Linux Framebuffer Layer development
 help / color / mirror / Atom feed
From: "Lorenzo Stoakes (ARM)" <ljs@kernel.org>
To: Andrew Morton <akpm@linux-foundation.org>,
	 "Liam R. Howlett" <liam@infradead.org>,
	Vlastimil Babka <vbabka@kernel.org>,
	 Jann Horn <jannh@google.com>, Pedro Falcato <pfalcato@suse.de>,
	 David Hildenbrand <david@kernel.org>,
	Mike Rapoport <rppt@kernel.org>,
	 Suren Baghdasaryan <surenb@google.com>,
	Michal Hocko <mhocko@suse.com>,  Jonathan Corbet <corbet@lwn.net>,
	 Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
	 Dennis Dalessandro <dennis.dalessandro@cornelisnetworks.com>,
	 Jason Gunthorpe <jgg@ziepe.ca>,
	Leon Romanovsky <leon@kernel.org>,
	 Paul Moore <paul@paul-moore.com>,
	 Stephen Smalley <stephen.smalley.work@gmail.com>,
	 Jaroslav Kysela <perex@perex.cz>, Takashi Iwai <tiwai@suse.com>,
	 Alexei Starovoitov <ast@kernel.org>,
	Daniel Borkmann <daniel@iogearbox.net>,
	 Andrii Nakryiko <andrii@kernel.org>,
	Eduard Zingerman <eddyz87@gmail.com>,
	 Kumar Kartikeya Dwivedi <memxor@gmail.com>,
	Zi Yan <ziy@nvidia.com>,
	 Baolin Wang <baolin.wang@linux.alibaba.com>,
	 Nico Pache <nico.pache@linux.dev>,
	Ryan Roberts <ryan.roberts@arm.com>,  Dev Jain <dev.jain@arm.com>,
	Barry Song <baohua@kernel.org>,
	 Lance Yang <lance.yang@linux.dev>,
	Usama Arif <usama.arif@linux.dev>,
	 Kiryl Shutsemau <kas@kernel.org>,
	Doug Gilbert <dgilbert@interlog.com>,
	 "James E.J. Bottomley" <James.Bottomley@HansenPartnership.com>,
	 "Martin K. Petersen" <mkp@kernel.org>,
	Jaya Kumar <jayalk@intworks.biz>,
	 Simona Vetter <simona@ffwll.ch>, Helge Deller <deller@gmx.de>,
	 Sebastian Reichel <sre@kernel.org>,
	John Hubbard <jhubbard@nvidia.com>,  Peter Xu <peterx@redhat.com>,
	Masami Hiramatsu <mhiramat@kernel.org>,
	 Oleg Nesterov <oleg@redhat.com>,
	Peter Zijlstra <peterz@infradead.org>,
	 Thomas Gleixner <tglx@kernel.org>,
	Ingo Molnar <mingo@redhat.com>,  Borislav Petkov <bp@alien8.de>,
	Dave Hansen <dave.hansen@linux.intel.com>,
	 x86@kernel.org, Arnaldo Carvalho de Melo <acme@kernel.org>,
	 Namhyung Kim <namhyung@kernel.org>,
	Mark Rutland <mark.rutland@arm.com>,
	 Rik van Riel <riel@surriel.com>, Harry Yoo <harry@kernel.org>,
	 Juri Lelli <juri.lelli@redhat.com>,
	 Vincent Guittot <vincent.guittot@linaro.org>,
	 Maarten Lankhorst <maarten.lankhorst@linux.intel.com>,
	 Maxime Ripard <mripard@kernel.org>,
	Thomas Zimmermann <tzimmermann@suse.de>,
	 David Airlie <airlied@gmail.com>, Will Deacon <will@kernel.org>,
	 "Aneesh Kumar K.V" <aneesh.kumar@kernel.org>,
	 Nick Piggin <npiggin@gmail.com>, Arnd Bergmann <arnd@arndb.de>,
	 Muchun Song <muchun.song@linux.dev>,
	Oscar Salvador <osalvador@suse.de>,
	 "Matthew Wilcox (Oracle)" <willy@infradead.org>,
