Commit graph

983,818 commits

Author SHA1 Message Date
Michael Bestas
fb2690e255
Revert "update btfm enable ch delay when freq 48000 ch 0"
This reverts commit e819d7d240.

Reason for revert: Remove useless log level change

Change-Id: I951522831e1b3376ce893a4c57343cf539703517
2025-03-21 19:50:12 +02:00
Michael Bestas
f8d17d91f1
binder: Resolve motorola merge issue
Change-Id: I9206602f10e1e99e033e4cc3fd0ef30b79ddee60
2025-03-21 19:50:11 +02:00
Michael Bestas
7edfa87463
arm64: dts: vendor: Remove .gitignore
Change-Id: If00813d768889dd27d26737abf165734ff7d75c5
2025-03-21 19:50:11 +02:00
Michael Bestas
af40082e75
Merge branch 'staging/motorola-kernel-modules/MMI-U1UGS34.23-110-23-2' into lineage-22.2
Based on tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/motorola-kernel-modules

Fogos push for Android 14

* staging/motorola-kernel-modules/MMI-U1UGS34.23-110-23-2: (3149 commits)
  Documentation: Remove slg51000.txt
  treewide: Remove conflicting Makefiles
  include: Remove unused synaptics_tcm.h header
  fs: Remove exfat drivers
  dlkm: goodix_fod_mmi: fix KE issue
  dlkm: goodix_fod: support drm panel notification
  moto_swap: Add reset_bdev to close backing dev for ramboost2.0
  add page fault pages to list head to avoid be swapped out soon
  fogos: TP: open 1st icnl9916c force up config
  workaround fix long page fault issue
  Revert "(CR) moto_swap: Add SWP_SYNCHRONOUS_IO cmd for ioctl"
  fix null pointer at quota_day_store
  moto_swap: Add SWP_SYNCHRONOUS_IO cmd for ioctl
  charge: config qg iterm small than FCC
  moto_swap:fix kernel panic on memcg conf
  Moto kernel protection module
  Add macro to close debug function in user build
  fogo/motorola:Fogo 5g na optimize stowed mode
  input: goodix_berlin: enable palm cancel for report id
  Update UWB driver to version 7.4
  ...

 Conflicts:
	Documentation/devicetree/bindings~HEAD

Change-Id: I1e380097e692b2efea451cbcf4dc42d972e6dd5a
2025-03-21 18:42:24 +02:00
Michael Bestas
327cbdcf54
Merge tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/kernel-msm-5.4-techpack-video into lineage-22.2
Fogos push for Android 14

* tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/kernel-msm-5.4-techpack-video:
  Adjust qbuf cache/dqbuf cache ops failed log to VIDC_HIGH
  extend codec limitation to 1080@90fps.
  msm: vidc: optimize HEIC output buffer calc for encoder
  msm: vidc: tune input buffer size based on buffer_size_limit
  msm: vidc: Avoid dma_buf memory leak under memory pressure
  msm-vidc: fix final BW voting to ICC

Change-Id: I7ff1d8e69765b5dc96cbce2a8c5df7fc12be10e1
2025-03-21 18:37:17 +02:00
Michael Bestas
654ea8a9cd
Merge tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/kernel-msm-5.4-techpack-display into lineage-22.2
Fogos push for Android 14

* tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/kernel-msm-5.4-techpack-display: (116 commits)
  dsi_panel: panel_feature: corret the code mistake
  dsi_panel: fix the bug of local HBM
  gpu/msm: check fps value before enable lhbm
  msm/display-drivers: release lhbm resource
  dsi/dfps: update the dfps code to support "OLED+vid mode"
  dsi/dfps: set the right fps when panel resume
  Support 120Hz command sending
  dts/display: [bangkok] update the dsc configure for tianma panel
  display-drivers: local hbm: add suport for dc_hybird_threshold
  optimze lcd log
  kernel:pnangn:update 2nd panel brightness settings to 11bits
  kernel/panel:power on/off reset sequence
  display/backlight: support hbm dcs only with 51 cmd
  display/dsi:add new lcd backlight align type for bit11_4
  display: The lcd backlight shift mode update
  drm_ioctl: add return value for set_param
  drm/dsi_panel: resend hbm off commands
  msm/drm:compatible with different hbm table in panel
  drm/msm:add delay between mipi0 to reset0 when power off
  drm/panel: check panel status before send custom commands
  ...

 Conflicts:
	techpack/display/msm/sde/sde_connector.c
	techpack/display/msm/sde/sde_kms.c

Change-Id: I13ede04c21415717cd009ae73871894f1be74927
2025-03-21 18:36:59 +02:00
Michael Bestas
9ca541ecda
Merge tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/kernel-msm-5.4-techpack-camera into lineage-22.2
Fogos push for Android 14

* tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/kernel-msm-5.4-techpack-camera: (86 commits)
  fogo: fix tombstone when use secure camera
  fogo: Fix secure mode switch error (2/2)
  Bangkk: reset ois when read standby_flag fail
  fogos: Actuator noise reduction[2/2]
  fogor: Actuator noise reduction[2/2]
  bangkk: Powerup and initialize sensor early [3/4]
  bangkk: Fix flash request GPIO-24 failed
  bangkk: support dw9784 af drift
  bangkk: Open Camera preview will be black then camera error
  bangkk: open Camera preview may be black sometimes
  bangkk: dw9784 ois bring up
  bangkk: Secondary supply flash driver ic compatible
  Tundra: restore ois delete submit
  Tundra: add delay at check ois data_ready
  Revert "(CR): milanf: modify ois vsync irq processing flow"
  penang: Adjust actuator noise reduction
  penang: Adjust actuator noise reduction
  penang: Actuator noise reduction
  milanf: modify ois vsync irq processing flow
  camera: ois: avoid ois power down twice when download firmware failed
  ...

 Conflicts:
	techpack/camera/drivers/cam_sensor_module/cam_ois/cam_ois_core.c

Change-Id: I9aa733fcd4412059a267c7cb9408b05e91eba111
2025-03-21 18:36:20 +02:00
Michael Bestas
0cd369436c
Merge tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/kernel-msm-5.4-techpack-audio into lineage-22.2
Fogos push for Android 14

* tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/kernel-msm-5.4-techpack-audio: (79 commits)
  Revert "asoc: msm-compress : Fix for CTS-on-gsi with gki"
  soc: swr-mstr-ctrl: allow runtime suspend first before system suspend
  audio:add lock for aw dynamics set dailink
  Revert "(CR):audio:add lock for aw dynamics set dailink"
  dsp: q6lsm: Address use after free for mmap handle
  dsp: q6lsm: Add check for payload buffer
  ASoC: msm-pcm-host-voice: Check validity of session idx
  audio:add lock for aw dynamics set dailink
  q6fsm:add protect for fs1815 algo
  fs1815:correct rotation code
  aw882xxacf: add hac scene algo ctrl
  audio-kernel: fix build fail caused by aw8838
  techpack:add aw8838 driver
  fsm:correct fsm vbat monitor logic
  audio/dsp:reduce fsm vbat monitor retry times
  audio/asoc:add PRI_MI2S_TX_HOSTLESS
  machie_driver:add aw pri I2S dailink
  audio:add fs1815 bypass algo code and logic.
  Awinic: update communicate with adsp logic
  codecs:add fs1815 PA driver
  ...

