From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 87D9AC9833B for ; Fri, 25 Sep 2026 23:41:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:In-Reply-To:MIME-Version:References: Message-ID:Subject:Cc:To:From:Date:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=rTqPJu2ONHjwL1vN1MiGZsfDPNI2Tska5Gw5MXTX0xc=; b=Z1oyA6Tk5OMXWx 45LNRGF3XV78DGvuAZ8cK2VGxcYAT+yzzrsv6was/dSuv9nOYvRf6YctL2cgYiK1WGlD8n3PjsJw7 5UW74qBTLSO3d4E6nvJiUk/n5O7W6e8LdqFRipuFz/jnfB21kmuardGDd7wBZIIVvK+a7PIa83K3w gTToX7WmL1nd4m5uCz4C4jhDto6Wt4rRbYAFpMsXIibVqQoIusZZbkYctTx8ha/Evf+X1Fs6HCum5 WTQsuzIRGUgLpmhFStGJ63LCDMXE7tXxGvE+01FikMjjhIjndZ6utQNNRzVjsepPizbzP3u6HIRoF rN1fJD4fXbZ339bIGRrQ==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.99.1 #2 (Red Hat Linux)) id 1xAFXL-0000000EeX1-3WA8; Fri, 25 Sep 2026 23:41:03 +0000 Received: from tor.source.kernel.org ([172.105.4.254]) by bombadil.infradead.org with esmtps (Exim 4.99.1 #2 (Red Hat Linux)) id 1x9gLu-0000000AfTd-26rY; Thu, 24 Sep 2026 10:06:54 +0000 Received: from smtp.kernel.org (quasi.space.kernel.org [100.103.45.18]) by tor.source.kernel.org (Postfix) with ESMTP id E9433602C3; Thu, 24 Sep 2026 10:06:53 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id C2C321F00893; Thu, 24 Sep 2026 10:06:23 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1790244413; bh=Tmln/mtpzj8HRD3oGhB2G+T5+fAuKHxHe9EIDa4XupE=; h=Date:From:To:Cc:Subject:References:In-Reply-To; b=PLQwBAOGo9zDSHvR7HKzryQ/BMyFMtzGN+nCViQmJtAxtR/cVtie3h8+uTfYAAuqI 031IL8YiCRbRgN3Lu0GdOWHF3up1c5eAkeUhEPdxuJ9q/SthtjUJM4e5DTQk3971Cv +R/NIvQEe5TAium5bmdEyB/qSUVvrKQ3N2k6WtmzwCU8Hw7KqZ3HuHqonUNceqtFUI gkBAcKeGMzG5vw33mskB8GCIprFrs11XV7eTU1DX4P4aEFuLfxG1bzkZcra4RB+dUr UBz/croW/YGWjUjo9iUnRJL3m1e4m9BS//Qzg5nKK/0JyOftW1GHHLTSp3iQSWnW2G YCgs9xZC0a5iw== Date: Thu, 24 Sep 2026 11:06:21 +0100 From: "Lorenzo Stoakes (ARM)" To: Zi Yan Cc: Andrew Morton , "Liam R. Howlett" , Vlastimil Babka , Jann Horn , Pedro Falcato , David Hildenbrand , Mike Rapoport , Suren Baghdasaryan , Michal Hocko , Jonathan Corbet , Greg Kroah-Hartman , Dennis Dalessandro , Jason Gunthorpe , Leon Romanovsky , Paul Moore , Stephen Smalley , Jaroslav Kysela , Takashi Iwai , Alexei Starovoitov , Daniel Borkmann , Andrii Nakryiko , Eduard Zingerman , Kumar Kartikeya Dwivedi , Baolin Wang , Nico Pache , Ryan Roberts , Dev Jain , Barry Song , Lance Yang , Usama Arif , Kiryl Shutsemau , Doug Gilbert , "James E.J. Bottomley" , "Martin K. Petersen" , Jaya Kumar , Simona Vetter , Helge Deller , Sebastian Reichel , John Hubbard , Peter Xu , Masami Hiramatsu , Oleg Nesterov , Peter Zijlstra , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, Arnaldo Carvalho de Melo , Namhyung Kim , Mark Rutland , Rik van Riel , Harry Yoo , Juri Lelli , Vincent Guittot , Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Will Deacon , "Aneesh Kumar K.V" , Nick Piggin , Arnd Bergmann , Muchun Song , Oscar Salvador , "Matthew Wilcox (Oracle)" , Jan Kara , Marc Zyngier , Oliver Upton , Catalin Marinas , Madhavan Srinivasan , Anup Patel , Paul Walmsley , Palmer Dabbelt , Albert Ou , Christian Borntraeger , Janosch Frank , Claudio Imbrenda , Alexander Gordeev , Gerald Schaefer , Heiko Carstens , Vasily Gorbik , "David S. Miller" , Andreas Larsson , Alexander Viro , Christian Brauner , Matthew Brost , Joshua Hahn , Rakie Kim , Byungchul Park , Gregory Price , Ying Huang , Alistair Popple , Chris Li , Kairui Song , Kemeng Shi , Nhat Pham , Baoquan He , Youngjun Park , Johannes Weiner , Qi Zheng , Shakeel Butt , Axel Rasmussen , Yuanchu Xie , Wei Xu , Chengming Zhou , Michal Hocko , Miklos Szeredi , Xu Xin , linux-mm@kvack.org, linux-kernel@vger.kernel.org, linux-doc@vger.kernel.org, linux-usb@vger.kernel.org, linux-rdma@vger.kernel.org, selinux@vger.kernel.org, linux-sound@vger.kernel.org, bpf@vger.kernel.org, linux-scsi@vger.kernel.org, linux-fbdev@vger.kernel.org, dri-devel@lists.freedesktop.org, linux-trace-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, linux-arch@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev, linuxppc-dev@lists.ozlabs.org, kvm@vger.kernel.org, kvm-riscv@lists.infradead.org, linux-riscv@lists.infradead.org, linux-s390@vger.kernel.org, sparclinux@vger.kernel.org, fuse-devel@lists.linux.dev Subject: Re: [PATCH v3 04/40] mm: consistently validate VMA state after mmap[_prepare] hooks Message-ID: References: <20260917-b4-mmap-prepare-vma-flag-sanify-v3-0-4583d8a23bca@kernel.org> <20260917-b4-mmap-prepare-vma-flag-sanify-v3-4-4583d8a23bca@kernel.org> MIME-Version: 1.0 Content-Disposition: inline In-Reply-To: X-Mailman-Approved-At: Fri, 25 Sep 2026 16:40:51 -0700 X-BeenThere: linux-riscv@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "linux-riscv" Errors-To: linux-riscv-bounces+linux-riscv=archiver.kernel.org@lists.infradead.org On Wed, Sep 23, 2026 at 10:52:06PM -0400, Zi Yan wrote: > On Thu Sep 17, 2026 at 12:22 PM EDT, Lorenzo Stoakes (ARM) wrote: > > When the f_op->mmap_prepare or deprecated f_op->mmap hooks are invoked, the > > driver might have done something crazy that is not permitted by the kernel. > > > > Currently we check for three such cases in __mmap_new_file_vma(), but only > > if the legacy f_op->mmap hook is used: > > > > * Did sparc ADI result in invalid flags? > > > > * Did the driver alter vma->vm_start? > > > > * Did the driver make a file-backed mapping on a read-only file writable? > > > > Generalise these checks for both mmap_prepare and mmap and apply to all > > invocations of mmap_file(), the f_op->mmap and f_op->mmap_prepare handling > > in the core VMA code and the mmap_prepare compatibility layer. > > > > Also extend the vm_start check to vm_end also - drivers must not change the > > VMA range at all. > > > > We also WARN_ON_ONCE() on these conditions as they are things that should > > simply not occur in the kernel and it's important to call it out when it > > does. > > > > We invoke mmap_prepare_validate() after mmap_action_prepare(), as mmap > > actions often manipulate state in the descriptor thus providing the final > > state the VMA will be derived from. > > > > Also call mmap_validate_vma_flags() in insert_vm_struct() to ensure that > > special regions which are inserted (such as a VDSO or VVAR) also satisfy > > the sanity checks. > > > > This way every VMA established through an mmap hook, whether via mmap() or > > the compatibility layer, or inserted via insert_vm_struct(), has been > > validated. brk() VMAs never pass through a driver hook and so need no such > > check. > > > > While we're here, also fixup a couple disjoint blocks of #ifdef CONFIG_MMU. > > > > Finally, update the VMA userland tests to reflect the change. > > > > Signed-off-by: Lorenzo Stoakes (ARM) > > --- > > mm/internal.h | 51 ++++++++++++-------- > > mm/util.c | 19 ++++++-- > > mm/vma.c | 100 ++++++++++++++++++++++++++++++++++------ > > mm/vma.h | 25 ++++++++-- > > tools/testing/vma/include/dup.h | 10 ++++ > > 5 files changed, 163 insertions(+), 42 deletions(-) > > > > > + > > +/* Check to ensure a driver hasn't done something crazy. */ > > +static int mmap_validate(unsigned long prev_start, unsigned long prev_end, > > + unsigned long curr_start, unsigned long curr_end, > > + const vma_flags_t *prev_flags, > > + const vma_flags_t *curr_flags) > > +{ > > + bool was_maywrite, is_maywrite; > > + > > + /* Drivers cannot alter the range of the VMA. */ > > + if (WARN_ON_ONCE(prev_start != curr_start || prev_end != curr_end)) > > + return -EINVAL; > > + > > + was_maywrite = vma_flags_test(prev_flags, VMA_MAYWRITE_BIT); > > + is_maywrite = vma_flags_test(curr_flags, VMA_MAYWRITE_BIT); > > + > > + /* A driver may not make a previously unwritable mapping writable. */ > > + if (WARN_ON_ONCE(!was_maywrite && is_maywrite)) > > Is it driver specific or generally applicable to all mmap(_preppare) > operations? Is the comment too specific? > > During my LLM quiz, making memfd write seals writable via a > hypothetically wrong shmem_mmap_prepare() implementation is an example > for this WARN_ON_ONCE. It is not driver related. Let me know if I get it > wrong. Driver is taken to mean anything with an mmap or mmap_prepare hook, like a general term for that. If we start getting into calling it different if it's a file system or memfd or something then it becomes quite hard to talk about it. And yeah I hate that it's not a good name because driver makes you think something in drivers/* or an OOT one or something but the kernel makes it vague :) Naming is hard... > > Otherwise, LGTM. > > Reviewed-by: Zi Yan Thanks! > > > -- > Best Regards, > Yan, Zi > -- Cheers, Lorenzo _______________________________________________ linux-riscv mailing list linux-riscv@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-riscv