xref: /linux/tools/testing/vma/include/dup.h (revision 67f8bc848ee31831336bd478e57d2f993551902e)
1 /* SPDX-License-Identifier: GPL-2.0+ */
2 
3 #pragma once
4 
5 /* Forward declarations to avoid header cycle. */
6 struct vm_area_struct;
7 static inline void vma_start_write(struct vm_area_struct *vma);
8 
9 extern const struct vm_operations_struct vma_dummy_vm_ops;
10 extern unsigned long stack_guard_gap;
11 extern const struct vm_operations_struct vma_dummy_vm_ops;
12 extern unsigned long rlimit(unsigned int limit);
13 struct task_struct *get_current(void);
14 
15 #define MMF_HAS_MDWE	28
16 #define current get_current()
17 
18 /*
19  * Define the task command name length as enum, then it can be visible to
20  * BPF programs.
21  */
22 enum {
23 	TASK_COMM_LEN = 16,
24 };
25 
26 /* PARTIALLY implemented types. */
27 struct mm_struct {
28 	struct maple_tree mm_mt;
29 	int map_count;			/* number of VMAs */
30 	unsigned long total_vm;	   /* Total pages mapped */
31 	unsigned long locked_vm;   /* Pages that have PG_mlocked set */
32 	unsigned long data_vm;	   /* VM_WRITE & ~VM_SHARED & ~VM_STACK */
33 	unsigned long exec_vm;	   /* VM_EXEC & ~VM_WRITE & ~VM_STACK */
34 	unsigned long stack_vm;	   /* VM_STACK */
35 
36 	union {
37 		vm_flags_t def_flags;
38 		vma_flags_t def_vma_flags;
39 	};
40 
41 	mm_flags_t flags; /* Must use mm_flags_* helpers to access */
42 };
43 struct address_space {
44 	struct rb_root_cached	i_mmap;
45 	unsigned long		flags;
46 	atomic_t		i_mmap_writable;
47 };
48 struct file_operations {
49 	int (*mmap)(struct file *, struct vm_area_struct *);
50 	int (*mmap_prepare)(struct vm_area_desc *);
51 };
52 struct file {
53 	struct address_space	*f_mapping;
54 	const struct file_operations	*f_op;
55 };
56 struct anon_vma_chain {
57 	struct anon_vma *anon_vma;
58 	struct list_head same_vma;
59 };
60 struct task_struct {
61 	char comm[TASK_COMM_LEN];
62 	pid_t pid;
63 	struct mm_struct *mm;
64 
65 	/* Used for emulating ABI behavior of previous Linux versions: */
66 	unsigned int			personality;
67 };
68 
69 struct kref {
70 	refcount_t refcount;
71 };
72 
73 struct anon_vma_name {
74 	struct kref kref;
75 	/* The name needs to be at the end because it is dynamically sized. */
76 	char name[];
77 };
78 
79 /*
80  * Contains declarations that are DUPLICATED from kernel source in order to
81  * faciliate userland VMA testing.
82  *
83  * These must be kept in sync with kernel source.
84  */
85 
86 #define VMA_LOCK_OFFSET	0x40000000
87 
88 typedef struct { unsigned long v; } freeptr_t;
89 
90 #define VM_NONE		0x00000000
91 
92 typedef int __bitwise vma_flag_t;
93 
94 #define ACCESS_PRIVATE(p, member) ((p)->member)
95 
96 #define DECLARE_VMA_BIT(name, bitnum) \
97 	VMA_ ## name ## _BIT = ((__force vma_flag_t)bitnum)
98 #define DECLARE_VMA_BIT_ALIAS(name, aliased) \
99 	VMA_ ## name ## _BIT = VMA_ ## aliased ## _BIT
100 enum {
101 	DECLARE_VMA_BIT(READ, 0),
102 	DECLARE_VMA_BIT(WRITE, 1),
103 	DECLARE_VMA_BIT(EXEC, 2),
104 	DECLARE_VMA_BIT(SHARED, 3),
105 	/* mprotect() hardcodes VM_MAYREAD >> 4 == VM_READ, and so for r/w/x bits. */
106 	DECLARE_VMA_BIT(MAYREAD, 4),	/* limits for mprotect() etc. */
107 	DECLARE_VMA_BIT(MAYWRITE, 5),
108 	DECLARE_VMA_BIT(MAYEXEC, 6),
109 	DECLARE_VMA_BIT(MAYSHARE, 7),
