]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
6.12-stable patches master
authorGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 29 Jul 2026 14:58:34 +0000 (16:58 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 29 Jul 2026 14:58:34 +0000 (16:58 +0200)
added patches:
mm-refactor-mm_access-to-not-return-null.patch
series

queue-6.12/mm-refactor-mm_access-to-not-return-null.patch [new file with mode: 0644]
queue-6.12/series [new file with mode: 0644]

diff --git a/queue-6.12/mm-refactor-mm_access-to-not-return-null.patch b/queue-6.12/mm-refactor-mm_access-to-not-return-null.patch
new file mode 100644 (file)
index 0000000..aa7bee6
--- /dev/null
@@ -0,0 +1,132 @@
+From 7e51752907c9bd2ed0203b7bec215834b16c11ce Mon Sep 17 00:00:00 2001
+From: Sasha Levin <sashal@kernel.org>
+Date: Tue, 24 Sep 2024 21:10:23 +0100
+Subject: mm: refactor mm_access() to not return NULL
+
+From: Lorenzo Stoakes <lorenzo.stoakes@oracle.com>
+
+[ Upstream commit cd3f8467afd470ccab0de2fbc7c76664af4a0bac ]
+
+mm_access() can return NULL if the mm is not found, but this is handled
+the same as an error in all callers, with some translating this into an
+-ESRCH error.
+
+Only proc_mem_open() returns NULL if no mm is found, however in this case
+it is clearer and makes more sense to explicitly handle the error.
+Additionally we take the opportunity to refactor the function to eliminate
+unnecessary nesting.
+
+Simplify things by simply returning -ESRCH if no mm is found - this both
+eliminates confusing use of the IS_ERR_OR_NULL() macro, and simplifies
+callers which would return -ESRCH by returning this error directly.
+
+[lorenzo.stoakes@oracle.com: prefer neater pointer error comparison]
+  Link: https://lkml.kernel.org/r/2fae1834-749a-45e1-8594-5e5979cf7103@lucifer.local
+Link: https://lkml.kernel.org/r/20240924201023.193135-1-lorenzo.stoakes@oracle.com
+Signed-off-by: Lorenzo Stoakes <lorenzo.stoakes@oracle.com>
+Suggested-by: Arnd Bergmann <arnd@arndb.de>
+Cc: Al Viro <viro@zeniv.linux.org.uk>
+Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
+Signed-off-by: Sasha Levin <sashal@kernel.org>
+---
+ fs/proc/base.c         | 26 ++++++++++++++------------
+ kernel/fork.c          |  5 +++--
+ mm/madvise.c           |  4 ++--
+ mm/process_vm_access.c |  4 ++--
+ 4 files changed, 21 insertions(+), 18 deletions(-)
+
+diff --git a/fs/proc/base.c b/fs/proc/base.c
+index 9f032236849783..427fb5abb07c7c 100644
+--- a/fs/proc/base.c
++++ b/fs/proc/base.c
+@@ -817,19 +817,21 @@ static const struct file_operations proc_single_file_operations = {
+ struct mm_struct *proc_mem_open(struct inode *inode, unsigned int mode)
+ {
+       struct task_struct *task = get_proc_task(inode);
+-      struct mm_struct *mm = ERR_PTR(-ESRCH);
++      struct mm_struct *mm;
+-      if (task) {
+-              mm = mm_access(task, mode | PTRACE_MODE_FSCREDS);
+-              put_task_struct(task);
++      if (!task)
++              return ERR_PTR(-ESRCH);
+-              if (!IS_ERR_OR_NULL(mm)) {
+-                      /* ensure this mm_struct can't be freed */
+-                      mmgrab(mm);
+-                      /* but do not pin its memory */
+-                      mmput(mm);
+-              }
+-      }
++      mm = mm_access(task, mode | PTRACE_MODE_FSCREDS);
++      put_task_struct(task);
++
++      if (IS_ERR(mm))
++              return mm == ERR_PTR(-ESRCH) ? NULL : mm;
++
++      /* ensure this mm_struct can't be freed */
++      mmgrab(mm);
++      /* but do not pin its memory */
++      mmput(mm);
+       return mm;
+ }
+@@ -2199,7 +2201,7 @@ static int map_files_d_revalidate(struct dentry *dentry, unsigned int flags)
+               goto out_notask;
+       mm = mm_access(task, PTRACE_MODE_READ_FSCREDS);
+-      if (IS_ERR_OR_NULL(mm))
++      if (IS_ERR(mm))
+               goto out;
+       if (!dname_to_vma_addr(dentry, &vm_start, &vm_end)) {
+diff --git a/kernel/fork.c b/kernel/fork.c
+index 6191f1f8bde86d..2b7577edffa2da 100644
+--- a/kernel/fork.c
++++ b/kernel/fork.c
+@@ -1580,8 +1580,9 @@ struct mm_struct *mm_access(struct task_struct *task, unsigned int mode)
+               return ERR_PTR(err);
+       mm = get_task_mm(task);
+-      if (mm && mm != current->mm &&
+-                      !ptrace_may_access(task, mode)) {
++      if (!mm) {
++              mm = ERR_PTR(-ESRCH);
++      } else if (mm != current->mm && !ptrace_may_access(task, mode)) {
+               mmput(mm);
+               mm = ERR_PTR(-EACCES);
+       }
+diff --git a/mm/madvise.c b/mm/madvise.c
+index 4a3b609a33e60d..d2b315993a1c01 100644
+--- a/mm/madvise.c
++++ b/mm/madvise.c
+@@ -1521,8 +1521,8 @@ SYSCALL_DEFINE5(process_madvise, int, pidfd, const struct iovec __user *, vec,
+       /* Require PTRACE_MODE_READ to avoid leaking ASLR metadata. */
+       mm = mm_access(task, PTRACE_MODE_READ_FSCREDS);
+-      if (IS_ERR_OR_NULL(mm)) {
+-              ret = IS_ERR(mm) ? PTR_ERR(mm) : -ESRCH;
++      if (IS_ERR(mm)) {
++              ret = PTR_ERR(mm);
+               goto release_task;
+       }
+diff --git a/mm/process_vm_access.c b/mm/process_vm_access.c
+index b308e96cd05a28..656d3e88755b6f 100644
+--- a/mm/process_vm_access.c
++++ b/mm/process_vm_access.c
+@@ -201,8 +201,8 @@ static ssize_t process_vm_rw_core(pid_t pid, struct iov_iter *iter,
+       }
+       mm = mm_access(task, PTRACE_MODE_ATTACH_REALCREDS);
+-      if (!mm || IS_ERR(mm)) {
+-              rc = IS_ERR(mm) ? PTR_ERR(mm) : -ESRCH;
++      if (IS_ERR(mm)) {
++              rc = PTR_ERR(mm);
+               /*
+                * Explicitly map EACCES to EPERM as EPERM is a more
+                * appropriate error code for process_vw_readv/writev
+-- 
+2.53.0
+
diff --git a/queue-6.12/series b/queue-6.12/series
new file mode 100644 (file)
index 0000000..70d3db2
--- /dev/null
@@ -0,0 +1 @@
+mm-refactor-mm_access-to-not-return-null.patch