baolin Wang <baolin.wang@linux.alibaba.com>,
Nico Pache <nico.pache@linux.dev>,
Ryan Roberts <ryan.roberts@arm.com>, Dev Jain <dev.jain@arm.com>,
Barry Song <baohua@kernel.org>,
Lance Yang <lance.yang@linux.dev>,
Usama Arif <usama.arif@linux.dev>,
Kiryl Shutsemau <kas@kernel.org>,
Doug Gilbert <dgilbert@interlog.com>,
"James E.J. Bottomley" <James.Bottomley@hansenpartnership.com>,
"Martin K. Petersen" <mkp@kernel.org>,
Jaya Kumar <jayalk@intworks.biz>,
Simona Vetter <simona@ffwll.ch>, Helge Deller <deller@gmx.de>,
Sebastian Reichel <sre@kernel.org>,
John Hubbard <jhubbard@nvidia.com>, Peter Xu <peterx@redhat.com>,
Masami Hiramatsu <mhiramat@kernel.org>,
Oleg Nesterov <oleg@redhat.com>,
Peter Zijlstra <peterz@infradead.org>,
Thomas Gleixner <tglx@kernel.org>,
Ingo Molnar <mingo@redhat.com>, Borislav Petkov <bp@alien8.de>,
Dave Hansen <dave.hansen@linux.intel.com>,
x86@kernel.org, Arnaldo Carvalho de Melo <acme@kernel.org>,
Namhyung Kim <namhyung@kernel.org>,
Mark Rutland <mark.rutland@arm.com>,
Rik van Riel <riel@surriel.com>, Harry Yoo <harry@kernel.org>,
Juri Lelli <juri.lelli@redhat.com>,
Vincent Guittot <vincent.guittot@linaro.org>,
Maarten Lankhorst <maarten.lankhorst@linux.intel.com>,
Maxime Ripard <mripard@kernel.org>,
Thomas Zimmermann <tzimmermann@suse.de>,
David Airlie <airlied@gmail.com>, Will Deacon <will@kernel.org>,
"Aneesh Kumar K.V" <aneesh.kumar@kernel.org>,
Nick Piggin <npiggin@gmail.com>, Arnd Bergmann <arnd@arndb.de>,
Muchun Song <muchun.song@linux.dev>,
Oscar Salvador <osalvador@suse.de>,
"Matthew Wilcox (Oracle)" <willy@infradead.org>,
Jan Kara <jack@suse.cz>, Marc Zyngier <maz@kernel.org>,
Oliver Upton <oupton@kernel.org>,
Catalin Marinas <catalin.marinas@arm.com>,
Madhavan Srinivasan <maddy@linux.ibm.com>,
Anup Patel <anup@brainfault.org>, Paul Walmsley <pjw@kernel.org>,
Palmer Dabbelt <palmer@dabbelt.com>,
Albert Ou <aou@eecs.berkeley.edu>,
Christian Borntraeger <borntraeger@linux.ibm.com>,
Janosch Frank <frankja@linux.ibm.com>,
Claudio Imbrenda <imbrenda@linux.ibm.com>,
Alexander Gordeev <agordeev@linux.ibm.com>,
Gerald Schaefer <gerald.schaefer@linux.ibm.com>,
Heiko Carstens <hca@linux.ibm.com>,
Vasily Gorbik <gor@linux.ibm.com>,
"David S. Miller" <davem@davemloft.net>,
Andreas Larsson <andreas@gaisler.com>,
Alexander Viro <viro@zeniv.linux.org.uk>,
Christian Brauner <brauner@kernel.org>,
Matthew Brost <matthew.brost@intel.com>,
Joshua Hahn <joshua.hahnjy@gmail.com>,
Rakie Kim <rakie.kim@sk.com>, Byungchul Park <byungchul@sk.com>,
Gregory Price <gourry@gourry.net>,
Ying Huang <ying.huang@linux.alibaba.com>,
Alistair Popple <apopple@nvidia.com>,
Chris Li <chrisl@kernel.org>, Kairui Song <kasong@tencent.com>,
Kemeng Shi <shikemeng@huaweicloud.com>,
Nhat Pham <nphamcs@gmail.com>, Baoquan He <baoquan.he@linux.dev>,
Youngjun Park <youngjun.park@lge.com>,
Johannes Weiner <hannes@cmpxchg.org>,
Qi Zheng <qi.zheng@linux.dev>,
Shakeel Butt <shakeel.butt@linux.dev>,
Axel Rasmussen <axelrasmussen@google.com>,
Yuanchu Xie <yuanchu@google.com>, Wei Xu <weixugc@google.com>,
Chengming Zhou <chengming.zhou@linux.dev>,
Michal Hocko <mhocko@kernel.org>,
Miklos Szeredi <miklos@szeredi.hu>, Xu Xin <xu.xin@linux.dev>,
linux-mm@kvack.org, linux-kernel@vger.kernel.org,
linux-doc@vger.kernel.org, linux-usb@vger.kernel.org,
linux-rdma@vger.kernel.org, selinux@vger.kernel.org,
linux-sound@vger.kernel.org, bpf@vger.kernel.org,
linux-scsi@vger.kernel.org, linux-fbdev@vger.kernel.org,
dri-devel@lists.freedesktop.org,
linux-trace-kernel@vger.kernel.org,
linux-perf-users@vger.kernel.org, linux-arch@vger.kernel.org,
linux-fsdevel@vger.kernel.org,
linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev,
linuxppc-dev@lists.ozlabs.org, kvm@vger.kernel.org,
kvm-riscv@lists.infradead.org, linux-riscv@lists.infradead.org,
linux-s390@vger.kernel.org, sparclinux@vger.kernel.org,
fuse-devel@lists.linux.dev
Subject: Re: [PATCH v3 04/40] mm: consistently validate VMA state after mmap[_prepare] hooks
Date: Wed, 23 Sep 2026 18:00:41 +0100 [thread overview]
Message-ID: <arQFp_bwAHnmkp2V@gremlin> (raw)
In-Reply-To: <CAJuCfpELP9Ups5XeS3PNbF=VtrfkYbkwRj-LuEHd7bLsTw4LUw@mail.gmail.com>
On Wed, Sep 23, 2026 at 09:47:20AM -0700, Suren Baghdasaryan wrote:
> On Thu, Sep 17, 2026 at 9:25 AM Lorenzo Stoakes (ARM) <ljs@kernel.org> wrote:
> >
> > When the f_op->mmap_prepare or deprecated f_op->mmap hooks are invoked, the
> > driver might have done something crazy that is not permitted by the kernel.
> >
> > Currently we check for three such cases in __mmap_new_file_vma(), but only
> > if the legacy f_op->mmap hook is used:
> >
> > * Did sparc ADI result in invalid flags?
> >
> > * Did the driver alter vma->vm_start?
> >
> > * Did the driver make a file-backed mapping on a read-only file writable?
> >
> > Generalise these checks for both mmap_prepare and mmap and apply to all
> > invocations of mmap_file(), the f_op->mmap and f_op->mmap_prepare handling
> > in the core VMA code and the mmap_prepare compatibility layer.
> >
> > Also extend the vm_start check to vm_end also - drivers must not change the
> > VMA range at all.
> >
> > We also WARN_ON_ONCE() on these conditions as they are things that should
> > simply not occur in the kernel and it's important to call it out when it
> > does.
> >
> > We invoke mmap_prepare_validate() after mmap_action_prepare(), as mmap
> > actions often manipulate state in the descriptor thus providing the final
> > state the VMA will be derived from.
> >
> > Also call mmap_validate_vma_flags() in insert_vm_struct() to ensure that
> > special regions which are inserted (such as a VDSO or VVAR) also satisfy
> > the sanity checks.
> >
> > This way every VMA established through an mmap hook, whether via mmap() or
> > the compatibility layer, or inserted via insert_vm_struct(), has been
> > validated. brk() VMAs never pass through a driver hook and so need no such
> > check.
> >
> > While we're here, also fixup a couple disjoint blocks of #ifdef CONFIG_MMU.
> >
> > Finally, update the VMA userland tests to reflect the change.
> >
> > Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
>
> Reviewed-by: Suren Baghdasaryan <surenb@google.com>
Thanks!
>
> > ---
> > mm/internal.h | 51 ++++++++++++--------
> > mm/util.c | 19 ++++++--
> > mm/vma.c | 100 ++++++++++++++++++++++++++++++++++------
> > mm/vma.h | 25 ++++++++--
> > tools/testing/vma/include/dup.h | 10 ++++
> > 5 files changed, 163 insertions(+), 42 deletions(-)
> >
> > diff --git a/mm/internal.h b/mm/internal.h
> > index fe576d468af4..970fb34898b2 100644
> > --- a/mm/internal.h
> > +++ b/mm/internal.h
> > @@ -213,6 +213,24 @@ static inline void *folio_raw_mapping(const struct folio *folio)
> > return (void *)(mapping & ~FOLIO_MAPPING_FLAGS);
> > }
> >
> > +/*
> > + * If the VMA has a close hook then close it, and since closing it might leave
> > + * it in an inconsistent state which makes the use of any hooks suspect, clear
> > + * them down by installing dummy empty hooks.
> > + */
> > +static inline void vma_close(struct vm_area_struct *vma)
> > +{
> > + if (vma->vm_ops && vma->vm_ops->close) {
> > + vma->vm_ops->close(vma);
> > +
> > + /*
> > + * The mapping is in an inconsistent state, and no further hooks
> > + * may be invoked upon it.
> > + */
> > + vma->vm_ops = &vma_dummy_vm_ops;
> > + }
> > +}
> > +
> > /*
> > * This is a file-backed mapping, and is about to be memory mapped - invoke its
> > * mmap hook and safely handle error conditions. On error, VMA hooks will be
> > @@ -225,8 +243,12 @@ static inline void *folio_raw_mapping(const struct folio *folio)
> > */
> > static inline int mmap_file(struct file *file, struct vm_area_struct *vma)
> > {
> > - int err = vfs_mmap(file, vma);
> > + const unsigned long prev_start = vma->vm_start;
> > + const unsigned long prev_end = vma->vm_end;
> > + const vma_flags_t prev_flags = vma->flags;
>
> nit: Might be just me but when I see prev_XXX in VMA-related code I
> picture previous VMA in the address space. Maybe call these orig_XXX?
Sure, will change.
>
> > + int err;
> >
> > + err = vfs_mmap(file, vma);
> > /*
> > * Either we tried to call the file hook for mmap() and an error arose
> > * or a driver set vma->vm_ops = NULL intending there to be no VMA
> > @@ -239,26 +261,17 @@ static inline int mmap_file(struct file *file, struct vm_area_struct *vma)
> > */
> > if (unlikely(err || !vma->vm_ops))
> > vma->vm_ops = &vma_dummy_vm_ops;
> > + if (unlikely(err))
> > + return err;
> >
> > - return err;
> > -}
> > -
> > -/*
> > - * If the VMA has a close hook then close it, and since closing it might leave
> > - * it in an inconsistent state which makes the use of any hooks suspect, clear
> > - * them down by installing dummy empty hooks.
> > - */
> > -static inline void vma_close(struct vm_area_struct *vma)
> > -{
> > - if (vma->vm_ops && vma->vm_ops->close) {
> > - vma->vm_ops->close(vma);
> > -
> > - /*
> > - * The mapping is in an inconsistent state, and no further hooks
> > - * may be invoked upon it.
> > - */
> > - vma->vm_ops = &vma_dummy_vm_ops;
> > + err = mmap_hook_validate(prev_start, prev_end, &prev_flags, vma);
> > + if (unlikely(err)) {
> > + vma->vm_start = prev_start;
> > + vma->vm_end = prev_end;
> > + vma_close(vma);
> > }
> > +
> > + return err;
> > }
> >
> > /* unmap_vmas is in mm/memory.c */
> > diff --git a/mm/util.c b/mm/util.c
> > index 016932780925..bdd5923eebc7 100644
> > --- a/mm/util.c
> > +++ b/mm/util.c
> > @@ -1224,19 +1224,28 @@ EXPORT_SYMBOL(compat_set_desc_from_vma);
> > int __compat_vma_mmap(struct vm_area_desc *desc,
> > struct vm_area_struct *vma)
> > {
> > + struct vm_area_desc prev_desc;
> > int err;
> >
> > + /* Derive state prior to mmap_prepare hook. */
> > + compat_set_desc_from_vma(&prev_desc, desc->file, vma);
> > /* Perform any preparatory tasks for mmap action. */
> > err = mmap_action_prepare(desc);
> > - if (err) {
> > - if (desc->vm_file != vma->vm_file)
> > - fput(desc->vm_file);
> > - return err;
> > - }
> > + if (err)
> > + goto err_put;
> > + /* Check the caller did nothing crazy. */
> > + err = mmap_prepare_validate(&prev_desc, desc);
> > + if (err)
> > + goto err_put;
> > /* Update the VMA from the descriptor. */
> > compat_set_vma_from_desc(vma, desc);
> > /* Complete any specified mmap actions. */
> > return mmap_action_complete(vma, &desc->action, /*is_compat=*/true);
> > +
> > +err_put:
> > + if (desc->vm_file != vma->vm_file)
> > + fput(desc->vm_file);
> > + return err;
> > }
> > EXPORT_SYMBOL(__compat_vma_mmap);
> >
> > diff --git a/mm/vma.c b/mm/vma.c
> > index 05d2c676672e..d6ed10cefc8f 100644
> > --- a/mm/vma.c
> > +++ b/mm/vma.c
> > @@ -2623,16 +2623,6 @@ static int __mmap_new_file_vma(struct mmap_state *map,
> > return error;
> > }
> >
> > - /* Drivers cannot alter the address of the VMA. */
> > - WARN_ON_ONCE(map->addr != vma->vm_start);
> > - /*
> > - * Drivers should not permit writability when previously it was
> > - * disallowed.