110 	DECLARE_VMA_BIT(GROWSDOWN, 8),	/* general info on the segment */
111 #ifdef CONFIG_MMU
112 	DECLARE_VMA_BIT(UFFD_MISSING, 9),/* missing pages tracking */
113 #else
114 	/* nommu: R/O MAP_PRIVATE mapping that might overlay a file mapping */
115 	DECLARE_VMA_BIT(MAYOVERLAY, 9),
116 #endif /* CONFIG_MMU */
117 	/* Page-ranges managed without "struct page", just pure PFN */
118 	DECLARE_VMA_BIT(PFNMAP, 10),
119 	DECLARE_VMA_BIT(MAYBE_GUARD, 11),
120 	DECLARE_VMA_BIT(UFFD_WP, 12),	/* wrprotect pages tracking */
121 	DECLARE_VMA_BIT(LOCKED, 13),
122 	DECLARE_VMA_BIT(IO, 14),	/* Memory mapped I/O or similar */
123 	DECLARE_VMA_BIT(SEQ_READ, 15),	/* App will access data sequentially */
124 	DECLARE_VMA_BIT(RAND_READ, 16),	/* App will not benefit from clustered reads */
125 	DECLARE_VMA_BIT(DONTCOPY, 17),	/* Do not copy this vma on fork */
126 	DECLARE_VMA_BIT(DONTEXPAND, 18),/* Cannot expand with mremap() */
127 	DECLARE_VMA_BIT(LOCKONFAULT, 19),/* Lock pages covered when faulted in */
128 	DECLARE_VMA_BIT(ACCOUNT, 20),	/* Is a VM accounted object */
129 	DECLARE_VMA_BIT(NORESERVE, 21),	/* should the VM suppress accounting */
130 	DECLARE_VMA_BIT(HUGETLB, 22),	/* Huge TLB Page VM */
131 	DECLARE_VMA_BIT(SYNC, 23),	/* Synchronous page faults */
132 	DECLARE_VMA_BIT(ARCH_1, 24),	/* Architecture-specific flag */
133 	DECLARE_VMA_BIT(WIPEONFORK, 25),/* Wipe VMA contents in child. */
134 	DECLARE_VMA_BIT(DONTDUMP, 26),	/* Do not include in the core dump */
135 	DECLARE_VMA_BIT(SOFTDIRTY, 27),	/* NOT soft dirty clean area */
136 	DECLARE_VMA_BIT(MIXEDMAP, 28),	/* Can contain struct page and pure PFN pages */
137 	DECLARE_VMA_BIT(HUGEPAGE, 29),	/* MADV_HUGEPAGE marked this vma */
138 	DECLARE_VMA_BIT(NOHUGEPAGE, 30),/* MADV_NOHUGEPAGE marked this vma */
139 	DECLARE_VMA_BIT(MERGEABLE, 31),	/* KSM may merge identical pages */
140 	/* These bits are reused, we define specific uses below. */
141 	DECLARE_VMA_BIT(HIGH_ARCH_0, 32),
142 	DECLARE_VMA_BIT(HIGH_ARCH_1, 33),
143 	DECLARE_VMA_BIT(HIGH_ARCH_2, 34),
144 	DECLARE_VMA_BIT(HIGH_ARCH_3, 35),
145 	DECLARE_VMA_BIT(HIGH_ARCH_4, 36),
146 	DECLARE_VMA_BIT(HIGH_ARCH_5, 37),
147 	DECLARE_VMA_BIT(HIGH_ARCH_6, 38),
148 	/*
149 	 * This flag is used to connect VFIO to arch specific KVM code. It
150 	 * indicates that the memory under this VMA is safe for use with any
151 	 * non-cachable memory type inside KVM. Some VFIO devices, on some
152 	 * platforms, are thought to be unsafe and can cause machine crashes
153 	 * if KVM does not lock down the memory type.
154 	 */
155 	DECLARE_VMA_BIT(ALLOW_ANY_UNCACHED, 39),
156 #ifdef CONFIG_PPC32
157 	DECLARE_VMA_BIT_ALIAS(DROPPABLE, ARCH_1),
158 #else
159 	DECLARE_VMA_BIT(DROPPABLE, 40),
160 #endif
161 	DECLARE_VMA_BIT(UFFD_MINOR, 41),
162 	DECLARE_VMA_BIT(SEALED, 42),
163 	/* Flags that reuse flags above. */
164 	DECLARE_VMA_BIT_ALIAS(PKEY_BIT0, HIGH_ARCH_0),
165 	DECLARE_VMA_BIT_ALIAS(PKEY_BIT1, HIGH_ARCH_1),
166 	DECLARE_VMA_BIT_ALIAS(PKEY_BIT2, HIGH_ARCH_2),
167 	DECLARE_VMA_BIT_ALIAS(PKEY_BIT3, HIGH_ARCH_3),
168 	DECLARE_VMA_BIT_ALIAS(PKEY_BIT4, HIGH_ARCH_4),
169 #if defined(CONFIG_X86_USER_SHADOW_STACK)
170 	/*
171 	 * VM_SHADOW_STACK should not be set with VM_SHARED because of lack of
172 	 * support core mm.
