mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Suren Baghdasaryan <surenb@google.com>
To: "Lorenzo Stoakes (ARM)" <ljs@kernel.org>
Cc: Andrew Morton <akpm@linux-foundation.org>,
	"Liam R. Howlett" <liam@infradead.org>,
	 Vlastimil Babka <vbabka@kernel.org>,
	Jann Horn <jannh@google.com>, Pedro Falcato <pfalcato@suse.de>,
	 David Hildenbrand <david@kernel.org>,
	Mike Rapoport <rppt@kernel.org>, Michal Hocko <mhocko@suse.com>,
	 Jonathan Corbet <corbet@lwn.net>,
	Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
	 Dennis Dalessandro <dennis.dalessandro@cornelisnetworks.com>,
	Jason Gunthorpe <jgg@ziepe.ca>,
	 Leon Romanovsky <leon@kernel.org>,
	Paul Moore <paul@paul-moore.com>,
	 Stephen Smalley <stephen.smalley.work@gmail.com>,
	Jaroslav Kysela <perex@perex.cz>,  Takashi Iwai <tiwai@suse.com>,
	Alexei Starovoitov <ast@kernel.org>,
	Daniel Borkmann <daniel@iogearbox.net>,
	 Andrii Nakryiko <andrii@kernel.org>,
	Eduard Zingerman <eddyz87@gmail.com>,
	 Kumar Kartikeya Dwivedi <memxor@gmail.com>,
	Zi Yan <ziy@nvidia.com>,
	 Baolin Wang <baolin.wang@linux.alibaba.com>,
	Nico Pache <nico.pache@linux.dev>,
	 Ryan Roberts <ryan.roberts@arm.com>, Dev Jain <dev.jain@arm.com>,
	Barry Song <baohua@kernel.org>,
	 Lance Yang <lance.yang@linux.dev>,
	Usama Arif <usama.arif@linux.dev>,
	 Kiryl Shutsemau <kas@kernel.org>,
	Doug Gilbert <dgilbert@interlog.com>,
	 "James E.J. Bottomley" <James.Bottomley@hansenpartnership.com>,
	 "Martin K. Petersen" <mkp@kernel.org>,
	Jaya Kumar <jayalk@intworks.biz>, Simona Vetter <simona@ffwll.ch>,
	 Helge Deller <deller@gmx.de>, Sebastian Reichel <sre@kernel.org>,
	John Hubbard <jhubbard@nvidia.com>,  Peter Xu <peterx@redhat.com>,
	Masami Hiramatsu <mhiramat@kernel.org>,
	Oleg Nesterov <oleg@redhat.com>,
	 Peter Zijlstra <peterz@infradead.org>,
	Thomas Gleixner <tglx@kernel.org>, Ingo Molnar <mingo@redhat.com>,
	 Borislav Petkov <bp@alien8.de>,
	Dave Hansen <dave.hansen@linux.intel.com>,
	x86@kernel.org,  Arnaldo Carvalho de Melo <acme@kernel.org>,
	Namhyung Kim <namhyung@kernel.org>,
	 Mark Rutland <mark.rutland@arm.com>,
	Rik van Riel <riel@surriel.com>, Harry Yoo <harry@kernel.org>,
	 Juri Lelli <juri.lelli@redhat.com>,
	Vincent Guittot <vincent.guittot@linaro.org>,
	 Maarten Lankhorst <maarten.lankhorst@linux.intel.com>,
	Maxime Ripard <mripard@kernel.org>,
	 Thomas Zimmermann <tzimmermann@suse.de>,
	David Airlie <airlied@gmail.com>, Will Deacon <will@kernel.org>,
	 "Aneesh Kumar K.V" <aneesh.kumar@kernel.org>,
	Nick Piggin <npiggin@gmail.com>,  Arnd Bergmann <arnd@arndb.de>,
	Muchun Song <muchun.song@linux.dev>,
	 Oscar Salvador <osalvador@suse.de>,
	"Matthew Wilcox (Oracle)" <willy@infradead.org>,
	Jan Kara <jack@suse.cz>,  Marc Zyngier <maz@kernel.org>,
	Oliver Upton <oupton@kernel.org>,
	 Catalin Marinas <catalin.marinas@arm.com>,
	Madhavan Srinivasan <maddy@linux.ibm.com>,
	 Anup Patel <anup@brainfault.org>, Paul Walmsley <pjw@kernel.org>,
	 Palmer Dabbelt <palmer@dabbelt.com>,
	Albert Ou <aou@eecs.berkeley.edu>,
	 Christian Borntraeger <borntraeger@linux.ibm.com>,
	Janosch Frank <frankja@linux.ibm.com>,
	 Claudio Imbrenda <imbrenda@linux.ibm.com>,
	Alexander Gordeev <agordeev@linux.ibm.com>,
	 Gerald Schaefer <gerald.schaefer@linux.ibm.com>,
	Heiko Carstens <hca@linux.ibm.com>,
	 Vasily Gorbik <gor@linux.ibm.com>,
	"David S. Miller" <davem@davemloft.net>,
	 Andreas Larsson <andreas@gaisler.com>,
	Alexander Viro <viro@zeniv.linux.org.uk>,
	 Christian Brauner <brauner@kernel.org>,
	Matthew Brost <matthew.brost@intel.com>,
	 Joshua Hahn <joshua.hahnjy@gmail.com>,
	Rakie Kim <rakie.kim@sk.com>,  Byungchul Park <byungchul@sk.com>,
	Gregory Price <gourry@gourry.net>,
	 Ying Huang <ying.huang@linux.alibaba.com>,
	Alistair Popple <apopple@nvidia.com>,
	 Chris Li <chrisl@kernel.org>, Kairui Song <kasong@tencent.com>,
	 Kemeng Shi <shikemeng@huaweicloud.com>,
	Nhat Pham <nphamcs@gmail.com>,  Baoquan He <baoquan.he@linux.dev>,
	Youngjun Park <youngjun.park@lge.com>,
	 Johannes Weiner <hannes@cmpxchg.org>,
	Qi Zheng <qi.zheng@linux.dev>,