> > - */
> > - VM_WARN_ON_ONCE(!vma_flags_same_pair(&map->vma_flags, &vma->flags) &&
> > - !vma_flags_test(&map->vma_flags, VMA_MAYWRITE_BIT) &&
> > - vma_test(vma, VMA_MAYWRITE_BIT));
> > -
> > map->vma_flags = vma->flags;
> >
> > return 0;
> > @@ -2710,11 +2700,6 @@ static int __mmap_new_vma(struct mmap_state *map, struct vm_area_struct **vmap,
> > vma->flags = map->vma_flags;
> > }
> >
> > -#ifdef CONFIG_SPARC64
> > - /* TODO: Fix SPARC ADI! */
> > - WARN_ON_ONCE(!arch_validate_flags(map->vm_flags));
> > -#endif
> > -
> > /* Lock the VMA since it is modified after insertion into VMA tree */
> > vma_start_write(vma);
> > vma_iter_store_new(vmi, vma);
> > @@ -2777,6 +2762,80 @@ static void __mmap_complete(struct mmap_state *map, struct vm_area_struct *vma)
> > vma_set_page_prot(vma);
> > }
> >
> > +/* Check to ensure that the VMA flags of a newly mapped VMA are sane. */
> > +static int mmap_validate_vma_flags(const vma_flags_t *flags)
> > +{
> > +#ifdef CONFIG_SPARC64
> > + const vm_flags_t legacy_flags = vma_flags_to_legacy(*flags);
> > +
> > + /* TODO: Fix SPARC ADI! */
> > + if (WARN_ON_ONCE(!arch_validate_flags(legacy_flags)))
> > + return -EINVAL;
> > +#endif
> > +
> > + return 0;
> > +}
> > +
> > +/* Check to ensure a driver hasn't done something crazy. */
> > +static int mmap_validate(unsigned long prev_start, unsigned long prev_end,
> > + unsigned long curr_start, unsigned long curr_end,
> > + const vma_flags_t *prev_flags,
> > + const vma_flags_t *curr_flags)
> > +{
> > + bool was_maywrite, is_maywrite;
> > +
> > + /* Drivers cannot alter the range of the VMA. */
> > + if (WARN_ON_ONCE(prev_start != curr_start || prev_end != curr_end))
> > + return -EINVAL;
> > +
> > + was_maywrite = vma_flags_test(prev_flags, VMA_MAYWRITE_BIT);
> > + is_maywrite = vma_flags_test(curr_flags, VMA_MAYWRITE_BIT);
> > +
> > + /* A driver may not make a previously unwritable mapping writable. */
> > + if (WARN_ON_ONCE(!was_maywrite && is_maywrite))
> > + return -EINVAL;
> > +
> > + return mmap_validate_vma_flags(curr_flags);
> > +}
> > +
> > +/**
> > + * mmap_prepare_validate() - Ensure the driver hasn't violated invariants in its
> > + * f_op->mmap_prepare hook.
> > + * @prev_desc: The VMA descriptor prior to the mmap_prepare hook being called.
> > + * @desc: The VMA descriptor after the mmap_prepare hook has been called.
> > + *
> > + * Returns: 0 on success, otherwise an error.
> > + */
> > +int mmap_prepare_validate(const struct vm_area_desc *prev_desc,
> > + const struct vm_area_desc *desc)
> > +{
> > + return mmap_validate(prev_desc->start, prev_desc->end,
> > + desc->start, desc->end,
> > + &prev_desc->vma_flags, &desc->vma_flags);
> > +}
> > +
> > +/**
> > + * mmap_hook_validate() - Ensure the driver hasn't violated invariants in
> > + * its f_op->mmap hook.
> > + * @prev_start: The start of the mapping prior to the mmap hook.
> > + * @prev_end: The end of the mapping prior to the mmap hook.
> > + * @prev_flags: The VMA flags set for the VMA prior to the mmap hook.
> > + * @vma: The VMA after the hook has been applied.
> > + *
> > + * Returns: 0 on success, otherwise an error.
> > + */
> > +int mmap_hook_validate(unsigned long prev_start, unsigned long prev_end,
> > + const vma_flags_t *prev_flags,
> > + const struct vm_area_struct *vma)
> > +{
> > + const unsigned long start = vma->vm_start;
> > + const unsigned long end = vma->vm_end;
> > + const vma_flags_t *flags = &vma->flags;
> > +
> > + return mmap_validate(prev_start, prev_end, start, end, prev_flags,
> > + flags);
> > +}
> > +
> > static int call_action_prepare(struct mmap_state *map,
> > struct vm_area_desc *desc)
> > {
> > @@ -2803,6 +2862,7 @@ static int call_action_prepare(struct mmap_state *map,
> > static int call_mmap_prepare(struct mmap_state *map,
> > struct vm_area_desc *desc)
> > {
> > + const struct vm_area_desc prev_desc = *desc;
> > int err;
> >
> > /* Invoke the hook. */
> > @@ -2822,6 +2882,11 @@ static int call_mmap_prepare(struct mmap_state *map,
> > if (err)
> > return err;
> >
> > + /* Check the caller did nothing crazy. */
> > + err = mmap_prepare_validate(&prev_desc, desc);
> > + if (err)
> > + return err;
> > +
> > /* Update fields permitted to be changed. */
> > map->pgoff = desc->pgoff;
> > map->vma_flags = desc->vma_flags;
> > @@ -3457,10 +3522,15 @@ int __vm_munmap(unsigned long start, size_t len, bool unlock)
> > int insert_vm_struct(struct mm_struct *mm, struct vm_area_struct *vma)
> > {
> > unsigned long charged = vma_pages(vma);
> > + int err;
> >
> > if (find_vma_intersection(mm, vma->vm_start, vma->vm_end))
> > return -ENOMEM;
> >
> > + err = mmap_validate_vma_flags(&vma->flags);
> > + if (err)
> > + return err;
> > +
> > if (vma_test(vma, VMA_ACCOUNT_BIT) &&
> > security_vm_enough_memory_mm(mm, charged))
> > return -ENOMEM;
> > diff --git a/mm/vma.h b/mm/vma.h
> > index f15faa83f3d6..b2c3bc832a48 100644
> > --- a/mm/vma.h
> > +++ b/mm/vma.h
> > @@ -782,14 +782,19 @@ struct vm_area_struct *vm_area_alloc(struct mm_struct *mm);
> > struct vm_area_struct *vm_area_dup(struct vm_area_struct *orig);
> > void vm_area_free(struct vm_area_struct *vma);
> >
> > -/* vma_exec.c */
> > #ifdef CONFIG_MMU
> > +int mmap_prepare_validate(const struct vm_area_desc *prev_desc,
> > + const struct vm_area_desc *desc);
> > +
> > +int mmap_hook_validate(unsigned long prev_start, unsigned long prev_end,
> > + const vma_flags_t *prev_flags,
> > + const struct vm_area_struct *vma);
> > +
> > +/* vma_exec.c */
> > int create_init_stack_vma(struct mm_struct *mm, struct vm_area_struct **vmap,
> > unsigned long *top_mem_p);
> > int relocate_vma_down(struct vm_area_struct *vma, unsigned long shift);
> > -#endif
> >
> > -#ifdef CONFIG_MMU
> > /*
> > * Denies creating a writable executable mapping or gaining executable permissions.
> > *
> > @@ -838,6 +843,20 @@ static inline bool map_deny_write_exec(const vma_flags_t *old,
> >
> > return false;
> > }
> > +#else
> > +static inline int mmap_prepare_validate(const struct vm_area_desc *prev_desc,
> > + const struct vm_area_desc *desc)
> > +{
> > + return 0;
> > +}
> > +
> > +static inline int mmap_hook_validate(unsigned long prev_start,
> > + unsigned long prev_end,
> > + const vma_flags_t *prev_flags,
> > + const struct vm_area_struct *vma)
> > +{
> > + return 0;
> > +}
> > #endif
> >
> > struct vm_area_struct *__install_special_mapping(struct mm_struct *mm,
> > diff --git a/tools/testing/vma/include/dup.h b/tools/testing/vma/include/dup.h
> > index 2fd422789717..2986ae6ca1e5 100644
> > --- a/tools/testing/vma/include/dup.h
> > +++ b/tools/testing/vma/include/dup.h
> > @@ -1359,13 +1359,23 @@ static inline int vfs_mmap_prepare(struct file *file, struct vm_area_desc *desc)
> > return file->f_op->mmap_prepare(desc);
> > }
> >
> > +int mmap_prepare_validate(const struct vm_area_desc *prev_desc,
> > + const struct vm_area_desc *desc);
> > +
> > static inline int __compat_vma_mmap(struct vm_area_desc *desc,
> > struct vm_area_struct *vma)
> > {
> > + struct vm_area_desc prev_desc;
> > int err;
> >
> > + /* Derive state prior to mmap_prepare hook. */
> > + compat_set_desc_from_vma(&prev_desc, desc->file, vma);
> > /* Perform any preparatory tasks for mmap action. */
> > err = mmap_action_prepare(desc);
> > + if (err)
> > + return err;
> > + /* Check the caller did nothing crazy. */
> > + err = mmap_prepare_validate(&prev_desc, desc);
> > if (err)
> > return err;
> > /* Update the VMA from the descriptor. */
> >
> > --
> > 2.55.0
> >
--
Cheers, Lorenzo
WARNING: multiple messages have this Message-ID (diff)
From: "Lorenzo Stoakes (ARM)" <ljs@kernel.org>
To: Suren Baghdasaryan <surenb@google.com>
Cc: Andrew Morton <akpm@linux-foundation.org>,
"Liam R. Howlett" <liam@infradead.org>,
Vlastimil Babka <vbabka@kernel.org>, Jann Horn <jannh@google.com>,
Pedro Falcato <pfalcato@suse.de>,
David Hildenbrand <david@kernel.org>,
Mike Rapoport <rppt@kernel.org>, Michal Hocko <mhocko@suse.com>,
Jonathan Corbet <corbet@lwn.net>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
Dennis Dalessandro <dennis.dalessandro@cornelisnetworks.com>,
Jason Gunthorpe <jgg@ziepe.ca>, Leon Romanovsky <leon@kernel.org>,
Paul Moore <paul@paul-moore.com>,
Stephen Smalley <stephen.smalley.work@gmail.com>,
Jaroslav Kysela <perex@perex.cz>, Takashi Iwai <tiwai@suse.com>,
Alexei Starovoitov <ast@kernel.org>,
Daniel Borkmann <daniel@iogearbox.net>,
Andrii Nakryiko <andrii@kernel.org>,
Eduard Zingerman <eddyz87@gmail.com>,
Kumar Kartikeya Dwivedi <memxor@gmail.com>,
Zi Yan <ziy@nvidia.com>,
Baolin Wang <baolin.wang@linux.alibaba.com>,
Nico Pache <nico.pache@linux.dev>,
Ryan Roberts <ryan.roberts@arm.com>, Dev Jain <dev.jain@arm.com>,
Barry Song <baohua@kernel.org>, Lance Yang <lance.yang@linux.dev>,
Usama Arif <usama.arif@linux.dev>,
Kiryl Shutsemau <kas@kernel.org>,
Doug Gilbert <dgilbert@interlog.com>,
"James E.J. Bottomley" <James.Bottomley@hansenpartnership.com>,
"Martin K. Petersen" <mkp@kernel.org>,
Jaya Kumar <jayalk@intworks.biz>, Simona Vetter <simona@ffwll.ch>,
Helge Deller <deller@gmx.de>, Sebastian Reichel <sre@kernel.org>,
John Hubbard <jhubbard@nvidia.com>, Peter Xu <peterx@redhat.com>,
Masami Hiramatsu <mhiramat@kernel.org>,
Oleg Nesterov <oleg@redhat.com>,
Peter Zijlstra <peterz@infradead.org>,
Thomas Gleixner <tglx@kernel.org>, Ingo Molnar <mingo@redhat.com>,
Borislav Petkov <bp@alien8.de>,
Dave Hansen <dave.hansen@linux.intel.com>,
x86@kernel.org, Arnaldo Carvalho de Melo <acme@kernel.org>,
Namhyung Kim <namhyung@kernel.org>,
Mark Rutland <mark.rutland@arm.com>,
Rik van Riel <riel@surriel.com>, Harry Yoo <harry@kernel.org>,
Juri Lelli <juri.lelli@redhat.com>,
Vincent Guittot <vincent.guittot@linaro.org>,
Maarten Lankhorst <maarten.lankhorst@linux.intel.com>,