	Jan Kara <jack@suse.cz>,  Marc Zyngier <maz@kernel.org>,
	Oliver Upton <oupton@kernel.org>,
	 Catalin Marinas <catalin.marinas@arm.com>,
	 Madhavan Srinivasan <maddy@linux.ibm.com>,
	Anup Patel <anup@brainfault.org>,  Paul Walmsley <pjw@kernel.org>,
	Palmer Dabbelt <palmer@dabbelt.com>,
	 Albert Ou <aou@eecs.berkeley.edu>,
	 Christian Borntraeger <borntraeger@linux.ibm.com>,
	 Janosch Frank <frankja@linux.ibm.com>,
	 Claudio Imbrenda <imbrenda@linux.ibm.com>,
	 Alexander Gordeev <agordeev@linux.ibm.com>,
	 Gerald Schaefer <gerald.schaefer@linux.ibm.com>,
	 Heiko Carstens <hca@linux.ibm.com>,
	Vasily Gorbik <gor@linux.ibm.com>,
	 "David S. Miller" <davem@davemloft.net>,
	 Andreas Larsson <andreas@gaisler.com>,
	 Alexander Viro <viro@zeniv.linux.org.uk>,
	 Christian Brauner <brauner@kernel.org>,
	 Matthew Brost <matthew.brost@intel.com>,
	 Joshua Hahn <joshua.hahnjy@gmail.com>,
	Rakie Kim <rakie.kim@sk.com>,  Byungchul Park <byungchul@sk.com>,
	Gregory Price <gourry@gourry.net>,
	 Ying Huang <ying.huang@linux.alibaba.com>,
	 Alistair Popple <apopple@nvidia.com>,
	Chris Li <chrisl@kernel.org>,  Kairui Song <kasong@tencent.com>,
	Kemeng Shi <shikemeng@huaweicloud.com>,
	 Nhat Pham <nphamcs@gmail.com>, Baoquan He <baoquan.he@linux.dev>,
	 Youngjun Park <youngjun.park@lge.com>,
	Johannes Weiner <hannes@cmpxchg.org>,
	 Qi Zheng <qi.zheng@linux.dev>,
	Shakeel Butt <shakeel.butt@linux.dev>,
	 Axel Rasmussen <axelrasmussen@google.com>,
	Yuanchu Xie <yuanchu@google.com>,  Wei Xu <weixugc@google.com>,
	Chengming Zhou <chengming.zhou@linux.dev>,
	 Michal Hocko <mhocko@kernel.org>,
	Miklos Szeredi <miklos@szeredi.hu>,  Xu Xin <xu.xin@linux.dev>
Cc: linux-mm@kvack.org, linux-kernel@vger.kernel.org,
	 linux-doc@vger.kernel.org, linux-usb@vger.kernel.org,
	 linux-rdma@vger.kernel.org, selinux@vger.kernel.org,
	 linux-sound@vger.kernel.org, bpf@vger.kernel.org,
	 linux-scsi@vger.kernel.org, linux-fbdev@vger.kernel.org,
	 dri-devel@lists.freedesktop.org,
	linux-trace-kernel@vger.kernel.org,
	 linux-perf-users@vger.kernel.org, linux-arch@vger.kernel.org,
	 linux-fsdevel@vger.kernel.org,
	linux-arm-kernel@lists.infradead.org,  kvmarm@lists.linux.dev,
	linuxppc-dev@lists.ozlabs.org, kvm@vger.kernel.org,
	 kvm-riscv@lists.infradead.org, linux-riscv@lists.infradead.org,
	 linux-s390@vger.kernel.org, sparclinux@vger.kernel.org,
	 fuse-devel@lists.linux.dev,
	"Lorenzo Stoakes (ARM)" <ljs@kernel.org>
Subject: [PATCH v3 01/40] mm/vma: fix mmap_prepare file handling, remove file_doesnt_need_get
Date: Thu, 17 Sep 2026 17:22:10 +0100	[thread overview]
Message-ID: <20260917-b4-mmap-prepare-vma-flag-sanify-v3-1-4583d8a23bca@kernel.org> (raw)
In-Reply-To: <20260917-b4-mmap-prepare-vma-flag-sanify-v3-0-4583d8a23bca@kernel.org>

