From: Helge Deller <deller@gmx.de>
To: "Christophe Leroy (CS GROUP)" <chleroy@kernel.org>,
Yury Norov <ynorov@nvidia.com>,
Andrew Morton <akpm@linux-foundation.org>,
Linus Torvalds <torvalds@linux-foundation.org>,
David Laight <david.laight.linux@gmail.com>,
Thomas Gleixner <tglx@linutronix.de>
Cc: linux-alpha@vger.kernel.org, linux-kernel@vger.kernel.org,
linux-snps-arc@lists.infradead.org,
linux-arm-kernel@lists.infradead.org, linux-mips@vger.kernel.org,
linuxppc-dev@lists.ozlabs.org, kvm@vger.kernel.org,
linux-riscv@lists.infradead.org, linux-s390@vger.kernel.org,
sparclinux@vger.kernel.org, linux-um@lists.infradead.org,
dmaengine@vger.kernel.org, linux-efi@vger.kernel.org,
linux-fsi@lists.ozlabs.org, amd-gfx@lists.freedesktop.org,
dri-devel@lists.freedesktop.org, intel-gfx@lists.freedesktop.org,
linux-wpan@vger.kernel.org, netdev@vger.kernel.org,
linux-wireless@vger.kernel.org, linux-spi@vger.kernel.org,
linux-media@vger.kernel.org, linux-staging@lists.linux.dev,
linux-serial@vger.kernel.org, linux-usb@vger.kernel.org,
xen-devel@lists.xenproject.org, linux-fsdevel@vger.kernel.org,
ocfs2-devel@lists.linux.dev, bpf@vger.kernel.org,
kasan-dev@googlegroups.com, linux-mm@kvack.org,
linux-x25@vger.kernel.org, rust-for-linux@vger.kernel.org,
linux-sound@vger.kernel.org,
sound-open-firmware@alsa-project.org, linux-csky@vger.kernel.org,
linux-hexagon@vger.kernel.org, loongarch@lists.linux.dev,
linux-m68k@lists.linux-m68k.org, linux-openrisc@vger.kernel.org,
linux-parisc@vger.kernel.org, linux-sh@vger.kernel.org,
linux-arch@vger.kernel.org
Subject: Re: [RFC PATCH v1 0/9] uaccess: Convert small fixed size copy_{to/from}_user() to scoped user access
Date: Mon, 27 Apr 2026 21:01:18 +0200 [thread overview]
Message-ID: <844ee1e8-e7e2-40ef-a2b1-b7a6b6a44cb2@gmx.de> (raw)
In-Reply-To: <cover.1777306795.git.chleroy@kernel.org>
Hello Christophe,
On 4/27/26 19:13, Christophe Leroy (CS GROUP) wrote:
> A lot of copy_from_user() and copy_to_user() perform copies of small
> fixed size pieces of data between kernel and userspace, and don't
> care about partial copies.
>
> copy_from_user() and copy_to_user() are big functions optimised for
> copying large amount of data, with cache management, etc ...
They take care of much more: alignments, exception handling (e.g. if userpage
is read-only and kernel writes to it), various rules when to return faults
(e.g. sometime reading from page0 is allowed for other arches not), and
much more. I've seen so many strange things during the last few years,
and you would need to get it right if you want to "make small" versions
of those functions.
> This is often overkill for small copies that could just be inlined
> instead.
Isn't put_user() and get_user() for that ?
And if you inline you need to take care of faults as well, so indirectly
you will add more fault handlers (or fault pointers) to the generated code,
effectively making the kernel bigger.
> What makes things a bit more tricky is that those copy functions
> are designed to handle partial copies in case of page fault. But among
> the 6000 callers of those functions, only 2% really care about the
> quantity of no-copied data that those functions return. All other ones
> fails as soon as the returned value is not 0, returning -EACCESS.