Maxime Ripard <mripard@kernel.org>,
Thomas Zimmermann <tzimmermann@suse.de>,
David Airlie <airlied@gmail.com>, Will Deacon <will@kernel.org>,
"Aneesh Kumar K.V" <aneesh.kumar@kernel.org>,
Nick Piggin <npiggin@gmail.com>, Arnd Bergmann <arnd@arndb.de>,
Muchun Song <muchun.song@linux.dev>,
Oscar Salvador <osalvador@suse.de>,
"Matthew Wilcox (Oracle)" <willy@infradead.org>,
Jan Kara <jack@suse.cz>, Marc Zyngier <maz@kernel.org>,
Oliver Upton <oupton@kernel.org>,
Catalin Marinas <catalin.marinas@arm.com>,
Madhavan Srinivasan <maddy@linux.ibm.com>,
Anup Patel <anup@brainfault.org>, Paul Walmsley <pjw@kernel.org>,
Palmer Dabbelt <palmer@dabbelt.com>,
Albert Ou <aou@eecs.berkeley.edu>,
Christian Borntraeger <borntraeger@linux.ibm.com>,
Janosch Frank <frankja@linux.ibm.com>,
Claudio Imbrenda <imbrenda@linux.ibm.com>,
Alexander Gordeev <agordeev@linux.ibm.com>,
Gerald Schaefer <gerald.schaefer@linux.ibm.com>,
Heiko Carstens <hca@linux.ibm.com>,
Vasily Gorbik <gor@linux.ibm.com>,
"David S. Miller" <davem@davemloft.net>,
Andreas Larsson <andreas@gaisler.com>,
Alexander Viro <viro@zeniv.linux.org.uk>,
Christian Brauner <brauner@kernel.org>,
Matthew Brost <matthew.brost@intel.com>,
Joshua Hahn <joshua.hahnjy@gmail.com>,
Rakie Kim <rakie.kim@sk.com>, Byungchul Park <byungchul@sk.com>,
Gregory Price <gourry@gourry.net>,
Ying Huang <ying.huang@linux.alibaba.com>,
Alistair Popple <apopple@nvidia.com>,
Chris Li <chrisl@kernel.org>, Kairui Song <kasong@tencent.com>,
Kemeng Shi <shikemeng@huaweicloud.com>,
Nhat Pham <nphamcs@gmail.com>, Baoquan He <baoquan.he@linux.dev>,
Youngjun Park <youngjun.park@lge.com>,
Johannes Weiner <hannes@cmpxchg.org>,
Qi Zheng <qi.zheng@linux.dev>,
Shakeel Butt <shakeel.butt@linux.dev>,
Axel Rasmussen <axelrasmussen@google.com>,
Yuanchu Xie <yuanchu@google.com>, Wei Xu <weixugc@google.com>,
Chengming Zhou <chengming.zhou@linux.dev>,
Michal Hocko <mhocko@kernel.org>,
Miklos Szeredi <miklos@szeredi.hu>, Xu Xin <xu.xin@linux.dev>,
linux-mm@kvack.org, linux-kernel@vger.kernel.org,
linux-doc@vger.kernel.org, linux-usb@vger.kernel.org,
linux-rdma@vger.kernel.org, selinux@vger.kernel.org,
linux-sound@vger.kernel.org, bpf@vger.kernel.org,
linux-scsi@vger.kernel.org, linux-fbdev@vger.kernel.org,
dri-devel@lists.freedesktop.org,
linux-trace-kernel@vger.kernel.org,
linux-perf-users@vger.kernel.org, linux-arch@vger.kernel.org,
linux-fsdevel@vger.kernel.org,
linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev,
linuxppc-dev@lists.ozlabs.org, kvm@vger.kernel.org,
kvm-riscv@lists.infradead.org, linux-riscv@lists.infradead.org,
linux-s390@vger.kernel.org, sparclinux@vger.kernel.org,
fuse-devel@lists.linux.dev
Subject: Re: [PATCH v3 04/40] mm: consistently validate VMA state after mmap[_prepare] hooks
Date: Wed, 23 Sep 2026 18:00:41 +0100 [thread overview]
Message-ID: <arQFp_bwAHnmkp2V@gremlin> (raw)
In-Reply-To: <CAJuCfpELP9Ups5XeS3PNbF=VtrfkYbkwRj-LuEHd7bLsTw4LUw@mail.gmail.com>
On Wed, Sep 23, 2026 at 09:47:20AM -0700, Suren Baghdasaryan wrote:
> On Thu, Sep 17, 2026 at 9:25 AM Lorenzo Stoakes (ARM) <ljs@kernel.org> wrote:
> >
> > When the f_op->mmap_prepare or deprecated f_op->mmap hooks are invoked, the
> > driver might have done something crazy that is not permitted by the kernel.
> >
> > Currently we check for three such cases in __mmap_new_file_vma(), but only
> > if the legacy f_op->mmap hook is used:
> >
> > * Did sparc ADI result in invalid flags?
> >
> > * Did the driver alter vma->vm_start?
> >
> > * Did the driver make a file-backed mapping on a read-only file writable?
> >
> > Generalise these checks for both mmap_prepare and mmap and apply to all
> > invocations of mmap_file(), the f_op->mmap and f_op->mmap_prepare handling
> > in the core VMA code and the mmap_prepare compatibility layer.
> >
> > Also extend the vm_start check to vm_end also - drivers must not change the
> > VMA range at all.
> >
> > We also WARN_ON_ONCE() on these conditions as they are things that should
> > simply not occur in the kernel and it's important to call it out when it
> > does.
> >
> > We invoke mmap_prepare_validate() after mmap_action_prepare(), as mmap
> > actions often manipulate state in the descriptor thus providing the final
> > state the VMA will be derived from.
> >
> > Also call mmap_validate_vma_flags() in insert_vm_struct() to ensure that
> > special regions which are inserted (such as a VDSO or VVAR) also satisfy
> > the sanity checks.
> >
> > This way every VMA established through an mmap hook, whether via mmap() or
> > the compatibility layer, or inserted via insert_vm_struct(), has been
> > validated. brk() VMAs never pass through a driver hook and so need no such
> > check.
> >
> > While we're here, also fixup a couple disjoint blocks of #ifdef CONFIG_MMU.
> >
> > Finally, update the VMA userland tests to reflect the change.
> >
> > Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
>
> Reviewed-by: Suren Baghdasaryan <surenb@google.com>
Thanks!
>
> > ---
> > mm/internal.h | 51 ++++++++++++--------
> > mm/util.c | 19 ++++++--
> > mm/vma.c | 100 ++++++++++++++++++++++++++++++++++------
> > mm/vma.h | 25 ++++++++--
> > tools/testing/vma/include/dup.h | 10 ++++
> > 5 files changed, 163 insertions(+), 42 deletions(-)
> >
> > diff --git a/mm/internal.h b/mm/internal.h
> > index fe576d468af4..970fb34898b2 100644
> > --- a/mm/internal.h
> > +++ b/mm/internal.h
> > @@ -213,6 +213,24 @@ static inline void *folio_raw_mapping(const struct folio *folio)
> > return (void *)(mapping & ~FOLIO_MAPPING_FLAGS);
> > }
> >
> > +/*
> > + * If the VMA has a close hook then close it, and since closing it might leave
> > + * it in an inconsistent state which makes the use of any hooks suspect, clear
> > + * them down by installing dummy empty hooks.
> > + */
> > +static inline void vma_close(struct vm_area_struct *vma)
> > +{
> > + if (vma->vm_ops && vma->vm_ops->close) {
> > + vma->vm_ops->close(vma);
> > +
> > + /*
> > + * The mapping is in an inconsistent state, and no further hooks
> > + * may be invoked upon it.
> > + */
> > + vma->vm_ops = &vma_dummy_vm_ops;
> > + }
> > +}
> > +
> > /*
> > * This is a file-backed mapping, and is about to be memory mapped - invoke its
> > * mmap hook and safely handle error conditions. On error, VMA hooks will be
> > @@ -225,8 +243,12 @@ static inline void *folio_raw_mapping(const struct folio *folio)
> > */
> > static inline int mmap_file(struct file *file, struct vm_area_struct *vma)
> > {
> > - int err = vfs_mmap(file, vma);
> > + const unsigned long prev_start = vma->vm_start;
> > + const unsigned long prev_end = vma->vm_end;
> > + const vma_flags_t prev_flags = vma->flags;
>
> nit: Might be just me but when I see prev_XXX in VMA-related code I
> picture previous VMA in the address space. Maybe call these orig_XXX?
Sure, will change.
>
> > + int err;
> >
> > + err = vfs_mmap(file, vma);
> > /*
> > * Either we tried to call the file hook for mmap() and an error arose
> > * or a driver set vma->vm_ops = NULL intending there to be no VMA
> > @@ -239,26 +261,17 @@ static inline int mmap_file(struct file *file, struct vm_area_struct *vma)
> > */
> > if (unlikely(err || !vma->vm_ops))
> > vma->vm_ops = &vma_dummy_vm_ops;
> > + if (unlikely(err))
> > + return err;
> >
> > - return err;
> > -}
> > -
> > -/*
> > - * If the VMA has a close hook then close it, and since closing it might leave
> > - * it in an inconsistent state which makes the use of any hooks suspect, clear
> > - * them down by installing dummy empty hooks.
> > - */
> > -static inline void vma_close(struct vm_area_struct *vma)
> > -{
> > - if (vma->vm_ops && vma->vm_ops->close) {
> > - vma->vm_ops->close(vma);
> > -
> > - /*
> > - * The mapping is in an inconsistent state, and no further hooks
> > - * may be invoked upon it.
> > - */
> > - vma->vm_ops = &vma_dummy_vm_ops;
> > + err = mmap_hook_validate(prev_start, prev_end, &prev_flags, vma);
> > + if (unlikely(err)) {
> > + vma->vm_start = prev_start;
> > + vma->vm_end = prev_end;
> > + vma_close(vma);
> > }
> > +
> > + return err;
> > }
> >
> > /* unmap_vmas is in mm/memory.c */
> > diff --git a/mm/util.c b/mm/util.c
> > index 016932780925..bdd5923eebc7 100644
> > --- a/mm/util.c
> > +++ b/mm/util.c
> > @@ -1224,19 +1224,28 @@ EXPORT_SYMBOL(compat_set_desc_from_vma);
> > int __compat_vma_mmap(struct vm_area_desc *desc,
> > struct vm_area_struct *vma)
> > {
> > + struct vm_area_desc prev_desc;
> > int err;
> >
> > + /* Derive state prior to mmap_prepare hook. */
> > + compat_set_desc_from_vma(&prev_desc, desc->file, vma);
> > /* Perform any preparatory tasks for mmap action. */
> > err = mmap_action_prepare(desc);
> > - if (err) {
> > - if (desc->vm_file != vma->vm_file)
> > - fput(desc->vm_file);
> > - return err;
> > - }
> > + if (err)
> > + goto err_put;
> > + /* Check the caller did nothing crazy. */
> > + err = mmap_prepare_validate(&prev_desc, desc);
> > + if (err)
> > + goto err_put;
> > /* Update the VMA from the descriptor. */
> > compat_set_vma_from_desc(vma, desc);
> > /* Complete any specified mmap actions. */
> > return mmap_action_complete(vma, &desc->action, /*is_compat=*/true);
> > +
> > +err_put:
> > + if (desc->vm_file != vma->vm_file)
> > + fput(desc->vm_file);
> > + return err;
> > }
> > EXPORT_SYMBOL(__compat_vma_mmap);
> >
> > diff --git a/mm/vma.c b/mm/vma.c
> > index 05d2c676672e..d6ed10cefc8f 100644
> > --- a/mm/vma.c
> > +++ b/mm/vma.c
> > @@ -2623,16 +2623,6 @@ static int __mmap_new_file_vma(struct mmap_state *map,
> > return error;
> > }
> >
> > - /* Drivers cannot alter the address of the VMA. */
> > - WARN_ON_ONCE(map->addr != vma->vm_start);
> > - /*
> > - * Drivers should not permit writability when previously it was
> > - * disallowed.