The map->file_doesnt_need_get flag is confusing and the existing
implementation has holes.

Drivers are permitted to change the owning file of a mapping. If they do
so, they are required to take a reference on that file.

The mmap() operation which ultimately invokes __mmap_region() is guaranteed
to drop the refcount for the original file the mapping was made under, but
this is not true for the replaced file.

This has been addressed so far by tracking map->file_doesnt_need_get, which
is rather poorly named and unfortunately fails to correctly track whether
or not an additional put were needed in a number of cases.

Make life easier by removing this flag, and instead drop the reference for
both mmap_prepare and the deprecated mmap callback in a new function
put_map().

Track whether this needs to be done by aligning mmap_state with
vm_area_desc and store the original file in the map->file field, keeping
the updated file in map->vm_file.

In order to have the same behaviour for both types of hooks, only drop the
reference __mmap_new_file_vma() itself took in its error path, deferring
the replaced file's reference to put_map().

To make this work correctly, map->vm_file has to be updated before any
error handling, so update __mmap_new_file_vma() and call_mmap_prepare() to
set this field first.

Also when mmap_prepare() changes the file and is then merged, the reference
count also must be decremented, so update the logic to call put_map() in
this case too.

Also update __compat_vma_mmap() to manually perform this step for stacked
file systems using the compatibility layer, and update
compat_set_vma_from_desc() to replace vma_set_file() with a correct
refcount/file update.

No in-tree driver is impacted by the incorrect implementation of this
currently (no driver that does this is mergeable for one), so this does not
need to be a fix.

Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
---
 mm/internal.h |  1 +
 mm/util.c     |  5 +++-
 mm/vma.c      | 83 +++++++++++++++++++++++++++++++++++------------------------
 mm/vma.h      |  6 +++--
 4 files changed, 59 insertions(+), 36 deletions(-)

diff --git a/mm/internal.h b/mm/internal.h
index 0dca33db068f..fe576d468af4 100644
--- a/mm/internal.h
+++ b/mm/internal.h
@@ -7,6 +7,7 @@
 #ifndef __MM_INTERNAL_H
 #define __MM_INTERNAL_H
 
+#include <linux/file.h>
 #include <linux/fs.h>
 #include <linux/khugepaged.h>
 #include <linux/mm.h>
diff --git a/mm/util.c b/mm/util.c
index bf0513d1d3d0..016932780925 100644
--- a/mm/util.c
+++ b/mm/util.c
@@ -1228,8 +1228,11 @@ int __compat_vma_mmap(struct vm_area_desc *desc,
 
 	/* Perform any preparatory tasks for mmap action. */
 	err = mmap_action_prepare(desc);
-	if (err)
+	if (err) {
+		if (desc->vm_file != vma->vm_file)
+			fput(desc->vm_file);
 		return err;
+	}
 	/* Update the VMA from the descriptor. */
 	compat_set_vma_from_desc(vma, desc);
 	/* Complete any specified mmap actions. */
diff --git a/mm/vma.c b/mm/vma.c
index 55917d097933..fa784f069da4 100644
--- a/mm/vma.c
+++ b/mm/vma.c
@@ -24,7 +24,8 @@ struct mmap_state {
 		vm_flags_t vm_flags;
 		vma_flags_t vma_flags;
 	};
-	struct file *file;
+	struct file *file;	/* mmap()-specified file. */
+	struct file *vm_file;	/* May be updated by mmap_prepare. */
 	pgprot_t page_prot;
 
 	/* User-defined fields, perhaps updated by .mmap_prepare(). */
@@ -43,8 +44,6 @@ struct mmap_state {
 
 	/* Determine if we can check KSM flags early in mmap() logic. */
 	bool check_ksm_early :1;
-	/* If .mmap_prepare changed the file, we don't need to pin. */
-	bool file_doesnt_need_get :1;
 };
 
 #define MMAP_STATE(name, mm_, vmi_, addr_, len_, pgoff_, anon_pgoff_, vma_flags_, file_) \
@@ -58,6 +57,7 @@ struct mmap_state {
 		.pglen = PHYS_PFN(len_),				\
 		.vma_flags = vma_flags_,				\
 		.file = file_,						\
+		.vm_file = file_,					\
 		.page_prot = vma_flags_to_page_prot(vma_flags_),	\
 	}
 
@@ -70,7 +70,7 @@ struct mmap_state {
 		.vma_flags = (map_)->vma_flags,				\
 		.pgoff = (map_)->pgoff,					\
 		.anon_pgoff = (map_)->anon_pgoff,			\
-		.file = (map_)->file,					\
+		.file = (map_)->vm_file,				\
 		.prev = (map_)->prev,					\
 		.middle = vma_,						\
 		.next = (vma_) ? NULL : (map_)->next,			\
@@ -2447,7 +2447,7 @@ void mm_drop_all_locks(struct mm_struct *mm)
  */
 static bool accountable_mapping(struct mmap_state *map)
 {
-	const struct file *file = map->file;
+	const struct file *file = map->vm_file;
 
 	/*
 	 * hugetlb has its own accounting separate from the core VM
@@ -2496,7 +2496,7 @@ static void vms_abort_munmap_vmas(struct vma_munmap_struct *vms,
 
 static void update_ksm_flags(struct mmap_state *map)
 {
-	map->vma_flags = ksm_vma_flags(map->mm, map->file, map->vma_flags);
+	map->vma_flags = ksm_vma_flags(map->mm, map->vm_file, map->vma_flags);
 }
 
 static void set_desc_from_map(struct vm_area_desc *desc,
@@ -2506,7 +2506,7 @@ static void set_desc_from_map(struct vm_area_desc *desc,
 	desc->end = map->end;
 
 	desc->pgoff = map->pgoff;
-	desc->vm_file = map->file;
+	desc->vm_file = map->vm_file;
 	desc->vma_flags = map->vma_flags;
 	desc->page_prot = map->page_prot;
 }
@@ -2586,6 +2586,10 @@ static int __mmap_setup(struct mmap_state *map, struct vm_area_desc *desc,
 	return 0;
 }
 
