From patchwork Thu Feb 16 00:41:16 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ackerley Tng X-Patchwork-Id: 13142345 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 69D17C64ED8 for ; Thu, 16 Feb 2023 00:41:38 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id A036D6B0073; Wed, 15 Feb 2023 19:41:37 -0500 (EST) Received: by kanga.kvack.org (Postfix, from userid 40) id 9B3746B0074; Wed, 15 Feb 2023 19:41:37 -0500 (EST) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 806BF6B0078; Wed, 15 Feb 2023 19:41:37 -0500 (EST) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0011.hostedemail.com [216.40.44.11]) by kanga.kvack.org (Postfix) with ESMTP id 6CA536B0073 for ; Wed, 15 Feb 2023 19:41:37 -0500 (EST) Received: from smtpin17.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay09.hostedemail.com (Postfix) with ESMTP id 3B8DE810D4 for ; Thu, 16 Feb 2023 00:41:37 +0000 (UTC) X-FDA: 80471301834.17.21880A9 Received: from mail-pg1-f202.google.com (mail-pg1-f202.google.com [209.85.215.202]) by imf13.hostedemail.com (Postfix) with ESMTP id 7E53020008 for ; Thu, 16 Feb 2023 00:41:35 +0000 (UTC) Authentication-Results: imf13.hostedemail.com; dkim=pass header.d=google.com header.s=20210112 header.b=cINlncli; dmarc=pass (policy=reject) header.from=google.com; spf=pass (imf13.hostedemail.com: domain of 3vnvtYwsKCJEvx5zC6zJE8119916z.x97638FI-775Gvx5.9C1@flex--ackerleytng.bounces.google.com designates 209.85.215.202 as permitted sender) smtp.mailfrom=3vnvtYwsKCJEvx5zC6zJE8119916z.x97638FI-775Gvx5.9C1@flex--ackerleytng.bounces.google.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1676508095; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=xFJSOOgmL/+0yEbfXc6ryYjQyU1/3hcKBEe5blgULG8=; b=thfNDPfejGzI/W1zbweU8gHqo5SscSKzlc910sTcQkcJEGmXgJ3tFUtayRV7fOz08Ph8u3 RZrpo4GVnU2nnSyCiAbwJ533u4YI986Z7wtCovr9oQ48Khthd5YWZK4fdZubTGYgcY86+m EHhetSuXXcT1nyq+tWK1ViY/PMi7e3k= ARC-Authentication-Results: i=1; imf13.hostedemail.com; dkim=pass header.d=google.com header.s=20210112 header.b=cINlncli; dmarc=pass (policy=reject) header.from=google.com; spf=pass (imf13.hostedemail.com: domain of 3vnvtYwsKCJEvx5zC6zJE8119916z.x97638FI-775Gvx5.9C1@flex--ackerleytng.bounces.google.com designates 209.85.215.202 as permitted sender) smtp.mailfrom=3vnvtYwsKCJEvx5zC6zJE8119916z.x97638FI-775Gvx5.9C1@flex--ackerleytng.bounces.google.com ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1676508095; a=rsa-sha256; cv=none; b=gMIuLY6kqCuu2wxdxrSrE0hwjYEd03Zdie3ZXgUF+D6V9Jvf5/Q2WDuyCbIoDnm0/3VUsv d/53lq5uMVYhUoP/gJ558y4mHQxa/5fDglEhJxSuwCkrKJ6JYXJKAT4ku0DwA/J2sdCnb6 QCoGN49/k+Nd9LP+19lemSMtB1KLpJs= Received: by mail-pg1-f202.google.com with SMTP id r126-20020a632b84000000b004393806c06eso160003pgr.4 for ; Wed, 15 Feb 2023 16:41:35 