> > - */
> > - VM_WARN_ON_ONCE(!vma_flags_same_pair(&map->vma_flags, &vma->flags) &&
> > - !vma_flags_test(&map->vma_flags, VMA_MAYWRITE_BIT) &&
> > - vma_test(vma, VMA_MAYWRITE_BIT));
> > -
> > map->vma_flags = vma->flags;
> >
> > return 0;
> > @@ -2710,11 +2700,6 @@ static int __mmap_new_vma(struct mmap_state *map, struct vm_area_struct **vmap,
> > vma->flags = map->vma_flags;
> > }
> >
> > -#ifdef CONFIG_SPARC64
> > - /* TODO: Fix SPARC ADI! */
> > - WARN_ON_ONCE(!arch_validate_flags(map->vm_flags));
> > -#endif
> > -
> > /* Lock the VMA since it is modified after insertion into VMA tree */
> > vma_start_write(vma);
> > vma_iter_store_new(vmi, vma);
> > @@ -2777,6 +2762,80 @@ static void __mmap_complete(struct mmap_state *map, struct vm_area_struct *vma)
> > vma_set_page_prot(vma);
> > }
> >
> > +/* Check to ensure that the VMA flags of a newly mapped VMA are sane. */
> > +static int mmap_validate_vma_flags(const vma_flags_t *flags)
> > +{
> > +#ifdef CONFIG_SPARC64
> > + const vm_flags_t legacy_flags = vma_flags_to_legacy(*flags);
> > +
> > + /* TODO: Fix SPARC ADI! */
> > + if (WARN_ON_ONCE(!arch_validate_flags(legacy_flags)))
> > + return -EINVAL;
> > +#endif
> > +
> > + return 0;
> > +}
> > +
> > +/* Check to ensure a driver hasn't done something crazy. */
> > +static int mmap_validate(unsigned long prev_start, unsigned long prev_end,
> > + unsigned long curr_start, unsigned long curr_end,
> > + const vma_flags_t *prev_flags,
> > + const vma_flags_t *curr_flags)
> > +{
> > + bool was_maywrite, is_maywrite;
> > +
> > + /* Drivers cannot alter the range of the VMA. */
> > + if (WARN_ON_ONCE(prev_start != curr_start || prev_end != curr_end))
> > + return -EINVAL;
> > +
> > + was_maywrite = vma_flags_test(prev_flags, VMA_MAYWRITE_BIT);
> > + is_maywrite = vma_flags_test(curr_flags, VMA_MAYWRITE_BIT);
> > +
> > + /* A driver may not make a previously unwritable mapping writable. */
> > + if (WARN_ON_ONCE(!was_maywrite && is_maywrite))
> > + return -EINVAL;
> > +
> > + return mmap_validate_vma_flags(curr_flags);
> > +}
> > +
> > +/**
> > + * mmap_prepare_validate() - Ensure the driver hasn't violated invariants in its
> > + * f_op->mmap_prepare hook.
> > + * @prev_desc: The VMA descriptor prior to the mmap_prepare hook being called.
> > + * @desc: The VMA descriptor after the mmap_prepare hook has been called.
> > + *
> > + * Returns: 0 on success, otherwise an error.
> > + */
> > +int mmap_prepare_validate(const struct vm_area_desc *prev_desc,
> > + const struct vm_area_desc *desc)
> > +{
> > + return mmap_validate(prev_desc->start, prev_desc->end,
> > + desc->start, desc->end,
> > + &prev_desc->vma_flags, &desc->vma_flags);
> > +}
> > +
> > +/**
> > + * mmap_hook_validate() - Ensure the driver hasn't violated invariants in
> > + * its f_op->mmap hook.
> > + * @prev_start: The start of the mapping prior to the mmap hook.
> > + * @prev_end: The end of the mapping prior to the mmap hook.
> > + * @prev_flags: The VMA flags set for the VMA prior to the mmap hook.
> > + * @vma: The VMA after the hook has been applied.
> > + *
> > + * Returns: 0 on success, otherwise an error.
> > + */
> > +int mmap_hook_validate(unsigned long prev_start, unsigned long prev_end,
> > + const vma_flags_t *prev_flags,
> > + const struct vm_area_struct *vma)
> > +{
> > + const unsigned long start = vma->vm_start;
> > + const unsigned long end = vma->vm_end;
> > + const vma_flags_t *flags = &vma->flags;
> > +
> > + return mmap_validate(prev_start, prev_end, start, end, prev_flags,
> > + flags);
> > +}
> > +
> > static int call_action_prepare(struct mmap_state *map,
> > struct vm_area_desc *desc)
> > {
> > @@ -2803,6 +2862,7 @@ static int call_action_prepare(struct mmap_state *map,
> > static int call_mmap_prepare(struct mmap_state *map,
> > struct vm_area_desc *desc)
> > {
> > + const struct vm_area_desc prev_desc = *desc;
> > int err;
> >
> > /* Invoke the hook. */
> > @@ -2822,6 +2882,11 @@ static int call_mmap_prepare(struct mmap_state *map,
> > if (err)
> > return err;
> >
> > + /* Check the caller did nothing crazy. */
> > + err = mmap_prepare_validate(&prev_desc, desc);
> > + if (err)
> > + return err;
> > +
> > /* Update fields permitted to be changed. */
> > map->pgoff = desc->pgoff;
> > map->vma_flags = desc->vma_flags;
> > @@ -3457,10 +3522,15 @@ int __vm_munmap(unsigned long start, size_t len, bool unlock)
> > int insert_vm_struct(struct mm_struct *mm, struct vm_area_struct *vma)
> > {
> > unsigned long charged = vma_pages(vma);
> > + int err;
> >
> > if (find_vma_intersection(mm, vma->vm_start, vma->vm_end))
> > return -ENOMEM;
> >
> > + err = mmap_validate_vma_flags(&vma->flags);
> > + if (err)
> > + return err;
> > +
> > if (vma_test(vma, VMA_ACCOUNT_BIT) &&
> > security_vm_enough_memory_mm(mm, charged))
> > return -ENOMEM;
> > diff --git a/mm/vma.h b/mm/vma.h
> > index f15faa83f3d6..b2c3bc832a48 100644
> > --- a/mm/vma.h
> > +++ b/mm/vma.h
> > @@ -782,14 +782,19 @@ struct vm_area_struct *vm_area_alloc(struct mm_struct *mm);
> > struct vm_area_struct *vm_area_dup(struct vm_area_struct *orig);
> > void vm_area_free(struct vm_area_struct *vma);
> >
> > -/* vma_exec.c */
> > #ifdef CONFIG_MMU
> > +int mmap_prepare_validate(const struct vm_area_desc *prev_desc,
> > + const struct vm_area_desc *desc);
> > +
> > +int mmap_hook_validate(unsigned long prev_start, unsigned long prev_end,
> > + const vma_flags_t *prev_flags,
> > + const struct vm_area_struct *vma);
> > +
> > +/* vma_exec.c */
> > int create_init_stack_vma(struct mm_struct *mm, struct vm_area_struct **vmap,
> > unsigned long *top_mem_p);
> > int relocate_vma_down(struct vm_area_struct *vma, unsigned long shift);
> > -#endif
> >
> > -#ifdef CONFIG_MMU
> > /*
> > * Denies creating a writable executable mapping or gaining executable permissions.
> > *
> > @@ -838,6 +843,20 @@ static inline bool map_deny_write_exec(const vma_flags_t *old,
> >
> > return false;
> > }
> > +#else
> > +static inline int mmap_prepare_validate(const struct vm_area_desc *prev_desc,
> > + const struct vm_area_desc *desc)
> > +{
> > + return 0;
> > +}
> > +
> > +static inline int mmap_hook_validate(unsigned long prev_start,
> > + unsigned long prev_end,
> > + const vma_flags_t *prev_flags,
> > + const struct vm_area_struct *vma)
> > +{
> > + return 0;
> > +}
> > #endif
> >
> > struct vm_area_struct *__install_special_mapping(struct mm_struct *mm,
> > diff --git a/tools/testing/vma/include/dup.h b/tools/testing/vma/include/dup.h
> > index 2fd422789717..2986ae6ca1e5 100644
> > --- a/tools/testing/vma/include/dup.h
> > +++ b/tools/testing/vma/include/dup.h
> > @@ -1359,13 +1359,23 @@ static inline int vfs_mmap_prepare(struct file *file, struct vm_area_desc *desc)
> > return file->f_op->mmap_prepare(desc);
> > }
> >
> > +int mmap_prepare_validate(const struct vm_area_desc *prev_desc,
> > + const struct vm_area_desc *desc);
> > +
> > static inline int __compat_vma_mmap(struct vm_area_desc *desc,
> > struct vm_area_struct *vma)
> > {
> > + struct vm_area_desc prev_desc;
> > int err;
> >
> > + /* Derive state prior to mmap_prepare hook. */
> > + compat_set_desc_from_vma(&prev_desc, desc->file, vma);
> > /* Perform any preparatory tasks for mmap action. */
> > err = mmap_action_prepare(desc);
> > + if (err)
> > + return err;
> > + /* Check the caller did nothing crazy. */
> > + err = mmap_prepare_validate(&prev_desc, desc);
> > if (err)
> > return err;
> > /* Update the VMA from the descriptor. */
> >
> > --
> > 2.55.0
> >
--
Cheers, Lorenzo
_______________________________________________
linux-riscv mailing list
linux-riscv@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-riscv
WARNING: multiple messages have this Message-ID (diff)
From: "Lorenzo Stoakes (ARM)" <ljs@kernel.org>
To: Suren Baghdasaryan <surenb@google.com>
Cc: Andrew Morton <akpm@linux-foundation.org>,
"Liam R. Howlett" <liam@infradead.org>,
Vlastimil Babka <vbabka@kernel.org>, Jann Horn <jannh@google.com>,
Pedro Falcato <pfalcato@suse.de>,
David Hildenbrand <david@kernel.org>,
Mike Rapoport <rppt@kernel.org>, Michal Hocko <mhocko@suse.com>,
Jonathan Corbet <corbet@lwn.net>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
Dennis Dalessandro <dennis.dalessandro@cornelisnetworks.com>,
Jason Gunthorpe <jgg@ziepe.ca>, Leon Romanovsky <leon@kernel.org>,
Paul Moore <paul@paul-moore.com>,
Stephen Smalley <stephen.smalley.work@gmail.com>,
Jaroslav Kysela <perex@perex.cz>, Takashi Iwai <tiwai@suse.com>,
Alexei Starovoitov <ast@kernel.org>,
Daniel Borkmann <daniel@iogearbox.net>,
Andrii Nakryiko <andrii@kernel.org>,
Eduard Zingerman <eddyz87@gmail.com>,
Kumar Kartikeya Dwivedi <memxor@gmail.com>,
Zi Yan <ziy@nvidia.com>,
Baolin Wang <baolin.wang@linux.alibaba.com>,
Nico Pache <nico.pache@linux.dev>,
Ryan Roberts <ryan.roberts@arm.com>, Dev Jain <dev.jain@arm.com>,
Barry Song <baohua@kernel.org>, Lance Yang <lance.yang@linux.dev>,
Usama Arif <usama.arif@linux.dev>,
Kiryl Shutsemau <kas@kernel.org>,
Doug Gilbert <dgilbert@interlog.com>,
"James E.J. Bottomley" <James.Bottomley@hansenpartnership.com>,
"Martin K. Petersen" <mkp@kernel.org>,
Jaya Kumar <jayalk@intworks.biz>, Simona Vetter <simona@ffwll.ch>,
Helge Deller <deller@gmx.de>, Sebastian Reichel <sre@kernel.org>,
John Hubbard <jhubbard@nvidia.com>, Peter Xu <peterx@redhat.com>,
Masami Hiramatsu <mhiramat@kernel.org>,
Oleg Nesterov <oleg@redhat.com>,
Peter Zijlstra <peterz@infradead.org>,
Thomas Gleixner <tglx@kernel.org>, Ingo Molnar <mingo@redhat.com>,
Borislav Petkov <bp@alien8.de>,
Dave Hansen <dave.hansen@linux.intel.com>,
x86@kernel.org, Arnaldo Carvalho de Melo <acme@kernel.org>,
Namhyung Kim <namhyung@kernel.org>,
Mark Rutland <mark.rutland@arm.com>,
Rik van Riel <riel@surriel.com>, Harry Yoo <harry@kernel.org>,
Juri Lelli <juri.lelli@redhat.com>,