 Conflicts:
	techpack/audio/dsp/q6lsm.c

Change-Id: I6ec23f0d578fd2494e5e29577ce470dc2cb90f5c
2025-03-21 18:35:48 +02:00
Michael Bestas
721895bde2
Merge tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/vendor-qcom-opensource-wlan-qcacld-3.0 into lineage-22.2
Fogos push for Android 14

* tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/vendor-qcom-opensource-wlan-qcacld-3.0: (55 commits)
  qcacld-3.0: Remove use-after-free of frame in tx mgmt send
  qcacld-3.0: Ignore CSA request for invalid channel
  Revert "qcacld-3.0: Fix OOB issue when access wma_find_vdev_by_addr"
  qcacld-3.0: Fix OOB issue when access wma_find_vdev_by_addr
  remove invoking "sock_from_file" function
  Print the process which is receiving data
  fix wifi reconnect issue
  wlan: Support loading moto specific ini configurations
  Revert "qcacld-3.0: Change PCL for throughput case in case of STA+GO"
  : Revert "qcacld-3.0: Add support to flush fragments for a particular peer"
  qcacld-3.0: Modify check to ensure consecutive PN for frags
  qcacld-3.0: Drop mcast and plaintext frags in protected network
  qcacld-3.0: Flush frags for peer on add key request
  qcacld-3.0: Add support to flush fragments for a particular peer
  use NONHLOS_PLATFORM_COMMON_PATH
  sm4350: Store WLAN Unstripped and ELF in build archives
  fix compile errors
  prop (CR) the MAC address more appropriately
  lito: Update FW version for R
  - Update wifimacaddr command line arg
  ...

Change-Id: Ibb7fd5d5df7ee9fd07a78069cc9b385c1bf34121
2025-03-21 18:35:16 +02:00
Michael Bestas
3522680e9f
Merge tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/vendor-qcom-opensource-wlan-qca-wifi-host-cmn into lineage-22.2
Fogos push for Android 14

* tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/vendor-qcom-opensource-wlan-qca-wifi-host-cmn:
  qcacmn: Add length checks for noninheritance_ie
  qcacmn: Fix OOB reads in util_gen_new_ie
  qcacmn: Fix potential OOB read in util_scan_parse_rnr_ie
  qcacmn: Fix out of bound read issue in ESP ie parse
  qcacmn: Add check to avoid NULL pointer deference in parse MBSSID
  qcacmn: Fix potential OOB read in util_scan_is_split_prof_found()
  qcacmn: Fix potential OOB read in util_scan_parse_mbssid()
  qcacmn: Fix use-after-free issue in util_scan_parse_mbssid
  qcacmn: Fix memleak in MBSSIE handler
  add NOTICE for vendor/qcom/opensource/wlan/qca-wifi-host-cmn
  Modify PNO timers.
  Support for 12M WLAN Radiated Power test on Production SW
  qcacmn: Fix out-of-bounds of src_freq
  qcacmn: Handle gracefully if scheduler cb is not registered
  qcacmn: Set default value of mawc_nlo_enabled ini as 0
  qcacmn: Use local skb pointer for reentrant cld80211_msg_allocator
  qcacmn: Validate NDP app info length before accessing NDP app info
  qcacmn: add cdp ops for IPA Tx buf smmu_unmapping
  qcacmn: Avoid array out of bound access for current channels list

 Conflicts:
	drivers/staging/qca-wifi-host-cmn/umac/scan/dispatcher/src/wlan_scan_utils_api.c

Change-Id: I00c00211511127de3ed3fece6a81879f998f0653
2025-03-21 18:34:57 +02:00
Michael Bestas
0f697d4b4b
Merge tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/kernel-display-devicetree into lineage-22.2
Fogos push for Android 14

* tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/kernel-display-devicetree:
  dts/panel: add the dts file of auo panel
  dts/panel: add the dts file of dummy panel

Change-Id: I621af395f50d93cbb288bff626c368ae1f21b364
2025-03-21 18:34:00 +02:00
Michael Bestas
25c1a87ecc
Merge tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/kernel-camera-devicetree into lineage-22.2
Fogos push for Android 14

* tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/kernel-camera-devicetree: (183 commits)
  fogos: Actuator noise reduction[1/2]
  fogor: Modify mclk for s5k4h7
  fogor: Actuator noise reduction[1/2]
  camera-devicetree: add init file for fogos bringup
  fogo: Bring up eeprom of main camera[1/2]
  fogo: Bring up flash[1/3]
  fogo: Bring up s5k4h7 otp[2/2]
  fogo: Bring up macro sc202acs otp
  fogo: Bring up actuator of main camera[1/2]
  fogo: Bring up front s5k4h7[2/2]
  fogo: Bring up macro sc202acs
  fogo: Bring up main s5kjns
  fogo: Setup camera driver baseline[2/3]
  fogor: Update the power pins of avdd
  fogor: Bring up eeprom of macro sc202acs
  fogor: Bring up flash[2/2]
  fogor: Bring up eeprom of front camera[2/2]
  fogor: Bring up eeprom of main camera[1/2]
  fogor: Bring up actuator of main camera[1/2]
  fogor: Bring up macro sc202acs
  ...

Change-Id: Ie6b083e7d9b99052d897af385cb1c6c48586124f
2025-03-21 18:30:55 +02:00
Michael Bestas
2d4c3b4e6f
Merge tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/kernel-devicetree into lineage-22.2
"Fogos push for Android 14"

* tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/kernel-devicetree: (1247 commits)
  Fogo5g+ introduce SB18E53186 battery
  arm/dts: config BCL SOC trigger threshold to 2%
  arm/dts: add new battery SN
  arm64/dt: fogos: add panel notify dts of fps
  arm64/dt: fogo: add panel notify dts of fps
  arm/dts: config CDP max current 1A
  system: remove cdsp_secure_heap_region
  fogos: dtsi/kernel: modify 2nd ili9883c init code
  fogos: dtsi/kernel: modify 2nd ili9883c init code
  arm/dts: config DCP max current 2.2A
  arm/dts: config mmi,enable-fcc-large-qg-iterm
  fogo/sensor: update sx937x params
  devicetree/fogo:1st panel low brightness turns off cabc
  fogos: dtsi/kernel: modify 1st icnl9916c min brightness turn off cabc
  fogos: dtsi/kernel: modify 2nd ili9883c min brightness turn off cabc
  fogos: dtsi/kernel: modify 2nd ili9883c timing
  devicetree/fogo:1st panel timing optimization
  fogor: dtsi/kernel: modify 2nd ili9883c tp-reset timing
  fogos: dtsi/kernel: modify 2nd ili9883c tp-reset timing
  dts/panel: fogo: add delay time of command 0x10
  ...

