From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-lj1-f201.google.com (mail-lj1-f201.google.com [209.85.208.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AA7C479F6 for ; Tue, 28 May 2024 14:58:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1716908297; cv=none; b=VuHH2w3y3LD1gEpcW+mwmQRIc9FqphNUZCF99dZyTE5ECNxi+xz8oAiEB8gw+8pB0RuDE/qeUCbQZ5f5uAZt6QuLv+D99jc0cMAWb/0ycpzbJgGZzbDYVBBmY1tVJoeulj2a/wFp46ZlmLWdEeOEvmZKA/Heg/HsLObO3VZEwL8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1716908297; c=relaxed/simple; bh=UGSUXvJPMuX9Bkae/WPEm6A6AVU8nmv5zPwgw0bs7/Y=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=Gkd5y9CDRg1YxPt2p5ng8giMZ721ZUEVCJOow+swuca481kdokMiQlPuq6dpCoNB8tvEKh3CIxAfciQtaGmrEHX4KQ9nQExVx2yVjHAbDSo35ZXkkedt4IvXmi8qazAYXYOUgOlxHI6hGdGRYmId1d9Q/rwc1sBC/GA5evrwohI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--aliceryhl.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=Jyr4jZOL; arc=none smtp.client-ip=209.85.208.201 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--aliceryhl.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="Jyr4jZOL" Received: by mail-lj1-f201.google.com with SMTP id 38308e7fff4ca-2e95abc0d8eso7611941fa.2 for ; Tue, 28 May 2024 07:58:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1716908294; x=1717513094; darn=vger.kernel.org; h=cc:to:from:subject:message-id:mime-version:date:from:to:cc:subject :date:message-id:reply-to; bh=xLfLKzdeYSLpodZjM1TmVnfFmup+gWezC6j62g1XHPU=; b=Jyr4jZOLI2Te9/VtxKIaQRi4538PI190E+cpqB93kjBDis43Y9LIJSe1hHGBRs6O/4 LLN3r4ycLleZP6f35C6I82l7MW5QRnZz5H2vIjcI7Wehu5olPWKQLSNgkZkzFyp5f3f5 VzevJno7SexdE7QFUVtLuGb/Y15ShVYmhyFfHHEPDfH05BcHL0udiOAtMtUmR2rHaLV3 gxlincMTiMzZZqPj9ZP81twa66Oz+EPSdC73ugxFpPUhqDhHWAQPUcJ1sMZ+iRRwtHh8 ojqki2Dz8gApGsaOfoL6EkSJNk5gDlnqw/J4srvmsnnIY6Cm6xL3zI/NRM920ll2Lgfz aNkw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1716908294; x=1717513094; h=cc:to:from:subject:message-id:mime-version:date:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=xLfLKzdeYSLpodZjM1TmVnfFmup+gWezC6j62g1XHPU=; b=aT4mKGxFqeaM2lhvi1HJ5y9VAgteIqFTtKpv7VN48YMtJFUANKZ+99vBDLHMipImRX qJgweqcB/b/AadGLHr1jXp7wlWY1z6EQ/xmKCXpRzAhARI2+ghb1nI0zaeEyxmza81Vp Y5Qa/zXjTdcKhYMfX6eheTRR1tNw46q3Tdnm6MHxmonOGnMVL4O7GCJbVFe0aSe6RXDC y8/U0INHrM8sWaUUaI61iX+5Wsar9fmLUzNvxwpyuceg6T3uB/4gkxCzTzHP8h0yM5AN T59JMka5Hlj+sBOBkFpNaSHTW0JuY4NQ1RUTroLaepp3Zo2XfhyzoeE3384Q7Vndz+mT V9tQ== X-Forwarded-Encrypted: i=1; AJvYcCUbgEChg6m8WtyrvxOhh8VSmg9124vaBbvhcrxnTBJ2l2VAgIPQmT/ctLtbLnVutMnXOznUx8lOq5WkrMALdGYsu98NzCbsUEVW4J9Wnoo= X-Gm-Message-State: AOJu0YzN81vns7OuT7lGTKqaacjoHeiOcA7kMb1dA1HhbFU3CUfkYDbB JQp7R81SHwk6t38Nc1p84J7mRhH+7vdcEcnkZCQmuT4AEjESkBf9+tE+fNe8PoHiiWAsSWx8HEc I2VltnhX4pyn43g== X-Google-Smtp-Source: AGHT+IG5oCwliI55QSm/nlB6Lw5lzzQdTvktowkRPiBa6vXNuKdy+E+CON0y6SPl/fSx7Q5eHzfvSrmI1t/i15A= X-Received: from aliceryhl2.c.googlers.com ([fda3:e722:ac3:cc00:68:949d:c0a8:572]) (user=aliceryhl job=sendgmr) by 2002:a05:6512:2c86:b0:529:b6cf:cd0c with SMTP id 2adb3069b0e04-529b6cfcebemr3146e87.2.1716908293547; Tue, 28 May 2024 07:58:13 -0700 (PDT) Date: Tue, 28 May 2024 14:58:01 +0000 Precedence: bulk X-Mailing-List: rust-for-linux@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-B4-Tracking: v=1; b=H4sIAPnwVWYC/2XPQW7DIBAF0KtErEsFw0BIV71H1QUeDw5SHFd2Z bWKfPcO2ZjKYvWB9xkeauG58KLeTg8181qWMt0lnF9Oiq7pPrAuvWQFBpy1EHW6FWI9jroj7xz 6QMxRyfWvmXP5eVZ9fEq+luV7mn+fzautu7UEjQXcS1arje5t6ogpOkJ8H6ZpuPErTaOqLSvsE