Vincent Guittot <vincent.guittot@linaro.org>,
Maarten Lankhorst <maarten.lankhorst@linux.intel.com>,
Maxime Ripard <mripard@kernel.org>,
Thomas Zimmermann <tzimmermann@suse.de>,
David Airlie <airlied@gmail.com>, Will Deacon <will@kernel.org>,
"Aneesh Kumar K.V" <aneesh.kumar@kernel.org>,
Nick Piggin <npiggin@gmail.com>, Arnd Bergmann <arnd@arndb.de>,
Muchun Song <muchun.song@linux.dev>,
Oscar Salvador <osalvador@suse.de>,
"Matthew Wilcox (Oracle)" <willy@infradead.org>,
Jan Kara <jack@suse.cz>, Marc Zyngier <maz@kernel.org>,
Oliver Upton <oupton@kernel.org>,
Catalin Marinas <catalin.marinas@arm.com>,
Madhavan Srinivasan <maddy@linux.ibm.com>,
Anup Patel <anup@brainfault.org>, Paul Walmsley <pjw@kernel.org>,
Palmer Dabbelt <palmer@dabbelt.com>,
Albert Ou <aou@eecs.berkeley.edu>,
Christian Borntraeger <borntraeger@linux.ibm.com>,
Janosch Frank <frankja@linux.ibm.com>,
Claudio Imbrenda <imbrenda@linux.ibm.com>,
Alexander Gordeev <agordeev@linux.ibm.com>,
Gerald Schaefer <gerald.schaefer@linux.ibm.com>,
Heiko Carstens <hca@linux.ibm.com>,
Vasily Gorbik <gor@linux.ibm.com>,
"David S. Miller" <davem@davemloft.net>,
Andreas Larsson <andreas@gaisler.com>,
Alexander Viro <viro@zeniv.linux.org.uk>,
Christian Brauner <brauner@kernel.org>,
Matthew Brost <matthew.brost@intel.com>,
Joshua Hahn <joshua.hahnjy@gmail.com>,
Rakie Kim <rakie.kim@sk.com>, Byungchul Park <byungchul@sk.com>,
Gregory Price <gourry@gourry.net>,
Ying Huang <ying.huang@linux.alibaba.com>,
Alistair Popple <apopple@nvidia.com>,
Chris Li <chrisl@kernel.org>, Kairui Song <kasong@tencent.com>,
Kemeng Shi <shikemeng@huaweicloud.com>,
Nhat Pham <nphamcs@gmail.com>, Baoquan He <baoquan.he@linux.dev>,
Youngjun Park <youngjun.park@lge.com>,
Johannes Weiner <hannes@cmpxchg.org>,
Qi Zheng <qi.zheng@linux.dev>,
Shakeel Butt <shakeel.butt@linux.dev>,
Axel Rasmussen <axelrasmussen@google.com>,
Yuanchu Xie <yuanchu@google.com>, Wei Xu <weixugc@google.com>,
Chengming Zhou <chengming.zhou@linux.dev>,
Michal Hocko <mhocko@kernel.org>,
Miklos Szeredi <miklos@szeredi.hu>, Xu Xin <xu.xin@linux.dev>,
linux-mm@kvack.org, linux-kernel@vger.kernel.org,
linux-doc@vger.kernel.org, linux-usb@vger.kernel.org,
linux-rdma@vger.kernel.org, selinux@vger.kernel.org,
linux-sound@vger.kernel.org, bpf@vger.kernel.org,
linux-scsi@vger.kernel.org, linux-fbdev@vger.kernel.org,
dri-devel@lists.freedesktop.org,
linux-trace-kernel@vger.kernel.org,
linux-perf-users@vger.kernel.org, linux-arch@vger.kernel.org,
linux-fsdevel@vger.kernel.org,
linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev,
linuxppc-dev@lists.ozlabs.org, kvm@vger.kernel.org,
kvm-riscv@lists.infradead.org, linux-riscv@lists.infradead.org,
linux-s390@vger.kernel.org, sparclinux@vger.kernel.org,
fuse-devel@lists.linux.dev
Subject: Re: [PATCH v3 04/40] mm: consistently validate VMA state after mmap[_prepare] hooks
Date: Wed, 23 Sep 2026 18:00:41 +0100 [thread overview]
Message-ID: <arQFp_bwAHnmkp2V@gremlin> (raw)
In-Reply-To: <CAJuCfpELP9Ups5XeS3PNbF=VtrfkYbkwRj-LuEHd7bLsTw4LUw@mail.gmail.com>
On Wed, Sep 23, 2026 at 09:47:20AM -0700, Suren Baghdasaryan wrote:
> On Thu, Sep 17, 2026 at 9:25 AM Lorenzo Stoakes (ARM) <ljs@kernel.org> wrote:
> >
> > When the f_op->mmap_prepare or deprecated f_op->mmap hooks are invoked, the
> > driver might have done something crazy that is not permitted by the kernel.
> >
> > Currently we check for three such cases in __mmap_new_file_vma(), but only
> > if the legacy f_op->mmap hook is used:
> >
> > * Did sparc ADI result in invalid flags?
> >
> > * Did the driver alter vma->vm_start?
> >
> > * Did the driver make a file-backed mapping on a read-only file writable?
> >
> > Generalise these checks for both mmap_prepare and mmap and apply to all
> > invocations of mmap_file(), the f_op->mmap and f_op->mmap_prepare handling
> > in the core VMA code and the mmap_prepare compatibility layer.
> >
> > Also extend the vm_start check to vm_end also - drivers must not change the
> > VMA range at all.
> >
> > We also WARN_ON_ONCE() on these conditions as they are things that should
> > simply not occur in the kernel and it's important to call it out when it
> > does.
> >
> > We invoke mmap_prepare_validate() after mmap_action_prepare(), as mmap
> > actions often manipulate state in the descriptor thus providing the final
> > state the VMA will be derived from.
> >
> > Also call mmap_validate_vma_flags() in insert_vm_struct() to ensure that
> > special regions which are inserted (such as a VDSO or VVAR) also satisfy
> > the sanity checks.
> >
> > This way every VMA established through an mmap hook, whether via mmap() or
> > the compatibility layer, or inserted via insert_vm_struct(), has been
> > validated. brk() VMAs never pass through a driver hook and so need no such
> > check.
> >
> > While we're here, also fixup a couple disjoint blocks of #ifdef CONFIG_MMU.
> >
> > Finally, update the VMA userland tests to reflect the change.
> >
> > Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
>
> Reviewed-by: Suren Baghdasaryan <surenb@google.com>
Thanks!
>
> > ---
> > mm/internal.h | 51 ++++++++++++--------
> > mm/util.c | 19 ++++++--
> > mm/vma.c | 100 ++++++++++++++++++++++++++++++++++------
> > mm/vma.h | 25 ++++++++--
> > tools/testing/vma/include/dup.h | 10 ++++
> > 5 files changed, 163 insertions(+), 42 deletions(-)
> >
> > diff --git a/mm/internal.h b/mm/internal.h
> > index fe576d468af4..970fb34898b2 100644
> > --- a/mm/internal.h
> > +++ b/mm/internal.h
> > @@ -213,6 +213,24 @@ static inline void *folio_raw_mapping(const struct folio *folio)
> > return (void *)(mapping & ~FOLIO_MAPPING_FLAGS);
> > }
> >
> > +/*
> > + * If the VMA has a close hook then close it, and since closing it might leave
> > + * it in an inconsistent state which makes the use of any hooks suspect, clear
> > + * them down by installing dummy empty hooks.
> > + */
> > +static inline void vma_close(struct vm_area_struct *vma)
> > +{
> > + if (vma->vm_ops && vma->vm_ops->close) {
> > + vma->vm_ops->close(vma);
> > +
> > + /*
> > + * The mapping is in an inconsistent state, and no further hooks
> > + * may be invoked upon it.
> > + */
> > + vma->vm_ops = &vma_dummy_vm_ops;
> > + }
> > +}
> > +
> > /*
> > * This is a file-backed mapping, and is about to be memory mapped - invoke its
> > * mmap hook and safely handle error conditions. On error, VMA hooks will be
> > @@ -225,8 +243,12 @@ static inline void *folio_raw_mapping(const struct folio *folio)
> > */
> > static inline int mmap_file(struct file *file, struct vm_area_struct *vma)
> > {
> > - int err = vfs_mmap(file, vma);
> > + const unsigned long prev_start = vma->vm_start;
> > + const unsigned long prev_end = vma->vm_end;
> > + const vma_flags_t prev_flags = vma->flags;
>
> nit: Might be just me but when I see prev_XXX in VMA-related code I
> picture previous VMA in the address space. Maybe call these orig_XXX?
Sure, will change.
>
> > + int err;
> >
> > + err = vfs_mmap(file, vma);
> > /*
> > * Either we tried to call the file hook for mmap() and an error arose
> > * or a driver set vma->vm_ops = NULL intending there to be no VMA
> > @@ -239,26 +261,17 @@ static inline int mmap_file(struct file *file, struct vm_area_struct *vma)
> > */
> > if (unlikely(err || !vma->vm_ops))
> > vma->vm_ops = &vma_dummy_vm_ops;
> > + if (unlikely(err))
> > + return err;
> >
> > - return err;
> > -}
> > -
> > -/*
> > - * If the VMA has a close hook then close it, and since closing it might leave
> > - * it in an inconsistent state which makes the use of any hooks suspect, clear
> > - * them down by installing dummy empty hooks.
> > - */
> > -static inline void vma_close(struct vm_area_struct *vma)
> > -{
> > - if (vma->vm_ops && vma->vm_ops->close) {
> > - vma->vm_ops->close(vma);
> > -
> > - /*
> > - * The mapping is in an inconsistent state, and no further hooks
> > - * may be invoked upon it.
> > - */
> > - vma->vm_ops = &vma_dummy_vm_ops;
> > + err = mmap_hook_validate(prev_start, prev_end, &prev_flags, vma);
> > + if (unlikely(err)) {
> > + vma->vm_start = prev_start;
> > + vma->vm_end = prev_end;
> > + vma_close(vma);
> > }
> > +
> > + return err;
> > }
> >
> > /* unmap_vmas is in mm/memory.c */
> > diff --git a/mm/util.c b/mm/util.c
> > index 016932780925..bdd5923eebc7 100644
> > --- a/mm/util.c
> > +++ b/mm/util.c
> > @@ -1224,19 +1224,28 @@ EXPORT_SYMBOL(compat_set_desc_from_vma);
> > int __compat_vma_mmap(struct vm_area_desc *desc,
> > struct vm_area_struct *vma)
> > {
> > + struct vm_area_desc prev_desc;
> > int err;
> >
> > + /* Derive state prior to mmap_prepare hook. */
> > + compat_set_desc_from_vma(&prev_desc, desc->file, vma);
> > /* Perform any preparatory tasks for mmap action. */
> > err = mmap_action_prepare(desc);
> > - if (err) {
> > - if (desc->vm_file != vma->vm_file)
> > - fput(desc->vm_file);
> > - return err;
> > - }
> > + if (err)
> > + goto err_put;
> > + /* Check the caller did nothing crazy. */
> > + err = mmap_prepare_validate(&prev_desc, desc);
> > + if (err)
> > + goto err_put;
> > /* Update the VMA from the descriptor. */
> > compat_set_vma_from_desc(vma, desc);
> > /* Complete any specified mmap actions. */
> > return mmap_action_complete(vma, &desc->action, /*is_compat=*/true);
> > +
> > +err_put:
> > + if (desc->vm_file != vma->vm_file)
> > + fput(desc->vm_file);
> > + return err;
> > }
> > EXPORT_SYMBOL(__compat_vma_mmap);
> >
> > diff --git a/mm/vma.c b/mm/vma.c
> > index 05d2c676672e..d6ed10cefc8f 100644
> > --- a/mm/vma.c
> > +++ b/mm/vma.c
> > @@ -2623,16 +2623,6 @@ static int __mmap_new_file_vma(struct mmap_state *map,
> > return error;
> > }
> >
> > - /* Drivers cannot alter the address of the VMA. */
> > - WARN_ON_ONCE(map->addr != vma->vm_start);
> > - /*
> > - * Drivers should not permit writability when previously it was
> > - * disallowed.