+static bool map_same_file(struct mmap_state *map)
+{
+	return map->vm_file == map->file;
+}
 
 static int __mmap_new_file_vma(struct mmap_state *map,
 			       struct vm_area_struct *vma)
@@ -2593,20 +2597,23 @@ static int __mmap_new_file_vma(struct mmap_state *map,
 	struct vma_iterator *vmi = map->vmi;
 	int error;
 
-	vma->vm_file = map->file;
-	if (!map->file_doesnt_need_get)
-		get_file(map->file);
+	vma->vm_file = map->vm_file;
+	if (map_same_file(map))
+		get_file(map->vm_file);
 
-	if (!map->file->f_op->mmap)
+	if (!map->vm_file->f_op->mmap)
 		return 0;
 
 	error = mmap_file(vma->vm_file, vma);
+	map->vm_file = vma->vm_file;
+
 	if (error) {
 		UNMAP_STATE(unmap, vmi, vma, vma->vm_start, vma->vm_end,
 			    map->prev, map->next);
-		fput(vma->vm_file);
-		vma->vm_file = NULL;
+		if (map_same_file(map))
+			fput(map->vm_file);
 
+		vma->vm_file = NULL;
 		vma_iter_set(vmi, vma->vm_end);
 		/* Undo any partial mapping done by a device driver. */
 		unmap_region(&unmap);
@@ -2623,7 +2630,6 @@ static int __mmap_new_file_vma(struct mmap_state *map,
 			!vma_flags_test(&map->vma_flags, VMA_MAYWRITE_BIT) &&
 			vma_test(vma, VMA_MAYWRITE_BIT));
 
-	map->file = vma->vm_file;
 	map->vma_flags = vma->flags;
 
 	return 0;
@@ -2631,7 +2637,7 @@ static int __mmap_new_file_vma(struct mmap_state *map,
 
 static void map_set_anon(struct mmap_state *map)
 {
-	map->file = NULL;
+	map->vm_file = NULL;
 	map->vm_ops = NULL;
 	map->pgoff = map->addr >> PAGE_SHIFT;
 }
@@ -2643,7 +2649,7 @@ static bool map_is_private(const struct mmap_state *map)
 
 static bool map_is_anon(const struct mmap_state *map)
 {
-	return map_is_private(map) && !map->file;
+	return map_is_private(map) && !map->vm_file;
 }
 
 /*
@@ -2688,7 +2694,7 @@ static int __mmap_new_vma(struct mmap_state *map, struct vm_area_struct **vmap,
 	}
 
 	/* Invoke callbacks. */
-	if (map->file)
+	if (map->vm_file)
 		error = __mmap_new_file_vma(map, vma);
 	else if (!is_anon)
 		error = shmem_zero_setup(vma);
@@ -2797,11 +2803,15 @@ static int call_mmap_prepare(struct mmap_state *map,
 	int err;
 
 	/* Invoke the hook. */
-	err = vfs_mmap_prepare(map->file, desc);
+	err = vfs_mmap_prepare(map->vm_file, desc);
 	if (err)
 		return err;
 
-	/* It's invalid for mmap_preprare hooks to clear vm_ops. */
+	/* Update first so file refcount tracked correctly. */
+	if (desc->vm_file != map->vm_file)
+		map->vm_file = desc->vm_file;
+
+	/* It's invalid for mmap_prepare hooks to clear vm_ops. */
 	if (!desc->vm_ops)
 		return -EINVAL;
 
@@ -2811,10 +2821,6 @@ static int call_mmap_prepare(struct mmap_state *map,
 
 	/* Update fields permitted to be changed. */
 	map->pgoff = desc->pgoff;
-	if (desc->vm_file != map->file) {
-		map->file_doesnt_need_get = true;
-		map->file = desc->vm_file;
-	}
 	map->vma_flags = desc->vma_flags;
 	map->page_prot = desc->page_prot;
 	/* User-defined fields. */
@@ -2826,7 +2832,7 @@ static int call_mmap_prepare(struct mmap_state *map,
 	 * anonymous mappings. Rather than allowing these mappings to be odd
 	 * outliers, simply make them truly anonymous.
 	 */
-	if (map_is_private(map) && file_is_dev_zero(map->file))
+	if (map_is_private(map) && file_is_dev_zero(map->vm_file))
 		map_set_anon(map);
 
 	return 0;
@@ -2845,7 +2851,7 @@ static void set_vma_user_defined_fields(struct vm_area_struct *vma,
  */
 static bool can_set_ksm_flags_early(struct mmap_state *map)
 {
-	struct file *file = map->file;
+	struct file *file = map->vm_file;
 
 	/* Anonymous mappings have no driver which can change them. */
 	if (!file)
@@ -2868,6 +2874,20 @@ static bool can_set_ksm_flags_early(struct mmap_state *map)
 	return false;
 }
 
