Message ID | 20231212231706.2680890-6-jeffxu@chromium.org (mailing list archive) |
---|---|
State | New |
Headers | show
Return-Path: <owner-linux-mm@kvack.org> X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id BC940C4332F for <linux-mm@archiver.kernel.org>; Tue, 12 Dec 2023 23:17:27 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 199316B03DE; Tue, 12 Dec 2023 18:17:20 -0500 (EST) Received: by kanga.kvack.org (Postfix, from userid 40) id 0A8F96B03D8; Tue, 12 Dec 2023 18:17:20 -0500 (EST) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id E3E216B03E0; Tue, 12 Dec 2023 18:17:19 -0500 (EST) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0016.hostedemail.com [216.40.44.16]) by kanga.kvack.org (Postfix) with ESMTP id 9DD056B03D8 for <linux-mm@kvack.org>; Tue, 12 Dec 2023 18:17:18 -0500 (EST) Received: from smtpin20.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay03.hostedemail.com (Postfix) with ESMTP id 7C46FA0924 for <linux-mm@kvack.org>; Tue, 12 Dec 2023 23:17:18 +0000 (UTC) X-FDA: 81559729356.20.5439302 Received: from mail-pl1-f179.google.com (mail-pl1-f179.google.com [209.85.214.179]) by imf14.hostedemail.com (Postfix) with ESMTP id AE9F5100015 for <linux-mm@kvack.org>; Tue, 12 Dec 2023 23:17:16 +0000 (UTC) Authentication-Results: imf14.hostedemail.com; dkim=pass header.d=chromium.org header.s=google header.b=OPfGLWR4; spf=pass (imf14.hostedemail.com: domain of jeffxu@chromium.org designates 209.85.214.179 as permitted sender) smtp.mailfrom=jeffxu@chromium.org; dmarc=pass (policy=none) header.from=chromium.org ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1702423036; a=rsa-sha256; cv=none; b=4XjHo6yHx5KSR6doIT+yJIrvlqq8QSaWCJR8GccypwOvYWa+d6EQwlL29kg1KsXX+Gz3Bn Z5KT5QihmsLaToHh+M2QzplfPsAEY69yTyjQf0ztspFxyjAap6+Yi9qvyIO72sTCKuHOmp dy8/81wcOCg3PMmaZL1B/AGOrnb2UHo= ARC-Authentication-Results: i=1; imf14.hostedemail.com; dkim=pass header.d=chromium.org header.s=google header.b=OPfGLWR4; spf=pass (imf14.hostedemail.com: domain of jeffxu@chromium.org designates 209.85.214.179 as permitted sender) smtp.mailfrom=jeffxu@chromium.org; dmarc=pass (policy=none) header.from=chromium.org ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1702423036; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=nL+BTz2K9JmfgWW40zZKnYHQ0fFwxEyXyS5r4SraM1c=; b=XDjY71SZHIlvfs0/9F1nnYnG9TRwAwEQl0n3DGMCg0OpX/BC3AErSI06Y5Yn1gmcqRE6yo 5xiwibvEurIMFSLzIST7GYYxd+vIRem/gpLusyTkfjX2vV5gTUCKIesbt8NBX8Rn8x+WpG S47KbJkUiT/hqBWe3DaY0dPpUu7p+So= Received: by mail-pl1-f179.google.com with SMTP id d9443c01a7336-1d331f12f45so11259185ad.2 for <linux-mm@kvack.org>; Tue, 12 Dec 2023 15:17:16 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; t=1702423035; x=1703027835; darn=kvack.