173 	 *
174 	 * These VMAs will get a single end guard page. This helps userspace
175 	 * protect itself from attacks. A single page is enough for current
176 	 * shadow stack archs (x86). See the comments near alloc_shstk() in
177 	 * arch/x86/kernel/shstk.c for more details on the guard size.
178 	 */
179 	DECLARE_VMA_BIT_ALIAS(SHADOW_STACK, HIGH_ARCH_5),
180 #elif defined(CONFIG_ARM64_GCS)
181 	/*
182 	 * arm64's Guarded Control Stack implements similar functionality and
183 	 * has similar constraints to shadow stacks.
184 	 */
185 	DECLARE_VMA_BIT_ALIAS(SHADOW_STACK, HIGH_ARCH_6),
186 #endif
187 	DECLARE_VMA_BIT_ALIAS(SAO, ARCH_1),		/* Strong Access Ordering (powerpc) */
188 	DECLARE_VMA_BIT_ALIAS(GROWSUP, ARCH_1),		/* parisc */
189 	DECLARE_VMA_BIT_ALIAS(SPARC_ADI, ARCH_1),	/* sparc64 */
190 	DECLARE_VMA_BIT_ALIAS(ARM64_BTI, ARCH_1),	/* arm64 */
191 	DECLARE_VMA_BIT_ALIAS(ARCH_CLEAR, ARCH_1),	/* sparc64, arm64 */
192 	DECLARE_VMA_BIT_ALIAS(MAPPED_COPY, ARCH_1),	/* !CONFIG_MMU */
193 	DECLARE_VMA_BIT_ALIAS(MTE, HIGH_ARCH_4),	/* arm64 */
194 	DECLARE_VMA_BIT_ALIAS(MTE_ALLOWED, HIGH_ARCH_5),/* arm64 */
195 #ifdef CONFIG_STACK_GROWSUP
196 	DECLARE_VMA_BIT_ALIAS(STACK, GROWSUP),
197 	DECLARE_VMA_BIT_ALIAS(STACK_EARLY, GROWSDOWN),
198 #else
199 	DECLARE_VMA_BIT_ALIAS(STACK, GROWSDOWN),
200 #endif
201 };
202 
203 #define INIT_VM_FLAG(name) BIT((__force int) VMA_ ## name ## _BIT)
204 #define VM_READ		INIT_VM_FLAG(READ)
205 #define VM_WRITE	INIT_VM_FLAG(WRITE)
206 #define VM_EXEC		INIT_VM_FLAG(EXEC)
207 #define VM_SHARED	INIT_VM_FLAG(SHARED)
208 #define VM_MAYREAD	INIT_VM_FLAG(MAYREAD)
209 #define VM_MAYWRITE	INIT_VM_FLAG(MAYWRITE)
210 #define VM_MAYEXEC	INIT_VM_FLAG(MAYEXEC)
211 #define VM_MAYSHARE	INIT_VM_FLAG(MAYSHARE)
212 #define VM_GROWSDOWN	INIT_VM_FLAG(GROWSDOWN)
213 #ifdef CONFIG_MMU
214 #define VM_UFFD_MISSING	INIT_VM_FLAG(UFFD_MISSING)
215 #else
216 #define VM_UFFD_MISSING	VM_NONE
217 #define VM_MAYOVERLAY	INIT_VM_FLAG(MAYOVERLAY)
218 #endif
219 #define VM_PFNMAP	INIT_VM_FLAG(PFNMAP)
220 #define VM_MAYBE_GUARD	INIT_VM_FLAG(MAYBE_GUARD)
221 #define VM_UFFD_WP	INIT_VM_FLAG(UFFD_WP)
222 #define VM_LOCKED	INIT_VM_FLAG(LOCKED)
223 #define VM_IO		INIT_VM_FLAG(IO)
224 #define VM_SEQ_READ	INIT_VM_FLAG(SEQ_READ)
225 #define VM_RAND_READ	INIT_VM_FLAG(RAND_READ)
226 #define VM_DONTCOPY	INIT_VM_FLAG(DONTCOPY)
227 #define VM_DONTEXPAND	INIT_VM_FLAG(DONTEXPAND)
228 #define VM_LOCKONFAULT	INIT_VM_FLAG(LOCKONFAULT)
229 #define VM_ACCOUNT	INIT_VM_FLAG(ACCOUNT)
