From nobody Sun Feb 8 17:36:57 2026 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 48693C83F3E for ; Thu, 31 Aug 2023 20:37:31 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1347431AbjHaUhc (ORCPT ); Thu, 31 Aug 2023 16:37:32 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:38502 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1347432AbjHaUh3 (ORCPT ); Thu, 31 Aug 2023 16:37:29 -0400 Received: from mail-yb1-xb4a.google.com (mail-yb1-xb4a.google.com [IPv6:2607:f8b0:4864:20::b4a]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id ACCEB10C0 for ; Thu, 31 Aug 2023 13:37:25 -0700 (PDT) Received: by mail-yb1-xb4a.google.com with SMTP id 3f1490d57ef6-d745094c496so1030931276.1 for ; Thu, 31 Aug 2023 13:37:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20221208; t=1693514245; x=1694119045; darn=vger.kernel.org; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:from:to:cc:subject:date:message-id:reply-to; bh=yBbx4b8+p9YSAXqpoHoy5g7vSJRSgSl+lhiyxSfb/eU=; b=0ZPTG/K7z5/cT3ShYOz0vb8RRH4Nw5JXxa7KNOL84iPd1CZJTHmMWpm+xmKxB9Vedi o6croEnyFXHRTciz3Ezy+AR6G9NjYBw/vR2C12GNnJbH9rG6IxMXq7cU+A/KN30iWzo0 C3kmfe//Nq5Upsh9aBAVG16S3pEbGPBhnd2VcTeSnecYNGtP0waNq6wqZhBL1Mrl3GgV exqBkHKhdfVkahdff25HfoKIw99yBYeqZbnLDr1ofsMz8R8AgCzoXG+wlrl6e83I3qnt WrAnR8VQUb5EsgG9+ZTMMgQOFUFLNAcDHIbyMmbDg+nmGxrxAKF0aoCHA/ey26lhxVZz OfYg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1693514245; x=1694119045; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=yBbx4b8+p9YSAXqpoHoy5g7vSJRSgSl+lhiyxSfb/eU=; b=WIyVjc6NMABng3+8EPU9zgMn2JbXFX5RKzwjFO4wKHOoadD3zxzyZ7Zm4jO1eMNYZC Q8SNE/0ir1/k8Vi8MjVzutFeYeEnmgCcn2wnBh/csm8l8beOZTrjJJ86YJq5oeaoFJZV C2RyTs2YSETPyHCuEXsZF2mMfzJxj9Pl9iaB+CcjMjzu8gNSuEadqkjOQVQJb5D8gA8Z Rn5jVA2oKmptfih3N/CuqXq9DPdnuEgWyFVUCweUn2ANYeQCFnggx03YU07xdCMSU0UA bYpg3UVtF2hBEBwemFCPyxY+q41cY75r246ONB8r+/5U0QSe2Eu6SyK53V1dJxfThYsR iwgQ== X-Gm-Message-State: AOJu0YyqhLqcYcg9vLVHSDbkQO2yZtq9/HZ2x2yYhczNg7Jkj7Ex91dm wp1lOc0oLFX6q0vPxZEvJaoTX+gtcSL+MhCQ X-Google-Smtp-Source: AGHT+IF1LWmDxsSgnrtvI1kzQAdmqG9kkHzoMRjXO6gEE8jOd/mbGmywsGSMUbTy0xnAonh3GTBUSjDNwaJZ1HZV X-Received: from mclapinski.waw.corp.google.com ([2a00:79e0:9b:0:36f8:f0a:6df2:a7d5]) (user=mclapinski job=sendgmr) by 2002:a05:6902:11c9:b0:d20:7752:e384 with SMTP id n9-20020a05690211c900b00d207752e384mr22037ybu.3.1693514245015; Thu, 31 Aug 2023 13:37:25 -0700 (PDT) Date: Thu, 31 Aug 2023 22:36:46 +0200 In-Reply-To: <20230831203647.558079-1-mclapinski@google.com> Mime-Version: 1.0 References: <20230831203647.558079-1-mclapinski@google.com> X-Mailer: git-send-email 2.42.0.283.g2d96d420d3-goog Message-ID: <20230831203647.558079-2-mclapinski@google.com> Subject: [PATCH 1/2] fcntl: add fcntl(F_CHECK_ORIGINAL_MEMFD) From: Michal Clapinski To: Jeff Layton , Chuck Lever , Alexander Viro , Christian Brauner , Shuah Khan , Andrew Morton , Jeff Xu , Aleksa Sarai , Daniel Verkamp , Kees Cook , Marc Dionne , linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org Cc: Michal Clapinski Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Add a way to check if an fd