[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20250924151101.2225820-2-patrick.roy@campus.lmu.de>
Date: Wed, 24 Sep 2025 16:10:41 +0100
From: Patrick Roy <patrick.roy@...pus.lmu.de>
To:
Cc: Patrick Roy <roypat@...zon.co.uk>,
pbonzini@...hat.com,
corbet@....net,
maz@...nel.org,
oliver.upton@...ux.dev,
joey.gouly@....com,
suzuki.poulose@....com,
yuzenghui@...wei.com,
catalin.marinas@....com,
will@...nel.org,
tglx@...utronix.de,
mingo@...hat.com,
bp@...en8.de,
dave.hansen@...ux.intel.com,
x86@...nel.org,
hpa@...or.com,
luto@...nel.org,
peterz@...radead.org,
willy@...radead.org,
akpm@...ux-foundation.org,
david@...hat.com,
lorenzo.stoakes@...cle.com,
Liam.Howlett@...cle.com,
vbabka@...e.cz,
rppt@...nel.org,
surenb@...gle.com,
mhocko@...e.com,
song@...nel.org,
jolsa@...nel.org,
ast@...nel.org,
daniel@...earbox.net,
andrii@...nel.org,
martin.lau@...ux.dev,
eddyz87@...il.com,
yonghong.song@...ux.dev,
john.fastabend@...il.com,
kpsingh@...nel.org,
sdf@...ichev.me,
haoluo@...gle.com,
jgg@...pe.ca,
jhubbard@...dia.com,
peterx@...hat.com,
jannh@...gle.com,
pfalcato@...e.de,
shuah@...nel.org,
seanjc@...gle.com,
kvm@...r.kernel.org,
linux-doc@...r.kernel.org,
linux-kernel@...r.kernel.org,
linux-arm-kernel@...ts.infradead.org,
kvmarm@...ts.linux.dev,
linux-fsdevel@...r.kernel.org,
linux-mm@...ck.org,
bpf@...r.kernel.org,
linux-kselftest@...r.kernel.org,
xmarcalx@...zon.co.uk,
kalyazin@...zon.co.uk,
jackabt@...zon.co.uk,
derekmn@...zon.co.uk,
tabba@...gle.com,
ackerleytng@...gle.com,
loongarch@...ts.linux.dev,
linux-riscv@...ts.infradead.org,
linux-s390@...r.kernel.org
Subject: [PATCH v7 01/12] arch: export set_direct_map_valid_noflush to KVM module
From: Patrick Roy <roypat@...zon.co.uk>
Use the new per-module export functionality to allow KVM (and only KVM)
access to set_direct_map_valid_noflush(). This allows guest_memfd to
remove its memory from the direct map, even if KVM is built as a module.
Direct map removal gives guest_memfd the same protection that
memfd_secret enjoys, such as hardening against Spectre-like attacks
through in-kernel gadgets.
Cc: linux-arm-kernel@...ts.infradead.org
Cc: loongarch@...ts.linux.dev
Cc: linux-riscv@...ts.infradead.org
Cc: linux-s390@...r.kernel.org
Reviewed-by: Fuad Tabba <tabba@...gle.com>
Signed-off-by: Patrick Roy <roypat@...zon.co.uk>
---
arch/arm64/mm/pageattr.c | 1 +
arch/loongarch/mm/pageattr.c | 1 +
arch/riscv/mm/pageattr.c | 1 +
arch/s390/mm/pageattr.c | 1 +
arch/x86/mm/pat/set_memory.c | 1 +
5 files changed, 5 insertions(+)
diff --git a/arch/arm64/mm/pageattr.c b/arch/arm64/mm/pageattr.c
index 04d4a8f676db..4f3cddfab9b0 100644
--- a/arch/arm64/mm/pageattr.c
+++ b/arch/arm64/mm/pageattr.c
@@ -291,6 +291,7 @@ int set_direct_map_valid_noflush(struct page *page, unsigned nr, bool valid)
return set_memory_valid(addr, nr, valid);
}
+EXPORT_SYMBOL_FOR_MODULES(set_direct_map_valid_noflush, "kvm");
#ifdef CONFIG_DEBUG_PAGEALLOC
/*
diff --git a/arch/loongarch/mm/pageattr.c b/arch/loongarch/mm/pageattr.c
index f5e910b68229..458f5ae6a89b 100644
--- a/arch/loongarch/mm/pageattr.c
+++ b/arch/loongarch/mm/pageattr.c
@@ -236,3 +236,4 @@ int set_direct_map_valid_noflush(struct page *page, unsigned nr, bool valid)
return __set_memory(addr, 1, set, clear);
}
+EXPORT_SYMBOL_FOR_MODULES(set_direct_map_valid_noflush, "kvm");
diff --git a/arch/riscv/mm/pageattr.c b/arch/riscv/mm/pageattr.c
index 3f76db3d2769..6db31040cd66 100644
--- a/arch/riscv/mm/pageattr.c
+++ b/arch/riscv/mm/pageattr.c
@@ -400,6 +400,7 @@ int set_direct_map_valid_noflush(struct page *page, unsigned nr, bool valid)
return __set_memory((unsigned long)page_address(page), nr, set, clear);
}
+EXPORT_SYMBOL_FOR_MODULES(set_direct_map_valid_noflush, "kvm");
#ifdef CONFIG_DEBUG_PAGEALLOC
static int debug_pagealloc_set_page(pte_t *pte, unsigned long addr, void *data)
diff --git a/arch/s390/mm/pageattr.c b/arch/s390/mm/pageattr.c
index 348e759840e7..8ffd9ef09bc6 100644
--- a/arch/s390/mm/pageattr.c
+++ b/arch/s390/mm/pageattr.c
@@ -413,6 +413,7 @@ int set_direct_map_valid_noflush(struct page *page, unsigned nr, bool valid)
return __set_memory((unsigned long)page_to_virt(page), nr, flags);
}
+EXPORT_SYMBOL_FOR_MODULES(set_direct_map_valid_noflush, "kvm");
bool kernel_page_present(struct page *page)
{
diff --git a/arch/x86/mm/pat/set_memory.c b/arch/x86/mm/pat/set_memory.c
index 8834c76f91c9..87e9c7d2dcdc 100644
--- a/arch/x86/mm/pat/set_memory.c
+++ b/arch/x86/mm/pat/set_memory.c
@@ -2661,6 +2661,7 @@ int set_direct_map_valid_noflush(struct page *page, unsigned nr, bool valid)
return __set_pages_np(page, nr);
}
+EXPORT_SYMBOL_FOR_MODULES(set_direct_map_valid_noflush, "kvm");
#ifdef CONFIG_DEBUG_PAGEALLOC
void __kernel_map_pages(struct page *page, int numpages, int enable)
--
2.51.0
Powered by blists - more mailing lists