Change-Id: I49f4dc89847f5fbeac996c5cc31952bea74bd413
2025-03-21 18:13:57 +02:00
Michael Bestas
869b1e64a6
Merge branch 'staging/kernel-msm/MMI-U1UGS34.23-110-23-2' into lineage-22.2
Based on tag 'MMI-U1UGS34.23-110-23-2' of https://github.com/MotorolaMobilityLLC/kernel-msm

"Fogos push for Android 14"

* staging/kernel-msm/MMI-U1UGS34.23-110-23-2: (698 commits)
  mmc: sdhci-msm: Move MMC_CAP2_MAX_DISCARD_SIZE to prevent merge conflict
  Reapply "UPSTREAM: binder: fix the missing BR_FROZEN_REPLY in binder_return_strings"
  Revert "qseecom: Suppress suspend warning if without bus scaling."
  Revert "Penang: fix for device suspend tests fail. [1/2]"
  Revert "Penang: resolve kasan panic"
  Revert "Penang: kasan panic"
  Revert "penang: device suspend tests fail"
  Revert "net: qrtr: get svc_id before queueing sk_buff"
  Revert "af_unix: Do not use atomic ops for unix_sk(sk)->inflight."
  Revert "af_unix: Fix garbage collector racing against connect()"
  Revert "BACKPORT: net: fix __dst_negative_advice() race"
  Revert "ANDROID: ABI fixup for abi break in struct dst_ops"
  Revert "BACKPORT:sched: Provide sched_set_fifo()"
  Revert "msm: npu: Fix use after free issue"
  Revert "fs:EROFS:Porting 5.10 erofs to 5.4"
  Revert "BACKPORT:erofs: add per-cpu threads for decompression as an option"
  Revert "UPSTREAM: erofs: fix an error code in z_erofs_init_zip_subsystem()"
  msm: adsprpc: Avoid taking reference for group_info
  adsprpc: Handle UAF scenario in put_args
  msm: adsprpc: use-after-free (UAF) in global maps
  ...

Change-Id: Ia48438f247670d77560472205994632fa62062dd
2025-03-21 18:12:22 +02:00
Michael Bestas
a546cb523d
Documentation: Remove slg51000.txt
This conflicts with the upstream kernel documentation.

Change-Id: I41c0a65bb0ade4e190f224f690715caba5a7d48d
2025-03-19 09:27:10 +02:00
Michael Bestas
8e590ea149
mmc: sdhci-msm: Move MMC_CAP2_MAX_DISCARD_SIZE to prevent merge conflict
Change-Id: I80acdb4f52811ebd371317acfc4afa41e4960656
2025-03-19 09:19:56 +02:00
Michael Bestas
fc5694ef93
treewide: Remove conflicting Makefiles
These conflict with the upstream kernel makefiles.

Change-Id: Ie6b22cb952f04b80b92a38b362f71dc7cebc19b4
2025-03-19 08:37:33 +02:00
Michael Bestas
910ae61e03
include: Remove unused synaptics_tcm.h header
This conflicts with the qcom kernel header.

Change-Id: I336b3e88171fa3d0b6fde54489f6194ca997d747
2025-03-19 08:36:46 +02:00
Michael Bestas
8f36bc1909
fs: Remove exfat drivers
We will be using the backport of the official upstream exfat driver

Change-Id: I0cc1441a53ecacd45dca266bb797faef280b9e43
2025-03-19 08:35:41 +02:00
Michael Bestas
408802114d
Reapply "UPSTREAM: binder: fix the missing BR_FROZEN_REPLY in binder_return_strings"
This reverts commit 3777eba3b1.

Reason for revert: Conflicts with upstream commits.

Change-Id: Id2eca0ce74ffbd1ca7146757336bc1b4e8a76bc2
2025-03-19 07:45:58 +02:00
Michael Bestas
dab88fd873
Revert "qseecom: Suppress suspend warning if without bus scaling."
This reverts commit 2208e80231.

Reason for revert: Conflicts with upstream commits.

Change-Id: I976cd54c43319a28892efdfe078ad146204d2eb0
2025-03-19 07:42:54 +02:00
Michael Bestas
e3819f8900
Revert "Penang: fix for device suspend tests fail. [1/2]"
This reverts commit f536ebe9fc.

Reason for revert: Conflicts with upstream commits.

Change-Id: Iba5cafaf37044b09e2fee65682881f0503c2c990
2025-03-19 07:40:48 +02:00
Michael Bestas
5585e8424d
Revert "Penang: resolve kasan panic"
This reverts commit a65aa65ad1.

Reason for revert: Conflicts with upstream commits.

Change-Id: Ib80fa2d49308fe7bf853a93b977370768212ae05
2025-03-19 07:40:47 +02:00
Michael Bestas
269e073bc3
Revert "Penang: kasan panic"
This reverts commit 0ab43c2ab5.

Reason for revert: Conflicts with upstream commits.

Change-Id: I02d3e77f611b75bb22f48f1492f7b3bdeb426a8f
2025-03-19 07:40:46 +02:00
Michael Bestas
403aa4c00b
Revert "penang: device suspend tests fail"
This reverts commit 485bfce748.

Reason for revert: Conflicts with upstream commits.

Change-Id: I5ca8bffe070c918271543678401d2d9ab25e4897
2025-03-19 07:40:45 +02:00
Michael Bestas
4267e716d3
Revert "net: qrtr: get svc_id before queueing sk_buff"
This reverts commit 836e3b0c9a.

Reason for revert: Conflicts with upstream commits.

Change-Id: I963f28698392f505661abcc115b86e3c4c8801be
2025-03-19 07:40:43 +02:00
Michael Bestas
ce75ac8da4
Revert "af_unix: Do not use atomic ops for unix_sk(sk)->inflight."
This reverts commit 9ef7c24511.

Reason for revert: Conflicts with upstream commits.

Change-Id: Id7ec5e6a24fd6702a7525893b6e3b3f2428b4704
2025-03-19 07:33:35 +02:00
Michael Bestas
3628064f37
Revert "af_unix: Fix garbage collector racing against connect()"
This reverts commit 6487f3d346.

Reason for revert: Conflicts with upstream commits.

Change-Id: I5e1ccd8f68283fe88f90eebc33ade79fddf0054a
2025-03-19 07:33:34 +02:00
Michael Bestas
5740e39ff5
Revert "BACKPORT: net: fix __dst_negative_advice() race"
This reverts commit c17f876810.

Reason for revert: Conflicts with upstream commits.

Change-Id: Iee731e1eca0f9a2cef4d301f92bbff758c1afe02
2025-03-19 07:32:15 +02:00
Michael Bestas
34d9540ea1
Revert "ANDROID: ABI fixup for abi break in struct dst_ops"
This reverts commit ec1b288e67.

Reason for revert: Conflicts with upstream commits.

Change-Id: I7dae59ba64170b508615e8ef7156c4eb3d840a96
2025-03-19 07:32:12 +02:00
Michael Bestas
6e34d77850
Revert "BACKPORT:sched: Provide sched_set_fifo()"
This reverts commit 250751cadf.

Reason for revert: Conflicts with upstream commits.

Change-Id: I3eac9acf461e6492ccae2870afebf03db3889632
2025-03-19 07:30:42 +02:00
Michael Bestas
6998b48898
Revert "msm: npu: Fix use after free issue"
This reverts commit f6795b4ad6.

Reason for revert: Conflicts with upstream commits.

Change-Id: I46f817266215e1bf230951f9ceee12a42083d62b
2025-03-19 07:25:35 +02:00
Michael Bestas
7d45106869
Revert "fs:EROFS:Porting 5.10 erofs to 5.4"
This reverts commit fa3b0b74bb.

Reason for revert: Conflicts with upstream commits.

Change-Id: I10bbd4c822e516266dd4be504f42ff9e1dcf9032
2025-03-19 07:25:33 +02:00
Michael Bestas
944e8a32b9
Revert "BACKPORT:erofs: add per-cpu threads for decompression as an option"
This reverts commit 8199049168.

Reason for revert: Conflicts with upstream commits.

Change-Id: Ifb8fc9271cea27ac8a9c282cd9a75329be06725d
2025-03-19 07:25:30 +02:00
Michael Bestas
848895a54d
Revert "UPSTREAM: erofs: fix an error code in z_erofs_init_zip_subsystem()"
This reverts commit 45482ab6d3.

Reason for revert: Conflicts with upstream commits.

Change-Id: I9f82deafc00f195ed1064146511b0642eb4a08a4
2025-03-19 07:25:27 +02:00
Aneesh Kumar K.V
23a17bf13e
BACKPORT: mm/mremap: hold the rmap lock in write mode when moving page table entries.
To avoid a race between rmap walk and mremap, mremap does
take_rmap_locks().  The lock was taken to ensure that rmap walk don't miss
a page table entry due to PTE moves via move_pagetables().  The kernel
does further optimization of this lock such that if we are going to find
the newly added vma after the old vma, the rmap lock is not taken.  This
is because rmap walk would find the vmas in the same order and if we don't
find the page table attached to older vma we would find it with the new
vma which we would iterate later.

As explained in commit eb66ae0308 ("mremap: properly flush TLB before
releasing the page") mremap is special in that it doesn't take ownership
of the page.  The optimized version for PUD/PMD aligned mremap also
doesn't hold the ptl lock.  This can result in stale TLB entries as show
below.

This patch updates the rmap locking requirement in mremap to handle the race condition
explained below with optimized mremap::

Optmized PMD move

    CPU 1                           CPU 2                                   CPU 3

    mremap(old_addr, new_addr)      page_shrinker/try_to_unmap_one

    mmap_write_lock_killable()

                                    addr = old_addr
                                    lock(pte_ptl)
    lock(pmd_ptl)
    pmd = *old_pmd
    pmd_clear(old_pmd)
    flush_tlb_range(old_addr)

    *new_pmd = pmd
                                                                            *new_addr = 10; and fills
                                                                            TLB with new addr
                                                                            and old pfn

    unlock(pmd_ptl)
                                    ptep_clear_flush()
                                    old pfn is free.
                                                                            Stale TLB entry

Optimized PUD move also suffers from a similar race.  Both the above race
condition can be fixed if we force mremap path to take rmap lock.

Link: https://lkml.kernel.org/r/20210616045239.370802-7-aneesh.kumar@linux.ibm.com
Fixes: 2c91bd4a4e ("mm: speed up mremap by 20x on large regions")
Fixes: c49dd3401802 ("mm: speedup mremap on 1GB or larger regions")
Link: https://lore.kernel.org/linux-mm/CAHk-=wgXVR04eBNtxQfevontWnP6FDm+oj5vauQXP3S-huwbPw@mail.gmail.com
Signed-off-by: Aneesh Kumar K.V <aneesh.kumar@linux.ibm.com>
Acked-by: Hugh Dickins <hughd@google.com>
Acked-by: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
Cc: Christophe Leroy <christophe.leroy@csgroup.eu>
Cc: Joel Fernandes <joel@joelfernandes.org>
Cc: Kalesh Singh <kaleshsingh@google.com>
Cc: Kirill A. Shutemov <kirill@shutemov.name>
Cc: Michael Ellerman <mpe@ellerman.id.au>
Cc: Nicholas Piggin <npiggin@gmail.com>
Cc: Stephen Rothwell <sfr@canb.auug.org.au>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
(cherry picked from commit 97113eb39fa7972722ff490b947d8af023e1f6a2)

[Kalesh Singh: Resolve some trivial conflicts in mm/mremap.c]

Bug: 151772539
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
Change-Id: I5b7235e982ea2efdc155018271fbaf2711fac4c1
2025-02-20 04:17:49 +02:00
Kalesh Singh
b254e3e87d
UPSTREAM: mm/mremap.c: fix extent calculation
When `next < old_addr`, `next - old_addr` arithmetic underflows causing
`extent` to be incorrect.

Make `extent` the smaller of `next - old_addr` or `old_end - old_addr`.