	 Shakeel Butt <shakeel.butt@linux.dev>,
	Axel Rasmussen <axelrasmussen@google.com>,
	 Yuanchu Xie <yuanchu@google.com>, Wei Xu <weixugc@google.com>,
	 Chengming Zhou <chengming.zhou@linux.dev>,
	Michal Hocko <mhocko@kernel.org>,
	 Miklos Szeredi <miklos@szeredi.hu>, Xu Xin <xu.xin@linux.dev>,
	linux-mm@kvack.org,  linux-kernel@vger.kernel.org,
	linux-doc@vger.kernel.org,  linux-usb@vger.kernel.org,
	linux-rdma@vger.kernel.org,  selinux@vger.kernel.org,
	linux-sound@vger.kernel.org, bpf@vger.kernel.org,
	 linux-scsi@vger.kernel.org, linux-fbdev@vger.kernel.org,
	 dri-devel@lists.freedesktop.org,
	linux-trace-kernel@vger.kernel.org,
	 linux-perf-users@vger.kernel.org, linux-arch@vger.kernel.org,
	 linux-fsdevel@vger.kernel.org,
	linux-arm-kernel@lists.infradead.org,  kvmarm@lists.linux.dev,
	linuxppc-dev@lists.ozlabs.org, kvm@vger.kernel.org,
	 kvm-riscv@lists.infradead.org, linux-riscv@lists.infradead.org,
	 linux-s390@vger.kernel.org, sparclinux@vger.kernel.org,
	 fuse-devel@lists.linux.dev
Subject: Re: [PATCH v3 04/40] mm: consistently validate VMA state after mmap[_prepare] hooks
Date: Wed, 23 Sep 2026 09:47:20 -0700	[thread overview]
Message-ID: <CAJuCfpELP9Ups5XeS3PNbF=VtrfkYbkwRj-LuEHd7bLsTw4LUw@mail.gmail.com> (raw)
In-Reply-To: <20260917-b4-mmap-prepare-vma-flag-sanify-v3-4-4583d8a23bca@kernel.org>

On Thu, Sep 17, 2026 at 9:25 AM Lorenzo Stoakes (ARM) <ljs@kernel.org> wrote:
>
> When the f_op->mmap_prepare or deprecated f_op->mmap hooks are invoked, the
> driver might have done something crazy that is not permitted by the kernel.
>
> Currently we check for three such cases in __mmap_new_file_vma(), but only
> if the legacy f_op->mmap hook is used:
>
> * Did sparc ADI result in invalid flags?
>
> * Did the driver alter vma->vm_start?
>
> * Did the driver make a file-backed mapping on a read-only file writable?
>
> Generalise these checks for both mmap_prepare and mmap and apply to all
> invocations of mmap_file(), the f_op->mmap and f_op->mmap_prepare handling
> in the core VMA code and the mmap_prepare compatibility layer.
>
> Also extend the vm_start check to vm_end also - drivers must not change the
> VMA range at all.
>
> We also WARN_ON_ONCE() on these conditions as they are things that should
> simply not occur in the kernel and it's important to call it out when it
> does.
>
> We invoke mmap_prepare_validate() after mmap_action_prepare(), as mmap
> actions often manipulate state in the descriptor thus providing the final
> state the VMA will be derived from.
>
> Also call mmap_validate_vma_flags() in insert_vm_struct() to ensure that
> special regions which are inserted (such as a VDSO or VVAR) also satisfy
> the sanity checks.
>
> This way every VMA established through an mmap hook, whether via mmap() or
> the compatibility layer, or inserted via insert_vm_struct(), has been
> validated. brk() VMAs never pass through a driver hook and so need no such
> check.
>
> While we're here, also fixup a couple disjoint blocks of #ifdef CONFIG_MMU.
>
> Finally, update the VMA userland tests to reflect the change.
>
> Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>

Reviewed-by: Suren Baghdasaryan <surenb@google.com>

> ---
>  mm/internal.h                   |  51 ++++++++++++--------
>  mm/util.c                       |  19 ++++++--
>  mm/vma.c                        | 100 ++++++++++++++++++++++++++++++++++------
>  mm/vma.h                        |  25 ++++++++--
>  tools/testing/vma/include/dup.h |  10 ++++
>  5 files changed, 163 insertions(+), 42 deletions(-)
>
> diff --git a/mm/internal.h b/mm/internal.h
> index fe576d468af4..970fb34898b2 100644
> --- a/mm/internal.h
> +++ b/mm/internal.h
> @@ -213,6 +213,24 @@ static inline void *folio_raw_mapping(const struct folio *folio)
>         return (void *)(mapping & ~FOLIO_MAPPING_FLAGS);
>  }
>
> +/*
> + * If the VMA has a close hook then close it, and since closing it might leave
> + * it in an inconsistent state which makes the use of any hooks suspect, clear
> + * them down by installing dummy empty hooks.