+static void put_map(struct mmap_state *map)
+{
+	/*
+	 * An error occurred or the VMA was merged.
+	 *
+	 * If the file was changed by the driver (which is required to increment
+	 * the replacement file's reference count), drop its reference count.
+	 *
+	 * On error, the caller always drops the original file regardless.
+	 */
+	if (map->vm_file && !map_same_file(map))
+		fput(map->vm_file);
+}
+
 static unsigned long __mmap_region(struct file *file, unsigned long addr,
 		unsigned long len, vma_flags_t vma_flags,
 		unsigned long pgoff, struct list_head *uf)
@@ -2922,7 +2942,10 @@ static unsigned long __mmap_region(struct file *file, unsigned long addr,
 
 	__mmap_complete(&map, vma);
 
-	if (have_mmap_prepare && allocated_new) {
+	if (!allocated_new) {
+		/* Merged, so need to drop refcount. */
+		put_map(&map);
+	} else if (have_mmap_prepare) {
 		error = mmap_action_complete(vma, &desc.action,
 					     /*is_compat=*/false);
 		if (error)
@@ -2936,13 +2959,7 @@ static unsigned long __mmap_region(struct file *file, unsigned long addr,
 	if (map.charged)
 		vm_unacct_memory(map.charged);
 abort_munmap:
-	/*
-	 * This indicates that .mmap_prepare has set a new file, differing from
-	 * desc->vm_file. But since we're aborting the operation, only the
-	 * original file will be cleaned up. Ensure we clean up both.
-	 */
-	if (map.file_doesnt_need_get)
-		fput(map.file);
+	put_map(&map);
 	vms_abort_munmap_vmas(&map.vms, &map.mas_detach);
 	return error;
 }
diff --git a/mm/vma.h b/mm/vma.h
index e97bd2dfa786..f15faa83f3d6 100644
--- a/mm/vma.h
+++ b/mm/vma.h
@@ -394,8 +394,10 @@ static inline void compat_set_vma_from_desc(struct vm_area_struct *vma,
 
 	/* Mutable fields. Populated with initial state. */
 	vma_set_pgoff(vma, desc->pgoff);
-	if (desc->vm_file != vma->vm_file)
-		vma_set_file(vma, desc->vm_file);
+	if (desc->vm_file != vma->vm_file) {
+		fput(vma->vm_file);
+		vma->vm_file = desc->vm_file;
+	}
 	vma->flags = desc->vma_flags;
 	vma->vm_page_prot = desc->page_prot;
 

-- 
2.55.0


  reply	other threads:[~2026-09-17 16:23 UTC|newest]