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=nL+BTz2K9JmfgWW40zZKnYHQ0fFwxEyXyS5r4SraM1c=; b=OPfGLWR4rRny0kx9Pmv3JxLCRjwQOKHF8PYTMA2QoaUwTZ7kglWJIIzejcqKTqOXoM bSsdCmftemqRaO6M+3ys214Ay3bCO6dih8Pr8mh5lVPd4N133vsTwT+4paeOR4qVScXj iLsaP7AZQ/cY3xsK24Fta8DVKcM3Frjmyuryw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1702423035; x=1703027835; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=nL+BTz2K9JmfgWW40zZKnYHQ0fFwxEyXyS5r4SraM1c=; b=OcPZugYaZ30XaEfj44T+ALAzJjjVgc8/tOvxo1jFNPXFnIBg9hjDqp/1LmMbUXbHot Tp2RikRjhzxTuVarLo2pgZNET89LnXmWQS2OoxmRIkMlFgO/mCD+hlEyhwOaKB5DIT/W uR0p1EkicAZKu7kMQga3eMSpu95lyBiasz1TtkuO1FnqfFi0ClTl+SW2/S+TJlD/zG9h dWTB0m9Xjz0yC8WEPhkq6eeLoZSvAFMQjQXNHfEykDKCNAHXjpnyisoJ2H5Sx4DAY1ra n34c74GvC/jO489UAKsiO5FAuMPlVdVtizUuaLaD/hXcvvObNMeadIlsrfS/9U++3uu4 zkXw== X-Gm-Message-State: AOJu0YweFy3oHWZn72mHOLPtBmpiWdJh6hw++WKh+vtp2tO2ZCCZNWAs NCAZd7ZJf5aDcw72LCRaJv2VZQ== X-Google-Smtp-Source: AGHT+IGFBfEL94OuzDJXPeAX8v2gc5zss9OFnE/JNle1zzc7v4J2psWLGmJv7VyTMrs5itl5BiG+DQ== X-Received: by 2002:a17:902:b702:b0:1d0:7d83:fdd9 with SMTP id d2-20020a170902b70200b001d07d83fdd9mr3543832pls.122.1702423035559; Tue, 12 Dec 2023 15:17:15 -0800 (PST) Received: from localhost (34.133.83.34.bc.googleusercontent.com. [34.83.133.34]) by smtp.gmail.com with UTF8SMTPSA id h2-20020a170902f54200b001cfc67d46efsm9074320plf.191.2023.12.12.15.17.15 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Tue, 12 Dec 2023 15:17:15 -0800 (PST) From: jeffxu@chromium.org To: akpm@linux-foundation.org, keescook@chromium.org, jannh@google.com, sroettger@google.com, willy@infradead.org, gregkh@linuxfoundation.org, torvalds@linux-foundation.org Cc: jeffxu@google.com, jorgelo@chromium.org, groeck@chromium.org, linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org, linux-mm@kvack.org, pedro.falcato@gmail.com, dave.hansen@intel.com, linux-hardening@vger.kernel.org, deraadt@openbsd.org, Jeff Xu <jeffxu@chromium.org> Subject: [RFC PATCH v3 05/11] mseal: add MM_SEAL_PROT_PKEY Date: Tue, 12 Dec 2023 23:16:59 +0000 Message-ID: <20231212231706.2680890-6-jeffxu@chromium.org> X-Mailer: git-send-email 2.43.0.472.g3155946c3a-goog In-Reply-To: <20231212231706.2680890-1-jeffxu@chromium.org> References: <20231212231706.2680890-1-jeffxu@chromium.org> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Rspamd-Server: rspam08 X-Rspamd-Queue-Id: AE9F5100015 