>
> So first step in this series is to introduce variants called
> copy_from_user_partial() and copy_to_user_partial() which will be
> called by the 2% users that care about the partial copy, then the
> original copy_from_user() and copy_to_user() are changed to return
> -EFAULT when the copy fails.
>
> Then the second step is to implement copy of small fixed-size data
> with scoped user access instead of calling the arch specific heavy
> user copy functions.
I'm not against your idea or your patch, but I wonder if you
really gain much from it.
Have you done some size or speed comparisons ?
Helge
> Patch 5, can be split in different patches for each archicture or
> subsystem, but let's get a first feedback and agree on the principle.
>
> Christophe Leroy (CS GROUP) (9):
> uaccess: Split check_zeroed_user() out of usercopy.c
> uaccess: Convert INLINE_COPY_{TO/FROM}_USER to kconfig and reduce
> ifdefery
> x86/umip: Be stricter in fixup_umip_exception()
> uaccess: Introduce copy_{to/from}_user_partial()
> uaccess: Switch to copy_{to/from}_user_partial() when relevant
> uaccess: Change copy_{to/from}_user to return -EFAULT
> x86: Add unsafe_copy_from_user()
> arm64: Add unsafe_copy_from_user()
> uaccess: Convert small fixed size copy_{to/from}_user() to scoped user
> access
>
> arch/alpha/Kconfig | 1 +
> arch/alpha/kernel/osf_sys.c | 4 +-
> arch/alpha/kernel/termios.c | 2 +-
> arch/arc/include/asm/uaccess.h | 3 -
> arch/arc/kernel/disasm.c | 2 +-
> arch/arm/include/asm/uaccess.h | 2 -
> arch/arm64/include/asm/gcs.h | 2 +-
> arch/arm64/include/asm/uaccess.h | 30 +++--
> arch/arm64/kernel/signal32.c | 2 +-
> arch/csky/Kconfig | 1 +
> arch/hexagon/include/asm/uaccess.h | 3 -
> arch/loongarch/include/asm/uaccess.h | 3 -
> arch/m68k/include/asm/uaccess.h | 3 -
> arch/microblaze/include/asm/uaccess.h | 2 -
> arch/mips/include/asm/uaccess.h | 3 -
> arch/mips/kernel/rtlx.c | 8 +-
> arch/mips/kernel/vpe.c | 2 +-
> arch/nios2/include/asm/uaccess.h | 2 -
> arch/openrisc/include/asm/uaccess.h | 2 -
> arch/parisc/include/asm/uaccess.h | 3 -
> arch/powerpc/Kconfig | 1 +
> arch/powerpc/kvm/book3s_64_mmu_hv.c | 4 +-
> arch/powerpc/kvm/book3s_64_mmu_radix.c | 4 +-
> arch/powerpc/kvm/book3s_hv.c | 2 +-
> arch/riscv/Kconfig | 1 +
> arch/riscv/kernel/signal.c | 2 +-
> arch/s390/include/asm/idals.h | 8 +-
> arch/s390/include/asm/uaccess.h | 3 -
> arch/sh/include/asm/uaccess.h | 2 -
> arch/sparc/include/asm/uaccess_32.h | 3 -
> arch/sparc/include/asm/uaccess_64.h | 2 -
> arch/sparc/kernel/termios.c | 2 +-
> arch/um/include/asm/uaccess.h | 3 -
> arch/um/kernel/process.c | 2 +-
> arch/x86/Kconfig | 1 +
> arch/x86/include/asm/uaccess.h | 29 ++++-
> arch/x86/kernel/umip.c | 2 +-
> arch/x86/lib/insn-eval.c | 2 +-
> arch/x86/um/signal.c | 2 +-
> arch/xtensa/include/asm/uaccess.h | 2 -