Link: https://lkml.kernel.org/r/20201219170433.2418867-1-kaleshsingh@google.com
Fixes: c49dd34018026 ("mm: speedup mremap on 1GB or larger regions")
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
Reported-by: Guenter Roeck <linux@roeck-us.net>
Tested-by: Guenter Roeck <linux@roeck-us.net>
Cc: Suren Baghdasaryan <surenb@google.com>
Cc: Minchan Kim <minchan@kernel.org>
Cc: Lokesh Gidra <lokeshgidra@google.com>
Cc: Helge Deller <deller@gmx.de>
Cc: Kalesh Singh <kaleshsingh@google.com>
Cc: "Kirill A. Shutemov" <kirill.shutemov@linux.intel.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
(cherry picked from commit e05986ee7a5814bec0e0075d813daca3d46e4a9e)

Bug: 151772539
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
Change-Id: Ibcbd39dfa16f8ebd1aeca469540b0ef43fb849c9
2025-02-20 04:17:48 +02:00
Kalesh Singh
4a832e8627
UPSTREAM: x86: mremap speedup - Enable HAVE_MOVE_PUD
HAVE_MOVE_PUD enables remapping pages at the PUD level if both the
source and destination addresses are PUD-aligned.

With HAVE_MOVE_PUD enabled it can be inferred that there is
approximately a 13x improvement in performance on x86.  (See data
below).

------- Test Results ---------

The following results were obtained using a 5.4 kernel, by remapping
a PUD-aligned, 1GB sized region to a PUD-aligned destination.
The results from 10 iterations of the test are given below:

Total mremap times for 1GB data on x86. All times are in nanoseconds.

  Control        HAVE_MOVE_PUD

  180394         15089
  235728         14056
  238931         25741
  187330         13838
  241742         14187
  177925         14778
  182758         14728
  160872         14418
  205813         15107
  245722         13998

  205721.5       15594    <-- Mean time in nanoseconds

A 1GB mremap completion time drops from ~205 microseconds
to ~15 microseconds on x86. (~13x speed up).

Link: https://lkml.kernel.org/r/20201014005320.2233162-6-kaleshsingh@google.com
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
Acked-by: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
Acked-by: Ingo Molnar <mingo@redhat.com>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: Borislav Petkov <bp@alien8.de>
Cc: H. Peter Anvin <hpa@zytor.com>
Cc: Aneesh Kumar K.V <aneesh.kumar@linux.ibm.com>
Cc: Anshuman Khandual <anshuman.khandual@arm.com>
Cc: Arnd Bergmann <arnd@arndb.de>
Cc: Brian Geffon <bgeffon@google.com>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: Christian Brauner <christian.brauner@ubuntu.com>
Cc: Dave Hansen <dave.hansen@intel.com>
Cc: Frederic Weisbecker <frederic@kernel.org>
Cc: Gavin Shan <gshan@redhat.com>
Cc: Hassan Naveed <hnaveed@wavecomp.com>
Cc: Jia He <justin.he@arm.com>
Cc: John Hubbard <jhubbard@nvidia.com>
Cc: Kees Cook <keescook@chromium.org>
Cc: Krzysztof Kozlowski <krzk@kernel.org>
Cc: Lokesh Gidra <lokeshgidra@google.com>
Cc: Mark Rutland <mark.rutland@arm.com>
Cc: Masahiro Yamada <masahiroy@kernel.org>
Cc: Masami Hiramatsu <mhiramat@kernel.org>
Cc: Mike Rapoport <rppt@kernel.org>
Cc: Mina Almasry <almasrymina@google.com>
Cc: Minchan Kim <minchan@google.com>
Cc: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: Ralph Campbell <rcampbell@nvidia.com>
Cc: Ram Pai <linuxram@us.ibm.com>
Cc: Sami Tolvanen <samitolvanen@google.com>
Cc: Sandipan Das <sandipan@linux.ibm.com>
Cc: SeongJae Park <sjpark@amazon.de>
Cc: Shuah Khan <shuah@kernel.org>
Cc: Steven Price <steven.price@arm.com>
Cc: Suren Baghdasaryan <surenb@google.com>
Cc: Will Deacon <will@kernel.org>
Cc: Zi Yan <ziy@nvidia.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
(cherry picked from commit be37c98d1134a8e068b52618c086dab6b34b9a2c)

Bug: 151772539
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
Change-Id: I7967951289885157ef3a487a6935abe3b860847f
2025-02-20 04:17:48 +02:00
Kalesh Singh
398cce17f8
UPSTREAM: arm64: mremap speedup - enable HAVE_MOVE_PUD
HAVE_MOVE_PUD enables remapping pages at the PUD level if both the source
and destination addresses are PUD-aligned.

With HAVE_MOVE_PUD enabled it can be inferred that there is approximately
a 19x improvement in performance on arm64.  (See data below).

------- Test Results ---------

The following results were obtained using a 5.4 kernel, by remapping a
PUD-aligned, 1GB sized region to a PUD-aligned destination.  The results
from 10 iterations of the test are given below:

Total mremap times for 1GB data on arm64. All times are in nanoseconds.

  Control          HAVE_MOVE_PUD

  1247761          74271
  1219896          46771
  1094792          59687
  1227760          48385
  1043698          76666
  1101771          50365
  1159896          52500
  1143594          75261
  1025833          61354
  1078125          48697

  1134312.6        59395.7    <-- Mean time in nanoseconds

A 1GB mremap completion time drops from ~1.1 milliseconds to ~59
microseconds on arm64.  (~19x speed up).

Link: https://lkml.kernel.org/r/20201014005320.2233162-5-kaleshsingh@google.com
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
Acked-by: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: Will Deacon <will@kernel.org>
Cc: Aneesh Kumar K.V <aneesh.kumar@linux.ibm.com>
Cc: Anshuman Khandual <anshuman.khandual@arm.com>
Cc: Arnd Bergmann <arnd@arndb.de>
Cc: Borislav Petkov <bp@alien8.de>
Cc: Brian Geffon <bgeffon@google.com>
Cc: Christian Brauner <christian.brauner@ubuntu.com>
Cc: Dave Hansen <dave.hansen@intel.com>
Cc: Frederic Weisbecker <frederic@kernel.org>
Cc: Gavin Shan <gshan@redhat.com>
Cc: Hassan Naveed <hnaveed@wavecomp.com>
Cc: "H. Peter Anvin" <hpa@zytor.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Jia He <justin.he@arm.com>
Cc: John Hubbard <jhubbard@nvidia.com>
Cc: Kees Cook <keescook@chromium.org>
Cc: Krzysztof Kozlowski <krzk@kernel.org>
Cc: Lokesh Gidra <lokeshgidra@google.com>
Cc: Mark Rutland <mark.rutland@arm.com>
Cc: Masahiro Yamada <masahiroy@kernel.org>
Cc: Masami Hiramatsu <mhiramat@kernel.org>
Cc: Mike Rapoport <rppt@kernel.org>
Cc: Mina Almasry <almasrymina@google.com>
Cc: Minchan Kim <minchan@google.com>
Cc: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: Ralph Campbell <rcampbell@nvidia.com>
Cc: Ram Pai <linuxram@us.ibm.com>
Cc: Sami Tolvanen <samitolvanen@google.com>
Cc: Sandipan Das <sandipan@linux.ibm.com>
Cc: SeongJae Park <sjpark@amazon.de>
Cc: Shuah Khan <shuah@kernel.org>
Cc: Steven Price <steven.price@arm.com>
Cc: Suren Baghdasaryan <surenb@google.com>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: Zi Yan <ziy@nvidia.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
(cherry picked from commit f5308c896d5de211245a9dc73b4e530f75185dd5)

Bug: 151772539
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
Change-Id: I30590b7375dde84fe345f4920a06f6a2c0b5aa31
2025-02-20 04:17:48 +02:00
Kalesh Singh
93d9ccf0cb
BACKPORT: mm: speedup mremap on 1GB or larger regions
Android needs to move large memory regions for garbage collection.  The GC
requires moving physical pages of multi-gigabyte heap using mremap.
During this move, the application threads have to be paused for
correctness.  It is critical to keep this pause as short as possible to
avoid jitters during user interaction.