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20210112; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:from:to:cc:subject:date:message-id:reply-to; bh=xFJSOOgmL/+0yEbfXc6ryYjQyU1/3hcKBEe5blgULG8=; b=cINlnclit+qIhReE+Kd7SxHPyCpYVP+gHpr/lFZIYMsvtqPRMGMguGhZ+AmtA8dFRc Djw+CXsM0iFzwsMurICuBsTP1scpM+tCEPKY9d7bDxdD5YrTS/xTPWBYVcL8YG0s8lEx aufd0oD+1ETay2cKPepbBkhK2DjZdGGh9+sIqO+Vcbz+DiP+awtJagXFXVVgNQbNgyf4 dLNAd50vYgR4BhTu4f/JtATvZK4wp3PfCPiwj0DiDlPx+B7yfpqr/PRhgYcbi/fNtz/R 06dsNug5WVXeH5PztldqJP7IVZaS+IwS51Y4HyfEGNLXO726iXRISqbDJTUc9PcT6yga oL2A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=xFJSOOgmL/+0yEbfXc6ryYjQyU1/3hcKBEe5blgULG8=; b=jmcPmVhNJuGzOP1+CpWn6zjX74R4lgcHVKSjMDTeBUt/Xas9VzwjBbre7HgMBbMkci BxjETgnap49bJ+jqJhPyhvNiygGimyvjm7gLc6BhmQG7+coKrawdU2kY+vnlSENXSluY vWPolRyGUEOXMC2Py3aty1xrBTZ3TU06LwIkEd/7HF8X0GaNyL4lup69EXB2nmeIJt1e THnl1F4nWRPzWDeNSYqxBOM78bxZ/h+JFvVrJ7eh4LX6Wlrw5gZzv7rtPhPwsnaOpsoQ zM77CKSCowGq4oNYUXPMysWIYlVEHuikDBbSFo2eaDRZ5w9yYOiufe8Mh2JuIBuG1VTL d+yA== X-Gm-Message-State: AO0yUKXpO1ppWPo4388XsMl+fLFAwPf/B3OHR1gW1h6sORn842b/vls+ V1LYZ+MwZr/XO8rhEb9KjgMu/roRfRxLIYfHhg== X-Google-Smtp-Source: AK7set92BIhFB8ochMzD8hkP3RpOuPg2nKV+W2zZrkSmVY9pLWldFkNDjP8CHQ6b9e/hAQ6o5kRRc8iwgxT607mX7Q== X-Received: from ackerleytng-cloudtop.c.googlers.com ([fda3:e722:ac3:cc00:7f:e700:c0a8:1f5f]) (user=ackerleytng job=sendgmr) by 2002:a63:33ce:0:b0:4e7:79c5:d682 with SMTP id z197-20020a6333ce000000b004e779c5d682mr625417pgz.9.1676508094293; Wed, 15 Feb 2023 16:41:34 -0800 (PST) Date: Thu, 16 Feb 2023 00:41:16 +0000 In-Reply-To: Mime-Version: 1.0 References: X-Mailer: git-send-email 2.39.1.637.g21b0678d19-goog Message-ID: <176081a4817e492965a864a8bc8bacb7d2c05078.1676507663.git.ackerleytng@google.com> Subject: [RFC PATCH 1/2] mm: restrictedmem: Allow userspace to specify mount_path for memfd_restricted From: Ackerley Tng To: kvm@vger.kernel.org, linux-api@vger.kernel.org, linux-arch@vger.kernel.org, linux-doc@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, linux-mm@kvack.org, qemu-devel@nongnu.org Cc: chao.p.peng@linux.intel.com, aarcange@redhat.com, ak@linux.intel.com, akpm@linux-foundation.org, arnd@arndb.de, bfields@fieldses.org, bp@alien8.de, corbet@lwn.net, dave.hansen@intel.com, david@redhat.com, ddutile@redhat.com, dhildenb@redhat.com, hpa@zytor.com, hughd@google.com, jlayton@kernel.org, jmattson@google.com, joro@8bytes.org, jun.nakajima@intel.com, kirill.shutemov@linux.intel.com, linmiaohe@huawei.com, luto@kernel.org, mail@maciej.szmigiero.name, mhocko@suse.com, michael.roth@amd.com, mingo@redhat.com, naoya.horiguchi@nec.com, pbonzini@redhat.com, qperret@google.com, rppt@kernel.org, seanjc@google.com, shuah@kernel.org, steven.price@arm.com, tabba@google.com, tglx@linutronix.de, vannapurve@google.com, vbabka@suse.cz, vkuznets@redhat.com, wanpengli@tencent.com, wei.w.wang@intel.com, x86@kernel.org, yu.c.zhang@linux.intel.com, Ackerley Tng X-Rspamd-Queue-Id: 7E53020008 X-Rspamd-Server: rspam09 X-Rspam-User: X-Stat-Signature: u84316q49yotwdhcsj5mzwc99gy93g1x X-HE-Tag: 1676508095-398088 X-HE-Meta: U2FsdGVkX1/77JkVHk1JsmiEC12IhM/JKQ2yaf3a1FdPiOgfYGEPNQKxuVib6Rs78FzMNL/HZyrona5I2C26OUslVv/gDLhml1VChGxLcj10hmh8Vr/mUd4580ROgFCUXzlkvy3qdkF9F64iKPha9iTKwcg92gDR5BdbECTrDHAvQdrDFDCD4HaONhYhMbbDR/Z2Z6/G4JVMylAkf+SrTPRObhRRZFWpnL5SzuZKgMlxBRT1k6FvyA9+cGqB82Gmj0orjeSqN3NPcDbbbnWcyjKHREJlJalQaZ4srLNaKwB9pzu36JMYkKD+7AlePAtmLC0QM7WIwqYe+EC0Q1eV3y5EcGmFY+G4f7qHaoW7mbSCW8nkaR8rMo5yx8569cFjFO2Si0xdjqbqd91wIK4d/z6vYadH4WEWMKgJAYKbMMKgPCMSxoKnDCE1vD85AomvcgHjQM5dc8MX8DPqRZxGpz2Vpglc7p+PQnB7ZU79IKkk5n6giN9YMi7jFkgMYhbn9AHCyKy4NtpZPTS0TMHFA9wYh+6sna3d8DGX74pc5BTsZfEJDRVuZTRtR3l5vLehM+Vsf38cmKDpUudaGAj45Qh9XKClHMtQAaqZMxUNC5HUYPBfWYBT6jJmRqCrjcvsTfPskLjw4FBo1zulrLSOnrXBhFk8fsvocTPO/SA69e6WzIr6gCfmYDkXPqXmrbj9BBv5nOKAGilFdS5B1E9me3FoQXVQcy6nlBLeefhqJYmMesTask/9nKgIRRuij6yMIkGl5VUmJje9+HgXQrUTlq47/RJzKOEk+USs4U+URAIRFXY4j+Nhq+NPv90Tiq28GSCiodTuAUnC4G2+nA9p5MXs2t7/kdekis9fh+mXdOGGUOGBbXXS+K0cHlOvPLJYsdiHgE4eKUz68Vs37Xt6sdZh3zJJUBdXxzHLmJAjUewzXqRtCwoYI90BY4VKGWd3Urf4Z9EglDEHMaWHpBq NdXxBUvq RYsBQIZE8u0xw1MZY+C4EoP5gj0sVJjRShAo0rf/bHFlfCVScbpWxPK063Fizh+sSRs9IxfosTjlS4KiJu0qlpbvZCthhl/j7HKeS1S+/Rtk8N9zbSMK23rvo/krqlJ/k7I0AbJGMaLSnTnBJUGK1PkI6GlodpL47Ra/wUIM4SBAGGLLcvy1ImVfev4G8dpZn/cFNO53q1jg6f/VOOj4ccRLTWw4w/6tQT9kictZsoMfpKFtXakfP4vyPup23sQ0S8PhHcu+ebmks6TI/fL8bN59YovTi5k1jQ/+3GkaAqxlC99/j5IRT/gQ8ZUnw6TSgTzPqUAA6vj/EX/Q6juGpn4GbWnfLsY/ereOMIINV42MlmDwuvR/UtxMwhPV6M52Adv2Jby2x3f+6gKsFlkIcEjEGhquCckejXCVLoO1I5Uj1ZlW78Yjkve6E4C8lT+E4xlpKsIvessDJWS8YS4X4vOlTxJxWBC4nC+k4sjIT9UeSlB+PZ9Ew9ATj4X4LDeWHEwZw/1h4SIQwzTXWjisrmHdx/QyypBZN8RvIHHSTTuHvClf/OVi1sBde8a4QIpI48f3S6du+3OnugyjPenZImTiII8D/xe1CWvQGbq5QQAhwA6sRUiDF9bhebSyT6EWonsHyy+09mc2gJpMtM6IUNbeFZITVzRqI6/57pyMBditwIj8G7101lrEab/MyIG2dwvYNnHt/vAWsnP28/I4vnDwhmQ== X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: By default, the backing shmem file for a restrictedmem fd is created on shmem's kernel space mount. With this patch, an optional tmpfs mount can be specified, which will be used as the mountpoint for backing the shmem file associated with a restrictedmem fd. This change is modeled after how sys_open() can create an unnamed temporary file in a given directory with O_TMPFILE. This will help restrictedmem fds inherit the properties of the provided tmpfs mounts, for example, hugepage allocation hints, NUMA binding hints, etc. Signed-off-by: Ackerley Tng --- include/linux/syscalls.h | 2 +- include/uapi/linux/restrictedmem.h | 8 ++++ mm/restrictedmem.c | 63 +++++++++++++++++++++++++++--- 3 files changed, 66 insertions(+), 7 deletions(-) create mode 100644 include/uapi/linux/restrictedmem.h diff --git a/include/linux/syscalls.h b/include/linux/syscalls.h index f9e9e0c820c5..4b8efe9a8680 100644 --- a/include/linux/syscalls.h +++ b/include/linux/syscalls.h @@ -1056,7 +1056,7 @@ asmlinkage long sys_memfd_secret(unsigned int flags); asmlinkage long sys_set_mempolicy_home_node(unsigned long start, unsigned long len, unsigned long home_node, unsigned long flags); -asmlinkage long sys_memfd_restricted(unsigned int flags); +asmlinkage long sys_memfd_restricted(unsigned int flags, const char __user *mount_path); /* * Architecture-specific system calls diff --git a/include/uapi/linux/restrictedmem.h b/include/uapi/linux/restrictedmem.h new file mode 100644 index 000000000000..9f108dd1ac4c --- /dev/null +++ b/include/uapi/linux/restrictedmem.h @@ -0,0 +1,8 @@ +/* SPDX-License-Identifier: GPL-2.0 WITH Linux-syscall-note */ +#ifndef _UAPI_LINUX_RESTRICTEDMEM_H +#define _UAPI_LINUX_RESTRICTEDMEM_H + +/* flags for memfd_restricted */ +#define RMFD_TMPFILE 0x0001U + +#endif /* _UAPI_LINUX_RESTRICTEDMEM_H */ diff --git a/mm/restrictedmem.c b/mm/restrictedmem.c index c5d869d8c2d8..97f3e2159e8b 100644 --- a/mm/restrictedmem.c +++ b/mm/restrictedmem.c @@ -1,11 +1,12 @@ // SPDX-License-Identifier: GPL-2.0 -#include "linux/sbitmap.h" +#include #include #include #include #include #include #include +#include #include struct restrictedmem { @@ -189,19 +190,20 @@ static struct file *restrictedmem_file_create(struct file *memfd) return file; } -SYSCALL_DEFINE1(memfd_restricted, unsigned int, flags) +static int restrictedmem_create(struct vfsmount *mount) { struct file *file, *restricted_file; int fd, err; - if (flags) - return -EINVAL; - fd = get_unused_fd_flags(0); if (fd < 0) return fd; - file = shmem_file_setup("memfd:restrictedmem", 0, VM_NORESERVE); + if (mount) + file = shmem_file_setup_with_mnt(mount, "memfd:restrictedmem", 0, VM_NORESERVE); + else + file = shmem_file_setup("memfd:restrictedmem", 0, VM_NORESERVE); + if (IS_ERR(file)) { err = PTR_ERR(file); goto err_fd; @@ -223,6 +225,55 @@ SYSCALL_DEFINE1(memfd_restricted, unsigned int, flags) return err; } +static bool is_shmem_mount(struct vfsmount *mnt) +{ + return mnt->mnt_sb->s_magic == TMPFS_MAGIC; +} + +static int restrictedmem_create_from_path(const char __user *mount_path) +{ + int ret; + struct path path; + + ret = user_path_at(AT_FDCWD, mount_path, + LOOKUP_FOLLOW | LOOKUP_MOUNTPOINT, + &path); + if (ret) + return ret; + + if (!is_shmem_mount(path.mnt)) { + ret = -EINVAL; + goto out; + } + + ret = mnt_want_write(path.mnt); + if (unlikely(ret)) + goto out; + + ret = restrictedmem_create(path.mnt); + + mnt_drop_write(path.mnt); +out: + path_put(&path); + + return ret; +} + +SYSCALL_DEFINE2(memfd_restricted, unsigned int, flags, const char __user *, mount_path) +{ + if (flags & ~RMFD_TMPFILE) + return -EINVAL; + + if (flags == RMFD_TMPFILE) { + if (!mount_path) + return -EINVAL; + + return restrictedmem_create_from_path(mount_path); + } else { + return restrictedmem_create(NULL); + } +} + int restrictedmem_bind(struct file *file, pgoff_t start, pgoff_t end, struct restrictedmem_notifier *notifier, bool exclusive) {