> > - */
> > - VM_WARN_ON_ONCE(!vma_flags_same_pair(&map->vma_flags, &vma->flags) &&
> > - !vma_flags_test(&map->vma_flags, VMA_MAYWRITE_BIT) &&
> > - vma_test(vma, VMA_MAYWRITE_BIT));
> > -
> > map->vma_flags = vma->flags;
> >
> > return 0;
> > @@ -2710,11 +2700,6 @@ static int __mmap_new_vma(struct mmap_state *map, struct vm_area_struct **vmap,
> > vma->flags = map->vma_flags;
> > }
> >
> > -#ifdef CONFIG_SPARC64
> > - /* TODO: Fix SPARC ADI! */
> > - WARN_ON_ONCE(!arch_validate_flags(map->vm_flags));
> > -#endif
> > -
> > /* Lock the VMA since it is modified after insertion into VMA tree */
> > vma_start_write(vma);
> > vma_iter_store_new(vmi, vma);
> > @@ -2777,6 +2762,80 @@ static void __mmap_complete(struct mmap_state *map, struct vm_area_struct *vma)
> > vma_set_page_prot(vma);
> > }
> >
> > +/* Check to ensure that the VMA flags of a newly mapped VMA are sane. */
> > +static int mmap_validate_vma_flags(const vma_flags_t *flags)
> > +{
> > +#ifdef CONFIG_SPARC64
> > + const vm_flags_t legacy_flags = vma_flags_to_legacy(*flags);
> > +
> > + /* TODO: Fix SPARC ADI! */
> > + if (WARN_ON_ONCE(!arch_validate_flags(legacy_flags)))
> > + return -EINVAL;
> > +#endif
> > +
> > + return 0;
> > +}
> > +
> > +/* Check to ensure a driver hasn't done something crazy. */
> > +static int mmap_validate(unsigned long prev_start, unsigned long prev_end,
> > + unsigned long curr_start, unsigned long curr_end,
> > + const vma_flags_t *prev_flags,
> > + const vma_flags_t *curr_flags)
> > +{
> > + bool was_maywrite, is_maywrite;
> > +
> > + /* Drivers cannot alter the range of the VMA. */
> > + if (WARN_ON_ONCE(prev_start != curr_start || prev_end != curr_end))
> > + return -EINVAL;
> > +
> > + was_maywrite = vma_flags_test(prev_flags, VMA_MAYWRITE_BIT);
> > + is_maywrite = vma_flags_test(curr_flags, VMA_MAYWRITE_BIT);
> > +
> > + /* A driver may not make a previously unwritable mapping writable. */
> > + if (WARN_ON_ONCE(!was_maywrite && is_maywrite))
> > + return -EINVAL;
> > +
> > + return mmap_validate_vma_flags(curr_flags);
> > +}
> > +
> > +/**
> > + * mmap_prepare_validate() - Ensure the driver hasn't violated invariants in its
> > + * f_op->mmap_prepare hook.
> > + * @prev_desc: The VMA descriptor prior to the mmap_prepare hook being called.
> > + * @desc: The VMA descriptor after the mmap_prepare hook has been called.
> > + *
> > + * Returns: 0 on success, otherwise an error.
> > + */
> > +int mmap_prepare_validate(const struct vm_area_desc *prev_desc,
> > + const struct vm_area_desc *desc)
> > +{
> > + return mmap_validate(prev_desc->start, prev_desc->end,
> > + desc->start, desc->end,
> > + &prev_desc->vma_flags, &desc->vma_flags);
> > +}
> > +
> > +/**
> > + * mmap_hook_validate() - Ensure the driver hasn't violated invariants in
> > + * its f_op->mmap hook.
> > + * @prev_start: The start of the mapping prior to the mmap hook.
> > + * @prev_end: The end of the mapping prior to the mmap hook.
> > + * @prev_flags: The VMA flags set for the VMA prior to the mmap hook.
> > + * @vma: The VMA after the hook has been applied.
> > + *
> > + * Returns: 0 on success, otherwise an error.
> > + */
> > +int mmap_hook_validate(unsigned long prev_start, unsigned long prev_end,
> > + const vma_flags_t *prev_flags,
> > + const struct vm_area_struct *vma)
> > +{
> > + const unsigned long start = vma->vm_start;
> > + const unsigned long end = vma->vm_end;
> > + const vma_flags_t *flags = &vma->flags;
> > +
> > + return mmap_validate(prev_start, prev_end, start, end, prev_flags,
> > + flags);
> > +}
> > +
> > static int call_action_prepare(struct mmap_state *map,
> > struct vm_area_desc *desc)
> > {
> > @@ -2803,6 +2862,7 @@ static int call_action_prepare(struct mmap_state *map,
> > static int call_mmap_prepare(struct mmap_state *map,
> > struct vm_area_desc *desc)
> > {
> > + const struct vm_area_desc prev_desc = *desc;
> > int err;
> >
> > /* Invoke the hook. */
> > @@ -2822,6 +2882,11 @@ static int call_mmap_prepare(struct mmap_state *map,
> > if (err)
> > return err;
> >
> > + /* Check the caller did nothing crazy. */
> > + err = mmap_prepare_validate(&prev_desc, desc);
> > + if (err)
> > + return err;
> > +
> > /* Update fields permitted to be changed. */
> > map->pgoff = desc->pgoff;
> > map->vma_flags = desc->vma_flags;
> > @@ -3457,10 +3522,15 @@ int __vm_munmap(unsigned long start, size_t len, bool unlock)
> > int insert_vm_struct(struct mm_struct *mm, struct vm_area_struct *vma)
> > {
> > unsigned long charged = vma_pages(vma);
> > + int err;
> >
> > if (find_vma_intersection(mm, vma->vm_start, vma->vm_end))
> > return -ENOMEM;
> >
> > + err = mmap_validate_vma_flags(&vma->flags);
> > + if (err)
> > + return err;
> > +
> > if (vma_test(vma, VMA_ACCOUNT_BIT) &&
> > security_vm_enough_memory_mm(mm, charged))
> > return -ENOMEM;
> > diff --git a/mm/vma.h b/mm/vma.h
> > index f15faa83f3d6..b2c3bc832a48 100644
> > --- a/mm/vma.h
> > +++ b/mm/vma.h
> > @@ -782,14 +782,19 @@ struct vm_area_struct *vm_area_alloc(struct mm_struct *mm);
> > struct vm_area_struct *vm_area_dup(struct vm_area_struct *orig);
> > void vm_area_free(struct vm_area_struct *vma);
> >
> > -/* vma_exec.c */
> > #ifdef CONFIG_MMU
> > +int mmap_prepare_validate(const struct vm_area_desc *prev_desc,
> > + const struct vm_area_desc *desc);
> > +
> > +int mmap_hook_validate(unsigned long prev_start, unsigned long prev_end,
> > + const vma_flags_t *prev_flags,
> > + const struct vm_area_struct *vma);
> > +
> > +/* vma_exec.c */
> > int create_init_stack_vma(struct mm_struct *mm, struct vm_area_struct **vmap,
> > unsigned long *top_mem_p);
> > int relocate_vma_down(struct vm_area_struct *vma, unsigned long shift);
> > -#endif
> >
> > -#ifdef CONFIG_MMU
> > /*
> > * Denies creating a writable executable mapping or gaining executable permissions.
> > *
> > @@ -838,6 +843,20 @@ static inline bool map_deny_write_exec(const vma_flags_t *old,
> >
> > return false;
> > }
> > +#else
> > +static inline int mmap_prepare_validate(const struct vm_area_desc *prev_desc,
> > + const struct vm_area_desc *desc)
> > +{
> > + return 0;
> > +}
> > +
> > +static inline int mmap_hook_validate(unsigned long prev_start,
> > + unsigned long prev_end,
> > + const vma_flags_t *prev_flags,
> > + const struct vm_area_struct *vma)
> > +{
> > + return 0;
> > +}
> > #endif
> >
> > struct vm_area_struct *__install_special_mapping(struct mm_struct *mm,
> > diff --git a/tools/testing/vma/include/dup.h b/tools/testing/vma/include/dup.h
> > index 2fd422789717..2986ae6ca1e5 100644
> > --- a/tools/testing/vma/include/dup.h
> > +++ b/tools/testing/vma/include/dup.h
> > @@ -1359,13 +1359,23 @@ static inline int vfs_mmap_prepare(struct file *file, struct vm_area_desc *desc)
> > return file->f_op->mmap_prepare(desc);
> > }
> >
> > +int mmap_prepare_validate(const struct vm_area_desc *prev_desc,
> > + const struct vm_area_desc *desc);
> > +
> > static inline int __compat_vma_mmap(struct vm_area_desc *desc,
> > struct vm_area_struct *vma)
> > {
> > + struct vm_area_desc prev_desc;
> > int err;
> >
> > + /* Derive state prior to mmap_prepare hook. */
> > + compat_set_desc_from_vma(&prev_desc, desc->file, vma);
> > /* Perform any preparatory tasks for mmap action. */
> > err = mmap_action_prepare(desc);
> > + if (err)
> > + return err;
> > + /* Check the caller did nothing crazy. */
> > + err = mmap_prepare_validate(&prev_desc, desc);
> > if (err)
> > return err;
> > /* Update the VMA from the descriptor. */
> >
> > --
> > 2.55.0
> >
--
Cheers, Lorenzo
--
kvm-riscv mailing list
kvm-riscv@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/kvm-riscv
next prev parent reply other threads:[~2026-09-23 17:01 UTC|newest]
Thread overview: 483+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 16:22 [PATCH v3 00/40] mm: make VMA flag semantics explicit, eliminate VM_SPECIAL Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 01/40] mm/vma: fix mmap_prepare file handling, remove file_doesnt_need_get Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:54 ` sashiko-bot
2026-09-23 15:21 ` Suren Baghdasaryan
2026-09-23 15:21 ` Suren Baghdasaryan
2026-09-23 15:21 ` Suren Baghdasaryan
2026-09-23 15:46 ` Lorenzo Stoakes (ARM)
2026-09-23 15:46 ` Lorenzo Stoakes (ARM)
2026-09-23 15:46 ` Lorenzo Stoakes (ARM)
2026-09-23 15:59 ` Suren Baghdasaryan
2026-09-23 15:59 ` Suren Baghdasaryan
2026-09-23 15:59 ` Suren Baghdasaryan
2026-09-24 2:20 ` Zi Yan
2026-09-24 2:20 ` Zi Yan
2026-09-24 2:20 ` Zi Yan
2026-09-24 10:03 ` Lorenzo Stoakes (ARM)
2026-09-24 10:03 ` Lorenzo Stoakes (ARM)
2026-09-24 10:03 ` Lorenzo Stoakes (ARM)
2026-09-24 16:28 ` Gregory Price
2026-09-25 9:30 ` Lorenzo Stoakes (ARM)
2026-09-24 19:00 ` Liam R. Howlett
2026-09-24 19:00 ` Liam R. Howlett
2026-09-24 19:00 ` Liam R. Howlett
2026-09-25 9:12 ` Lorenzo Stoakes (ARM)
2026-09-25 9:12 ` Lorenzo Stoakes (ARM)
2026-09-25 9:12 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 02/40] mm/vma: predicate setting mmap_prepare VMA fields on new vma alloc Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:07 ` sashiko-bot
2026-09-23 15:32 ` Suren Baghdasaryan
2026-09-23 15:32 ` Suren Baghdasaryan
2026-09-23 15:32 ` Suren Baghdasaryan
2026-09-23 15:53 ` Lorenzo Stoakes (ARM)
2026-09-23 15:53 ` Lorenzo Stoakes (ARM)
2026-09-23 15:53 ` Lorenzo Stoakes (ARM)
2026-09-23 16:09 ` Suren Baghdasaryan
2026-09-23 16:09 ` Suren Baghdasaryan
2026-09-23 16:09 ` Suren Baghdasaryan
2026-09-23 17:07 ` Lorenzo Stoakes (ARM)
2026-09-23 17:07 ` Lorenzo Stoakes (ARM)
2026-09-23 17:07 ` Lorenzo Stoakes (ARM)
2026-09-23 17:33 ` Lorenzo Stoakes (ARM)
2026-09-23 17:33 ` Lorenzo Stoakes (ARM)
2026-09-23 17:33 ` Lorenzo Stoakes (ARM)
2026-09-24 2:25 ` Zi Yan
2026-09-24 2:25 ` Zi Yan
2026-09-24 2:25 ` Zi Yan
2026-09-17 16:22 ` [PATCH v3 03/40] mm/vma: introduce and use vma_[flags_]can_merge() Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:11 ` sashiko-bot
2026-09-23 16:23 ` Suren Baghdasaryan
