Lorenzo Stoakes
f11d31371b
mm: perform the mapping_map_writable() check after call_mmap()
...
[ Upstream commit 158978945f3173b8c1a88f8c5684a629736a57ac ]
In order for a F_SEAL_WRITE sealed memfd mapping to have an opportunity to
clear VM_MAYWRITE, we must be able to invoke the appropriate
vm_ops->mmap() handler to do so. We would otherwise fail the
mapping_map_writable() check before we had the opportunity to avoid it.
This patch moves this check after the call_mmap() invocation. Only memfd
actively denies write access causing a potential failure here (in
memfd_add_seals()), so there should be no impact on non-memfd cases.
This patch makes the userland-visible change that MAP_SHARED, PROT_READ
mappings of an F_SEAL_WRITE sealed memfd mapping will now succeed.
There is a delicate situation with cleanup paths assuming that a writable
mapping must have occurred in circumstances where it may now not have. In
order to ensure we do not accidentally mark a writable file unwritable by
mistake, we explicitly track whether we have a writable mapping and unmap
only if we do.
[lstoakes@gmail.com: do not set writable_file_mapping in inappropriate case]
Link: https://lkml.kernel.org/r/c9eb4cc6-7db4-4c2b-838d-43a0b319a4f0@lucifer.local
Link: https://bugzilla.kernel.org/show_bug.cgi?id=217238
Link: https://lkml.kernel.org/r/55e413d20678a1bb4c7cce889062bbb07b0df892.1697116581.git.lstoakes@gmail.com
Signed-off-by: Lorenzo Stoakes <lstoakes@gmail.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Cc: Alexander Viro <viro@zeniv.linux.org.uk>
Cc: Andy Lutomirski <luto@kernel.org>
Cc: Christian Brauner <brauner@kernel.org>
Cc: Hugh Dickins <hughd@google.com>
Cc: Matthew Wilcox (Oracle) <willy@infradead.org>
Cc: Mike Kravetz <mike.kravetz@oracle.com>
Cc: Muchun Song <muchun.song@linux.dev>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Cc: stable@vger.kernel.org
[isaacmanjarres: added error handling to cleanup the work done by the
mmap() callback and removed unused label.]
Signed-off-by: Isaac J. Manjarres <isaacmanjarres@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-08-28 16:21:36 +02:00
..
kasan
panic: Consolidate open-coded panic_on_warn checks
2023-02-06 07:52:50 +01:00
backing-dev.c
mm: bdi: initialize bdi_min_ratio when bdi is unregistered
2021-12-14 14:49:00 +01:00
balloon_compaction.c
cleancache.c
cma.c
mm/cma: use nth_page() in place of direct struct page manipulation
2023-11-28 16:50:19 +00:00
cma.h
cma_debug.c
compaction.c
mm, vmscan: prevent infinite loop for costly GFP_NOIO | __GFP_RETRY_MAYFAIL allocations
2024-04-13 12:51:34 +02:00
debug.c
debug_page_ref.c
dmapool.c
early_ioremap.c
fadvise.c
failslab.c
filemap.c
mm: drop the assumption that VM_SHARED always implies writable
2025-08-28 16:21:36 +02:00
frame_vector.c
v4l2: don't fall back to follow_pfn() if pin_user_pages_fast() fails
2022-12-08 11:23:06 +01:00
frontswap.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
gup.c
mm/hugetlb: fix races when looking up a CONT-PTE/PMD size hugetlb page
2022-12-19 12:24:15 +01:00
gup_benchmark.c
highmem.c
hmm.c
mm/hmm: move pmd_to_hmm_pfn_flags() to the respective #ifdeffery
2025-08-28 16:21:34 +02:00
huge_memory.c
mm/huge_memory: fix dereferencing invalid pmd migration entry
2025-06-27 11:02:58 +01:00
hugetlb.c
mm/hugetlb: fix races when looking up a CONT-PTE/PMD size hugetlb page
2022-12-19 12:24:15 +01:00
hugetlb_cgroup.c
hwpoison-inject.c
init-mm.c
internal.h
mm/thp: fix vma_address() if virtual address below file offset
2021-06-30 08:47:52 -04:00
interval_tree.c
Kconfig
mm/zsmalloc.c: drop ZSMALLOC_PGTABLE_MAPPING
2020-12-16 10:56:59 +01:00
Kconfig.debug
khugepaged.c
mm/khugepaged: fix collapse_pte_mapped_thp() to allow anon_vma
2023-01-24 07:18:01 +01:00
kmemleak-test.c
kmemleak.c
mm/kmemleak: avoid deadlock by moving pr_warn() outside kmemleak_lock
2025-08-28 16:21:34 +02:00
ksm.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
list_lru.c
mm: list_lru: set shrinker map bit when child nr_items is not zero
2020-12-11 13:23:31 +01:00
maccess.c
madvise.c
mm: drop the assumption that VM_SHARED always implies writable
2025-08-28 16:21:36 +02:00
Makefile
memblock.c
Revert "mm: Always release pages to the buddy allocator in memblock_free_late()."
