From: Greg Kroah-Hartman Date: Wed, 29 Jul 2026 14:58:23 +0000 (+0200) Subject: 6.6-stable patches X-Git-Tag: v6.1.179~3 X-Git-Url: http://git.ipfire.org/gitweb/?a=commitdiff_plain;h=32bdfb48fc784d33b691eecf837d10b40ac2a5e0;p=thirdparty%2Fkernel%2Fstable-queue.git 6.6-stable patches added patches: mm-refactor-mm_access-to-not-return-null.patch series --- diff --git a/queue-6.6/mm-refactor-mm_access-to-not-return-null.patch b/queue-6.6/mm-refactor-mm_access-to-not-return-null.patch new file mode 100644 index 0000000000..88bdb6857a --- /dev/null +++ b/queue-6.6/mm-refactor-mm_access-to-not-return-null.patch @@ -0,0 +1,132 @@ +From f99ae878d27857cf473a19743d6a59f22b22506e Mon Sep 17 00:00:00 2001 +From: Sasha Levin +Date: Tue, 24 Sep 2024 21:10:23 +0100 +Subject: mm: refactor mm_access() to not return NULL + +From: Lorenzo Stoakes + +[ Upstream commit cd3f8467afd470ccab0de2fbc7c76664af4a0bac ] + +mm_access() can return NULL if the mm is not found, but this is handled +the same as an error in all callers, with some translating this into an +-ESRCH error. + +Only proc_mem_open() returns NULL if no mm is found, however in this case +it is clearer and makes more sense to explicitly handle the error. +Additionally we take the opportunity to refactor the function to eliminate +unnecessary nesting. + +Simplify things by simply returning -ESRCH if no mm is found - this both +eliminates confusing use of the IS_ERR_OR_NULL() macro, and simplifies +callers which would return -ESRCH by returning this error directly. + +[lorenzo.stoakes@oracle.com: prefer neater pointer error comparison] + Link: https://lkml.kernel.org/r/2fae1834-749a-45e1-8594-5e5979cf7103@lucifer.local +Link: https://lkml.kernel.org/r/20240924201023.193135-1-lorenzo.stoakes@oracle.com +Signed-off-by: Lorenzo Stoakes +Suggested-by: Arnd Bergmann +Cc: Al Viro +Signed-off-by: Andrew Morton +Signed-off-by: Sasha Levin +--- + fs/proc/base.c | 26 ++++++++++++++------------ + kernel/fork.c | 5 +++-- + mm/madvise.c | 4 ++-- + mm/process_vm_access.c | 4 ++-- + 4 files changed, 21 insertions(+), 18 deletions(-) + +diff --git a/fs/proc/base.c b/fs/proc/base.c +index da5c436ea36fd6..881c2d4846d7ce 100644 +--- a/fs/proc/base.c ++++ b/fs/proc/base.c +@@ -811,19 +811,21 @@ static const struct file_operations proc_single_file_operations = { + struct mm_struct *proc_mem_open(struct inode *inode, unsigned int mode) + { + struct task_struct *task = get_proc_task(inode); +- struct mm_struct *mm = ERR_PTR(-ESRCH); ++ struct mm_struct *mm; + +- if (task) { +- mm = mm_access(task, mode | PTRACE_MODE_FSCREDS); +- put_task_struct(task); ++ if (!task) ++ return ERR_PTR(-ESRCH); + +- if (!IS_ERR_OR_NULL(mm)) { +- /* ensure this mm_struct can't be freed */ +- mmgrab(mm); +- /* but do not pin its memory */ +- mmput(mm); +- } +- } ++ mm = mm_access(task, mode | PTRACE_MODE_FSCREDS); ++ put_task_struct(task); ++ ++ if (IS_ERR(mm)) ++ return mm == ERR_PTR(-ESRCH) ? NULL : mm; ++ ++ /* ensure this mm_struct can't be freed */ ++ mmgrab(mm); ++ /* but do not pin its memory */ ++ mmput(mm); + + return mm; + } +@@ -2201,7 +2203,7 @@ static int map_files_d_revalidate(struct dentry *dentry, unsigned int flags) + goto out_notask; + + mm = mm_access(task, PTRACE_MODE_READ_FSCREDS); +- if (IS_ERR_OR_NULL(mm)) ++ if (IS_ERR(mm)) + goto out; + + if (!dname_to_vma_addr(dentry, &vm_start, &vm_end)) { +diff --git a/kernel/fork.c b/kernel/fork.c +index 724040ac589501..36854aaec482d6 100644 +--- a/kernel/fork.c ++++ b/kernel/fork.c +@@ -1570,8 +1570,9 @@ struct mm_struct *mm_access(struct task_struct *task, unsigned int mode) + return ERR_PTR(err); + + mm = get_task_mm(task); +- if (mm && mm != current->mm && +- !ptrace_may_access(task, mode)) { ++ if (!mm) { ++ mm = ERR_PTR(-ESRCH); ++ } else if (mm != current->mm && !ptrace_may_access(task, mode)) { + mmput(mm); + mm = ERR_PTR(-EACCES); + } +diff --git a/mm/madvise.c b/mm/madvise.c +index 73ea053c9003ab..0c30710bfd859f 100644 +--- a/mm/madvise.c ++++ b/mm/madvise.c +@@ -1492,8 +1492,8 @@ SYSCALL_DEFINE5(process_madvise, int, pidfd, const struct iovec __user *, vec, + + /* Require PTRACE_MODE_READ to avoid leaking ASLR metadata. */ + mm = mm_access(task, PTRACE_MODE_READ_FSCREDS); +- if (IS_ERR_OR_NULL(mm)) { +- ret = IS_ERR(mm) ? PTR_ERR(mm) : -ESRCH; ++ if (IS_ERR(mm)) { ++ ret = PTR_ERR(mm); + goto release_task; + } + +diff --git a/mm/process_vm_access.c b/mm/process_vm_access.c +index 0523edab03a6a5..5be8e91aa87209 100644 +--- a/mm/process_vm_access.c ++++ b/mm/process_vm_access.c +@@ -200,8 +200,8 @@ static ssize_t process_vm_rw_core(pid_t pid, struct iov_iter *iter, + } + + mm = mm_access(task, PTRACE_MODE_ATTACH_REALCREDS); +- if (!mm || IS_ERR(mm)) { +- rc = IS_ERR(mm) ? PTR_ERR(mm) : -ESRCH; ++ if (IS_ERR(mm)) { ++ rc = PTR_ERR(mm); + /* + * Explicitly map EACCES to EPERM as EPERM is a more + * appropriate error code for process_vw_readv/writev +-- +2.53.0 + diff --git a/queue-6.6/series b/queue-6.6/series new file mode 100644 index 0000000000..70d3db2ddc --- /dev/null +++ b/queue-6.6/series @@ -0,0 +1 @@ +mm-refactor-mm_access-to-not-return-null.patch