2026-09-23 16:23 ` Suren Baghdasaryan
2026-09-23 16:23 ` Suren Baghdasaryan
2026-09-24 2:27 ` Zi Yan
2026-09-24 2:27 ` Zi Yan
2026-09-24 2:27 ` Zi Yan
2026-09-24 16:38 ` Gregory Price
2026-09-24 16:38 ` Gregory Price
2026-09-24 16:38 ` Gregory Price
2026-10-01 12:03 ` David Hildenbrand (Arm)
2026-10-01 12:03 ` David Hildenbrand (Arm)
2026-10-01 12:03 ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 04/40] mm: consistently validate VMA state after mmap[_prepare] hooks Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:38 ` sashiko-bot
2026-09-23 16:47 ` Suren Baghdasaryan
2026-09-23 16:47 ` Suren Baghdasaryan
2026-09-23 16:47 ` Suren Baghdasaryan
2026-09-23 17:00 ` Lorenzo Stoakes (ARM) [this message]
2026-09-23 17:00 ` Lorenzo Stoakes (ARM)
2026-09-23 17:00 ` Lorenzo Stoakes (ARM)
2026-09-24 2:52 ` Zi Yan
2026-09-24 2:52 ` Zi Yan
2026-09-24 2:52 ` Zi Yan
2026-09-24 10:06 ` Lorenzo Stoakes (ARM)
2026-09-24 10:06 ` Lorenzo Stoakes (ARM)
2026-09-24 10:06 ` Lorenzo Stoakes (ARM)
2026-09-24 17:17 ` Gregory Price
2026-09-24 17:17 ` Gregory Price
2026-09-24 17:17 ` Gregory Price
2026-09-25 12:51 ` Lorenzo Stoakes (ARM)
2026-09-25 12:51 ` Lorenzo Stoakes (ARM)
2026-09-25 12:51 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 05/40] mm/vma: ensure mmap_prepare doesn't set actions on a mergeable vma Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:32 ` sashiko-bot
2026-09-24 18:00 ` Gregory Price
2026-09-24 18:00 ` Gregory Price
2026-09-24 18:00 ` Gregory Price
2026-09-25 9:51 ` Lorenzo Stoakes (ARM)
2026-09-25 9:51 ` Lorenzo Stoakes (ARM)
2026-09-25 9:51 ` Lorenzo Stoakes (ARM)
2026-09-24 19:28 ` Zi Yan
2026-09-24 19:28 ` Zi Yan
2026-09-24 19:28 ` Zi Yan
2026-09-25 9:55 ` Lorenzo Stoakes (ARM)
2026-09-25 9:55 ` Lorenzo Stoakes (ARM)
2026-09-25 9:55 ` Lorenzo Stoakes (ARM)
2026-09-25 7:28 ` Suren Baghdasaryan
2026-09-25 7:28 ` Suren Baghdasaryan
2026-09-25 7:28 ` Suren Baghdasaryan
2026-09-25 9:53 ` Lorenzo Stoakes (ARM)
2026-09-25 9:53 ` Lorenzo Stoakes (ARM)
2026-09-25 9:53 ` Lorenzo Stoakes (ARM)
2026-10-01 12:11 ` David Hildenbrand (Arm)
2026-10-01 12:11 ` David Hildenbrand (Arm)
2026-10-01 12:11 ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 06/40] mm: make map_kernel_pages_[prepare,complete] internal and unexported Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:17 ` sashiko-bot
2026-09-24 19:30 ` Zi Yan
2026-09-24 19:30 ` Zi Yan
2026-09-24 19:30 ` Zi Yan
2026-09-25 7:35 ` Suren Baghdasaryan
2026-09-25 7:35 ` Suren Baghdasaryan
2026-09-25 7:35 ` Suren Baghdasaryan
2026-09-29 15:58 ` Gregory Price
2026-09-29 15:58 ` Gregory Price
2026-09-29 15:58 ` Gregory Price
2026-10-01 12:11 ` David Hildenbrand (Arm)
2026-10-01 12:11 ` David Hildenbrand (Arm)
2026-10-01 12:11 ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 07/40] mm/vma: tidy up map kernel pages enum values Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:17 ` sashiko-bot
2026-09-24 19:30 ` Zi Yan
2026-09-24 19:30 ` Zi Yan
2026-09-24 19:30 ` Zi Yan
2026-09-25 7:37 ` Suren Baghdasaryan
2026-09-25 7:37 ` Suren Baghdasaryan
2026-09-25 7:37 ` Suren Baghdasaryan
2026-09-29 15:59 ` Gregory Price
2026-09-29 15:59 ` Gregory Price
2026-09-29 15:59 ` Gregory Price
2026-10-01 12:12 ` David Hildenbrand (Arm)
2026-10-01 12:12 ` David Hildenbrand (Arm)
2026-10-01 12:12 ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 08/40] mm: add mmap action for discontiguous kernel page mapping Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:25 ` sashiko-bot
2026-09-25 20:53 ` Zi Yan
2026-09-25 20:53 ` Zi Yan
2026-09-25 20:53 ` Zi Yan
2026-09-27 21:44 ` Suren Baghdasaryan
2026-09-27 21:44 ` Suren Baghdasaryan
2026-09-27 21:44 ` Suren Baghdasaryan
2026-09-29 11:11 ` Lorenzo Stoakes (ARM)
2026-09-29 11:11 ` Lorenzo Stoakes (ARM)
2026-09-29 11:11 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 09/40] docs: filesystems: update mmap_prepare docs for discontig kernel pgs Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:32 ` sashiko-bot
2026-09-25 21:01 ` Zi Yan
2026-09-25 21:01 ` Zi Yan
2026-09-25 21:01 ` Zi Yan
2026-09-29 11:21 ` Lorenzo Stoakes (ARM)
2026-09-29 11:21 ` Lorenzo Stoakes (ARM)
2026-09-29 11:21 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 10/40] drivers/usb/mon: update to use mmap_prepare + map kernel pages Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:29 ` sashiko-bot
2026-10-02 9:55 ` Lance Yang
2026-10-02 12:12 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 11/40] infiniband: update hfi1 to use remap_vmalloc_range() Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:36 ` sashiko-bot
2026-09-17 16:22 ` [PATCH v3 12/40] selinux: reject writable opens of policy file, drop mmap shared/write check Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:25 ` sashiko-bot
2026-09-17 16:22 ` [PATCH v3 13/40] ALSA: pcm: use vm_insert_page() to map PCM status page Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:34 ` sashiko-bot
2026-09-17 16:22 ` [PATCH v3 14/40] bpf: arena: mark arena_map_mmap() mappings VM_MIXEDMAP Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:25 ` sashiko-bot
2026-09-17 16:22 ` [PATCH v3 15/40] mm/vma: add vma[_flags]_is_kernel_owned() predicates Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:21 ` sashiko-bot
2026-09-26 1:37 ` Zi Yan
2026-09-26 1:37 ` Zi Yan
2026-09-26 1:37 ` Zi Yan
2026-10-01 12:36 ` David Hildenbrand (Arm)
2026-10-01 12:36 ` David Hildenbrand (Arm)
2026-10-01 12:36 ` David Hildenbrand (Arm)
2026-10-02 14:56 ` Lorenzo Stoakes (ARM)
2026-10-02 14:56 ` Lorenzo Stoakes (ARM)
2026-10-02 14:56 ` Lorenzo Stoakes (ARM)
2026-10-02 21:19 ` David Hildenbrand (Arm)
2026-10-02 21:19 ` David Hildenbrand (Arm)
2026-10-02 21:19 ` David Hildenbrand (Arm)
2026-10-03 9:03 ` Lorenzo Stoakes (ARM)
2026-10-03 9:03 ` Lorenzo Stoakes (ARM)
2026-10-03 9:03 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 16/40] mm/vma: only allow mmap to clear VMA_MAYWRITE_BIT if kernel-owned Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:28 ` sashiko-bot
2026-09-26 2:07 ` Zi Yan
2026-09-26 2:07 ` Zi Yan
2026-09-26 2:07 ` Zi Yan
2026-09-26 2:17 ` Zi Yan
2026-09-26 2:17 ` Zi Yan
2026-09-26 2:17 ` Zi Yan
2026-09-26 10:06 ` Lorenzo Stoakes (ARM)
2026-09-26 10:06 ` Lorenzo Stoakes (ARM)
2026-09-26 10:06 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 17/40] mm/vma: add and use vma_[flags]_is_fixed_mapping Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:27 ` sashiko-bot
2026-09-26 2:27 ` Zi Yan
2026-09-26 2:27 ` Zi Yan
2026-09-26 2:27 ` Zi Yan
2026-09-26 10:03 ` Lorenzo Stoakes (ARM)
2026-09-26 10:03 ` Lorenzo Stoakes (ARM)
2026-09-26 10:03 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 18/40] scsi: sg: convert mmap hook to mmap_prepare and rework Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:34 ` sashiko-bot
2026-09-17 16:22 ` [PATCH v3 19/40] fbdev: defio: assert FBINFO_VIRTFB, drop VM_IO, add VM_MIXEDMAP Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:27 ` sashiko-bot
2026-09-17 16:22 ` [PATCH v3 20/40] HSI: cmt_speech: convert mmap hook to mmap_prepare, refactor Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:31 ` sashiko-bot
2026-09-17 16:22 ` [PATCH v3 21/40] mm/gup: error out early on !VMA_MAYREAD_BIT VMAs Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:30 ` sashiko-bot
2026-09-26 2:30 ` Zi Yan
2026-09-26 2:30 ` Zi Yan
2026-09-26 2:30 ` Zi Yan
2026-09-17 16:22 ` [PATCH v3 22/40] uprobes: remove VM_IO, set VM_MIXEDMAP for mapped kernel pages Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:30 ` sashiko-bot
2026-09-17 16:22 ` [PATCH v3 23/40] mm/mlock: clear VMA_LOCKED_MASK over mmap callback Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:32 ` sashiko-bot
2026-10-01 15:20 ` Zi Yan
2026-10-01 15:20 ` Zi Yan
2026-10-01 15:20 ` Zi Yan
2026-10-02 12:26 ` Lorenzo Stoakes (ARM)
2026-10-02 12:26 ` Lorenzo Stoakes (ARM)
2026-10-02 12:26 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 24/40] mm/mlock: eliminate weird VMA_IO_BIT abuse and simplify Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:43 ` sashiko-bot
2026-09-23 20:06 ` Zi Yan
2026-09-23 20:06 ` Zi Yan
2026-09-23 20:06 ` Zi Yan
2026-09-24 10:21 ` Lorenzo Stoakes (ARM)
2026-09-24 10:21 ` Lorenzo Stoakes (ARM)
2026-09-24 10:21 ` Lorenzo Stoakes (ARM)
2026-09-24 15:50 ` Zi Yan
2026-09-24 15:50 ` Zi Yan
2026-09-24 15:50 ` Zi Yan
2026-09-25 9:35 ` Lorenzo Stoakes (ARM)
2026-09-25 9:35 ` Lorenzo Stoakes (ARM)
2026-09-25 9:35 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 25/40] mm/vma: enforce that only kernel-owned mappings may set VMA_IO_BIT Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:31 ` sashiko-bot
2026-09-29 2:12 ` Zi Yan
2026-09-29 2:12 ` Zi Yan
2026-09-29 2:12 ` Zi Yan
2026-09-17 16:22 ` [PATCH v3 26/40] mm: remove VMA_IO_BIT check in vma[_flags]_is_kernel_owned() Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:34 ` sashiko-bot
2026-09-17 16:22 ` [PATCH v3 27/40] mm: remove hugetlb_inline.h Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:31 ` sashiko-bot
2026-09-29 2:13 ` Zi Yan
2026-09-29 2:13 ` Zi Yan
2026-09-29 2:13 ` Zi Yan
2026-10-02 6:52 ` David Hildenbrand (Arm)
2026-10-02 6:52 ` David Hildenbrand (Arm)
2026-10-02 6:52 ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 28/40] mm: rename is_vm_hugetlb_page() to vma_is_hugetlb() Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:30 ` sashiko-bot
2026-09-29 2:14 ` Zi Yan
2026-09-29 2:14 ` Zi Yan
2026-09-29 2:14 ` Zi Yan
2026-10-02 6:53 ` David Hildenbrand (Arm)
2026-10-02 6:53 ` David Hildenbrand (Arm)
2026-10-02 6:53 ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 29/40] mm: drop some redundant checks around hugetlb VMAs Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:32 ` sashiko-bot
2026-09-29 2:36 ` Zi Yan
2026-09-29 2:36 ` Zi Yan
2026-09-29 2:36 ` Zi Yan
2026-10-02 6:54 ` David Hildenbrand (Arm)
2026-10-02 6:54 ` David Hildenbrand (Arm)
