summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorLorenzo Stoakes (ARM) <ljs@kernel.org>2026-09-17 17:22:49 +0100
committerAndrew Morton <akpm@linux-foundation.org>2026-09-29 23:13:22 -0700
commit70fd34de90fb69fd0f44ebfb72f0cb1e7fe539aa (patch)
treeb8ced0bf8e4f9f5b6d1d0f16e98ee2a748a62441
parent2154041376ddf8298d4832e145c982723ddf39d0 (diff)
downloadlinux-next-70fd34de90fb69fd0f44ebfb72f0cb1e7fe539aa.tar.gz
linux-next-70fd34de90fb69fd0f44ebfb72f0cb1e7fe539aa.zip
mm/vma: introduce and use vma[_flags]_can_gup()
GUP cannot be used for VMAs which set VMA_IO_BIT - because memory-mapped I/O must not be accessed on the user's behalf - or VMA_PFNMAP_BIT - because PFN maps have no folios which the kernel is permitted to access. Rather than keeping these checks open-coded, abstract them to vma_flags_can_gup() and its VMA wrapper vma_can_gup(). A number of other places make the same check to decide whether a mapping can be populated or accessed as GUP would, so update those too. While here, drop a reference to 'special' and replace a use of the deprecated VMA flags API in vma_dump_size(). No functional change intended. Link: https://lore.kernel.org/20260917-b4-mmap-prepare-vma-flag-sanify-v3-40-4583d8a23bca@kernel.org Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> Cc: Albert Ou <aou@eecs.berkeley.edu> Cc: Alexander Gordeev <agordeev@linux.ibm.com> Cc: Alexei Starovoitov <ast@kernel.org> Cc: Alistair Popple <apopple@nvidia.com> Cc: Al Viro <viro@zeniv.linux.org.uk> Cc: Andreas Larsson <andreas@gaisler.com> Cc: Andrii Nakryiko <andrii@kernel.org> Cc: "Aneesh Kumar K.V" <aneesh.kumar@kernel.org> Cc: Anup Patel <anup@brainfault.org> Cc: Arnaldo Carvalho de Melo <acme@kernel.org> Cc: Arnd Bergmann <arnd@arndb.de> Cc: Axel Rasmussen <axelrasmussen@google.com> Cc: Baolin Wang <baolin.wang@linux.alibaba.com> Cc: Baoquan He <baoquan.he@linux.dev> Cc: Barry Song <baohua@kernel.org> Cc: "Borislav Petkov (AMD)" <bp@alien8.de> Cc: Byungchul Park <byungchul@sk.com> Cc: Catalin Marinas <catalin.marinas@arm.com> Cc: Chengming Zhou <chengming.zhou@linux.dev> Cc: Chris Li <chrisl@kernel.org> Cc: Christian Borntraeger <borntraeger@linux.ibm.com> Cc: Christian Brauner <brauner@kernel.org> Cc: Claudio Imbrenda <imbrenda@linux.ibm.com> Cc: Dave Airlie <airlied@gmail.com> Cc: Dave Hansen <dave.hansen@linux.intel.com> Cc: David Hildenbrand <david@kernel.org> Cc: David S. Miller <davem@davemloft.net> Cc: Dennis Dalessandro <dennis.dalessandro@cornelisnetworks.com> Cc: Dev Jain <dev.jain@arm.com> Cc: Doug Gilbert <dgilbert@interlog.com> Cc: Eduard Zingerman <eddyz87@gmail.com> Cc: Emil Tsalapatis <emil@etsalapatis.com> Cc: Gerald Schaefer <gerald.schaefer@linux.ibm.com> Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Cc: Gregory Price <gourry@gourry.net> Cc: Harry Yoo <harry@kernel.org> Cc: Heiko Carstens <hca@linux.ibm.com> Cc: Helge Deller <deller@gmx.de> Cc: "Huang, Ying" <ying.huang@linux.alibaba.com> Cc: Ingo Molnar <mingo@redhat.com> Cc: James Bottomley <james.bottomley@HansenPartnership.com> Cc: Jan Kara <jack@suse.cz> Cc: Jann Horn <jannh@google.com> Cc: Janosch Frank <frankja@linux.ibm.com> Cc: Jaroslav Kysela <perex@perex.cz> Cc: Jason Gunthorpe <jgg@ziepe.ca> Cc: Jaya Kumar <jayalk@intworks.biz> Cc: Johannes Weiner <hannes@cmpxchg.org> Cc: John Hubbard <jhubbard@nvidia.com> Cc: Jonathan Corbet <corbet@lwn.net> Cc: Joshua Hahn <joshua.hahnjy@gmail.com> Cc: Juri Lelli <juri.lelli@redhat.com> Cc: Kairui Song <kasong@tencent.com> Cc: Kemeng Shi <shikemeng@huaweicloud.com> Cc: Kiryl Shutsemau <kas@kernel.org> Cc: Kumar Kartikeya Dwivedi <memxor@gmail.com> Cc: Lance Yang <lance.yang@linux.dev> Cc: Leon Romanovsky <leon@kernel.org> Cc: Liam R. Howlett <liam@infradead.org> Cc: Maarten Lankhorst <maarten.lankhorst@linux.intel.com> Cc: Madhavan Srinivasan <maddy@linux.ibm.com> Cc: Marc Rutland <mark.rutland@arm.com> Cc: Marc Zyngier <maz@kernel.org> Cc: "Masami Hiramatsu (Google)" <mhiramat@kernel.org> Cc: Matthew Brost <matthew.brost@intel.com> Cc: Matthew Wilcox (Oracle) <willy@infradead.org> Cc: Maxime Ripard <mripard@kernel.org> Cc: Michal Hocko <mhocko@kernel.org> Cc: Michal Hocko <mhocko@suse.com> Cc: Mike Rapoport <rppt@kernel.org> Cc: Miklos Szeredi <miklos@szeredi.hu> Cc: Muchun Song <muchun.song@linux.dev> Cc: Namhyung kim <namhyung@kernel.org> Cc: Nhat Pham <nphamcs@gmail.com> Cc: Nicholas Piggin <npiggin@gmail.com> Cc: Oleg Nesterov <oleg@redhat.com> Cc: Oscar Salvador <osalvador@suse.de> Cc: Palmer Dabbelt <palmer@dabbelt.com> Cc: Paul Moore <paul@paul-moore.com> Cc: Pedro Falcato <pfalcato@suse.de> Cc: Peter Xu <peterx@redhat.com> Cc: Peter Zijlstra <peterz@infradead.org> Cc: Rakie Kim <rakie.kim@sk.com> Cc: Rik van Riel <riel@surriel.com> Cc: Ryan Roberts <ryan.roberts@arm.com> Cc: Sebastian Reichel <sre@kernel.org> Cc: Shakeel Butt <shakeel.butt@linux.dev> Cc: Stephen Smalley <stephen.smalley.work@gmail.com> Cc: Suren Baghdasaryan <surenb@google.com> Cc: Takashi Iwai (SUSE) <tiwai@suse.de> Cc: Takashi Iwai <tiwai@suse.com> Cc: Thomas Zimemrmann <tzimmermann@suse.de> Cc: Vasily Gorbik <gor@linux.ibm.com> Cc: Vincent Guittot <vincent.guittot@linaro.org> Cc: Vlastimil Babka <vbabka@kernel.org> Cc: Wei Xu <weixugc@google.com> Cc: Will Deacon <will@kernel.org> Cc: Yuanchu Xie <yuanchu@google.com> Cc: Zi Yan <ziy@nvidia.com>
-rw-r--r--fs/coredump.c4
-rw-r--r--include/linux/mm.h29
-rw-r--r--mm/gup.c7
-rw-r--r--mm/hmm.c3
-rw-r--r--mm/memory.c14
-rw-r--r--mm/mempolicy.c3
6 files changed, 45 insertions, 15 deletions
diff --git a/fs/coredump.c b/fs/coredump.c
index 5820cb8ec88e..4d03826dd249 100644
--- a/fs/coredump.c
+++ b/fs/coredump.c
@@ -1616,8 +1616,8 @@ static unsigned long vma_dump_size(struct vm_area_struct *vma,
return 0;
}
- /* Do not dump I/O mapped devices or special mappings */
- if (vma->vm_flags & VM_IO)
+ /* Do not dump memory-mapped I/O, which may have side effects on read. */
+ if (vma_test(vma, VMA_IO_BIT))
return 0;
/* By default, dump shared memory if mapped from an anonymous file. */
diff --git a/include/linux/mm.h b/include/linux/mm.h
index 448384fdb594..4fd47cc796a6 100644
--- a/include/linux/mm.h
+++ b/include/linux/mm.h
@@ -1779,6 +1779,35 @@ static inline bool vma_is_persistent(const struct vm_area_struct *vma)
}
/**
+ * vma_flags_can_gup() - Do the specified VMA flags permit GUP to access the
+ * mapping's pages?
+ * @flags: The VMA flags to test.
+ *
+ * GUP cannot obtain pages from a PFN map (VMA_PFNMAP_BIT), which may have no
+ * struct pages behind it, and must not provide access to memory-mapped I/O
+ * (VMA_IO_BIT).
+ *
+ * Returns: true if GUP may access pages from the mapping, otherwise false.
+ */
+static inline bool vma_flags_can_gup(const vma_flags_t *flags)
+{
+ return !vma_flags_test_any(flags, VMA_IO_BIT, VMA_PFNMAP_BIT);
+}
+
+/**
+ * vma_can_gup() - May GUP obtain pages from @vma?
+ * @vma: The VMA to test.
+ *
+ * See vma_flags_can_gup() for details.
+ *
+ * Returns: true if GUP may access pages from the mapping, otherwise false.