points to the memfd's original open fd (the one created by memfd_create). Useful because only the original open fd can be both writable and executable. Signed-off-by: Michal Clapinski --- fs/fcntl.c | 3 +++ include/uapi/linux/fcntl.h | 9 +++++++++ 2 files changed, 12 insertions(+) diff --git a/fs/fcntl.c b/fs/fcntl.c index e871009f6c88..301527e07a4d 100644 --- a/fs/fcntl.c +++ b/fs/fcntl.c @@ -419,6 +419,9 @@ static long do_fcntl(int fd, unsigned int cmd, unsigned= long arg, case F_SET_RW_HINT: err =3D fcntl_rw_hint(filp, cmd, arg); break; + case F_CHECK_ORIGINAL_MEMFD: + err =3D !(filp->f_mode & FMODE_WRITER); + break; default: break; } diff --git a/include/uapi/linux/fcntl.h b/include/uapi/linux/fcntl.h index 6c80f96049bd..9a10fe3aafa7 100644 --- a/include/uapi/linux/fcntl.h +++ b/include/uapi/linux/fcntl.h @@ -56,6 +56,15 @@ #define F_GET_FILE_RW_HINT (F_LINUX_SPECIFIC_BASE + 13) #define F_SET_FILE_RW_HINT (F_LINUX_SPECIFIC_BASE + 14) =20 +/* + * Check if the fd points to the memfd's original open fd (the one created= by + * memfd_create). Returns 1 if yes, 0 if no. + * If the fd doesn't point to a memfd, the value should not be interpreted. + * Useful because only the original open fd can be both writable and + * executable. + */ +#define F_CHECK_ORIGINAL_MEMFD (F_LINUX_SPECIFIC_BASE + 15) + /* * Valid hint values for F_{GET,SET}_RW_HINT. 0 is "not set", or can be * used to clear any hints previously set. --=20 2.42.0.283.g2d96d420d3-goog From nobody Sun Feb 8 17:36:57 2026 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id B7575C83F3E for ; Thu, 31 Aug 2023 20:37:45 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1347437AbjHaUhq (ORCPT ); Thu, 31 Aug 2023 16:37:46 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:50458 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1347430AbjHaUho (ORCPT ); Thu, 31 Aug 2023 16:37:44 -0400 Received: from mail-yw1-x1149.google.com (mail-yw1-x1149.google.com [IPv6:2607:f8b0:4864:20::1149]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id C2B33E5D for ; Thu, 31 Aug 2023 13:37:38 -0700 (PDT) Received: by mail-yw1-x1149.google.com with SMTP id 00721157ae682-5925f39aa5cso21500557b3.1 for ; Thu, 31 Aug 2023 13:37:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20221208; t=1693514258; x=1694119058; darn=vger.kernel.org; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:from:to:cc:subject:date:message-id:reply-to; bh=xGxCZUuxbWSlNwkUI6nwNutDuYApOwCOxRWfVwGAJ3o=; b=aPRx0fT3CkSVIUrV1PmRN5ysG5vkys23TxgntCvZjZmRN3QniZCggOCA9k7y7K3v9h FrI4K80Xv1u9VMu9jmSo4bhQacOu1p2oqbOhfUI5Kbv+wMBWBXBNSCLaduV+uI4DDtq8 Z1GFMFhr5LPG+g91Z98MRMwvrnqBy3wlV/pDdgdBz5TWQlbGqhR4FFCpUXOWQYz+CpWw X+YUHGmAhuIwkPHdJR5JhVYargvNqzLZlSAY2Y2BqOX/ritvItNqFvn4l5g0CiO58vz1 APGqJ0r93JUep3jiNB4pqvtZXvMXWBurUia7FZgC64riK11fv7j/bW9yGJinxYytA67E vhKg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1693514258; x=1694119058; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=xGxCZUuxbWSlNwkUI6nwNutDuYApOwCOxRWfVwGAJ3o=; b=kRUTn/LlS6D3eZLHSSGLAvcU1/P7CI+6NhX4Nj/IRWHCD21JJZC++vLxVe5tPFSt63 +VAJhOcwfRIRdH8G5f7Ye+8q1UBei2p+4jGh7+ciHP84HYefEOPpBiwqnAE2QObh0og3 VdtaXstPW6AlS/3Fc3k7JaUVQkBXnkoDJ+DNZv/oLdJy0sPWC17MuavftLsojFuSSRJR jy1FRB6xJvi50lQq21dFNc/NQPk48GHYey2FxmAXwlPqad138BKLYb3N0+J1gOYPrDOs 7XoXxRZNmlZT0Tu2hqunH0GQsrBLfCs0YyU3sRCsRuRn/3oZ+xF9h+rOjuGk1VuNh+UI KChg== X-Gm-Message-State: AOJu0YwMb4i7fvM2X4enkQb09PTgZzl5UkbmjdRhXrSuRa7lVUolStjf FSMF4m+TO+gvmmiSnPpThkttW1T1yOTGkWq4 X-Google-Smtp-Source: AGHT+IERJHbjR+c/ciTN5Esvviq3kVNk3iU0MzA8FlGygkmNX9iS6RTXYbmmUYknoi7aexCc3wAuxahV5uNuP5zC X-Received: from mclapinski.waw.corp.google.com ([2a00:79e0:9b:0:36f8:f0a:6df2:a7d5]) (user=mclapinski job=sendgmr) by 2002:a05:690c:2b8b:b0:594:f596:e232 with SMTP id en11-20020a05690c2b8b00b00594f596e232mr20144ywb.2.1693514257991; Thu, 31 Aug 2023 13:37:37 -0700 (PDT) Date: Thu, 31 Aug 2023 22:36:47 +0200 In-Reply-To: <20230831203647.558079-1-mclapinski@google.com> Mime-Version: 1.0 References: <20230831203647.558079-1-mclapinski@google.com> X-Mailer: git-send-email 2.42.0.283.g2d96d420d3-goog Message-ID: <20230831203647.558079-3-mclapinski@google.com> Subject: [PATCH 2/2] selftests: test fcntl(F_CHECK_ORIGINAL_MEMFD) From: Michal Clapinski To: Jeff Layton , Chuck Lever , Alexander Viro , Christian Brauner , Shuah Khan , Andrew Morton , Jeff Xu , Aleksa Sarai , Daniel Verkamp , Kees Cook , Marc Dionne , linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org Cc: Michal Clapinski Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Signed-off-by: Michal Clapinski --- tools/testing/selftests/memfd/memfd_test.c | 32 ++++++++++++++++++++++ 1 file changed, 32 insertions(+) diff --git a/tools/testing/selftests/memfd/memfd_test.c b/tools/testing/sel= ftests/memfd/memfd_test.c index 3df008677239..4f3b7615ca87 100644 --- a/tools/testing/selftests/memfd/memfd_test.c +++ b/tools/testing/selftests/memfd/memfd_test.c @@ -39,6 +39,10 @@ =20 #define MFD_NOEXEC_SEAL 0x0008U =20 +#ifndef F_CHECK_ORIGINAL_MEMFD +#define F_CHECK_ORIGINAL_MEMFD (1024 + 15) +#endif + /* * Default is not to test hugetlbfs */ @@ -1567,6 +1571,32 @@ static void test_share_fork(char *banner, char *b_su= ffix) close(fd); } =20 +static void test_fcntl_check_original(void) +{ + int fd, fd2; + char path[128]; + + printf("%s FCNTL-CHECK-ORIGINAL\n", memfd_str); + fd =3D sys_memfd_create("kern_memfd_exec_reopen", 0); + if (fd < 0) { + printf("memfd_create failed: %m\n"); + abort(); + } + if (fcntl(fd, F_CHECK_ORIGINAL_MEMFD) !=3D 1) { + printf("fcntl(F_CHECK_ORIGINAL_MEMFD) failed\n"); + abort(); + } + + fd2 =3D mfd_assert_reopen_fd(fd); + if (fcntl(fd2, F_CHECK_ORIGINAL_MEMFD) !=3D 0) { + printf("fcntl(F_CHECK_ORIGINAL_MEMFD) failed\n"); + abort(); + } + + close(fd); + close(fd2); +} + int main(int argc, char **argv) { pid_t pid; @@ -1609,6 +1639,8 @@ int main(int argc, char **argv) test_share_open("SHARE-OPEN", ""); test_share_fork("SHARE-FORK", ""); =20 + test_fcntl_check_original(); + /* Run test-suite in a multi-threaded environment with a shared * file-table. */ pid =3D spawn_idle_thread(CLONE_FILES | CLONE_FS | CLONE_VM); --=20 2.42.0.283.g2d96d420d3-goog