> + */
> +static inline void vma_close(struct vm_area_struct *vma)
> +{
> +       if (vma->vm_ops && vma->vm_ops->close) {
> +               vma->vm_ops->close(vma);
> +
> +               /*
> +                * The mapping is in an inconsistent state, and no further hooks
> +                * may be invoked upon it.
> +                */
> +               vma->vm_ops = &vma_dummy_vm_ops;
> +       }
> +}
> +
>  /*
>   * This is a file-backed mapping, and is about to be memory mapped - invoke its
>   * mmap hook and safely handle error conditions. On error, VMA hooks will be
> @@ -225,8 +243,12 @@ static inline void *folio_raw_mapping(const struct folio *folio)
>   */
>  static inline int mmap_file(struct file *file, struct vm_area_struct *vma)
>  {
> -       int err = vfs_mmap(file, vma);
> +       const unsigned long prev_start = vma->vm_start;
> +       const unsigned long prev_end = vma->vm_end;
> +       const vma_flags_t prev_flags = vma->flags;

nit: Might be just me but when I see prev_XXX in VMA-related code I
picture previous VMA in the address space. Maybe call these orig_XXX?

> +       int err;
>
> +       err = vfs_mmap(file, vma);
>         /*
>          * Either we tried to call the file hook for mmap() and an error arose
>          * or a driver set vma->vm_ops = NULL intending there to be no VMA
> @@ -239,26 +261,17 @@ static inline int mmap_file(struct file *file, struct vm_area_struct *vma)
>          */
>         if (unlikely(err || !vma->vm_ops))
>                 vma->vm_ops = &vma_dummy_vm_ops;
> +       if (unlikely(err))
> +               return err;
>
> -       return err;
> -}
> -
> -/*
> - * If the VMA has a close hook then close it, and since closing it might leave
> - * it in an inconsistent state which makes the use of any hooks suspect, clear
> - * them down by installing dummy empty hooks.
> - */
> -static inline void vma_close(struct vm_area_struct *vma)
> -{
> -       if (vma->vm_ops && vma->vm_ops->close) {
> -               vma->vm_ops->close(vma);
> -
> -               /*
> -                * The mapping is in an inconsistent state, and no further hooks
> -                * may be invoked upon it.
> -                */
> -               vma->vm_ops = &vma_dummy_vm_ops;
> +       err = mmap_hook_validate(prev_start, prev_end, &prev_flags, vma);
> +       if (unlikely(err)) {
> +               vma->vm_start = prev_start;
> +               vma->vm_end = prev_end;
> +               vma_close(vma);
>         }
> +
> +       return err;
>  }
>
>  /* unmap_vmas is in mm/memory.c */
> diff --git a/mm/util.c b/mm/util.c
> index 016932780925..bdd5923eebc7 100644
> --- a/mm/util.c
> +++ b/mm/util.c
> @@ -1224,19 +1224,28 @@ EXPORT_SYMBOL(compat_set_desc_from_vma);
>  int __compat_vma_mmap(struct vm_area_desc *desc,
>                       struct vm_area_struct *vma)
>  {
> +       struct vm_area_desc prev_desc;
>         int err;
>
> +       /* Derive state prior to mmap_prepare hook. */
> +       compat_set_desc_from_vma(&prev_desc, desc->file, vma);
>         /* Perform any preparatory tasks for mmap action. */
>         err = mmap_action_prepare(desc);
> -       if (err) {
> -               if (desc->vm_file != vma->vm_file)
> -                       fput(desc->vm_file);
> -               return err;
> -       }
> +       if (err)
> +               goto err_put;
> +       /* Check the caller did nothing crazy. */
> +       err = mmap_prepare_validate(&prev_desc, desc);
> +       if (err)
> +               goto err_put;
>         /* Update the VMA from the descriptor. */
>         compat_set_vma_from_desc(vma, desc);
>         /* Complete any specified mmap actions. */
>         return mmap_action_complete(vma, &desc->action, /*is_compat=*/true);
> +
> +err_put:
> +       if (desc->vm_file != vma->vm_file)
> +               fput(desc->vm_file);
> +       return err;
>  }
>  EXPORT_SYMBOL(__compat_vma_mmap);
>
> diff --git a/mm/vma.c b/mm/vma.c
> index 05d2c676672e..d6ed10cefc8f 100644
> --- a/mm/vma.c
> +++ b/mm/vma.c
> @@ -2623,16 +2623,6 @@ static int __mmap_new_file_vma(struct mmap_state *map,
>                 return error;
>         }
>
> -       /* Drivers cannot alter the address of the VMA. */
> -       WARN_ON_ONCE(map->addr != vma->vm_start);
> -       /*
> -        * Drivers should not permit writability when previously it was
> -        * disallowed.
