From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id C583ACDD0F4 for ; Tue, 22 Oct 2024 21:15:59 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 56B5D6B00B2; Tue, 22 Oct 2024 17:15:59 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 519EB6B00B3; Tue, 22 Oct 2024 17:15:59 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 393C96B00B4; Tue, 22 Oct 2024 17:15:59 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0012.hostedemail.com [216.40.44.12]) by kanga.kvack.org (Postfix) with ESMTP id 1A8646B00B2 for ; Tue, 22 Oct 2024 17:15:59 -0400 (EDT) Received: from smtpin29.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay05.hostedemail.com (Postfix) with ESMTP id 681BC40589 for ; Tue, 22 Oct 2024 21:15:49 +0000 (UTC) X-FDA: 82702495428.29.EC1919A Received: from mail-wm1-f50.google.com (mail-wm1-f50.google.com [209.85.128.50]) by imf13.hostedemail.com (Postfix) with ESMTP id D98C620020 for ; Tue, 22 Oct 2024 21:15:39 +0000 (UTC) Authentication-Results: imf13.hostedemail.com; dkim=pass header.d=google.com header.s=20230601 header.b=D2kqgQZr; spf=pass (imf13.hostedemail.com: domain of jannh@google.com designates 209.85.128.50 as permitted sender) smtp.mailfrom=jannh@google.com; dmarc=pass (policy=reject) header.from=google.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1729631555; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=MdUm3KNWQIjqYQ7AyrEbFp7iBDzg82iIjXFUakJE6os=; b=nHflHeTwCJCC3DHPc1NHRP3j7fG9W0Gk/fGLnMST30RcrbSY+HhaHBKBDTnFC97oIONS3W 0K4JSsoaKozaSjE8toFyMKXGhBQ0Wq9zrlKOe57E/WqeUqUF2Djt4ZCHOwFZHhepfx11ls Fw/P63j4aSxm3jdnM8tYIS7C09X+2tU= ARC-Authentication-Results: i=1; imf13.hostedemail.com; dkim=pass header.d=google.com header.s=20230601 header.b=D2kqgQZr; spf=pass (imf13.hostedemail.com: domain of jannh@google.com designates 209.85.128.50 as permitted sender) smtp.mailfrom=jannh@google.com; dmarc=pass (policy=reject) header.from=google.com ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1729631555; a=rsa-sha256; cv=none; b=RI0FiimtiT2NqtgC1fhKcu1ikoMvxiP/fttcPoscKJsReJHbeX5p75iWloAMbWq6+T1abx BkG6IY4BsWK4o3eShyc1Y9CBwsa4Grjh5MAaDy5RL0R3hunGP0ndGi5Ov0omOUoP7HA4Uu dW3H0tJtabc+/Js8isSXV1kojAR6VNo= Received: by mail-wm1-f50.google.com with SMTP id 5b1f17b1804b1-4315a8cff85so82875e9.0 for ; Tue, 22 Oct 2024 14:15:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1729631755; x=1730236555; darn=kvack.org; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=MdUm3KNWQIjqYQ7AyrEbFp7iBDzg82iIjXFUakJE6os=; b=D2kqgQZrMtTNdUPCM0gnHYdwYyRtGPFPNh3rx6Foxnwt6NjcvfCaHHPayzKfmZ+GMY