230 #define VM_NORESERVE	INIT_VM_FLAG(NORESERVE)
231 #define VM_HUGETLB	INIT_VM_FLAG(HUGETLB)
232 #define VM_SYNC		INIT_VM_FLAG(SYNC)
233 #define VM_ARCH_1	INIT_VM_FLAG(ARCH_1)
234 #define VM_WIPEONFORK	INIT_VM_FLAG(WIPEONFORK)
235 #define VM_DONTDUMP	INIT_VM_FLAG(DONTDUMP)
236 #ifdef CONFIG_MEM_SOFT_DIRTY
237 #define VM_SOFTDIRTY	INIT_VM_FLAG(SOFTDIRTY)
238 #else
239 #define VM_SOFTDIRTY	VM_NONE
240 #endif
241 #define VM_MIXEDMAP	INIT_VM_FLAG(MIXEDMAP)
242 #define VM_HUGEPAGE	INIT_VM_FLAG(HUGEPAGE)
243 #define VM_NOHUGEPAGE	INIT_VM_FLAG(NOHUGEPAGE)
244 #define VM_MERGEABLE	INIT_VM_FLAG(MERGEABLE)
245 #define VM_STACK	INIT_VM_FLAG(STACK)
246 #ifdef CONFIG_STACK_GROWSUP
247 #define VM_STACK_EARLY	INIT_VM_FLAG(STACK_EARLY)
248 #define VMA_STACK_EARLY mk_vma_flags(VMA_STACK_EARLY_BIT)
249 #else
250 #define VM_STACK_EARLY	VM_NONE
251 #define VMA_STACK_EARLY EMPTY_VMA_FLAGS
252 #endif
253 #ifdef CONFIG_ARCH_HAS_PKEYS
254 #define VM_PKEY_SHIFT ((__force int)VMA_HIGH_ARCH_0_BIT)
255 /* Despite the naming, these are FLAGS not bits. */
256 #define VM_PKEY_BIT0 INIT_VM_FLAG(PKEY_BIT0)
257 #define VM_PKEY_BIT1 INIT_VM_FLAG(PKEY_BIT1)
258 #define VM_PKEY_BIT2 INIT_VM_FLAG(PKEY_BIT2)
259 #if CONFIG_ARCH_PKEY_BITS > 3
260 #define VM_PKEY_BIT3 INIT_VM_FLAG(PKEY_BIT3)
261 #else
262 #define VM_PKEY_BIT3  VM_NONE
263 #endif /* CONFIG_ARCH_PKEY_BITS > 3 */
264 #if CONFIG_ARCH_PKEY_BITS > 4
265 #define VM_PKEY_BIT4 INIT_VM_FLAG(PKEY_BIT4)
266 #else
267 #define VM_PKEY_BIT4  VM_NONE
268 #endif /* CONFIG_ARCH_PKEY_BITS > 4 */
269 #endif /* CONFIG_ARCH_HAS_PKEYS */
270 #if defined(CONFIG_X86_USER_SHADOW_STACK) || defined(CONFIG_ARM64_GCS)
271 #define VM_SHADOW_STACK	INIT_VM_FLAG(SHADOW_STACK)
272 #define VMA_STARTGAP_FLAGS mk_vma_flags(VMA_GROWSDOWN_BIT, VMA_SHADOW_STACK_BIT)
273 #else
274 #define VM_SHADOW_STACK	VM_NONE
275 #define VMA_STARTGAP_FLAGS mk_vma_flags(VMA_GROWSDOWN_BIT)
276 #endif
277 #if defined(CONFIG_PPC64)
278 #define VM_SAO		INIT_VM_FLAG(SAO)
279 #elif defined(CONFIG_PARISC)
280 #define VM_GROWSUP	INIT_VM_FLAG(GROWSUP)
281 #elif defined(CONFIG_SPARC64)
282 #define VM_SPARC_ADI	INIT_VM_FLAG(SPARC_ADI)
283 #define VM_ARCH_CLEAR	INIT_VM_FLAG(ARCH_CLEAR)
284 #elif defined(CONFIG_ARM64)
285 #define VM_ARM64_BTI	INIT_VM_FLAG(ARM64_BTI)
286 #define VM_ARCH_CLEAR	INIT_VM_FLAG(ARCH_CLEAR)
287 #elif !defined(CONFIG_MMU)
288 #define VM_MAPPED_COPY	INIT_VM_FLAG(MAPPED_COPY)
289 #endif
290 #ifndef VM_GROWSUP
291 #define VM_GROWSUP	VM_NONE
292 #endif