> -        */
> -       VM_WARN_ON_ONCE(!vma_flags_same_pair(&map->vma_flags, &vma->flags) &&
> -                       !vma_flags_test(&map->vma_flags, VMA_MAYWRITE_BIT) &&
> -                       vma_test(vma, VMA_MAYWRITE_BIT));
> -
>         map->vma_flags = vma->flags;
>
>         return 0;
> @@ -2710,11 +2700,6 @@ static int __mmap_new_vma(struct mmap_state *map, struct vm_area_struct **vmap,
>                 vma->flags = map->vma_flags;
>         }
>
> -#ifdef CONFIG_SPARC64
> -       /* TODO: Fix SPARC ADI! */
> -       WARN_ON_ONCE(!arch_validate_flags(map->vm_flags));
> -#endif
> -
>         /* Lock the VMA since it is modified after insertion into VMA tree */
>         vma_start_write(vma);
>         vma_iter_store_new(vmi, vma);
> @@ -2777,6 +2762,80 @@ static void __mmap_complete(struct mmap_state *map, struct vm_area_struct *vma)
>         vma_set_page_prot(vma);
>  }
>
> +/* Check to ensure that the VMA flags of a newly mapped VMA are sane. */
> +static int mmap_validate_vma_flags(const vma_flags_t *flags)
> +{
> +#ifdef CONFIG_SPARC64
> +       const vm_flags_t legacy_flags = vma_flags_to_legacy(*flags);
> +
> +       /* TODO: Fix SPARC ADI! */
> +       if (WARN_ON_ONCE(!arch_validate_flags(legacy_flags)))
> +               return -EINVAL;
> +#endif
> +
> +       return 0;
> +}
> +
> +/* Check to ensure a driver hasn't done something crazy. */
> +static int mmap_validate(unsigned long prev_start, unsigned long prev_end,
> +                        unsigned long curr_start, unsigned long curr_end,
> +                        const vma_flags_t *prev_flags,
> +                        const vma_flags_t *curr_flags)
> +{
> +       bool was_maywrite, is_maywrite;
> +
> +       /* Drivers cannot alter the range of the VMA. */
> +       if (WARN_ON_ONCE(prev_start != curr_start || prev_end != curr_end))
> +               return -EINVAL;
> +
> +       was_maywrite = vma_flags_test(prev_flags, VMA_MAYWRITE_BIT);
> +       is_maywrite = vma_flags_test(curr_flags, VMA_MAYWRITE_BIT);
> +
> +       /* A driver may not make a previously unwritable mapping writable. */
> +       if (WARN_ON_ONCE(!was_maywrite && is_maywrite))
> +               return -EINVAL;
> +
> +       return mmap_validate_vma_flags(curr_flags);
> +}
> +
> +/**
> + * mmap_prepare_validate() - Ensure the driver hasn't violated invariants in its
> + * f_op->mmap_prepare hook.
> + * @prev_desc: The VMA descriptor prior to the mmap_prepare hook being called.
> + * @desc: The VMA descriptor after the mmap_prepare hook has been called.
> + *
> + * Returns: 0 on success, otherwise an error.
> + */
> +int mmap_prepare_validate(const struct vm_area_desc *prev_desc,
> +                         const struct vm_area_desc *desc)
> +{
> +       return mmap_validate(prev_desc->start, prev_desc->end,
> +                            desc->start, desc->end,
> +                            &prev_desc->vma_flags, &desc->vma_flags);
> +}
> +
> +/**
> + * mmap_hook_validate() - Ensure the driver hasn't violated invariants in
> + * its f_op->mmap hook.
> + * @prev_start: The start of the mapping prior to the mmap hook.
> + * @prev_end: The end of the mapping prior to the mmap hook.
> + * @prev_flags: The VMA flags set for the VMA prior to the mmap hook.
> + * @vma: The VMA after the hook has been applied.
> + *
> + * Returns: 0 on success, otherwise an error.