> drivers/android/binder_alloc.c | 2 +-
> drivers/comedi/comedi_fops.c | 4 +-
> drivers/dma/idxd/cdev.c | 2 +-
> drivers/firmware/efi/test/efi_test.c | 2 +-
> drivers/fsi/fsi-scom.c | 2 +-
> .../amd/display/amdgpu_dm/amdgpu_dm_debugfs.c | 2 +-
> drivers/gpu/drm/i915/gt/intel_sseu.c | 4 +-
> drivers/gpu/drm/i915/i915_gem.c | 4 +-
> drivers/hwtracing/intel_th/msu.c | 2 +-
> drivers/misc/ibmvmc.c | 2 +-
> drivers/misc/vmw_vmci/vmci_host.c | 2 +-
> drivers/most/most_cdev.c | 2 +-
> drivers/net/ieee802154/ca8210.c | 4 +-
> drivers/net/wireless/ath/wil6210/debugfs.c | 2 +-
> .../intel/iwlwifi/pcie/gen1_2/trans.c | 2 +-
> drivers/net/wireless/ti/wlcore/debugfs.c | 2 +-
> drivers/ps3/ps3-lpm.c | 2 +-
> drivers/s390/crypto/zcrypt_api.h | 4 +-
> drivers/spi/spidev.c | 2 +-
> .../staging/media/atomisp/pci/atomisp_cmd.c | 8 +-
> drivers/tty/tty_ioctl.c | 14 +--
> drivers/tty/vt/vc_screen.c | 4 +-
> drivers/usb/gadget/function/f_hid.c | 4 +-
> drivers/usb/gadget/function/f_printer.c | 2 +-
> drivers/vfio/vfio_iommu_type1.c | 4 +-
> drivers/xen/xenbus/xenbus_dev_frontend.c | 2 +-
> fs/namespace.c | 2 +-
> fs/ocfs2/dlmfs/dlmfs.c | 2 +-
> fs/proc/base.c | 4 +-
> include/asm-generic/uaccess.h | 2 -
> include/linux/bpfptr.h | 2 +-
> include/linux/sockptr.h | 4 +-
> include/linux/uaccess.h | 107 ++++++++++++++----
> ipc/msg.c | 8 +-
> ipc/sem.c | 8 +-
> ipc/shm.c | 18 +--
> kernel/regset.c | 2 +-
> kernel/sys.c | 4 +-
> lib/Kconfig | 3 +
> lib/Makefile | 4 +-
> lib/kfifo.c | 8 +-
> lib/{usercopy.c => usercheck.c} | 22 ----
> lib/usercopy.c | 66 -----------
> mm/kasan/kasan_test_c.c | 4 +-
> mm/memory.c | 2 +-
> net/x25/af_x25.c | 2 +-
> rust/helpers/uaccess.c | 6 +-
> sound/pci/emu10k1/emufx.c | 4 +-
> sound/pci/rme9652/hdsp.c | 6 +-
> sound/soc/intel/avs/probes.c | 6 +-
> sound/soc/sof/compress.c | 12 +-
> sound/soc/sof/sof-client-probes.c | 6 +-
> 92 files changed, 269 insertions(+), 288 deletions(-)
> copy lib/{usercopy.c => usercheck.c} (73%)
>
prev parent reply other threads:[~2026-04-27 19:01 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-04-27 17:13 [RFC PATCH v1 0/9] uaccess: Convert small fixed size copy_{to/from}_user() to scoped user access Christophe Leroy (CS GROUP)
2026-04-27 17:13 ` [RFC PATCH v1 1/9] uaccess: Split check_zeroed_user() out of usercopy.c Christophe Leroy (CS GROUP)
2026-04-27 17:13 ` [RFC PATCH v1 2/9] uaccess: Convert INLINE_COPY_{TO/FROM}_USER to kconfig and reduce ifdefery Christophe Leroy (CS GROUP)
2026-04-27 18:39 ` Yury Norov
2026-04-27 20:39 ` Andrew Cooper
2026-04-27 20:47 ` Yury Norov
2026-04-27 17:13 ` [RFC PATCH v1 3/9] x86/umip: Be stricter in fixup_umip_exception() Christophe Leroy (CS GROUP)
2026-04-27 17:13 ` [RFC PATCH v1 4/9] uaccess: Introduce copy_{to/from}_user_partial() Christophe Leroy (CS GROUP)