2023-02-22 12:50:39 +01:00
memcontrol.c
memcg: always call cond_resched() after fn()
2025-06-04 14:32:35 +02:00
memfd.c
memfd: fix F_SEAL_WRITE after shmem huge page allocated
2022-03-08 19:07:49 +01:00
memory-failure.c
mm/memory-failure: fix an incorrect use of tail pages
2024-04-13 12:51:31 +02:00
memory.c
mm: avoid leaving partial pfn mappings around in error case
2024-11-17 14:58:53 +01:00
memory_hotplug.c
mm/memory_hotplug: use "unsigned long" for PFN in zone_for_pfn_range()
2021-09-22 12:26:43 +02:00
mempolicy.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
mempool.c
memremap.c
memtest.c
memtest: use {READ,WRITE}_ONCE in memory scanning
2024-04-13 12:51:27 +02:00
migrate.c
mm/migrate: set swap entry values of THP tail pages properly.
2024-04-13 12:51:31 +02:00
mincore.c
mlock.c
mm_init.c
mmap.c
mm: perform the mapping_map_writable() check after call_mmap()
2025-08-28 16:21:36 +02:00
mmu_context.c
mmu_gather.c
mm/khugepaged: fix GUP-fast interaction by sending IPI
2022-12-14 11:30:42 +01:00
mmu_notifier.c
mmzone.c
arm: remove CONFIG_ARCH_HAS_HOLES_MEMORYMODEL
2022-05-15 19:54:46 +02:00
mprotect.c
mremap.c
mm/mremap: hold the rmap lock in write mode when moving page table entries.
2022-08-25 11:17:20 +02:00
msync.c
nommu.c
oom_kill.c
memcg: fix soft lockup in the OOM process
2025-03-13 12:43:21 +01:00
page-writeback.c
mm: fix ratelimit_pages update error in dirty_ratio_handler()
2025-06-27 11:02:52 +01:00
page_alloc.c
mm/page_alloc.c: avoid infinite retries caused by cpuset race
2025-06-04 14:32:36 +02:00
page_counter.c
page_ext.c
page_idle.c
page_io.c
mm: fix unexpected zeroed page mapping with zram swap
2022-05-12 12:23:48 +02:00
page_isolation.c
page_owner.c
page_poison.c
page_vma_mapped.c
mm/thp: another PVMW_SYNC fix in page_vma_mapped_walk()
2021-06-30 08:47:55 -04:00
pagewalk.c
mm: pagewalk: Fix race between unmap and page walker
2022-10-15 07:54:36 +02:00
percpu-internal.h
percpu-km.c
percpu-stats.c
percpu-vm.c
percpu.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
pgtable-generic.c
mm/thp: fix __split_huge_pmd_locked() on shmem migration entry
2021-06-30 08:47:52 -04:00
process_vm_access.c
readahead.c
vfs: fix readahead(2) on block devices
2023-11-20 10:30:08 +01:00
rmap.c
mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse
2022-09-05 10:27:46 +02:00
rodata_test.c
shmem.c
mm: update memfd seal write check to include F_SEAL_WRITE
2025-08-28 16:21:36 +02:00
shuffle.c
shuffle.h
slab.c
slab.h
mm: kmemleak: slob: respect SLAB_NOLEAKTRACE flag
2021-11-26 10:47:21 +01:00
slab_common.c
mm: krealloc: Fix MTE false alarm in __do_krealloc
2024-11-08 16:20:54 +01:00
slob.c
slub.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
sparse-vmemmap.c
sparse.c
mm/sparse: add the missing sparse_buffer_fini() in error branch
2021-05-14 09:44:32 +02:00
swap.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
swap_cgroup.c
swap_slots.c
swap_state.c
swapfile.c
mm/swapfile: skip HugeTLB pages for unuse_vma
2024-11-08 16:20:47 +01:00
truncate.c
mm/thp: unmap_mapping_page() to fix THP truncate_cleanup_page()
2021-06-30 08:47:53 -04:00
usercopy.c
mm/usercopy: return 1 from hardened_usercopy __setup() handler
2022-04-15 14:18:30 +02:00
userfaultfd.c
userfaultfd: fix mmap_changing checking in mfill_atomic_hugetlb
2024-03-01 13:13:33 +01:00
util.c
mm: only enforce minimum stack gap size if it's sensible
2024-11-08 16:20:35 +01:00
vmacache.c
vmalloc.c
vmpressure.c
vmscan.c
mm: add missing release barrier on PGDAT_RECLAIM_LOCKED unlock
2025-05-02 07:39:16 +02:00
vmstat.c
arm: remove CONFIG_ARCH_HAS_HOLES_MEMORYMODEL
2022-05-15 19:54:46 +02:00
workingset.c
z3fold.c
mm/z3fold: fix potential memory leak in z3fold_destroy_pool()
2021-07-14 16:53:47 +02:00
zbud.c
zpool.c
zsmalloc.c
mm/zsmalloc: do not pass __GFP_MOVABLE if CONFIG_COMPACTION=n
2025-08-28 16:21:33 +02:00
zswap.c