> + */
> +int mmap_hook_validate(unsigned long prev_start, unsigned long prev_end,
> +                      const vma_flags_t *prev_flags,
> +                      const struct vm_area_struct *vma)
> +{
> +       const unsigned long start = vma->vm_start;
> +       const unsigned long end = vma->vm_end;
> +       const vma_flags_t *flags = &vma->flags;
> +
> +       return mmap_validate(prev_start, prev_end, start, end, prev_flags,
> +                            flags);
> +}
> +
>  static int call_action_prepare(struct mmap_state *map,
>                                struct vm_area_desc *desc)
>  {
> @@ -2803,6 +2862,7 @@ static int call_action_prepare(struct mmap_state *map,
>  static int call_mmap_prepare(struct mmap_state *map,
>                 struct vm_area_desc *desc)
>  {
> +       const struct vm_area_desc prev_desc = *desc;
>         int err;
>
>         /* Invoke the hook. */
> @@ -2822,6 +2882,11 @@ static int call_mmap_prepare(struct mmap_state *map,
>         if (err)
>                 return err;
>
> +       /* Check the caller did nothing crazy. */
> +       err = mmap_prepare_validate(&prev_desc, desc);
> +       if (err)
> +               return err;
> +
>         /* Update fields permitted to be changed. */
>         map->pgoff = desc->pgoff;
>         map->vma_flags = desc->vma_flags;
> @@ -3457,10 +3522,15 @@ int __vm_munmap(unsigned long start, size_t len, bool unlock)
>  int insert_vm_struct(struct mm_struct *mm, struct vm_area_struct *vma)
>  {
>         unsigned long charged = vma_pages(vma);
> +       int err;
>
>         if (find_vma_intersection(mm, vma->vm_start, vma->vm_end))
>                 return -ENOMEM;
>
> +       err = mmap_validate_vma_flags(&vma->flags);
> +       if (err)
> +               return err;
> +
>         if (vma_test(vma, VMA_ACCOUNT_BIT) &&
>              security_vm_enough_memory_mm(mm, charged))
>                 return -ENOMEM;
> diff --git a/mm/vma.h b/mm/vma.h
> index f15faa83f3d6..b2c3bc832a48 100644
> --- a/mm/vma.h
> +++ b/mm/vma.h
> @@ -782,14 +782,19 @@ struct vm_area_struct *vm_area_alloc(struct mm_struct *mm);
>  struct vm_area_struct *vm_area_dup(struct vm_area_struct *orig);
>  void vm_area_free(struct vm_area_struct *vma);
>
> -/* vma_exec.c */
>  #ifdef CONFIG_MMU
> +int mmap_prepare_validate(const struct vm_area_desc *prev_desc,
> +                         const struct vm_area_desc *desc);
> +
> +int mmap_hook_validate(unsigned long prev_start, unsigned long prev_end,
> +                      const vma_flags_t *prev_flags,
> +                      const struct vm_area_struct *vma);
> +
> +/* vma_exec.c */
>  int create_init_stack_vma(struct mm_struct *mm, struct vm_area_struct **vmap,
>                           unsigned long *top_mem_p);
>  int relocate_vma_down(struct vm_area_struct *vma, unsigned long shift);
> -#endif
>
> -#ifdef CONFIG_MMU
>  /*
>   * Denies creating a writable executable mapping or gaining executable permissions.
>   *
> @@ -838,6 +843,20 @@ static inline bool map_deny_write_exec(const vma_flags_t *old,
>
>         return false;
>  }
> +#else
> +static inline int mmap_prepare_validate(const struct vm_area_desc *prev_desc,
> +                                       const struct vm_area_desc *desc)
> +{
> +       return 0;
> +}
> +
> +static inline int mmap_hook_validate(unsigned long prev_start,
> +                                    unsigned long prev_end,
> +                                    const vma_flags_t *prev_flags,
> +                                    const struct vm_area_struct *vma)
> +{
> +       return 0;
> +}
>  #endif
>
>  struct vm_area_struct *__install_special_mapping(struct mm_struct *mm,
> diff --git a/tools/testing/vma/include/dup.h b/tools/testing/vma/include/dup.h
> index 2fd422789717..2986ae6ca1e5 100644
> --- a/tools/testing/vma/include/dup.h
> +++ b/tools/testing/vma/include/dup.h
> @@ -1359,13 +1359,23 @@ static inline int vfs_mmap_prepare(struct file *file, struct vm_area_desc *desc)
>         return file->f_op->mmap_prepare(desc);
>  }
>
> +int mmap_prepare_validate(const struct vm_area_desc *prev_desc,
> +                         const struct vm_area_desc *desc);
> +
>  static inline int __compat_vma_mmap(struct vm_area_desc *desc,
>                 struct vm_area_struct *vma)
>  {
> +       struct vm_area_desc prev_desc;
>         int err;
>
> +       /* Derive state prior to mmap_prepare hook. */
> +       compat_set_desc_from_vma(&prev_desc, desc->file, vma);
>         /* Perform any preparatory tasks for mmap action. */
>         err = mmap_action_prepare(desc);
> +       if (err)
> +               return err;