293 #ifdef CONFIG_ARM64_MTE
294 #define VM_MTE		INIT_VM_FLAG(MTE)
295 #define VM_MTE_ALLOWED	INIT_VM_FLAG(MTE_ALLOWED)
296 #else
297 #define VM_MTE		VM_NONE
298 #define VM_MTE_ALLOWED	VM_NONE
299 #endif
300 #ifdef CONFIG_HAVE_ARCH_USERFAULTFD_MINOR
301 #define VM_UFFD_MINOR	INIT_VM_FLAG(UFFD_MINOR)
302 #else
303 #define VM_UFFD_MINOR	VM_NONE
304 #endif
305 #ifdef CONFIG_64BIT
306 #define VM_ALLOW_ANY_UNCACHED	INIT_VM_FLAG(ALLOW_ANY_UNCACHED)
307 #define VM_SEALED		INIT_VM_FLAG(SEALED)
308 #else
309 #define VM_ALLOW_ANY_UNCACHED	VM_NONE
310 #define VM_SEALED		VM_NONE
311 #endif
312 #if defined(CONFIG_64BIT) || defined(CONFIG_PPC32)
313 #define VM_DROPPABLE		INIT_VM_FLAG(DROPPABLE)
314 #else
315 #define VM_DROPPABLE		VM_NONE
316 #endif
317 
318 /* Bits set in the VMA until the stack is in its final location */
319 #define VM_STACK_INCOMPLETE_SETUP (VM_RAND_READ | VM_SEQ_READ | VM_STACK_EARLY)
320 #define VMA_STACK_INCOMPLETE_SETUP append_vma_flags(		\
321 	VMA_STACK_EARLY, VMA_RAND_READ_BIT, VMA_SEQ_READ_BIT)
322 
323 #define TASK_EXEC_BIT ((current->personality & READ_IMPLIES_EXEC) ? \
324 		       VM_EXEC_BIT : VM_READ_BIT)
325 
326 /* Common data flag combinations */
327 #define VMA_DATA_FLAGS_TSK_EXEC	mk_vma_flags(VMA_READ_BIT, VMA_WRITE_BIT, \
328 		TASK_EXEC_BIT, VMA_MAYREAD_BIT, VMA_MAYWRITE_BIT,	  \
329 		VMA_MAYEXEC_BIT)
330 #define VMA_DATA_FLAGS_NON_EXEC	mk_vma_flags(VMA_READ_BIT, VMA_WRITE_BIT, \
331 		VMA_MAYREAD_BIT, VMA_MAYWRITE_BIT, VMA_MAYEXEC_BIT)
332 #define VMA_DATA_FLAGS_EXEC	mk_vma_flags(VMA_READ_BIT, VMA_WRITE_BIT, \
333 		VMA_EXEC_BIT, VMA_MAYREAD_BIT, VMA_MAYWRITE_BIT,	  \
334 		VMA_MAYEXEC_BIT)
335 
336 #ifndef VMA_DATA_DEFAULT_FLAGS		/* arch can override this */
337 #define VMA_DATA_DEFAULT_FLAGS  VMA_DATA_FLAGS_EXEC
338 #endif
339 
340 #ifndef VMA_STACK_DEFAULT_FLAGS		/* arch can override this */
341 #define VMA_STACK_DEFAULT_FLAGS VMA_DATA_DEFAULT_FLAGS
342 #endif
343 
344 #define VMA_STACK_FLAGS	append_vma_flags(VMA_STACK_DEFAULT_FLAGS,	\
345 		VMA_STACK_BIT, VMA_ACCOUNT_BIT)
346 /* Temporary until VMA flags conversion complete. */
347 #define VM_STACK_FLAGS vma_flags_to_legacy(VMA_STACK_FLAGS)
348 
349 #define VM_STARTGAP_FLAGS (VM_GROWSDOWN | VM_SHADOW_STACK)
350 
351 /* VMA basic access permission flags */
352 #define VM_ACCESS_FLAGS (VM_READ | VM_WRITE | VM_EXEC)
353 #define VMA_ACCESS_FLAGS mk_vma_flags(VMA_READ_BIT, VMA_WRITE_BIT, VMA_EXEC_BIT)
354 
355 /*
356  * Special vmas that are non-mergable, non-mlock()able.