Thread overview: 146+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-17 16:22 [PATCH v3 00/40] mm: make VMA flag semantics explicit, eliminate VM_SPECIAL Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` Lorenzo Stoakes (ARM) [this message]
2026-09-23 15:21   ` [PATCH v3 01/40] mm/vma: fix mmap_prepare file handling, remove file_doesnt_need_get Suren Baghdasaryan
2026-09-23 15:46     ` Lorenzo Stoakes (ARM)
2026-09-23 15:59       ` Suren Baghdasaryan
2026-09-24  2:20   ` Zi Yan
2026-09-24 10:03     ` Lorenzo Stoakes (ARM)
2026-09-24 19:00   ` Liam R. Howlett
2026-09-25  9:12     ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 02/40] mm/vma: predicate setting mmap_prepare VMA fields on new vma alloc Lorenzo Stoakes (ARM)
2026-09-23 15:32   ` Suren Baghdasaryan
2026-09-23 15:53     ` Lorenzo Stoakes (ARM)
2026-09-23 16:09       ` Suren Baghdasaryan
2026-09-23 17:07         ` Lorenzo Stoakes (ARM)
2026-09-23 17:33   ` Lorenzo Stoakes (ARM)
2026-09-24  2:25   ` Zi Yan
2026-09-17 16:22 ` [PATCH v3 03/40] mm/vma: introduce and use vma_[flags_]can_merge() Lorenzo Stoakes (ARM)
2026-09-23 16:23   ` Suren Baghdasaryan
2026-09-24  2:27   ` Zi Yan
2026-09-24 16:38   ` Gregory Price
2026-10-01 12:03   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 04/40] mm: consistently validate VMA state after mmap[_prepare] hooks Lorenzo Stoakes (ARM)
2026-09-23 16:47   ` Suren Baghdasaryan
2026-09-23 17:00     ` Lorenzo Stoakes (ARM)
2026-09-24  2:52   ` Zi Yan
2026-09-24 10:06     ` Lorenzo Stoakes (ARM)
2026-09-24 17:17   ` Gregory Price
2026-09-25 12:51     ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 05/40] mm/vma: ensure mmap_prepare doesn't set actions on a mergeable vma Lorenzo Stoakes (ARM)
2026-09-24 18:00   ` Gregory Price
2026-09-25  9:51     ` Lorenzo Stoakes (ARM)
2026-09-24 19:28   ` Zi Yan
2026-09-25  9:55     ` Lorenzo Stoakes (ARM)
2026-09-25  7:28   ` Suren Baghdasaryan
2026-09-25  9:53     ` Lorenzo Stoakes (ARM)
2026-10-01 12:11       ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 06/40] mm: make map_kernel_pages_[prepare,complete] internal and unexported Lorenzo Stoakes (ARM)
2026-09-24 19:30   ` Zi Yan
2026-09-25  7:35     ` Suren Baghdasaryan
2026-09-29 15:58   ` Gregory Price
2026-10-01 12:11   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 07/40] mm/vma: tidy up map kernel pages enum values Lorenzo Stoakes (ARM)
2026-09-24 19:30   ` Zi Yan
2026-09-25  7:37     ` Suren Baghdasaryan
2026-09-29 15:59   ` Gregory Price
2026-10-01 12:12   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 08/40] mm: add mmap action for discontiguous kernel page mapping Lorenzo Stoakes (ARM)
2026-09-25 20:53   ` Zi Yan
2026-09-27 21:44   ` Suren Baghdasaryan
2026-09-29 11:11     ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 09/40] docs: filesystems: update mmap_prepare docs for discontig kernel pgs Lorenzo Stoakes (ARM)
2026-09-25 21:01   ` Zi Yan
2026-09-29 11:21     ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 10/40] drivers/usb/mon: update to use mmap_prepare + map kernel pages Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 11/40] infiniband: update hfi1 to use remap_vmalloc_range() Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 12/40] selinux: reject writable opens of policy file, drop mmap shared/write check Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 13/40] ALSA: pcm: use vm_insert_page() to map PCM status page Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 14/40] bpf: arena: mark arena_map_mmap() mappings VM_MIXEDMAP Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 15/40] mm/vma: add vma[_flags]_is_kernel_owned() predicates Lorenzo Stoakes (ARM)
2026-09-26  1:37   ` Zi Yan
2026-10-01 12:36   ` David Hildenbrand (Arm)
2026-10-02 14:56     ` Lorenzo Stoakes (ARM)
2026-10-02 21:19       ` David Hildenbrand (Arm)
2026-10-03  9:03         ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 16/40] mm/vma: only allow mmap to clear VMA_MAYWRITE_BIT if kernel-owned Lorenzo Stoakes (ARM)
2026-09-26  2:07   ` Zi Yan
2026-09-26  2:17     ` Zi Yan
2026-09-26 10:06       ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 17/40] mm/vma: add and use vma_[flags]_is_fixed_mapping Lorenzo Stoakes (ARM)
2026-09-26  2:27   ` Zi Yan