> +       /* Check the caller did nothing crazy. */
> +       err = mmap_prepare_validate(&prev_desc, desc);
>         if (err)
>                 return err;
>         /* Update the VMA from the descriptor. */
>
> --
> 2.55.0
>

  reply	other threads:[~2026-09-23 16:47 UTC|newest]

Thread overview: 151+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-17 16:22 [PATCH v3 00/40] mm: make VMA flag semantics explicit, eliminate VM_SPECIAL Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 01/40] mm/vma: fix mmap_prepare file handling, remove file_doesnt_need_get Lorenzo Stoakes (ARM)
2026-09-23 15:21   ` Suren Baghdasaryan
2026-09-23 15:46     ` Lorenzo Stoakes (ARM)
2026-09-23 15:59       ` Suren Baghdasaryan
2026-09-24  2:20   ` Zi Yan
2026-09-24 10:03     ` Lorenzo Stoakes (ARM)
2026-09-24 16:28   ` Gregory Price
2026-09-25  9:30     ` Lorenzo Stoakes (ARM)
2026-09-24 19:00   ` Liam R. Howlett
2026-09-25  9:12     ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 02/40] mm/vma: predicate setting mmap_prepare VMA fields on new vma alloc Lorenzo Stoakes (ARM)
2026-09-23 15:32   ` Suren Baghdasaryan
2026-09-23 15:53     ` Lorenzo Stoakes (ARM)
2026-09-23 16:09       ` Suren Baghdasaryan
2026-09-23 17:07         ` Lorenzo Stoakes (ARM)
2026-09-23 17:33   ` Lorenzo Stoakes (ARM)
2026-09-24  2:25   ` Zi Yan
2026-09-17 16:22 ` [PATCH v3 03/40] mm/vma: introduce and use vma_[flags_]can_merge() Lorenzo Stoakes (ARM)
2026-09-23 16:23   ` Suren Baghdasaryan
2026-09-24  2:27   ` Zi Yan
2026-09-24 16:38   ` Gregory Price
2026-10-01 12:03   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 04/40] mm: consistently validate VMA state after mmap[_prepare] hooks Lorenzo Stoakes (ARM)
2026-09-23 16:47   ` Suren Baghdasaryan [this message]
2026-09-23 17:00     ` Lorenzo Stoakes (ARM)
2026-09-24  2:52   ` Zi Yan
2026-09-24 10:06     ` Lorenzo Stoakes (ARM)
2026-09-24 17:17   ` Gregory Price
2026-09-25 12:51     ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 05/40] mm/vma: ensure mmap_prepare doesn't set actions on a mergeable vma Lorenzo Stoakes (ARM)
2026-09-24 18:00   ` Gregory Price
2026-09-25  9:51     ` Lorenzo Stoakes (ARM)
2026-09-24 19:28   ` Zi Yan
2026-09-25  9:55     ` Lorenzo Stoakes (ARM)
2026-09-25  7:28   ` Suren Baghdasaryan
2026-09-25  9:53     ` Lorenzo Stoakes (ARM)
2026-10-01 12:11       ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 06/40] mm: make map_kernel_pages_[prepare,complete] internal and unexported Lorenzo Stoakes (ARM)
2026-09-24 19:30   ` Zi Yan
2026-09-25  7:35     ` Suren Baghdasaryan
2026-09-29 15:58   ` Gregory Price
2026-10-01 12:11   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 07/40] mm/vma: tidy up map kernel pages enum values Lorenzo Stoakes (ARM)
2026-09-24 19:30   ` Zi Yan
2026-09-25  7:37     ` Suren Baghdasaryan
2026-09-29 15:59   ` Gregory Price
2026-10-01 12:12   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 08/40] mm: add mmap action for discontiguous kernel page mapping Lorenzo Stoakes (ARM)
2026-09-25 20:53   ` Zi Yan
2026-09-27 21:44   ` Suren Baghdasaryan
2026-09-29 11:11     ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 09/40] docs: filesystems: update mmap_prepare docs for discontig kernel pgs Lorenzo Stoakes (ARM)
2026-09-25 21:01   ` Zi Yan
2026-09-29 11:21     ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 10/40] drivers/usb/mon: update to use mmap_prepare + map kernel pages Lorenzo Stoakes (ARM)
2026-10-02  9:55   ` Lance Yang
2026-10-02 12:12     ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 11/40] infiniband: update hfi1 to use remap_vmalloc_range() Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 12/40] selinux: reject writable opens of policy file, drop mmap shared/write check Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 13/40] ALSA: pcm: use vm_insert_page() to map PCM status page Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 14/40] bpf: arena: mark arena_map_mmap() mappings VM_MIXEDMAP Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 15/40] mm/vma: add vma[_flags]_is_kernel_owned() predicates Lorenzo Stoakes (ARM)
2026-09-26  1:37   ` Zi Yan
2026-10-01 12:36   ` David Hildenbrand (Arm)
2026-10-02 14:56     ` Lorenzo Stoakes (ARM)
2026-10-02 21:19       ` David Hildenbrand (Arm)
2026-10-03  9:03         ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 16/40] mm/vma: only allow mmap to clear VMA_MAYWRITE_BIT if kernel-owned Lorenzo Stoakes (ARM)
2026-09-26  2:07   ` Zi Yan
2026-09-26  2:17     ` Zi Yan
2026-09-26 10:06       ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 17/40] mm/vma: add and use vma_[flags]_is_fixed_mapping Lorenzo Stoakes (ARM)