2026-10-02 6:54 ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 30/40] mm/madvise: update is_valid_guard_vma() to use vma_can_merge() Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:37 ` sashiko-bot
2026-09-29 2:38 ` Zi Yan
2026-09-29 2:38 ` Zi Yan
2026-09-29 2:38 ` Zi Yan
2026-10-02 6:57 ` David Hildenbrand (Arm)
2026-10-02 6:57 ` David Hildenbrand (Arm)
2026-10-02 6:57 ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 31/40] mm/vma: introduce vma[_flags]_is_persistent() Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:35 ` sashiko-bot
2026-09-30 2:00 ` Zi Yan
2026-09-30 2:00 ` Zi Yan
2026-09-30 2:00 ` Zi Yan
2026-10-02 6:59 ` David Hildenbrand (Arm)
2026-10-02 6:59 ` David Hildenbrand (Arm)
2026-10-02 6:59 ` David Hildenbrand (Arm)
2026-10-02 7:02 ` David Hildenbrand (Arm)
2026-10-02 7:02 ` David Hildenbrand (Arm)
2026-10-02 7:02 ` David Hildenbrand (Arm)
2026-10-02 7:05 ` David Hildenbrand (Arm)
2026-10-02 7:05 ` David Hildenbrand (Arm)
2026-10-02 7:05 ` David Hildenbrand (Arm)
2026-10-02 12:08 ` Lorenzo Stoakes (ARM)
2026-10-02 12:08 ` Lorenzo Stoakes (ARM)
2026-10-02 12:08 ` Lorenzo Stoakes (ARM)
2026-10-02 12:35 ` David Hildenbrand (Arm)
2026-10-02 12:35 ` David Hildenbrand (Arm)
2026-10-02 12:35 ` David Hildenbrand (Arm)
2026-10-02 12:48 ` Lorenzo Stoakes (ARM)
2026-10-02 12:48 ` Lorenzo Stoakes (ARM)
2026-10-02 12:48 ` Lorenzo Stoakes (ARM)
2026-10-02 13:11 ` David Hildenbrand (Arm)
2026-10-02 13:11 ` David Hildenbrand (Arm)
2026-10-02 13:11 ` David Hildenbrand (Arm)
2026-10-02 13:59 ` Lorenzo Stoakes (ARM)
2026-10-02 13:59 ` Lorenzo Stoakes (ARM)
2026-10-02 13:59 ` Lorenzo Stoakes (ARM)
2026-10-02 21:43 ` David Hildenbrand (Arm)
2026-10-02 21:43 ` David Hildenbrand (Arm)
2026-10-02 21:43 ` David Hildenbrand (Arm)
2026-10-03 13:16 ` Lorenzo Stoakes (ARM)
2026-10-03 13:16 ` Lorenzo Stoakes (ARM)
2026-10-03 13:16 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 32/40] mm/uffd: use predicates for userfaultfd checks Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:38 ` sashiko-bot
2026-09-30 2:02 ` Zi Yan
2026-09-30 2:02 ` Zi Yan
2026-09-30 2:02 ` Zi Yan
2026-10-02 7:04 ` David Hildenbrand (Arm)
2026-10-02 7:04 ` David Hildenbrand (Arm)
2026-10-02 7:04 ` David Hildenbrand (Arm)
2026-10-02 12:35 ` Lorenzo Stoakes (ARM)
2026-10-02 12:35 ` Lorenzo Stoakes (ARM)
2026-10-02 12:35 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 33/40] mm/madvise: use predicates for madvise(..., MADV_DOFORK) Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:37 ` sashiko-bot
2026-09-30 2:28 ` Zi Yan
2026-09-30 2:28 ` Zi Yan
2026-09-30 2:28 ` Zi Yan
2026-09-17 16:22 ` [PATCH v3 34/40] mm: eliminate VMA_SPECIAL_FLAGS usage when hugetlb explicitly tested Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:45 ` sashiko-bot
2026-09-30 2:42 ` Zi Yan
2026-09-30 2:42 ` Zi Yan
2026-09-30 2:42 ` Zi Yan
2026-09-30 9:32 ` Lorenzo Stoakes (ARM)
2026-09-30 9:32 ` Lorenzo Stoakes (ARM)
2026-09-30 9:32 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 35/40] mm: eliminate VMA_SPECIAL_FLAGS check in lru_gen_look_around() Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:41 ` sashiko-bot
2026-09-30 2:42 ` Zi Yan
2026-09-30 2:42 ` Zi Yan
2026-09-30 2:42 ` Zi Yan
2026-10-02 7:06 ` David Hildenbrand (Arm)
2026-10-02 7:06 ` David Hildenbrand (Arm)
2026-10-02 7:06 ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 36/40] mm: avoid use of VMA_SPECIAL_FLAGS in migrate_vma_setup() Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:40 ` sashiko-bot
2026-09-30 2:47 ` Zi Yan
2026-09-30 2:47 ` Zi Yan
2026-09-30 2:47 ` Zi Yan
2026-10-02 7:07 ` David Hildenbrand (Arm)
2026-10-02 7:07 ` David Hildenbrand (Arm)
2026-10-02 7:07 ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 37/40] mm: eliminate VM_SPECIAL, VMA_SPECIAL_FLAGS Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:44 ` sashiko-bot
2026-09-30 2:48 ` Zi Yan
2026-09-30 2:48 ` Zi Yan
2026-09-30 2:48 ` Zi Yan
2026-10-02 7:07 ` David Hildenbrand (Arm)
2026-10-02 7:07 ` David Hildenbrand (Arm)
2026-10-02 7:07 ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 38/40] fuse: dax: do not set VM_MIXEDMAP Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:38 ` sashiko-bot
2026-10-02 7:09 ` David Hildenbrand (Arm)
2026-10-02 7:09 ` David Hildenbrand (Arm)
2026-10-02 7:09 ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 39/40] mm/huge_memory: remove vma_is_special_huge() Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:38 ` sashiko-bot
2026-10-01 15:21 ` Zi Yan
2026-10-01 15:21 ` Zi Yan
2026-10-01 15:21 ` Zi Yan
2026-10-02 7:11 ` David Hildenbrand (Arm)
2026-10-02 7:11 ` David Hildenbrand (Arm)
2026-10-02 7:11 ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 40/40] mm/vma: introduce and use vma[_flags]_can_gup() Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM)
2026-09-17 17:36 ` sashiko-bot
2026-10-01 15:23 ` Zi Yan
2026-10-01 15:23 ` Zi Yan
2026-10-01 15:23 ` Zi Yan
2026-10-02 7:48 ` David Hildenbrand (Arm)
2026-10-02 7:48 ` David Hildenbrand (Arm)
2026-10-02 7:48 ` David Hildenbrand (Arm)
2026-10-02 16:11 ` Lorenzo Stoakes (ARM)
2026-10-02 16:11 ` Lorenzo Stoakes (ARM)
2026-10-02 16:11 ` Lorenzo Stoakes (ARM)
2026-09-17 21:23 ` [PATCH v3 00/40] mm: make VMA flag semantics explicit, eliminate VM_SPECIAL Andrew Morton
2026-09-17 21:23 ` Andrew Morton
2026-09-17 21:23 ` Andrew Morton
2026-09-23 8:57 ` Lorenzo Stoakes (ARM)
2026-09-23 8:57 ` Lorenzo Stoakes (ARM)
2026-09-23 8:57 ` Lorenzo Stoakes (ARM)
2026-09-25 15:58 ` Lorenzo Stoakes (ARM)
2026-09-25 22:06 ` Arnd Bergmann
2026-09-25 22:06 ` Arnd Bergmann
2026-09-25 22:06 ` Arnd Bergmann
2026-09-26 9:40 ` Lorenzo Stoakes (ARM)
2026-09-26 9:40 ` Lorenzo Stoakes (ARM)
2026-09-26 9:40 ` Lorenzo Stoakes (ARM)
2026-09-26 13:06 ` Arnd Bergmann
2026-09-26 13:06 ` Arnd Bergmann
2026-09-26 13:06 ` Arnd Bergmann
2026-09-26 13:22 ` Lorenzo Stoakes (ARM)
2026-09-26 13:22 ` Lorenzo Stoakes (ARM)
2026-09-26 13:22 ` Lorenzo Stoakes (ARM)
2026-09-26 17:14 ` Arnd Bergmann
2026-09-26 17:14 ` Arnd Bergmann
2026-09-26 17:14 ` Arnd Bergmann
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=arQFp_bwAHnmkp2V@gremlin \
--to=ljs@kernel.org \
--cc=James.Bottomley@hansenpartnership.com \
--cc=acme@kernel.org \
--cc=agordeev@linux.ibm.com \
--cc=airlied@gmail.com \
--cc=akpm@linux-foundation.org \
--cc=andreas@gaisler.com \
--cc=andrii@kernel.org \
--cc=aneesh.kumar@kernel.org \
--cc=anup@brainfault.org \
--cc=aou@eecs.berkeley.edu \
--cc=apopple@nvidia.com \
--cc=arnd@arndb.de \
--cc=ast@kernel.org \
--cc=axelrasmussen@google.com \
--cc=baohua@kernel.org \
--cc=baolin.wang@linux.alibaba.com \
--cc=baoquan.he@linux.dev \
--cc=borntraeger@linux.ibm.com \
--cc=bp@alien8.de \
--cc=bpf@vger.kernel.org \
--cc=brauner@kernel.org \
--cc=byungchul@sk.com \
--cc=catalin.marinas@arm.com \
--cc=chengming.zhou@linux.dev \
--cc=chrisl@kernel.org \
--cc=corbet@lwn.net \
--cc=daniel@iogearbox.net \
--cc=dave.hansen@linux.intel.com \
--cc=davem@davemloft.net \
--cc=david@kernel.org \
--cc=deller@gmx.de \
--cc=dennis.dalessandro@cornelisnetworks.com \
--cc=dev.jain@arm.com \
--cc=dgilbert@interlog.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=eddyz87@gmail.com \
--cc=frankja@linux.ibm.com \
--cc=fuse-devel@lists.linux.dev \
--cc=gerald.schaefer@linux.ibm.com \
--cc=gor@linux.ibm.com \
--cc=gourry@gourry.net \
--cc=gregkh@linuxfoundation.org \
--cc=hannes@cmpxchg.org \
--cc=harry@kernel.org \
--cc=hca@linux.ibm.com \
--cc=imbrenda@linux.ibm.com \
--cc=jack@suse.cz \
--cc=jannh@google.com \
--cc=jayalk@intworks.biz \
--cc=jgg@ziepe.ca \
--cc=jhubbard@nvidia.com \
--cc=joshua.hahnjy@gmail.com \
--cc=juri.lelli@redhat.com \
--cc=kas@kernel.org \
--cc=kasong@tencent.com \
--cc=kvm-riscv@lists.infradead.org \
--cc=kvm@vger.kernel.org \
--cc=kvmarm@lists.linux.dev \
--cc=lance.yang@linux.dev \
--cc=leon@kernel.org \
--cc=liam@infradead.org \
--cc=linux-arch@vger.kernel.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-doc@vger.kernel.org \
--cc=linux-fbdev@vger.kernel.org \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=linux-perf-users@vger.kernel.org \
--cc=linux-rdma@vger.kernel.org \
--cc=linux-riscv@lists.infradead.org \
--cc=linux-s390@vger.kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=linux-sound@vger.kernel.org \
--cc=linux-trace-kernel@vger.kernel.org \
--cc=linux-usb@vger.kernel.org \
--cc=linuxppc-dev@lists.ozlabs.org \
--cc=maarten.lankhorst@linux.intel.com \
--cc=maddy@linux.ibm.com \
--cc=mark.rutland@arm.com \
--cc=matthew.brost@intel.com \
--cc=maz@kernel.org \
--cc=memxor@gmail.com \
--cc=mhiramat@kernel.org \
--cc=mhocko@kernel.org \
--cc=mhocko@suse.com \
--cc=miklos@szeredi.hu \
--cc=mingo@redhat.com \
--cc=mkp@kernel.org \
--cc=mripard@kernel.org \
--cc=muchun.song@linux.dev \
--cc=namhyung@kernel.org \
--cc=nico.pache@linux.dev \
--cc=nphamcs@gmail.com \
--cc=npiggin@gmail.com \
--cc=oleg@redhat.com \
--cc=osalvador@suse.de \
--cc=oupton@kernel.org \
--cc=palmer@dabbelt.com \
--cc=paul@paul-moore.com \
--cc=perex@perex.cz \
--cc=peterx@redhat.com \
--cc=peterz@infradead.org \
--cc=pfalcato@suse.de \
--cc=pjw@kernel.org \
--cc=qi.zheng@linux.dev \
--cc=rakie.kim@sk.com \
--cc=riel@surriel.com \
--cc=rppt@kernel.org \
--cc=ryan.roberts@arm.com \
--cc=selinux@vger.kernel.org \
--cc=shakeel.butt@linux.dev \
--cc=shikemeng@huaweicloud.com \
--cc=simona@ffwll.ch \
--cc=sparclinux@vger.kernel.org \
--cc=sre@kernel.org \
--cc=stephen.smalley.work@gmail.com \
--cc=surenb@google.com \
--cc=tglx@kernel.org \
--cc=tiwai@suse.com \
--cc=tzimmermann@suse.de \
--cc=usama.arif@linux.dev \
--cc=vbabka@kernel.org \
--cc=vincent.guittot@linaro.org \
--cc=viro@zeniv.linux.org.uk \
--cc=weixugc@google.com \
--cc=will@kernel.org \
--cc=willy@infradead.org \
--cc=x86@kernel.org \
--cc=xu.xin@linux.dev \
--cc=ying.huang@linux.alibaba.com \
--cc=youngjun.park@lge.com \
--cc=yuanchu@google.com \
--cc=ziy@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.