Re: [PATCH] mm/nommu: Reject wrapping ranges in access_remote_vm()
From: Lorenzo Stoakes (ARM)
Date: Fri Sep 25 2026 - 09:12:09 EST
On Thu, Sep 10, 2026 at 05:11:03AM +0900, Hajime Tazaki wrote:
>
> Hello,
>
> On Wed, 09 Sep 2026 16:13:41 +0900,
> Andrew Morton wrote:
> >
> > On Wed, 9 Sep 2026 09:42:31 +0300 Anastasios Papagiannis <tasos.papagiannnis@xxxxxxxxx> wrote:
> >
> > > The NOMMU implementation of access_process_vm() rejects address ranges
> > > whose end wraps around, but access_remote_vm() bypasses this check even
> > > though both functions delegate to __access_remote_vm().
> > >
> > > Move the wraparound check into __access_remote_vm() so it applies to
> > > both entry points.
> >
> > lgtm, thanks.
> >
> > > This is originally reported in [1].
> > >
> > > [1] https://lore.kernel.org/bpf/4ef240a5bea36ff84df9589671367832860795159386a4c8fba546a0fa8b786f@xxxxxxxxxxxxxxx/
> >
> > Ah, bpfbot scored one.
> >
> > Sashiko might have found more issues in there:
> > https://sashiko.dev/#/patchset/20260909064231.18693-1-tasos.papagiannnis@xxxxxxxxx
> >
> > I'll optimistically cc Hajime Tazaki, who has been doing some NOMMU
> > work recently.
>
> I got a similar review (from Sashiko) that current use of
> !vma->vm_file isn't appropriate and should use vma_set_anonymous(). IIUC
> that case happens only (I may miss something) with /dev/zero (via
> mmap_zero_prepare()).
That's no longer an issue as MAP_PRIVATE-/dev/zero is truly anon now.
>
> I also had a patch but am currently waiting for Lorenzo's input for
> his work on /dev/zero, which mentioned in his reply.
Sorry, I just added a script to find call outs in neomutt :)
As above.
>
> https://lore.kernel.org/linux-mm/an8BlTgk7sc5vFJ1@lucifer/
>
> Thus 3 comments of Sashiko (all about vma->vm_file) can be addressed
> in future, and are not needed an immediate fix.
You can use vma_is_anonymous() now.
>
> I wish to ask this to Lorenzo too.
>
> -- Hajime
--
Cheers, Lorenzo