Optimize mremap for >= 1GB-sized regions by moving at the PUD/PGD level if
the source and destination addresses are PUD-aligned.  For
CONFIG_PGTABLE_LEVELS == 3, moving at the PUD level in effect moves PGD
entries, since the PUD entry is “folded back” onto the PGD entry.  Add
HAVE_MOVE_PUD so that architectures where moving at the PUD level isn't
supported/tested can turn this off by not selecting the config.

Link: https://lkml.kernel.org/r/20201014005320.2233162-4-kaleshsingh@google.com
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
Acked-by: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
Reported-by: kernel test robot <lkp@intel.com>
Cc: Aneesh Kumar K.V <aneesh.kumar@linux.ibm.com>
Cc: Anshuman Khandual <anshuman.khandual@arm.com>
Cc: Arnd Bergmann <arnd@arndb.de>
Cc: Borislav Petkov <bp@alien8.de>
Cc: Brian Geffon <bgeffon@google.com>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: Christian Brauner <christian.brauner@ubuntu.com>
Cc: Dave Hansen <dave.hansen@intel.com>
Cc: Frederic Weisbecker <frederic@kernel.org>
Cc: Gavin Shan <gshan@redhat.com>
Cc: Hassan Naveed <hnaveed@wavecomp.com>
Cc: "H. Peter Anvin" <hpa@zytor.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Jia He <justin.he@arm.com>
Cc: John Hubbard <jhubbard@nvidia.com>
Cc: Kees Cook <keescook@chromium.org>
Cc: Krzysztof Kozlowski <krzk@kernel.org>
Cc: Lokesh Gidra <lokeshgidra@google.com>
Cc: Mark Rutland <mark.rutland@arm.com>
Cc: Masahiro Yamada <masahiroy@kernel.org>
Cc: Masami Hiramatsu <mhiramat@kernel.org>
Cc: Mike Rapoport <rppt@kernel.org>
Cc: Mina Almasry <almasrymina@google.com>
Cc: Minchan Kim <minchan@google.com>
Cc: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: Ralph Campbell <rcampbell@nvidia.com>
Cc: Ram Pai <linuxram@us.ibm.com>
Cc: Sami Tolvanen <samitolvanen@google.com>
Cc: Sandipan Das <sandipan@linux.ibm.com>
Cc: SeongJae Park <sjpark@amazon.de>
Cc: Shuah Khan <shuah@kernel.org>
Cc: Steven Price <steven.price@arm.com>
Cc: Suren Baghdasaryan <surenb@google.com>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: Will Deacon <will@kernel.org>
Cc: Zi Yan <ziy@nvidia.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
(cherry picked from commit c49dd340180260c6239e453263a9a244da9a7c85)

[Kalesh Singh: Resolve conflicts in mm/mremap.c]
Bug: 151772539
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
Change-Id: Ia9b065f5059044815fd05f22bad33c484b2b2b73
2025-02-20 04:17:48 +02:00
Kalesh Singh
ae867acb06
UPSTREAM: arm64: mremap speedup - Enable HAVE_MOVE_PMD
HAVE_MOVE_PMD enables remapping pages at the PMD level if both the
source and destination addresses are PMD-aligned.

HAVE_MOVE_PMD is already enabled on x86. The original patch [1] that
introduced this config did not enable it on arm64 at the time because
of performance issues with flushing the TLB on every PMD move. These
issues have since been addressed in more recent releases with
improvements to the arm64 TLB invalidation and core mmu_gather code as
Will Deacon mentioned in [2].

>From the data below, it can be inferred that there is approximately
8x improvement in performance when HAVE_MOVE_PMD is enabled on arm64.

--------- Test Results ----------

The following results were obtained on an arm64 device running a 5.4
kernel, by remapping a PMD-aligned, 1GB sized region to a PMD-aligned
destination. The results from 10 iterations of the test are given below.
All times are in nanoseconds.

Control    HAVE_MOVE_PMD

9220833    1247761
9002552    1219896
9254115    1094792
8725885    1227760
9308646    1043698
9001667    1101771
8793385    1159896
8774636    1143594
9553125    1025833
9374010    1078125

9100885.4  1134312.6    <-- Mean Time in nanoseconds

Total mremap time for a 1GB sized PMD-aligned region drops from
~9.1 milliseconds to ~1.1 milliseconds. (~8x speedup).

[1] https://lore.kernel.org/r/20181108181201.88826-3-joelaf@google.com
[2] https://www.mail-archive.com/linuxppc-dev@lists.ozlabs.org/msg140837.html

Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
Acked-by: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: Will Deacon <will@kernel.org>
Cc: Andrew Morton <akpm@linux-foundation.org>
Link: https://lore.kernel.org/r/20201014005320.2233162-3-kaleshsingh@google.com
Link: https://lore.kernel.org/kvmarm/20181029102840.GC13965@arm.com/
Signed-off-by: Will Deacon <will@kernel.org>
(cherry picked from commit 45544eee96065cf183fbb937fe1f45a172b06f4e)

Bug: 151772539
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
Change-Id: If0d97276cf8de1a5893e97444f2d961db05abea5
2025-02-20 04:17:47 +02:00
Michael Bestas
815e412767
Revert "UPSTREAM: mm/mremap: hold the rmap lock in write mode when moving page table entries."
This reverts commit 482efd771f.

Reason for revert: Will be replaced by android12-5.4 commit.

Change-Id: I9c36cdcd36b812274ba95ca48673750ff0d7e8e9
2025-02-20 04:17:47 +02:00
Lokesh Gidra
38e508079d
ANDROID: GKI: Enable CONFIG_USERFAULTFD
Patches for SELinux support and kernel page-fault restriction in
userfaultfd have been backported. See references below.
So from security perspective it should be safe to enable it in Android.