mfA9+xzdyzvcjn0P4KPYCa25941kem+CaLuhXmVBgB3f8y6lrW0SThzdKr3mFjahyq5F 8s0C3dH7eQaT9BagSz8n1ngCMMlgc/uMJU1MCNthorabEs5mWDzw7Y9ivedgT7tljxPc DgqgPcAgAhsngohJvOKq9EXD/trLqXOuChWvvAsyjuJLq3pyWvvHQKDyuKIPGmyVnrsC 3joL/o99wztOb3Oe2ETgnjGPdgLSeBUGdadY5BihdQFasS/gVPYjETwp68w6p93OdQg2 0t/A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1729631755; x=1730236555; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=MdUm3KNWQIjqYQ7AyrEbFp7iBDzg82iIjXFUakJE6os=; b=cNXt/v3JGwzBdReiWWjZYNPWUcUXXs8vwTVigSjlMJV+un5x7U4f89g/VTg//mJ3kO qlsrDMyjdxIgkDe4Wkn+8WldLAmWzLPDztIDiA2zs4XQ7IfRiBrVgWtQJ5Ba+FlKMJ7H z8TpMc91MHY2GKTBDxDVD3drpNBuv4ef8SlmL/uCuEOLLXYbWSXSzVw7BgYPB+G44j9A O0w/3yIRDbcGUfMDMbYSNWrO1bKS0nG05kTYey69E1LZR9PIpvu113hNkIMWXphZ/cvA uTpAuGYsVRQvdIiVT3utVrPSMmbcV0/v4qynpU66SNgjhTmFspbeNCh5AmhOjiNxLxPQ krOw== X-Forwarded-Encrypted: i=1; AJvYcCX39haBUtDWrZJ9xKe+Vz5pFlIQR9C+cMRQq2V2Wfyf+tGfBgpd3T3C29u0gYCYtTU8z9WG+AnzqA==@kvack.org X-Gm-Message-State: AOJu0YxQpbsjC16baSqXvnM+5nRgkJdsljBFn3qbzaF7f0QqSGDRDJ9p 7o5H/VG8V/vmNgBgLWyAssDcGNVT1jtMxBg/lnXTzoyXcgZArEzsf3kKsr/uL8WXQFLXqnCxtl6 Rbu9Xg4aAQL4kjOr3fgK9CGcxx1U7ZEsbOoZ0 X-Google-Smtp-Source: AGHT+IGtrqV60ZkV3BGIQyPZYzwOEUmaX+5yYuXLJqZC8XpI8oT/zOjATJNvODovgWW0J2IbZP9DDr391T0f57IVmbg= X-Received: by 2002:a05:600c:4e12:b0:42b:8ff7:bee2 with SMTP id 5b1f17b1804b1-431851b8022mr138205e9.5.1729631755169; Tue, 22 Oct 2024 14:15:55 -0700 (PDT) MIME-Version: 1.0 References: In-Reply-To: From: Jann Horn Date: Tue, 22 Oct 2024 23:15:18 +0200 Message-ID: Subject: Re: [PATCH hotfix 6.12 3/8] mm: refactor map_deny_write_exec() To: Lorenzo Stoakes Cc: Andrew Morton , "Liam R . Howlett" , Vlastimil Babka , linux-kernel@vger.kernel.org, linux-mm@kvack.org, Linus Torvalds , Peter Xu Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Rspamd-Server: rspam06 X-Rspamd-Queue-Id: D98C620020 X-Stat-Signature: 6cnsbxw9djd7hxwgfrfgfs5toq5r3u4q X-Rspam-User: X-HE-Tag: 1729631739-111444 X-HE-Meta: U2FsdGVkX18oxCyrkukaQUKKVBJdkNZZOJQ2CdKo2mpsgVUqoQPSeLVsgMCfmc7tm11Z6WqKQlPYJkBSqePm6lPR+wsV062pk+r4/KzlCU3WuqS0Idz/dlAGKEO2m6lNp1TsjY8q2a5UkEpcXfYt3BGNBP1fKaUkQJj2IFhLwbSWbx3a+YoXY9/Lf6Yn6CCZ40N8PdcvJJSBXygcfEvGfItzaNUd2Ps0/6ePOCzcnbUShvv3YWHI+ilOG0YtT9pVz3N1jhR8mN7/K8mGsQoyHrWXAkpnKl/JbGifpesgcjUmcbTU+CcgKquIq8vf8r1/Q5zPDZMx76g341ob/FbZH/qGViZ/Ce2o6piNKoZ80JtoawWj1sMoR2h3gD+hR8aYGrTIU8