2026-04-27 17:13 ` [RFC PATCH v1 5/9] uaccess: Switch to copy_{to/from}_user_partial() when relevant Christophe Leroy (CS GROUP)
2026-04-27 18:07 ` Alice Ryhl
2026-04-27 19:01 ` Linus Torvalds
2026-04-27 21:29 ` David Laight
2026-04-27 21:39 ` Linus Torvalds
2026-04-27 17:13 ` [RFC PATCH v1 6/9] uaccess: Change copy_{to/from}_user to return -EFAULT Christophe Leroy (CS GROUP)
2026-04-27 17:13 ` [RFC PATCH v1 7/9] x86: Add unsafe_copy_from_user() Christophe Leroy (CS GROUP)
2026-04-27 17:58 ` Yury Norov
2026-04-27 18:20 ` Christophe Leroy (CS GROUP)
2026-04-27 19:19 ` Yury Norov
2026-04-27 21:52 ` Linus Torvalds
2026-04-27 22:30 ` Yury Norov
2026-04-27 17:13 ` [RFC PATCH v1 8/9] arm64: " Christophe Leroy (CS GROUP)
2026-04-27 17:13 ` [RFC PATCH v1 9/9] uaccess: Convert small fixed size copy_{to/from}_user() to scoped user access Christophe Leroy (CS GROUP)
2026-04-27 20:12 ` Yury Norov
2026-04-27 19:01 ` Helge Deller [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=844ee1e8-e7e2-40ef-a2b1-b7a6b6a44cb2@gmx.de \
--to=deller@gmx.de \
--cc=akpm@linux-foundation.org \
--cc=amd-gfx@lists.freedesktop.org \
--cc=bpf@vger.kernel.org \
--cc=chleroy@kernel.org \
--cc=david.laight.linux@gmail.com \
--cc=dmaengine@vger.kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=intel-gfx@lists.freedesktop.org \
--cc=kasan-dev@googlegroups.com \
--cc=kvm@vger.kernel.org \
--cc=linux-alpha@vger.kernel.org \
--cc=linux-arch@vger.kernel.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-csky@vger.kernel.org \
--cc=linux-efi@vger.kernel.org \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-fsi@lists.ozlabs.org \
--cc=linux-hexagon@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-m68k@lists.linux-m68k.org \
--cc=linux-media@vger.kernel.org \
--cc=linux-mips@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=linux-openrisc@vger.kernel.org \
--cc=linux-parisc@vger.kernel.org \
--cc=linux-riscv@lists.infradead.org \
--cc=linux-s390@vger.kernel.org \
--cc=linux-serial@vger.kernel.org \
--cc=linux-sh@vger.kernel.org \
--cc=linux-snps-arc@lists.infradead.org \
--cc=linux-sound@vger.kernel.org \
--cc=linux-spi@vger.kernel.org \
--cc=linux-staging@lists.linux.dev \
--cc=linux-um@lists.infradead.org \
--cc=linux-usb@vger.kernel.org \
--cc=linux-wireless@vger.kernel.org \
--cc=linux-wpan@vger.kernel.org \
--cc=linux-x25@vger.kernel.org \
--cc=linuxppc-dev@lists.ozlabs.org \
--cc=loongarch@lists.linux.dev \
--cc=netdev@vger.kernel.org \
--cc=ocfs2-devel@lists.linux.dev \
--cc=rust-for-linux@vger.kernel.org \
--cc=sound-open-firmware@alsa-project.org \
--cc=sparclinux@vger.kernel.org \
--cc=tglx@linutronix.de \
--cc=torvalds@linux-foundation.org \
--cc=xen-devel@lists.xenproject.org \
--cc=ynorov@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox