Message ID | cover.1681176340.git.ackerleytng@google.com |
---|---|
Headers |
Return-Path: <linux-kernel-owner@vger.kernel.org> Delivered-To: ouuuleilei@gmail.com Received: by 2002:a59:b0ea:0:b0:3b6:4342:cba0 with SMTP id b10csp2266528vqo; Mon, 10 Apr 2023 18:38:50 -0700 (PDT) X-Google-Smtp-Source: AKy350YaFLTs6PVEjo40l4pHTNRc1JU+yLJs3ZS4nXwtXn3hTk/87nFpFO9kGacwKkVoT5a4WobW X-Received: by 2002:a17:902:ea07:b0:1a2:8f0d:766d with SMTP id s7-20020a170902ea0700b001a28f0d766dmr16815082plg.62.1681177130056; Mon, 10 Apr 2023 18:38:50 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1681177130; cv=none; d=google.com; s=arc-20160816; b=vDGpx/f8w75iVRAGAS3jTensdk8EVZW6llMiCaHrxzRjxXC+sZ2Hy5uRAmbG/2k2Qc GWAmdGubceEkctWBuZfj4f7kk6fix4aGsFnKI0CF/xWs23OoAgkb6JReWagnFj1iaqH8 Nx/3TLE19gEzJPHAFHvyPKVKEceAsnT0TapHt/3FRjDjFpFf1Vw0Zmy7w7K3TnF5R8fE hydA6urJGX/2bMCccY2DXna2tYBYNVPW2QqIlBAHqOL+W+37OGF3m/eDR8x9AAXR+ffs iM5TJKHArK2Niv95S8jCCOU3Y13f4dya0am+QnfhL5beJXhzkvynk+gWFgbo+zhAHhHW 1UnQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:cc:to:from:subject :message-id:mime-version:date:dkim-signature; bh=u35FXb24rxXsoG0aCEe4m7ddoHISWHWt5V4ebjSzsz4=; b=hxXUnoZQ8BSE3Ad4mopYW9s8bPs0/EuDgMkEcpYnBY6MzBwD1JiTDhMA+bGp9XWUvA TOBBfaQmsqItMVB0sIZFSTUlcDc/bMl3zCq7pJcsUD/8hkXLNcGQ+QhINkjoT/oNXCfz zDwsjO0RrP8wv4dyC3BlXE41yKpP7ZKlXmpV0k9UupXg2gEEx3laMoagQDptGTkyHff2 Sg8rnWPiUPd1pbREXKBUYeVpc6tY1QFxqbUlqeipBFUv/wg9kOcfKm3GINC1ozOw1Px5 lNLdeL/Wu2YU8Q8QxSZT1y25D9xLVVhB6dVoy2cXM1J50Dr4St/9I57mL410R+2KXhwh 5fDA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20210112 header.b=o2tU5lXa; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id ky8-20020a170902f98800b001a1faee77fesi6320896plb.302.2023.04.10.18.38.37; Mon, 10 Apr 2023 18:38:50 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20210112 header.b=o2tU5lXa; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S229971AbjDKB3l (ORCPT <rfc822;yuanzuo1009@gmail.com> + 99 others); Mon, 10 Apr 2023 21:29:41 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:35450 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229853AbjDKB3j (ORCPT <rfc822;linux-kernel@vger.kernel.org>); Mon, 10 Apr 2023 21:29:39 -0400 Received: from mail-yb1-xb4a.google.com (mail-yb1-xb4a.google.com [IPv6:2607:f8b0:4864:20::b4a]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 5D5F910FC for <linux-kernel@vger.kernel.org>; Mon, 10 Apr 2023 18:29:37 -0700 (PDT) Received: by mail-yb1-xb4a.google.com with SMTP id 206-20020a2504d7000000b00aeb1e3dbd1bso7101989ybe.9 for <linux-kernel@vger.kernel.org>; Mon, 10 Apr 2023 18:29:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20210112; t=1681176576; h=content-transfer-encoding:cc:to:from:subject:message-id :mime-version:date:from:to:cc:subject:date:message-id:reply-to; bh=u35FXb24rxXsoG0aCEe4m7ddoHISWHWt5V4ebjSzsz4=; b=o2tU5lXa5GgaaWuGTbd5bbvKtG3z3RSme5Cet24inDTS7nOrViJmL/iq51gozQkU0w fSc14g51lyAN7EZ2W2YdqFHXsQ6fhtJt3Ww8txhLuuaqZ7otipQp1kY2GirbtpvPd8tz qOFtr4vKJdNigycQsXduABdE6Mx/1K8btlYWEfUtLHRYy5H01FBzkck2ffnGkGbDsNsT ZbsMLLNEojFf+Yy7PynOmDitIMxxEZiFMr4qBeOETiKphih3BdTfUf4XHIT8Qtk4z1z+ d9h/ldEYXKqGvPbthLo+j90zJo0SUaeonPgvSapyQgn4pLlBWcLiJxpQI3QivbmMF29i 8afA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; t=1681176576; h=content-transfer-encoding:cc:to:from:subject:message-id :mime-version:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=u35FXb24rxXsoG0aCEe4m7ddoHISWHWt5V4ebjSzsz4=; b=ZVU1sr5CyDExg9OrBy5pS2RJmajAr2T9UmpIm14KEnMUjpOzrDWG8B/k8dxJmFQXI6 d4u1NDJSH7wS0u6F/wKj/KBlsAmUuVHu+uycMLdnXmiej/J6AFzOkv/bFzfS/8nrTux8 v+aR0uNRmrx+F26nBHfTXQnRCln3XOFn216zHYtLhmUv8AQuFdFRb6uFdyN7NUxJ/RVW t4ZYbEIdKbCOKXqLtI4c+eichOi0wscOqim6DzcBr1H1m4LDfLAHR/APDRXka8YZ6LTI Z2zuXOF19zy/QwEiYL05yNcySB/0JK+7+WkSweWrnAS0vfXsOfD0KIaCS4rWIWz+RbR4 0dEg== X-Gm-Message-State: AAQBX9dDsOzHH9+QR+6QpktonXovfn+5b8VPEVn+ITVTpS5T69v4MkNH kl2HZ5JV3mhKpGd1J7mLXMgAl4xiGn7UOd9kaw== X-Received: from ackerleytng-cloudtop.c.googlers.com ([fda3:e722:ac3:cc00:7f:e700:c0a8:1f5f]) (user=ackerleytng job=sendgmr) by 2002:a05:690c:1:b0:544:bbd2:74be with SMTP id bc1-20020a05690c000100b00544bbd274bemr8286702ywb.4.1681176576562; Mon, 10 Apr 2023 18:29:36 -0700 (PDT) Date: Tue, 11 Apr 2023 01:29:31 +0000 Mime-Version: 1.0 X-Mailer: git-send-email 2.40.0.577.gac1e443424-goog Message-ID: <cover.1681176340.git.ackerleytng@google.com> Subject: [RFC PATCH v4 0/2] Providing mount in memfd_restricted() syscall From: Ackerley Tng <ackerleytng@google.com> To: kvm@vger.kernel.org, linux-api@vger.kernel.org, linux-arch@vger.kernel.org, linux-doc@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, linux-mm@kvack.org, qemu-devel@nongnu.org Cc: aarcange@redhat.com, ak@linux.intel.com, akpm@linux-foundation.org, arnd@arndb.de, bfields@fieldses.org, bp@alien8.de, chao.p.peng@linux.intel.com, corbet@lwn.net, dave.hansen@intel.com, david@redhat.com, ddutile@redhat.com, dhildenb@redhat.com, hpa@zytor.com, hughd@google.com, jlayton@kernel.org, jmattson@google.com, joro@8bytes.org, jun.nakajima@intel.com, kirill.shutemov@linux.intel.com, linmiaohe@huawei.com, luto@kernel.org, mail@maciej.szmigiero.name, mhocko@suse.com, michael.roth@amd.com, mingo@redhat.com, naoya.horiguchi@nec.com, pbonzini@redhat.com, qperret@google.com, rppt@kernel.org, seanjc@google.com, shuah@kernel.org, steven.price@arm.com, tabba@google.com, tglx@linutronix.de, vannapurve@google.com, vbabka@suse.cz, vkuznets@redhat.com, wanpengli@tencent.com, wei.w.wang@intel.com, x86@kernel.org, yu.c.zhang@linux.intel.com, Ackerley Tng <ackerleytng@google.com> Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Spam-Status: No, score=-7.7 required=5.0 tests=DKIMWL_WL_MED,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_NONE, SPF_HELO_NONE,SPF_PASS,USER_IN_DEF_DKIM_WL autolearn=unavailable autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: <linux-kernel.vger.kernel.org> X-Mailing-List: linux-kernel@vger.kernel.org X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= X-GMAIL-THRID: =?utf-8?q?1762841990613558868?= X-GMAIL-MSGID: =?utf-8?q?1762841990613558868?= |
Series |
Providing mount in memfd_restricted() syscall
|
|
Message
Ackerley Tng