2026-09-26 10:03     ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 18/40] scsi: sg: convert mmap hook to mmap_prepare and rework Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 19/40] fbdev: defio: assert FBINFO_VIRTFB, drop VM_IO, add VM_MIXEDMAP Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 20/40] HSI: cmt_speech: convert mmap hook to mmap_prepare, refactor Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 21/40] mm/gup: error out early on !VMA_MAYREAD_BIT VMAs Lorenzo Stoakes (ARM)
2026-09-26  2:30   ` Zi Yan
2026-09-17 16:22 ` [PATCH v3 22/40] uprobes: remove VM_IO, set VM_MIXEDMAP for mapped kernel pages Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 23/40] mm/mlock: clear VMA_LOCKED_MASK over mmap callback Lorenzo Stoakes (ARM)
2026-10-01 15:20   ` Zi Yan
2026-10-02 12:26     ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 24/40] mm/mlock: eliminate weird VMA_IO_BIT abuse and simplify Lorenzo Stoakes (ARM)
2026-09-23 20:06   ` Zi Yan
2026-09-24 10:21     ` Lorenzo Stoakes (ARM)
2026-09-24 15:50       ` Zi Yan
2026-09-25  9:35         ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 25/40] mm/vma: enforce that only kernel-owned mappings may set VMA_IO_BIT Lorenzo Stoakes (ARM)
2026-09-29  2:12   ` Zi Yan
2026-09-17 16:22 ` [PATCH v3 26/40] mm: remove VMA_IO_BIT check in vma[_flags]_is_kernel_owned() Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 27/40] mm: remove hugetlb_inline.h Lorenzo Stoakes (ARM)
2026-09-29  2:13   ` Zi Yan
2026-10-02  6:52   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 28/40] mm: rename is_vm_hugetlb_page() to vma_is_hugetlb() Lorenzo Stoakes (ARM)
2026-09-29  2:14   ` Zi Yan
2026-10-02  6:53   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 29/40] mm: drop some redundant checks around hugetlb VMAs Lorenzo Stoakes (ARM)
2026-09-29  2:36   ` Zi Yan
2026-10-02  6:54   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 30/40] mm/madvise: update is_valid_guard_vma() to use vma_can_merge() Lorenzo Stoakes (ARM)
2026-09-29  2:38   ` Zi Yan
2026-10-02  6:57   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 31/40] mm/vma: introduce vma[_flags]_is_persistent() Lorenzo Stoakes (ARM)
2026-09-30  2:00   ` Zi Yan
2026-10-02  6:59   ` David Hildenbrand (Arm)
2026-10-02  7:02     ` David Hildenbrand (Arm)
2026-10-02  7:05       ` David Hildenbrand (Arm)
2026-10-02 12:08         ` Lorenzo Stoakes (ARM)
2026-10-02 12:35           ` David Hildenbrand (Arm)
2026-10-02 12:48             ` Lorenzo Stoakes (ARM)
2026-10-02 13:11               ` David Hildenbrand (Arm)
2026-10-02 13:59                 ` Lorenzo Stoakes (ARM)
2026-10-02 21:43                   ` David Hildenbrand (Arm)
2026-10-03 13:16                     ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 32/40] mm/uffd: use predicates for userfaultfd checks Lorenzo Stoakes (ARM)
2026-09-30  2:02   ` Zi Yan
2026-10-02  7:04   ` David Hildenbrand (Arm)
2026-10-02 12:35     ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 33/40] mm/madvise: use predicates for madvise(..., MADV_DOFORK) Lorenzo Stoakes (ARM)
2026-09-30  2:28   ` Zi Yan
2026-09-17 16:22 ` [PATCH v3 34/40] mm: eliminate VMA_SPECIAL_FLAGS usage when hugetlb explicitly tested Lorenzo Stoakes (ARM)
2026-09-30  2:42   ` Zi Yan
2026-09-30  9:32     ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 35/40] mm: eliminate VMA_SPECIAL_FLAGS check in lru_gen_look_around() Lorenzo Stoakes (ARM)
2026-09-30  2:42   ` Zi Yan
2026-10-02  7:06   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 36/40] mm: avoid use of VMA_SPECIAL_FLAGS in migrate_vma_setup() Lorenzo Stoakes (ARM)
2026-09-30  2:47   ` Zi Yan
2026-10-02  7:07   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 37/40] mm: eliminate VM_SPECIAL, VMA_SPECIAL_FLAGS Lorenzo Stoakes (ARM)
2026-09-30  2:48   ` Zi Yan
2026-10-02  7:07   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 38/40] fuse: dax: do not set VM_MIXEDMAP Lorenzo Stoakes (ARM)
2026-10-02  7:09   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 39/40] mm/huge_memory: remove vma_is_special_huge() Lorenzo Stoakes (ARM)
2026-10-01 15:21   ` Zi Yan
2026-10-02  7:11   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 40/40] mm/vma: introduce and use vma[_flags]_can_gup() Lorenzo Stoakes (ARM)
2026-10-01 15:23   ` Zi Yan
2026-10-02  7:48   ` David Hildenbrand (Arm)
2026-10-02 16:11     ` Lorenzo Stoakes (ARM)
2026-09-17 21:23 ` [PATCH v3 00/40] mm: make VMA flag semantics explicit, eliminate VM_SPECIAL Andrew Morton
2026-09-23  8:57 ` Lorenzo Stoakes (ARM)
2026-09-25 22:06 ` Arnd Bergmann
2026-09-26  9:40   ` Lorenzo Stoakes (ARM)
2026-09-26 13:06     ` Arnd Bergmann
2026-09-26 13:22       ` Lorenzo Stoakes (ARM)
2026-09-26 17:14         ` Arnd Bergmann