1) https://android-review.googlesource.com/c/kernel/common/+/1576486
2) https://android-review.googlesource.com/c/kernel/common/+/1576704
3) https://android-review.googlesource.com/c/kernel/common/+/1612597
4) https://android-review.googlesource.com/c/kernel/common/+/1574667

Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: Iac5143da76783de57dba229f5761aff9297c17ae
2025-02-20 04:17:47 +02:00
Lukas Bulwahn
3342e7b17d
UPSTREAM: fs: anon_inodes: rephrase to appropriate kernel-doc
Commit e7e832ce6fa7 ("fs: add LSM-supporting anon-inode interface") adds
more kerneldoc description, but also a few new warnings on
anon_inode_getfd_secure() due to missing parameter descriptions.

Rephrase to appropriate kernel-doc for anon_inode_getfd_secure().

Signed-off-by: Lukas Bulwahn <lukas.bulwahn@gmail.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
(cherry picked from commit 365982aba1f264dba26f0908700d62bfa046918c)
Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: Ie7837f21dfe28c03594ebc65fd293c00c57ba5c5
2025-02-20 04:17:46 +02:00
Daniel Colascione
5ab13036d8
UPSTREAM: userfaultfd: use secure anon inodes for userfaultfd
This change gives userfaultfd file descriptors a real security
context, allowing policy to act on them.

Signed-off-by: Daniel Colascione <dancol@google.com>
[LG: Remove owner inode from userfaultfd_ctx]
[LG: Use anon_inode_getfd_secure() in userfaultfd syscall]
[LG: Use inode of file in userfaultfd_read() in resolve_userfault_fork()]
Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Reviewed-by: Eric Biggers <ebiggers@google.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
(cherry picked from commit b537900f1598b67bcb8acac20da73c6e26ebbf99)
Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: Ifd3faca4058bd9e4c51767aa0246e1c53ad410d4
2025-02-20 04:17:46 +02:00
Daniel Colascione
43067ac3a3
BACKPORT: selinux: teach SELinux about anonymous inodes
This change uses the anon_inodes and LSM infrastructure introduced in
the previous patches to give SELinux the ability to control
anonymous-inode files that are created using the new
anon_inode_getfd_secure() function.

A SELinux policy author detects and controls these anonymous inodes by
adding a name-based type_transition rule that assigns a new security
type to anonymous-inode files created in some domain. The name used
for the name-based transition is the name associated with the
anonymous inode for file listings --- e.g., "[userfaultfd]" or
"[perf_event]".

Example:

type uffd_t;
type_transition sysadm_t sysadm_t : anon_inode uffd_t "[userfaultfd]";
allow sysadm_t uffd_t:anon_inode { create };

(The next patch in this series is necessary for making userfaultfd
support this new interface.  The example above is just
for exposition.)

Signed-off-by: Daniel Colascione <dancol@google.com>
Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
(cherry picked from commit 29cd6591ab6fee3125ea5c1bf350f5013bc615e1)

Conflicts:
    security/selinux/include/classmap.h
Compile errors:
    security/selinux/hooks.c

(1. Removed 'lockdown' mapping to be in sync with d9cb255af3a03d7b9cdb5ddbab10d9f5c68f97f2)
(2. Replace usage of selinux_initialized() with
selinux_state.initialized)

Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: I85df2757f121cd7072e91cf3b93c09657bd36b76
2025-02-20 04:17:46 +02:00
Daniel Colascione
8b618316b7
UPSTREAM: fs: add LSM-supporting anon-inode interface
This change adds a new function, anon_inode_getfd_secure, that creates
anonymous-node file with individual non-S_PRIVATE inode to which security
modules can apply policy. Existing callers continue using the original
singleton-inode kind of anonymous-inode file. We can transition anonymous
inode users to the new kind of anonymous inode in individual patches for
the sake of bisection and review.

The new function accepts an optional context_inode parameter that callers
can use to provide additional contextual information to security modules.
For example, in case of userfaultfd, the created inode is a 'logical child'
of the context_inode (userfaultfd inode of the parent process) in the sense
that it provides the security context required during creation of the child
process' userfaultfd inode.

Signed-off-by: Daniel Colascione <dancol@google.com>
[LG: Delete obsolete comments to alloc_anon_inode()]
[LG: Add context_inode description in comments to anon_inode_getfd_secure()]
[LG: Remove definition of anon_inode_getfile_secure() as there are no callers]
[LG: Make __anon_inode_getfile() static]
[LG: Use correct error cast in __anon_inode_getfile()]
[LG: Fix error handling in __anon_inode_getfile()]
Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Reviewed-by: Eric Biggers <ebiggers@google.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
(cherry picked from commit e7e832ce6fa769f800cd7eaebdb0459ad31e0416)
Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: I88f1821243c58454ce445fd50fd804221e0bfc67
2025-02-20 04:17:45 +02:00
Lokesh Gidra
4849cd6fa3
BACKPORT: security: add inode_init_security_anon() LSM hook
This change adds a new LSM hook, inode_init_security_anon(), that will
be used while creating secure anonymous inodes. The hook allows/denies
its creation and assigns a security context to the inode.

The new hook accepts an optional context_inode parameter that callers
can use to provide additional contextual information to security modules
for granting/denying permission to create an anon-inode of the same type.
This context_inode's security_context can also be used to initialize the
newly created anon-inode's security_context.

Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Reviewed-by: Eric Biggers <ebiggers@google.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
(cherry picked from commit 215b674b84dd052098fe6389e32a5afaff8b4d56)

Conflicts:
    include/linux/lsm_hook_defs.h

(1. Added LSM hook in lsm_hook.h and removd lsm_hook_defs.h as per
98e828a0650f348be85728c69875260cf78069e6, which is not merged here)

Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: I83fe318c891f034b4dd7f3f357cc74964b55ffc8
2025-02-20 04:17:45 +02:00
Lokesh Gidra
a04582fb0f
UPSTREAM: userfaultfd: add user-mode only option to unprivileged_userfaultfd sysctl knob
With this change, when the knob is set to 0, it allows unprivileged users
to call userfaultfd, like when it is set to 1, but with the restriction
that page faults from only user-mode can be handled.  In this mode, an
unprivileged user (without SYS_CAP_PTRACE capability) must pass
UFFD_USER_MODE_ONLY to userfaultd or the API will fail with EPERM.

This enables administrators to reduce the likelihood that an attacker with
access to userfaultfd can delay faulting kernel code to widen timing
windows for other exploits.

The default value of this knob is changed to 0.  This is required for
correct functioning of pipe mutex.  However, this will fail postcopy live
migration, which will be unnoticeable to the VM guests.  To avoid this,
set 'vm.userfault = 1' in /sys/sysctl.conf.