April 11, 2023, 1:29 a.m. UTC
Hello, This patchset builds upon the memfd_restricted() system call that was discussed in the 'KVM: mm: fd-based approach for supporting KVM' patch series, at https://lore.kernel.org/lkml/20221202061347.1070246-1-chao.p.peng@linux.intel.com/T/ The tree can be found at: https://github.com/googleprodkernel/linux-cc/tree/restrictedmem-provide-mount-fd-rfc-v4 In this patchset, a modification to the memfd_restricted() syscall is proposed, which allows userspace to provide a mount, on which the restrictedmem file will be created and returned from the memfd_restricted(). Allowing userspace to provide a mount allows userspace to control various memory binding policies via tmpfs mount options, such as Transparent HugePage memory allocation policy through 'huge=always/never' and NUMA memory allocation policy through 'mpol=local/bind:*'. Changes since RFCv3: + Added check to ensure that bind mounts must be bind mounts of the whole filesystem + Removed inappropriate check on fd’s permissions as Christian suggested + Renamed RMFD_USERMNT to MEMFD_RSTD_USERMNT as David suggested + Added selftest to check that bind mounts must be bind mounts of the whole filesystem Changes since RFCv2: + Tightened semantics to accept only fds of the root of a tmpfs mount, as Christian suggested + Added permissions check on the inode represented by the fd to guard against creation of restrictedmem files on read-only tmpfs filesystems or mounts + Renamed RMFD_TMPFILE to RMFD_USERMNT to better represent providing a userspace mount to create a restrictedmem file on + Updated selftests for tighter semantics and added selftests to check for permissions Changes since RFCv1: + Use fd to represent mount instead of path string, as Kirill suggested. I believe using fds makes this syscall interface more aligned with the other syscalls like fsopen(), fsconfig(), and fsmount() in terms of using and passing around fds + Remove unused variable char *orig_shmem_enabled from selftests Dependencies: + Chao’s work on UPM, at https://github.com/chao-p/linux/commits/privmem-v11.5 Links to earlier patch series: + RFC v3: https://lore.kernel.org/lkml/cover.1680306489.git.ackerleytng@google.com/T/ + RFC v2: https://lore.kernel.org/lkml/cover.1679428901.git.ackerleytng@google.com/T/ + RFC v1: https://lore.kernel.org/lkml/cover.1676507663.git.ackerleytng@google.com/T/ Ackerley Tng (2): mm: restrictedmem: Allow userspace to specify mount for memfd_restricted selftests: restrictedmem: Check memfd_restricted()'s handling of provided userspace mount include/linux/syscalls.h | 2 +- include/uapi/linux/restrictedmem.h | 8 + mm/restrictedmem.c | 73 ++- tools/testing/selftests/mm/.gitignore | 1 + tools/testing/selftests/mm/Makefile | 1 + .../selftests/mm/memfd_restricted_usermnt.c | 529 ++++++++++++++++++ tools/testing/selftests/mm/run_vmtests.sh | 3 + 7 files changed, 611 insertions(+), 6 deletions(-) create mode 100644 include/uapi/linux/restrictedmem.h create mode 100644 tools/testing/selftests/mm/memfd_restricted_usermnt.c -- 2.40.0.577.gac1e443424-goog