X-Stat-Signature: 4z9khjap6wsuywpxyu5dnz7i93qb4g5m X-Rspam-User: X-HE-Tag: 1702423036-531428 X-HE-Meta: U2FsdGVkX1+2eOWaarbaBac8e9+FfNCBuo/btqkvtckVsikogwlsaRVhzbWiE3zI/19dAH5pFm0yH8O6VTmVrWwEMKDifUZ29wZUrXNQVIJb/aBHiTKkVPTjbKiDRg2TS+cpU65xT7YSW0s1pp6BTislJz3Gk6Y8ObVvcdnI3TBZM9HDYb2dpUmsmEP39HLSMc2CVBofphQehrcQ5uYw8yhggIhq/ZHHuD/Lr9pvs+uPQEuDNi4Q6knRofXaMA284yHR05fk/djmog3GYSnQ7Liq79RQM6f2X30ogOUk4bn9Sz8Z/i/rl8vNjJChhCpmBDJz4LHH+cGsoZz9lAhnMqUfNR2FZqTQPSREIneH/+bT7AGWzRTMPPPPbhmPXdPGwVGot86HjJUcbOFHRj/8ir/LGi9Gl/B4jGOFvuaFEecX2NIgbGqOGTSGy9qEUIc9T1rqWN6rI1KfX6ezEZgmXlLheG/4hdZ+EmK4jWmbZWzmXipupjk0YuCy+0iN/ra/ji606y9drZHT+nC7QbL5w4HLprYcHkKNIUfYsydh0ZI7K9JTDG/2VFGHpGOH3/gYIdXZJYuyEFUsKRrgLHsfdtWRRXJUl10C44UKdfq02Vec1cj1TeTBa6IAOkjOdTCOLvfhpgt3pJVXst3LykqluGW+vWl8VETnCASWstmSxDXebk62ZppvM4HhptqWuazv7vpEcYNlrEZKMCkpEYEjNzDOMrLpg3jez8yj8ibf9hLnm7eJE2FM4KK/gFcNkWib/9k9ShuhGM1RYch62NWROcZb72Kf+iKubNI+5ryAavHkW9zt/9d6//0gIPfmxpvcWwCHtAwFURE2qGzvet+p6+ayvFk+s6XyPA5gYgb2x7XkRahXuIs7g5vhBI9pBdpSmDwiou18d8NvYKmBxJ0DbJbefcDxe4x8Km2polMTfUxceHw7GrqJRH9vfgMx1SWUoI/WuE8mA83B+UljzXq SuI8tbxQ yiJdRL0wECNAmbtWmpSv14l3I0VkNnmcnx6NCjYcK9e5v1KyHomwHI4MRZb9zuGGZrOj/+/BxwJ4K6ZUWpFzcCiTG8kxvGYB4k6VRC1a2ANQ+2Zo02b5rx7KiATgixoFirBfRxL9uSLRAbWncxWMvnSkx//a/VZmzDVxPWki1Y+iSumyyf8dJnSPrTLn6V8ZLSvXPMk3Dyny7LXuFNAqT5ZW11m413pvaGPUNauRcMyKp0KMtkrYwmmStdoAQU5kqpWw4+nTdVTjv8tLhHFxGyRt4bZ5J8DyBGYLD9xH2r6RSQsPSyjHFzbb0iOVnXEkJ5RLOxloCJAwXrJSxavZXNDl18pgXETJM543PJC0zcCsmc3Hp/XpC8wwzOENGUmJ+5tXOY+XLIaL61PRREjUrD8f/bKbxfftohsRLbs1YW6GiDnKBz5vcrHTNInQqRAzbOp5ijAenb+furaBnkjux/EJusKOVzvlMb2Bsi0tXPt4P9y2fPnOpDKhCyhSAKC6lDw1Avkt86fu4Z/0= X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: <linux-mm.kvack.org> List-Subscribe: <mailto:majordomo@kvack.org> List-Unsubscribe: <mailto:majordomo@kvack.org> |
Series |
Introduce mseal()
|
expand
|
diff --git a/mm/mprotect.c b/mm/mprotect.c index b94fbb45d5c7..1527188b1e92 100644 --- a/mm/mprotect.c +++ b/mm/mprotect.c @@ -32,6 +32,7 @@ #include <linux/sched/sysctl.h> #include <linux/userfaultfd_k.h> #include <linux/memory-tiers.h> +#include <uapi/linux/mman.h> #include <asm/cacheflush.h> #include <asm/mmu_context.h> #include <asm/tlbflush.h> @@ -753,6 +754,15 @@ static int do_mprotect_pkey(unsigned long start, size_t len, } } + /* + * checking if PROT and PKEY is sealed. + * can_modify_mm assumes we have acquired the lock on MM. + */ + if (!can_modify_mm(current->mm, start, end, MM_SEAL_PROT_PKEY)) { + error = -EACCES; + goto out; + } + prev = vma_prev(&vmi); if (start > vma->vm_start) prev = vma;