357  */
358 #define VM_SPECIAL (VM_IO | VM_DONTEXPAND | VM_PFNMAP | VM_MIXEDMAP)
359 
360 #define VMA_SPECIAL_FLAGS mk_vma_flags(VMA_IO_BIT, VMA_DONTEXPAND_BIT, \
361 				       VMA_PFNMAP_BIT, VMA_MIXEDMAP_BIT)
362 
363 #define VMA_REMAP_FLAGS mk_vma_flags(VMA_IO_BIT, VMA_PFNMAP_BIT,	\
364 				     VMA_DONTEXPAND_BIT, VMA_DONTDUMP_BIT)
365 
366 #define DEFAULT_MAP_WINDOW	((1UL << 47) - PAGE_SIZE)
367 #define TASK_SIZE_LOW		DEFAULT_MAP_WINDOW
368 #define TASK_SIZE_MAX		DEFAULT_MAP_WINDOW
369 #define STACK_TOP		TASK_SIZE_LOW
370 #define STACK_TOP_MAX		TASK_SIZE_MAX
371 
372 /* This mask represents all the VMA flag bits used by mlock */
373 #define VM_LOCKED_MASK	(VM_LOCKED | VM_LOCKONFAULT)
374 
375 #define VMA_LOCKED_MASK	mk_vma_flags(VMA_LOCKED_BIT, VMA_LOCKONFAULT_BIT)
376 
377 #define RLIMIT_STACK		3	/* max stack size */
378 #define RLIMIT_MEMLOCK		8	/* max locked-in-memory address space */
379 
380 #define CAP_IPC_LOCK         14
381 
382 #ifdef CONFIG_MEM_SOFT_DIRTY
383 #define VMA_STICKY_FLAGS mk_vma_flags(VMA_SOFTDIRTY_BIT, VMA_MAYBE_GUARD_BIT)
384 #else
385 #define VMA_STICKY_FLAGS mk_vma_flags(VMA_MAYBE_GUARD_BIT)
386 #endif
387 
388 #define VMA_IGNORE_MERGE_FLAGS VMA_STICKY_FLAGS
389 
390 #define VM_COPY_ON_FORK (VM_PFNMAP | VM_MIXEDMAP | VM_UFFD_WP | VM_MAYBE_GUARD)
391 
392 #define pgprot_val(x)		((x).pgprot)
393 #define __pgprot(x)		((pgprot_t) { (x) } )
394 
395 #define for_each_vma(__vmi, __vma)					\
396 	while (((__vma) = vma_next(&(__vmi))) != NULL)
397 
398 /* The MM code likes to work with exclusive end addresses */
399 #define for_each_vma_range(__vmi, __vma, __end)				\
400 	while (((__vma) = vma_find(&(__vmi), (__end))) != NULL)
401 
402 #define offset_in_page(p)	((unsigned long)(p) & ~PAGE_MASK)
403 
404 #define PHYS_PFN(x)	((unsigned long)((x) >> PAGE_SHIFT))
405 
406 #define test_and_set_bit(nr, addr) __test_and_set_bit(nr, addr)
407 #define test_and_clear_bit(nr, addr) __test_and_clear_bit(nr, addr)
408 
409 #define AS_MM_ALL_LOCKS 2
410 
411 #define swap(a, b) \
412 	do { typeof(a) __tmp = (a); (a) = (b); (b) = __tmp; } while (0)
413 
414 /*
415  * Flags for bug emulation.
416  *
417  * These occupy the top three bytes.
418  */
419 enum {
420 	READ_IMPLIES_EXEC =	0x0400000,
421 };
422 
423 struct vma_iterator {
424 	struct ma_state mas;
425 };
426 
427 #define VMA_ITERATOR(name, __mm, __addr)				\
428 	struct vma_iterator name = {					\
429 		.mas = {						\
430 			.tree = &(__mm)->mm_mt,				\
431 			.index = __addr,				\
432 			.node = NULL,					\
433 			.status = ma_start,				\
434 		},							\
435 	}
436 
437 #define DEFINE_MUTEX(mutexname) \
438 	struct mutex mutexname = {}
439 
440 #define DECLARE_BITMAP(name, bits) \
441 	unsigned long name[BITS_TO_LONGS(bits)]
442 
443 #define EMPTY_VMA_FLAGS ((vma_flags_t){ })
444 
445 #define MAPCOUNT_ELF_CORE_MARGIN	(5)
446 #define DEFAULT_MAX_MAP_COUNT	(USHRT_MAX - MAPCOUNT_ELF_CORE_MARGIN)
447 
448 static __always_inline bool vma_flags_empty(const vma_flags_t *flags)
449 {
450 	const unsigned long *bitmap = flags->__vma_flags;
451 
452 	return bitmap_empty(bitmap, NUM_VMA_FLAG_BITS);
453 }
454 
455 /* What action should be taken after an .mmap_prepare call is complete? */
456 enum mmap_action_type {
457 	MMAP_NOTHING,		/* Mapping is complete, no further action. */
458 	MMAP_REMAP_PFN,		/* Remap PFN range. */
459 	MMAP_IO_REMAP_PFN,	/* I/O remap PFN range. */
460 	MMAP_SIMPLE_IO_REMAP,	/* I/O remap with guardrails. */
461 	MMAP_MAP_KERNEL_PAGES,	/* Map kernel page range from an array. */
462 };
463 
464 /*
465  * Describes an action an mmap_prepare hook can instruct to be taken to complete
466  * the mapping of a VMA. Specified in vm_area_desc.
467  */
468 struct mmap_action {
469 	union {
470 		struct {
471 			unsigned long start;
472 			unsigned long start_pfn;
473 			unsigned long size;
474 			pgprot_t pgprot;
475 		} remap;
476 		struct {
477 			phys_addr_t start_phys_addr;
478 			unsigned long size;
479 		} simple_ioremap;
480 		struct {
481 			unsigned long start;
482 			struct page **pages;
483 			unsigned long nr_pages;
484 			pgoff_t pgoff;
485 		} map_kernel;
486 	};
487 	enum mmap_action_type type;
488 
489 	/*
490 	 * If non-zero, replace errors that arise from mmap actions with this
491 	 * value instead. Only valid error codes may be specified.
