diff options
| author | Dan Williams <dan.j.williams@intel.com> | 2017-11-29 16:10:21 -0800 | 
|---|---|---|
| committer | Linus Torvalds <torvalds@linux-foundation.org> | 2017-11-29 18:40:42 -0800 | 
| commit | 5c9d2d5c269c498aa9a546e8d2158a3e4142a1a2 (patch) | |
| tree | b8454bda3e8830a40159b89b2d8cdf3412d0ac25 /mm | |
| parent | c7da82b894e9eef60a04a15f065a8502341bf13b (diff) | |
| download | linux-5c9d2d5c269c498aa9a546e8d2158a3e4142a1a2.tar.bz2 | |
mm: replace pte_write with pte_access_permitted in fault + gup paths
The 'access_permitted' helper is used in the gup-fast path and goes
beyond the simple _PAGE_RW check to also:
 - validate that the mapping is writable from a protection keys
   standpoint
 - validate that the pte has _PAGE_USER set since all fault paths where
   pte_write is must be referencing user-memory.
Link: http://lkml.kernel.org/r/151043111604.2842.8051684481794973100.stgit@dwillia2-desk3.amr.corp.intel.com
Signed-off-by: Dan Williams <dan.j.williams@intel.com>
Cc: Dave Hansen <dave.hansen@intel.com>
Cc: Kirill A. Shutemov <kirill.shutemov@linux.intel.com>
Cc: "Jérôme Glisse" <jglisse@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Diffstat (limited to 'mm')
| -rw-r--r-- | mm/gup.c | 2 | ||||
| -rw-r--r-- | mm/hmm.c | 4 | ||||
| -rw-r--r-- | mm/memory.c | 4 | 
3 files changed, 5 insertions, 5 deletions
| @@ -66,7 +66,7 @@ static int follow_pfn_pte(struct vm_area_struct *vma, unsigned long address,   */  static inline bool can_follow_write_pte(pte_t pte, unsigned int flags)  { -	return pte_write(pte) || +	return pte_access_permitted(pte, WRITE) ||  		((flags & FOLL_FORCE) && (flags & FOLL_COW) && pte_dirty(pte));  } @@ -456,11 +456,11 @@ again:  			continue;  		} -		if (write_fault && !pte_write(pte)) +		if (!pte_access_permitted(pte, write_fault))  			goto fault;  		pfns[i] = hmm_pfn_t_from_pfn(pte_pfn(pte)) | flag; -		pfns[i] |= pte_write(pte) ? HMM_PFN_WRITE : 0; +		pfns[i] |= pte_access_permitted(pte, WRITE) ? HMM_PFN_WRITE : 0;  		continue;  fault: diff --git a/mm/memory.c b/mm/memory.c index 416e451a707e..4f07acd1695f 100644 --- a/mm/memory.c +++ b/mm/memory.c @@ -3948,7 +3948,7 @@ static int handle_pte_fault(struct vm_fault *vmf)  	if (unlikely(!pte_same(*vmf->pte, entry)))  		goto unlock;  	if (vmf->flags & FAULT_FLAG_WRITE) { -		if (!pte_write(entry)) +		if (!pte_access_permitted(entry, WRITE))  			return do_wp_page(vmf);  		entry = pte_mkdirty(entry);  	} @@ -4336,7 +4336,7 @@ int follow_phys(struct vm_area_struct *vma,  		goto out;  	pte = *ptep; -	if ((flags & FOLL_WRITE) && !pte_write(pte)) +	if (!pte_access_permitted(pte, flags & FOLL_WRITE))  		goto unlock;  	*prot = pgprot_val(pte_pgprot(pte)); |