+ */
+static inline bool vma_can_gup(const struct vm_area_struct *vma)
+{
+ return vma_flags_can_gup(&vma->flags);
+}
+
+/**
* vma_kernel_pagesize - Default page size granularity for this VMA.
* @vma: The user mapping.
*
diff --git a/mm/gup.c b/mm/gup.c
index f166acf794e3..8e9ef5ee7498 100644
--- a/mm/gup.c
+++ b/mm/gup.c
@@ -1204,7 +1204,7 @@ static int check_vma_flags(struct vm_area_struct *vma, unsigned long gup_flags)
int foreign = (gup_flags & FOLL_REMOTE);
bool vma_anon = vma_is_anonymous(vma);
- if (vm_flags & (VM_IO | VM_PFNMAP))
+ if (!vma_can_gup(vma))
return -EFAULT;
if ((gup_flags & FOLL_ANON) && !vma_anon)
@@ -1955,7 +1955,7 @@ int __mm_populate(unsigned long start, unsigned long len, int ignore_errors)
* range with the first VMA. Also, skip undesirable VMA types.
*/
nend = min(end, vma->vm_end);
- if (vma->vm_flags & (VM_IO | VM_PFNMAP))
+ if (!vma_can_gup(vma))
continue;
if (nstart < vma->vm_start)
nstart = vma->vm_start;
@@ -2017,8 +2017,7 @@ static long __get_user_pages_locked(struct mm_struct *mm, unsigned long start,
break;
/* protect what we can, including chardevs */
- if ((vma->vm_flags & (VM_IO | VM_PFNMAP)) ||
- !(vm_flags & vma->vm_flags))
+ if (!vma_can_gup(vma) || !(vm_flags & vma->vm_flags))
break;
if (pages) {
diff --git a/mm/hmm.c b/mm/hmm.c
index 2f1e98c6b644..e9569b82a1f0 100644
--- a/mm/hmm.c
+++ b/mm/hmm.c
@@ -595,8 +595,7 @@ static int hmm_vma_walk_test(unsigned long start, unsigned long end,
struct hmm_range *range = hmm_vma_walk->range;
struct vm_area_struct *vma = walk->vma;
- if (!(vma->vm_flags & (VM_IO | VM_PFNMAP)) &&
- vma->vm_flags & VM_READ)
+ if (vma_can_gup(vma) && vma_test(vma, VMA_READ_BIT))
return 0;
/*
diff --git a/mm/memory.c b/mm/memory.c
index 6c011979401a..338fce99e711 100644
--- a/mm/memory.c
+++ b/mm/memory.c
@@ -2417,11 +2417,11 @@ static bool vm_mixed_zeropage_allowed(struct vm_area_struct *vma)
* be problematic as soon as the zeropage gets replaced by a different
* page due to vma->vm_ops->pfn_mkwrite, because what's mapped would
* now differ to what GUP looked up. FSDAX is incompatible to
- * FOLL_LONGTERM and VM_IO is incompatible to GUP completely (see
- * check_vma_flags).
+ * FOLL_LONGTERM and memory-mapped I/O is incompatible to GUP completely
+ * (see vma_can_gup()).
*/
return vma->vm_ops && vma->vm_ops->pfn_mkwrite &&
- (vma_is_fsdax(vma) || vma->vm_flags & VM_IO);
+ (vma_is_fsdax(vma) || vma_test(vma, VMA_IO_BIT));
}
static int validate_page_before_insert(struct vm_area_struct *vma,
@@ -7116,7 +7116,8 @@ int follow_pfnmap_start(struct follow_pfnmap_args *args)
if (unlikely(address < vma->vm_start || address >= vma->vm_end))
goto out;
- if (!(vma->vm_flags & (VM_IO | VM_PFNMAP)))
+ /* Only mappings GUP cannot handle are followed here. */
+ if (vma_can_gup(vma))
goto out;
retry:
pgdp = pgd_offset(mm, address);
@@ -7316,8 +7317,9 @@ static int __access_remote_vm(struct mm_struct *mm, unsigned long addr,
}
/*
- * Check if this is a VM_IO | VM_PFNMAP VMA, which
- * we can access using slightly different code.
+ * GUP failed, perhaps because this is a mapping it
+ * cannot handle (see vma_can_gup()) - such mappings may
+ * provide access via vm_ops->access() instead.
*/
bytes = 0;
#ifdef CONFIG_HAVE_IOREMAP_PROT
diff --git a/mm/mempolicy.c b/mm/mempolicy.c
index 70298fded1b4..40744658483b 100644
--- a/mm/mempolicy.c
+++ b/mm/mempolicy.c
@@ -2008,7 +2008,8 @@ SYSCALL_DEFINE5(get_mempolicy, int __user *, policy,
bool vma_migratable(struct vm_area_struct *vma)
{
- if (vma->vm_flags & (VM_IO | VM_PFNMAP))
+ /* Pages which GUP cannot obtain cannot be migrated either. */
+ if (!vma_can_gup(vma))
return false;
/*