492 	 */
493 	int error_override;
494 
495 	/*
496 	 * This should be set in rare instances where the operation required
497 	 * that the rmap should not be able to access the VMA until
498 	 * completely set up.
499 	 */
500 	bool hide_from_rmap_until_complete :1;
501 };
502 
503 /* Operations which modify VMAs. */
504 enum vma_operation {
505 	VMA_OP_SPLIT,
506 	VMA_OP_MERGE_UNFAULTED,
507 	VMA_OP_REMAP,
508 	VMA_OP_FORK,
509 };
510 
511 /*
512  * Describes a VMA that is about to be mmap()'ed. Drivers may choose to
513  * manipulate mutable fields which will cause those fields to be updated in the
514  * resultant VMA.
515  *
516  * Helper functions are not required for manipulating any field.
517  */
518 struct vm_area_desc {
519 	/* Immutable state. */
520 	struct mm_struct *mm;
521 	struct file *file; /* May vary from vm_file in stacked callers. */
522 	unsigned long start;
523 	unsigned long end;
524 
525 	/* Mutable fields. Populated with initial state. */
526 	pgoff_t pgoff;
527 	struct file *vm_file;
528 	vma_flags_t vma_flags;
529 	pgprot_t page_prot;
530 
531 	/* Write-only fields. */
532 	const struct vm_operations_struct *vm_ops;
533 	void *private_data;
534 
535 	/* Take further action? */
536 	struct mmap_action action;
537 };
538 
539 struct vm_area_struct {
540 	/* The first cache line has the info for VMA tree walking. */
541 
542 	union {
543 		struct {
544 			/* VMA covers [vm_start; vm_end) addresses within mm */
545 			unsigned long vm_start;
546 			unsigned long vm_end;
547 		};
548 		freeptr_t vm_freeptr; /* Pointer used by SLAB_TYPESAFE_BY_RCU */
549 	};
550 
551 	struct mm_struct *vm_mm;	/* The address space we belong to. */
552 	pgprot_t vm_page_prot;          /* Access permissions of this VMA. */
553 
554 	/*
555 	 * Flags, see mm.h.
556 	 * To modify use vm_flags_{init|reset|set|clear|mod} functions.
557 	 */
558 	union {
559 		const vm_flags_t vm_flags;
560 		vma_flags_t flags;
561 	};
562 
563 #ifdef CONFIG_PER_VMA_LOCK
564 	/*
565 	 * Can only be written (using WRITE_ONCE()) while holding both:
566 	 *  - mmap_lock (in write mode)
567 	 *  - vm_refcnt bit at VMA_LOCK_OFFSET is set
568 	 * Can be read reliably while holding one of:
569 	 *  - mmap_lock (in read or write mode)
570 	 *  - vm_refcnt bit at VMA_LOCK_OFFSET is set or vm_refcnt > 1
571 	 * Can be read unreliably (using READ_ONCE()) for pessimistic bailout
572 	 * while holding nothing (except RCU to keep the VMA struct allocated).
573 	 *
574 	 * This sequence counter is explicitly allowed to overflow; sequence
575 	 * counter reuse can only lead to occasional unnecessary use of the
576 	 * slowpath.
577 	 */
578 	unsigned int vm_lock_seq;
579 #endif
580 	unsigned int __vm_anon_pgoff_lo;
581 
582 	/*
583 	 * A file's MAP_PRIVATE vma can be in both i_mmap tree and anon_vma
584 	 * list, after a COW of one of the file pages.	A MAP_SHARED vma
585 	 * can only be in the i_mmap tree.  An anonymous MAP_PRIVATE, stack
586 	 * or brk vma (with NULL file) can only be in an anon_vma list.
587 	 */
588 	struct list_head anon_vma_chain; /* Serialized by mmap_lock &
589 					  * page_table_lock */
590 	struct anon_vma *anon_vma;	/* Serialized by page_table_lock */
591 
592 	/* Function pointers to deal with this struct. */
593 	const struct vm_operations_struct *vm_ops;
594 
595 	/* Information about our backing store: */
596 	unsigned long vm_pgoff;		/* Offset (within vm_file) in PAGE_SIZE
597 					   units */
598 	struct file * vm_file;		/* File we map to (can be NULL). */
599 	void * vm_private_data;		/* was vm_pte (shared mem) */
600 
601 #ifdef CONFIG_SWAP
602 	atomic_long_t swap_readahead_info;
603 #endif
604 #ifndef CONFIG_MMU
605 	struct vm_region *vm_region;	/* NOMMU mapping region */
606 #endif
607 #ifdef CONFIG_NUMA
608 	struct mempolicy *vm_policy;	/* NUMA policy for the VMA */
609 #endif
610 #ifdef CONFIG_NUMA_BALANCING
611 	struct vma_numab_state *numab_state;	/* NUMA Balancing state */
612 #endif
613 #ifdef CONFIG_PER_VMA_LOCK
614 	/* Unstable RCU readers are allowed to read this. */
615 	refcount_t vm_refcnt;
616 #endif
617 #ifdef CONFIG_64BIT
618 	unsigned int __vm_anon_pgoff_hi;
619 #endif
620 	/*
621 	 * For areas with an address space and backing store,
622 	 * linkage into the address_space->i_mmap interval tree.