kzz/ApVRrDg5QBTOEi3Sxm9kU4k9fncuSTyQgeJu5TVSBSJlxQRECgbOEjfSOsb6UWG7D1jHzl 7e5Chle0/Q522i9mx70OM+Z/ctu0PVYM4psMBAAA= X-Developer-Key: i=aliceryhl@google.com; a=openpgp; fpr=49F6C1FAA74960F43A5B86A1EE7A392FDE96209F X-Developer-Signature: v=1; a=openpgp-sha256; l=5369; i=aliceryhl@google.com; h=from:subject:message-id; bh=UGSUXvJPMuX9Bkae/WPEm6A6AVU8nmv5zPwgw0bs7/Y=; b=owEBbQKS/ZANAwAKAQRYvu5YxjlGAcsmYgBmVfD/kk+kkk74MgEVp2uFripge2b1MUFf9QTh8 lMpBFLiVYqJAjMEAAEKAB0WIQSDkqKUTWQHCvFIvbIEWL7uWMY5RgUCZlXw/wAKCRAEWL7uWMY5 RjK4D/9tsWpL60+RGj9Xb+y1ietr1OB2e/gUpbdzbfoK8fTqVGvkw1xvetxbsGyDjHtkhrB/Qou uzTgJBqVbbBBXK6Udk7MXKirnMOpoW3L05zP9fDm8p4JRFvwX69B5p0d+9YplqWmjEFBPg3Qv+I kvW4YcV4gq0LP9wYQDHoE9CoIUq5vR9gmtxRz2xPRjSGUXiJJCTquL23dOaJ1AVPRoeZTi0xde4 0NPm/CAPEXCye1BY/G/favUIfvl3jPSQjPdETIwpv9jEJ/ASp5Hgwr78ij/lzl25FxVEqjRloaQ Ob5pcTDrxJ+5porJkDPaHxsKXVVqunRKepKIyrL/xEe2Ykd5upy/kQR+3CBeZMd5WPy6UTqYzJP rEXlKc+ha895BR8UMiCbd2ezCpBy7Si5u3oJvoBR/E2ZVESfzu1uWghhsVUs6KA1IMo2iwHJzgm d2XAJJcHCRHHuvJt4OqXqP7gXEDeJ/JGZ2sVCV2GLcn+7TUc1ibp10BySSlCWgolC6Yxtz/HLO3 SZAGc7hvjI4okhSdcXOFf8Qnc5JNodCoFX4fL237/v/Z/nXXgN2yu5dDsnnPToW+d6qSXkSs6RG NppAJvA0n53Rpn1pMIGQNXCTf0+YpZSGgAKobh3c3CrSsPfYTQK4JSlHWDFrV77nw4vwCVS/Vwd uanXNPTOk0FEDKA== X-Mailer: b4 0.13-dev-26615 Message-ID: <20240528-alice-mm-v7-0-78222c31b8f4@google.com> Subject: [PATCH v7 0/4] Memory management patches needed by Rust Binder From: Alice Ryhl To: Miguel Ojeda , Matthew Wilcox , Al Viro , Andrew Morton , Kees Cook Cc: Alex Gaynor , Wedson Almeida Filho , Boqun Feng , Gary Guo , "=?utf-8?q?Bj=C3=B6rn_Roy_Baron?=" , Benno Lossin , Andreas Hindborg , Greg Kroah-Hartman , "=?utf-8?q?Arve_Hj=C3=B8nnev=C3=A5g?=" , Todd Kjos , Martijn Coenen , Joel Fernandes , Carlos Llamas , Suren Baghdasaryan , Arnd Bergmann , Trevor Gross , linux-mm@kvack.org, linux-kernel@vger.kernel.org, rust-for-linux@vger.kernel.org, Alice Ryhl , Christian Brauner Content-Type: text/plain; charset="utf-8" This patchset contains some abstractions needed by the Rust implementation of the Binder driver for passing data between userspace, kernelspace, and directly into other processes. These abstractions do not exactly match what was included in the Rust Binder RFC - I have made various improvements and simplifications since then. Nonetheless, please see the Rust Binder RFC [1] to get an understanding for how this will be used: Users of "rust: add userspace pointers" and "rust: add typed accessors for userspace pointers": rust_binder: add binderfs support to Rust binder rust_binder: add threading support rust_binder: add nodes and context managers rust_binder: add oneway transactions rust_binder: add death notifications rust_binder: send nodes in transactions rust_binder: add BINDER_TYPE_PTR support rust_binder: add BINDER_TYPE_FDA support rust_binder: add process freezing Users of "rust: add abstraction for `struct page`": rust_binder: add oneway transactions rust_binder: add vma shrinker Links: https://lore.kernel.org/rust-for-linux/20231101-rust-binder-v1-0-08ba9197f637@google.com/ [1] Signed-off-by: Alice Ryhl --- Changes in v7: - Fix call to `reserve` under `make rusttest`. - Add comment on _inline_copy_from_user. - Add Reviewed-by tags. - Link to v6: https://lore.kernel.org/r/20240418-alice-mm-v6-0-cb8f3e5d688f@google.com Changes in v6: - Base on top of Wedson's Allocation APIs patchset. - Do not define my own gfp flags, instead use the ones that are now available in `kernel::alloc`. - Add gfp flags to `read_all` methods instead of always using GFP_KERNEL. - The __GFP_HIGHMEM flag is not provided by the Allocation APIs patchset, and I do not add it here. I will send a separate patchset for adding it. - Use usize instead of void pointer for userspace address. - Add _raw suffix to `fill_zero` and `copy_from_user_slice`. - Do not allow interior mutability in AsBytes/FromBytes. - Doc changes: - Mention that validity of user slices is checked at read/write time, not in the constructor of the user slice. - Mention that methods can also return EFAULT if a bounds check fails. - Mention that methods may have partially copied data even if they return EFAULT. - Add link from `read_raw` to `read_slice`. - Move comment about initialized memory on `read_raw` to `# Guarantees` section. - Add examples for `Page::alloc_page`. - A previous version renamed UserSlicePtr to UserSlice but forgot to update that in the commit message. Commit message fixed in this version. - Add Reviewed-by tags submitted on v5. - Link to v5: https://lore.kernel.org/rust-for-linux/20240415-alice-mm-v5-0-6f55e4d8ef51@google.com/ Changes in v5: - Fix casts in declarations of PAGE_* constants. - Fix formatting of PAGE_MASK. - Reformat comments at 100 line length. - Minor fixes to safety comments of `read_raw` and `write_slice`. - Link to v4: https://lore.kernel.org/rust-for-linux/20240404-alice-mm-v4-0-49a84242cf02@google.com/ Changes in v4: - Rephrase when we fail with EFAULT. - Remove `pub` from examples. - Use slices for raw uaccess methods. - Fix PAGE_MASK constant. - Rephrase most safety comments in Page abstraction. - Make with_pointer_into_page and with_page_mapped private. - Explain how raw pointers into pages are used correctly. - Other minor doc improvements. - Link to v3: https://lore.kernel.org/rust-for-linux/20240311-alice-mm-v3-0-cdf7b3a2049c@google.com/ Changes in v3: - Fix bug in read_all. - Add missing `#include `. - Mention that the second patch passes CONFIG_TEST_USER_COPY. - Add gfp flags for Page. - Minor documentation adjustments. - Link to v2: https://lore.kernel.org/rust-for-linux/20240208-alice-mm-v2-0-d821250204a6@google.com/ Changes in v2: - Rename user_ptr module to uaccess. - Use srctree-relative links. - Improve documentation. - Rename UserSlicePtr to UserSlice. - Make read_to_end append to the buffer. - Use named fields for uaccess types. - Add examples. - Use _copy_from/to_user to skip check_object_size. - Rename traits and move to kernel::types. - Remove PAGE_MASK constant. - Rename page methods to say _raw. - Link to v1: https://lore.kernel.org/rust-for-linux/20240124-alice-mm-v1-0-d1abcec83c44@google.com/ --- Alice Ryhl (2): rust: uaccess: add typed accessors for userspace pointers rust: add abstraction for `struct page` Arnd Bergmann (1): uaccess: always export _copy_[from|to]_user with CONFIG_RUST Wedson Almeida Filho (1): rust: uaccess: add userspace pointers include/linux/uaccess.h | 46 +++-- lib/usercopy.c | 30 +--- rust/bindings/bindings_helper.h | 1 + rust/helpers.c | 34 ++++ rust/kernel/alloc.rs | 7 + rust/kernel/lib.rs | 2 + rust/kernel/page.rs | 250 ++++++++++++++++++++++++++ rust/kernel/types.rs | 64 +++++++ rust/kernel/uaccess.rs | 388 ++++++++++++++++++++++++++++++++++++++++ 9 files changed, 782 insertions(+), 40 deletions(-) --- base-commit: 1613e604df0cd359cf2a7fbd9be7a0bcfacfabd0 change-id: 20231128-alice-mm-bc533456cee8 Best regards, -- Alice Ryhl