The main reason this change is desirable as in the short term is that the
Android userland will behave as with the sysctl set to zero.  So without
this commit, any Linux binary using userfaultfd to manage its memory would
behave differently if run within the Android userland.  For more details,
refer to Andrea's reply [1].

[1] https://lore.kernel.org/lkml/20200904033438.GI9411@redhat.com/

Link: https://lkml.kernel.org/r/20201120030411.2690816-3-lokeshgidra@google.com
Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Reviewed-by: Andrea Arcangeli <aarcange@redhat.com>
Cc: Kees Cook <keescook@chromium.org>
Cc: Jonathan Corbet <corbet@lwn.net>
Cc: Peter Xu <peterx@redhat.com>
Cc: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Cc: Alexander Viro <viro@zeniv.linux.org.uk>
Cc: Stephen Smalley <stephen.smalley.work@gmail.com>
Cc: Eric Biggers <ebiggers@kernel.org>
Cc: Daniel Colascione <dancol@dancol.org>
Cc: "Joel Fernandes (Google)" <joel@joelfernandes.org>
Cc: Kalesh Singh <kaleshsingh@google.com>
Cc: Suren Baghdasaryan <surenb@google.com>
Cc: Jeff Vander Stoep <jeffv@google.com>
Cc: <calin@google.com>
Cc: Mike Rapoport <rppt@linux.vnet.ibm.com>
Cc: Shaohua Li <shli@fb.com>
Cc: Jerome Glisse <jglisse@redhat.com>
Cc: Mauro Carvalho Chehab <mchehab+huawei@kernel.org>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Mel Gorman <mgorman@techsingularity.net>
Cc: Nitin Gupta <nigupta@nvidia.com>
Cc: Vlastimil Babka <vbabka@suse.cz>
Cc: Iurii Zaikin <yzaikin@google.com>
Cc: Luis Chamberlain <mcgrof@kernel.org>
Cc: Daniel Colascione <dancol@google.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
(cherry picked from commit d0d4730ac2e404a5b0da9a87ef38c73e51cb1664)
Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Bug: 160737021
Bug: 169683130
Change-Id: Ic46c0be47d6394d25bd3443ff524936fa568ab85
2025-02-20 04:17:45 +02:00
Lokesh Gidra
c73faa2aa2
BACKPORT: userfaultfd: add UFFD_USER_MODE_ONLY
Patch series "Control over userfaultfd kernel-fault handling", v6.

This patch series is split from [1].  The other series enables SELinux
support for userfaultfd file descriptors so that its creation and movement
can be controlled.

It has been demonstrated on various occasions that suspending kernel code
execution for an arbitrary amount of time at any access to userspace
memory (copy_from_user()/copy_to_user()/...) can be exploited to change
the intended behavior of the kernel.  For instance, handling page faults
in kernel-mode using userfaultfd has been exploited in [2, 3].  Likewise,
FUSE, which is similar to userfaultfd in this respect, has been exploited
in [4, 5] for similar outcome.

This small patch series adds a new flag to userfaultfd(2) that allows
callers to give up the ability to handle kernel-mode faults with the
resulting UFFD file object.  It then adds a 'user-mode only' option to the
unprivileged_userfaultfd sysctl knob to require unprivileged callers to
use this new flag.

The purpose of this new interface is to decrease the chance of an
unprivileged userfaultfd user taking advantage of userfaultfd to enhance
security vulnerabilities by lengthening the race window in kernel code.

[1] https://lore.kernel.org/lkml/20200211225547.235083-1-dancol@google.com/
[2] https://duasynt.com/blog/linux-kernel-heap-spray
[3] https://duasynt.com/blog/cve-2016-6187-heap-off-by-one-exploit
[4] https://googleprojectzero.blogspot.com/2016/06/exploiting-recursion-in-linux-kernel_20.html
[5] https://bugs.chromium.org/p/project-zero/issues/detail?id=808

This patch (of 2):

userfaultfd handles page faults from both user and kernel code.  Add a new
UFFD_USER_MODE_ONLY flag for userfaultfd(2) that makes the resulting
userfaultfd object refuse to handle faults from kernel mode, treating
these faults as if SIGBUS were always raised, causing the kernel code to
fail with EFAULT.

A future patch adds a knob allowing administrators to give some processes
the ability to create userfaultfd file objects only if they pass
UFFD_USER_MODE_ONLY, reducing the likelihood that these processes will
exploit userfaultfd's ability to delay kernel page faults to open timing
windows for future exploits.

Link: https://lkml.kernel.org/r/20201120030411.2690816-1-lokeshgidra@google.com
Link: https://lkml.kernel.org/r/20201120030411.2690816-2-lokeshgidra@google.com
Signed-off-by: Daniel Colascione <dancol@google.com>
Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Reviewed-by: Andrea Arcangeli <aarcange@redhat.com>
Cc: Alexander Viro <viro@zeniv.linux.org.uk>
Cc: <calin@google.com>
Cc: Daniel Colascione <dancol@dancol.org>
Cc: Eric Biggers <ebiggers@kernel.org>
Cc: Iurii Zaikin <yzaikin@google.com>
Cc: Jeff Vander Stoep <jeffv@google.com>
Cc: Jerome Glisse <jglisse@redhat.com>
Cc: "Joel Fernandes (Google)" <joel@joelfernandes.org>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Jonathan Corbet <corbet@lwn.net>
Cc: Kalesh Singh <kaleshsingh@google.com>
Cc: Kees Cook <keescook@chromium.org>
Cc: Luis Chamberlain <mcgrof@kernel.org>
Cc: Mauro Carvalho Chehab <mchehab+huawei@kernel.org>
Cc: Mel Gorman <mgorman@techsingularity.net>
Cc: Mike Rapoport <rppt@linux.vnet.ibm.com>
Cc: Nitin Gupta <nigupta@nvidia.com>
Cc: Peter Xu <peterx@redhat.com>
Cc: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Cc: Shaohua Li <shli@fb.com>
Cc: Stephen Smalley <stephen.smalley.work@gmail.com>
Cc: Suren Baghdasaryan <surenb@google.com>
Cc: Vlastimil Babka <vbabka@suse.cz>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
(cherry picked from commit 37cd0575b8510159992d279c530c05f872990b02)

Conflicts:
    include/uapi/linux/userfaultfd.h
(1. Removed uffdio_writeprotect struct part of 63b2d4174c4ad)

Bug: 160737021
Bug: 169683130
Signed-off-by: Lokesh Gidra <lokeshgidra@google.com>
Change-Id: Ic4cecce08956402f91f866ae08f1d4ec21d64289
2025-02-20 04:17:44 +02:00