RBarhTtiNV4CxWnf+3xCuGbWzCKMZr64szSuMld0x+9y4IXZNXB7UOPOaprTZF244aVshfEh/Me1Xhl7jrPlr4rwLl6t8A3sq3i4XAFgR9CSN3c/dl+sQbZXzy9GfUPnpMZiEeD0JyZYOoGPXbz30+rhU2A8zOsuwvOJTnwfVIT+R/g1Ygd8Ayn6CjtluQiE5K68wxwHIbBj0m1rIYCOnhlvp1+ftgO1crVUk23cK17c0g6j2sJjA+D8zTLxrS7WbM8i59JR5KWNQNg47d9wpx9vHqr7po3JwoeBr7ESbf+ZpMTavHp+si5OXXM6VdsxG0QoQCDOcBetHwkZn3ctERlaa7NVGlCsM3waA/AmY4pc1DbA3X3byrzIAfB6L06jlMcQncJ+/t00ArnwSUe1jmnaPln4RNcqw2jNedjrVOeKK3HiPwGXz8GKic2Zleo85yfj3P2EZ25WCaJSaSPQkV+Rk/5E6YU4j5eBJxfKXFNbSoRYaGKPWIE0jOfnT182qiEkI2m8sZTrcXnsnPJA1cs7cgPBYMr/h5MGdIoTEHp3SeEaJahEaCds8RP9wGOBlQ9Pz9s8l1AdP vMaO4ueU n2Xt2y2CgXkat+y6g0HA2QObsoitW3Yr9OoxvJFpalk3/GlVeogTHFnF+kIL4teKKC48ut2Pe+bFE2funoNSlXd7DuA9fN+i4nK0wRjM6hxXQANw4PFcFJItTzI0khkMe8jNxmzgcpdXi8SKvstBA+XEM0kBTRQLb6ciQyt2tDht+6/veqLHAcWW6viwk/yTlCrCb6D2HUmkNUlJ78ddYNgLXEjpgb3vHn3a1JHKC85p21pnyu0h/lbC797YkG2OdkBasxzNZdACNcAVsHwSdzt0fBDk7R1zNY/iiFpwXOa2Al4MfITiAYwrJwg== X-Bogosity: Ham, tests=bogofilter, spamicity=0.000001, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: On Tue, Oct 22, 2024 at 10:41=E2=80=AFPM Lorenzo Stoakes wrote: > Refactor the map_deny_write_exec() to not unnecessarily require a VMA > parameter but rather to accept VMA flags parameters, which allows us to u= se > this function early in mmap_region() in a subsequent commit. > > While we're here, we refactor the function to be more readable and add so= me > additional documentation. > > Reported-by: Jann Horn > Fixes: deb0f6562884 ("mm/mmap: undo ->mmap() when arch_validate_flags() f= ails") > Cc: stable > Signed-off-by: Lorenzo Stoakes Reviewed-by: Jann Horn [..] > -static inline bool map_deny_write_exec(struct vm_area_struct *vma, unsi= gned long vm_flags) > +static inline bool map_deny_write_exec(unsigned long old, unsigned long = new) > { > + /* If MDWE is disabled, we have nothing to deny. */ > if (!test_bit(MMF_HAS_MDWE, ¤t->mm->flags)) > return false; > > - if ((vm_flags & VM_EXEC) && (vm_flags & VM_WRITE)) > + /* If the new VMA is not executable, we have nothing to deny. */ > + if (!(new & VM_EXEC)) > + return false; > + > + /* Under MDWE we absolutely do not accept writably executable... = */ > + if (new & VM_WRITE) > return true; > > - if (!(vma->vm_flags & VM_EXEC) && (vm_flags & VM_EXEC)) > + /* ...nor newly executable VMAs. */ nit: maybe clarify this as "nor existing VMAs newly becoming executable" or something like that > + if (!(old & VM_EXEC)) > return true; > > return false;