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260917-b4-mmap-prepare-vma-flag-sanify-v3-1-4583d8a23bca@kernel.org \
    --to=ljs@kernel.org \
    --cc=James.Bottomley@HansenPartnership.com \
    --cc=acme@kernel.org \
    --cc=agordeev@linux.ibm.com \
    --cc=airlied@gmail.com \
    --cc=akpm@linux-foundation.org \
    --cc=andreas@gaisler.com \
    --cc=andrii@kernel.org \
    --cc=aneesh.kumar@kernel.org \
    --cc=anup@brainfault.org \
    --cc=aou@eecs.berkeley.edu \
    --cc=apopple@nvidia.com \
    --cc=arnd@arndb.de \
    --cc=ast@kernel.org \
    --cc=axelrasmussen@google.com \
    --cc=baohua@kernel.org \
    --cc=baolin.wang@linux.alibaba.com \
    --cc=baoquan.he@linux.dev \
    --cc=borntraeger@linux.ibm.com \
    --cc=bp@alien8.de \
    --cc=bpf@vger.kernel.org \
    --cc=brauner@kernel.org \
    --cc=byungchul@sk.com \
    --cc=catalin.marinas@arm.com \
    --cc=chengming.zhou@linux.dev \
    --cc=chrisl@kernel.org \
    --cc=corbet@lwn.net \
    --cc=daniel@iogearbox.net \
    --cc=dave.hansen@linux.intel.com \
    --cc=davem@davemloft.net \
    --cc=david@kernel.org \
    --cc=deller@gmx.de \
    --cc=dennis.dalessandro@cornelisnetworks.com \
    --cc=dev.jain@arm.com \
    --cc=dgilbert@interlog.com \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=eddyz87@gmail.com \
    --cc=frankja@linux.ibm.com \
    --cc=fuse-devel@lists.linux.dev \
    --cc=gerald.schaefer@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=gourry@gourry.net \
    --cc=gregkh@linuxfoundation.org \
    --cc=hannes@cmpxchg.org \
    --cc=harry@kernel.org \
    --cc=hca@linux.ibm.com \
    --cc=imbrenda@linux.ibm.com \
    --cc=jack@suse.cz \
    --cc=jannh@google.com \
    --cc=jayalk@intworks.biz \
    --cc=jgg@ziepe.ca \
    --cc=jhubbard@nvidia.com \
    --cc=joshua.hahnjy@gmail.com \
    --cc=juri.lelli@redhat.com \
    --cc=kas@kernel.org \
    --cc=kasong@tencent.com \
    --cc=kvm-riscv@lists.infradead.org \
    --cc=kvm@vger.kernel.org \
    --cc=kvmarm@lists.linux.dev \
    --cc=lance.yang@linux.dev \
    --cc=leon@kernel.org \
    --cc=liam@infradead.org \
    --cc=linux-arch@vger.kernel.org \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-doc@vger.kernel.org \
    --cc=linux-fbdev@vger.kernel.org \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=linux-rdma@vger.kernel.org \
    --cc=linux-riscv@lists.infradead.org \
    --cc=linux-s390@vger.kernel.org \
    --cc=linux-scsi@vger.kernel.org \
    --cc=linux-sound@vger.kernel.org \
    --cc=linux-trace-kernel@vger.kernel.org \
    --cc=linux-usb@vger.kernel.org \
    --cc=linuxppc-dev@lists.ozlabs.org \
    --cc=maarten.lankhorst@linux.intel.com \
    --cc=maddy@linux.ibm.com \
    --cc=mark.rutland@arm.com \
    --cc=matthew.brost@intel.com \
    --cc=maz@kernel.org \
    --cc=memxor@gmail.com \
    --cc=mhiramat@kernel.org \
    --cc=mhocko@kernel.org \
    --cc=mhocko@suse.com \
    --cc=miklos@szeredi.hu \
    --cc=mingo@redhat.com \
    --cc=mkp@kernel.org \
    --cc=mripard@kernel.org \
    --cc=muchun.song@linux.dev \
    --cc=namhyung@kernel.org \
    --cc=nico.pache@linux.dev \
    --cc=nphamcs@gmail.com \
    --cc=npiggin@gmail.com \
    --cc=oleg@redhat.com \
    --cc=osalvador@suse.de \
    --cc=oupton@kernel.org \
    --cc=palmer@dabbelt.com \
    --cc=paul@paul-moore.com \
    --cc=perex@perex.cz \
    --cc=peterx@redhat.com \
    --cc=peterz@infradead.org \
    --cc=pfalcato@suse.de \
    --cc=pjw@kernel.org \
    --cc=qi.zheng@linux.dev \
    --cc=rakie.kim@sk.com \
    --cc=riel@surriel.com \
    --cc=rppt@kernel.org \
    --cc=ryan.roberts@arm.com \
    --cc=selinux@vger.kernel.org \
    --cc=shakeel.butt@linux.dev \
    --cc=shikemeng@huaweicloud.com \
    --cc=simona@ffwll.ch \
    --cc=sparclinux@vger.kernel.org \
    --cc=sre@kernel.org \
    --cc=stephen.smalley.work@gmail.com \
    --cc=surenb@google.com \
    --cc=tglx@kernel.org \
    --cc=tiwai@suse.com \
    --cc=tzimmermann@suse.de \
    --cc=usama.arif@linux.dev \
    --cc=vbabka@kernel.org \
    --cc=vincent.guittot@linaro.org \
    --cc=viro@zeniv.linux.org.uk \
    --cc=weixugc@google.com \
    --cc=will@kernel.org \
    --cc=willy@infradead.org \
    --cc=x86@kernel.org \
    --cc=xu.xin@linux.dev \
    --cc=ying.huang@linux.alibaba.com \
    --cc=youngjun.park@lge.com \
    --cc=yuanchu@google.com \
    --cc=ziy@nvidia.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox