[PATCH v4 31/38] mm/uffd: use predicates for userfaultfd checks
flat view
HOTtoday
IN LINUX-NEXT: 4 (4M)
From: "Lorenzo Stoakes (ARM)" <ljs@kernel.org>
Date: 2026-10-03 16:44:08
Also in:
bpf, fuse-devel, kvm, kvm-riscv, kvmarm, linux-arch, linux-doc, linux-fsdevel, linux-mm, linux-perf-users, linux-rdma, linux-s390, linux-scsi, linux-sound, linux-trace-kernel, linux-usb, linuxppc-dev, lkml, selinux, sparclinux
Subsystem:
memory management, memory management - userfaultfd, the rest · Maintainers:
Andrew Morton, Mike Rapoport, Linus Torvalds
Rather than directly checking VMA flags, use the newly introduced
vma_is_mm_managed() and vma_is_mm_backed() helpers in userfaultfd
when assessing VMA suitability for userfaultfd and UFFDIO_MOVE.
Update vma_move_compatible() so it's expressed in terms of VMA
characteristics rather than arbitrary flags.
Additionally, update the use of the deprecated VMA flag API when checking
VMA_SHADOW_STACK_BIT.
A VMA_IO_BIT check is no longer required but that is fine as a hard
invariant has been established that mm-managed mappings may not set
VMA_IO_BIT so the check is now redundant.
Acked-by: Zi Yan <ziy@nvidia.com>
Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
---
mm/userfaultfd.c | 19 +++++++++++++------
1 file changed, 13 insertions(+), 6 deletions(-)
diff --git a/mm/userfaultfd.c b/mm/userfaultfd.c
index 949017e60608..f33b04700838 100644
--- a/mm/userfaultfd.c
+++ b/mm/userfaultfd.c
@@ -1754,10 +1754,16 @@ static inline bool move_splits_huge_pmd(unsigned long dst_addr,
}
#endif
-static inline bool vma_move_compatible(struct vm_area_struct *vma)
+static inline bool vma_move_compatible(const struct vm_area_struct *vma)
{
- return !(vma->vm_flags & (VM_PFNMAP | VM_IO | VM_HUGETLB |
- VM_MIXEDMAP | VM_SHADOW_STACK));
+ /* uffd is generally incompatible with mappings not managed by core mm. */
+ if (!vma_is_mm_managed(vma))
+ return false;
+ /* The shadow stack should not be written to by userspace. */
+ if (vma_test_single_mask(vma, VMA_SHADOW_STACK))
+ return false;
+ /* hugetlb mappings cannot be safely moved. */
+ return !vma_is_hugetlb(vma);
}
static int validate_move_areas(struct userfaultfd_ctx *ctx,@@ -2146,10 +2152,11 @@ static bool vma_can_userfault(struct vm_area_struct *vma, vm_flags_t vm_flags,
{
const struct vm_uffd_ops *ops = vma_uffd_ops(vma);
- if (vma->vm_flags & (VM_DROPPABLE | VM_SHADOW_STACK))
+ /* Only mm-backed memory can have its faults handled by userspace. */
+ if (!vma_is_mm_backed(vma))
return false;
-
- if (!vma_is_hugetlb(vma) && (vma->vm_flags & VM_SPECIAL))
+ /* The shadow stack should not be written to by userspace. */
+ if (vma_test_single_mask(vma, VMA_SHADOW_STACK))
return false;
vm_flags &= __VM_UFFD_FLAGS;
--
2.55.0