2026-09-26  2:27   ` Zi Yan
2026-09-26 10:03     ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 18/40] scsi: sg: convert mmap hook to mmap_prepare and rework Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 19/40] fbdev: defio: assert FBINFO_VIRTFB, drop VM_IO, add VM_MIXEDMAP Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 20/40] HSI: cmt_speech: convert mmap hook to mmap_prepare, refactor Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 21/40] mm/gup: error out early on !VMA_MAYREAD_BIT VMAs Lorenzo Stoakes (ARM)
2026-09-26  2:30   ` Zi Yan
2026-09-17 16:22 ` [PATCH v3 22/40] uprobes: remove VM_IO, set VM_MIXEDMAP for mapped kernel pages Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 23/40] mm/mlock: clear VMA_LOCKED_MASK over mmap callback Lorenzo Stoakes (ARM)
2026-10-01 15:20   ` Zi Yan
2026-10-02 12:26     ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 24/40] mm/mlock: eliminate weird VMA_IO_BIT abuse and simplify Lorenzo Stoakes (ARM)
2026-09-23 20:06   ` Zi Yan
2026-09-24 10:21     ` Lorenzo Stoakes (ARM)
2026-09-24 15:50       ` Zi Yan
2026-09-25  9:35         ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 25/40] mm/vma: enforce that only kernel-owned mappings may set VMA_IO_BIT Lorenzo Stoakes (ARM)
2026-09-29  2:12   ` Zi Yan
2026-09-17 16:22 ` [PATCH v3 26/40] mm: remove VMA_IO_BIT check in vma[_flags]_is_kernel_owned() Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 27/40] mm: remove hugetlb_inline.h Lorenzo Stoakes (ARM)
2026-09-29  2:13   ` Zi Yan
2026-10-02  6:52   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 28/40] mm: rename is_vm_hugetlb_page() to vma_is_hugetlb() Lorenzo Stoakes (ARM)
2026-09-29  2:14   ` Zi Yan
2026-10-02  6:53   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 29/40] mm: drop some redundant checks around hugetlb VMAs Lorenzo Stoakes (ARM)
2026-09-29  2:36   ` Zi Yan
2026-10-02  6:54   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 30/40] mm/madvise: update is_valid_guard_vma() to use vma_can_merge() Lorenzo Stoakes (ARM)
2026-09-29  2:38   ` Zi Yan
2026-10-02  6:57   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 31/40] mm/vma: introduce vma[_flags]_is_persistent() Lorenzo Stoakes (ARM)
2026-09-30  2:00   ` Zi Yan
2026-10-02  6:59   ` David Hildenbrand (Arm)
2026-10-02  7:02     ` David Hildenbrand (Arm)
2026-10-02  7:05       ` David Hildenbrand (Arm)
2026-10-02 12:08         ` Lorenzo Stoakes (ARM)
2026-10-02 12:35           ` David Hildenbrand (Arm)
2026-10-02 12:48             ` Lorenzo Stoakes (ARM)
2026-10-02 13:11               ` David Hildenbrand (Arm)
2026-10-02 13:59                 ` Lorenzo Stoakes (ARM)
2026-10-02 21:43                   ` David Hildenbrand (Arm)
2026-10-03 13:16                     ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 32/40] mm/uffd: use predicates for userfaultfd checks Lorenzo Stoakes (ARM)
2026-09-30  2:02   ` Zi Yan
2026-10-02  7:04   ` David Hildenbrand (Arm)
2026-10-02 12:35     ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 33/40] mm/madvise: use predicates for madvise(..., MADV_DOFORK) Lorenzo Stoakes (ARM)
2026-09-30  2:28   ` Zi Yan
2026-09-17 16:22 ` [PATCH v3 34/40] mm: eliminate VMA_SPECIAL_FLAGS usage when hugetlb explicitly tested Lorenzo Stoakes (ARM)
2026-09-30  2:42   ` Zi Yan
2026-09-30  9:32     ` Lorenzo Stoakes (ARM)
2026-09-17 16:22 ` [PATCH v3 35/40] mm: eliminate VMA_SPECIAL_FLAGS check in lru_gen_look_around() Lorenzo Stoakes (ARM)
2026-09-30  2:42   ` Zi Yan
2026-10-02  7:06   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 36/40] mm: avoid use of VMA_SPECIAL_FLAGS in migrate_vma_setup() Lorenzo Stoakes (ARM)
2026-09-30  2:47   ` Zi Yan
2026-10-02  7:07   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 37/40] mm: eliminate VM_SPECIAL, VMA_SPECIAL_FLAGS Lorenzo Stoakes (ARM)
2026-09-30  2:48   ` Zi Yan
2026-10-02  7:07   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 38/40] fuse: dax: do not set VM_MIXEDMAP Lorenzo Stoakes (ARM)
2026-10-02  7:09   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 39/40] mm/huge_memory: remove vma_is_special_huge() Lorenzo Stoakes (ARM)
2026-10-01 15:21   ` Zi Yan
2026-10-02  7:11   ` David Hildenbrand (Arm)
2026-09-17 16:22 ` [PATCH v3 40/40] mm/vma: introduce and use vma[_flags]_can_gup() Lorenzo Stoakes (ARM)
2026-10-01 15:23   ` Zi Yan
2026-10-02  7:48   ` David Hildenbrand (Arm)
2026-10-02 16:11     ` Lorenzo Stoakes (ARM)
2026-09-17 21:23 ` [PATCH v3 00/40] mm: make VMA flag semantics explicit, eliminate VM_SPECIAL Andrew Morton
2026-09-23  8:57 ` Lorenzo Stoakes (ARM)
2026-09-25 15:58 ` Lorenzo Stoakes (ARM)
2026-09-25 22:06 ` Arnd Bergmann
2026-09-26  9:40   ` Lorenzo Stoakes (ARM)
2026-09-26 13:06     ` Arnd Bergmann
2026-09-26 13:22       ` Lorenzo Stoakes (ARM)
2026-09-26 17:14         ` Arnd Bergmann

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to='CAJuCfpELP9Ups5XeS3PNbF=VtrfkYbkwRj-LuEHd7bLsTw4LUw@mail.gmail.com' \
    --to=surenb@google.com \
    --cc=James.Bottomley@hansenpartnership.com \
    --cc=acme@kernel.org \
    --cc=agordeev@linux.ibm.com \
    --cc=airlied@gmail.com \
    --cc=akpm@linux-foundation.org \
    --cc=andreas@gaisler.com \
    --cc=andrii@kernel.org \
    --cc=aneesh.kumar@kernel.org \
    --cc=anup@brainfault.org \
    --cc=aou@eecs.berkeley.edu \
    --cc=apopple@nvidia.com \
    --cc=arnd@arndb.de \
    --cc=ast@kernel.org \
    --cc=axelrasmussen@google.com \
    --cc=baohua@kernel.org \
    --cc=baolin.wang@linux.alibaba.com \
    --cc=baoquan.he@linux.dev \
    --cc=borntraeger@linux.ibm.com \
    --cc=bp@alien8.de \
    --cc=bpf@vger.kernel.org \
    --cc=brauner@kernel.org \
    --cc=byungchul@sk.com \
    --cc=catalin.marinas@arm.com \
    --cc=chengming.zhou@linux.dev \
    --cc=chrisl@kernel.org \
    --cc=corbet@lwn.net \
    --cc=daniel@iogearbox.net \
    --cc=dave.hansen@linux.intel.com \
    --cc=davem@davemloft.net \
    --cc=david@kernel.org \
    --cc=deller@gmx.de \
    --cc=dennis.dalessandro@cornelisnetworks.com \
    --cc=dev.jain@arm.com \
    --cc=dgilbert@interlog.com \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=eddyz87@gmail.com \
    --cc=frankja@linux.ibm.com \
    --cc=fuse-devel@lists.linux.dev \
    --cc=gerald.schaefer@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=gourry@gourry.net \
    --cc=gregkh@linuxfoundation.org \
    --cc=hannes@cmpxchg.org \
    --cc=harry@kernel.org \
    --cc=hca@linux.ibm.com \
    --cc=imbrenda@linux.ibm.com \
    --cc=jack@suse.cz \
    --cc=jannh@google.com \
    --cc=jayalk@intworks.biz \
    --cc=jgg@ziepe.ca \
    --cc=jhubbard@nvidia.com \
    --cc=joshua.hahnjy@gmail.com \
    --cc=juri.lelli@redhat.com \
    --cc=kas@kernel.org \
    --cc=kasong@tencent.com \
    --cc=kvm-riscv@lists.infradead.org \
    --cc=kvm@vger.kernel.org \
    --cc=kvmarm@lists.linux.dev \
    --cc=lance.yang@linux.dev \
    --cc=leon@kernel.org \
    --cc=liam@infradead.org \
    --cc=linux-arch@vger.kernel.org \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-doc@vger.kernel.org \
    --cc=linux-fbdev@vger.kernel.org \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=linux-rdma@vger.kernel.org \
    --cc=linux-riscv@lists.infradead.org \
    --cc=linux-s390@vger.kernel.org \
    --cc=linux-scsi@vger.kernel.org \
    --cc=linux-sound@vger.kernel.org \
    --cc=linux-trace-kernel@vger.kernel.org \
    --cc=linux-usb@vger.kernel.org \
    --cc=linuxppc-dev@lists.ozlabs.org \
    --cc=ljs@kernel.org \
    --cc=maarten.lankhorst@linux.intel.com \
    --cc=maddy@linux.ibm.com \
    --cc=mark.rutland@arm.com \
    --cc=matthew.brost@intel.com \
    --cc=maz@kernel.org \
    --cc=memxor@gmail.com \
    --cc=mhiramat@kernel.org \
    --cc=mhocko@kernel.org \
    --cc=mhocko@suse.com \
    --cc=miklos@szeredi.hu \
    --cc=mingo@redhat.com \
    --cc=mkp@kernel.org \
    --cc=mripard@kernel.org \
    --cc=muchun.song@linux.dev \
    --cc=namhyung@kernel.org \
    --cc=nico.pache@linux.dev \
    --cc=nphamcs@gmail.com \
    --cc=npiggin@gmail.com \
    --cc=oleg@redhat.com \
    --cc=osalvador@suse.de \
    --cc=oupton@kernel.org \
    --cc=palmer@dabbelt.com \
    --cc=paul@paul-moore.com \
    --cc=perex@perex.cz \
    --cc=peterx@redhat.com \
    --cc=peterz@infradead.org \
    --cc=pfalcato@suse.de \
    --cc=pjw@kernel.org \
    --cc=qi.zheng@linux.dev \
    --cc=rakie.kim@sk.com \
    --cc=riel@surriel.com \
    --cc=rppt@kernel.org \
    --cc=ryan.roberts@arm.com \
    --cc=selinux@vger.kernel.org \
    --cc=shakeel.butt@linux.dev \
    --cc=shikemeng@huaweicloud.com \
    --cc=simona@ffwll.ch \
    --cc=sparclinux@vger.kernel.org \
    --cc=sre@kernel.org \
    --cc=stephen.smalley.work@gmail.com \
    --cc=tglx@kernel.org \
    --cc=tiwai@suse.com \
    --cc=tzimmermann@suse.de \
    --cc=usama.arif@linux.dev \
    --cc=vbabka@kernel.org \
    --cc=vincent.guittot@linaro.org \
    --cc=viro@zeniv.linux.org.uk \
    --cc=weixugc@google.com \
    --cc=will@kernel.org \
    --cc=willy@infradead.org \
    --cc=x86@kernel.org \
    --cc=xu.xin@linux.dev \
    --cc=ying.huang@linux.alibaba.com \
    --cc=youngjun.park@lge.com \
    --cc=yuanchu@google.com \
    --cc=ziy@nvidia.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®