623 	 *
624 	 */
625 	struct {
626 		struct rb_node rb;
627 		unsigned long rb_subtree_last;
628 	} shared;
629 #ifdef CONFIG_ANON_VMA_NAME
630 	/*
631 	 * For private and shared anonymous mappings, a pointer to a null
632 	 * terminated string containing the name given to the vma, or NULL if
633 	 * unnamed. Serialized by mmap_lock. Use anon_vma_name to access.
634 	 */
635 	struct anon_vma_name *anon_name;
636 #endif
637 	struct vm_userfaultfd_ctx vm_userfaultfd_ctx;
638 } __randomize_layout;
639 
640 struct vm_operations_struct {
641 	/**
642 	 * @open: Called when a VMA is remapped, split or forked. Not called
643 	 * upon first mapping a VMA.
644 	 * Context: User context.  May sleep.  Caller holds mmap_lock.
645 	 */
646 	void (*open)(struct vm_area_struct *vma);
647 	/**
648 	 * @close: Called when the VMA is being removed from the MM.
649 	 * Context: User context.  May sleep.  Caller holds mmap_lock.
650 	 */
651 	void (*close)(struct vm_area_struct *vma);
652 	/**
653 	 * @mapped: Called when the VMA is first mapped in the MM. Not called if
654 	 * the new VMA is merged with an adjacent VMA.
655 	 *
656 	 * The @vm_private_data field is an output field allowing the user to
657 	 * modify vma->vm_private_data as necessary.
658 	 *
659 	 * ONLY valid if set from f_op->mmap_prepare. Will result in an error if
660 	 * set from f_op->mmap.
661 	 *
662 	 * Returns %0 on success, or an error otherwise. On error, the VMA will
663 	 * be unmapped.
664 	 *
665 	 * Context: User context.  May sleep.  Caller holds mmap_lock.
666 	 */
667 	int (*mapped)(unsigned long start, unsigned long end, pgoff_t pgoff,
668 		      const struct file *file, void **vm_private_data);
669 	/* Called any time before splitting to check if it's allowed */
670 	int (*may_split)(struct vm_area_struct *vma, unsigned long addr);
671 	int (*mremap)(struct vm_area_struct *vma);
672 	/*
673 	 * Called by mprotect() to make driver-specific permission
674 	 * checks before mprotect() is finalised.   The VMA must not
675 	 * be modified.  Returns 0 if mprotect() can proceed.
676 	 */
677 	int (*mprotect)(struct vm_area_struct *vma, unsigned long start,
678 			unsigned long end, unsigned long newflags);
679 	vm_fault_t (*fault)(struct vm_fault *vmf);
680 	vm_fault_t (*huge_fault)(struct vm_fault *vmf, unsigned int order);
681 	vm_fault_t (*map_pages)(struct vm_fault *vmf,
682 			pgoff_t start_pgoff, pgoff_t end_pgoff);
683 	unsigned long (*pagesize)(struct vm_area_struct *vma);
684 
685 	/* notification that a previously read-only page is about to become
686 	 * writable, if an error is returned it will cause a SIGBUS */
687 	vm_fault_t (*page_mkwrite)(struct vm_fault *vmf);
688 
689 	/* same as page_mkwrite when using VM_PFNMAP|VM_MIXEDMAP */
690 	vm_fault_t (*pfn_mkwrite)(struct vm_fault *vmf);
691 
692 	/* called by access_process_vm when get_user_pages() fails, typically
693 	 * for use by special VMAs. See also generic_access_phys() for a generic
694 	 * implementation useful for any iomem mapping.
695 	 */
696 	int (*access)(struct vm_area_struct *vma, unsigned long addr,
697 		      void *buf, int len, int write);
698 
699 	/* Called by the /proc/PID/maps code to ask the vma whether it
700 	 * has a special name.  Returning non-NULL will also cause this
701 	 * vma to be dumped unconditionally. */
702 	const char *(*name)(struct vm_area_struct *vma);
703 
704 #ifdef CONFIG_NUMA
705 	/*
706 	 * set_policy() op must add a reference to any non-NULL @new mempolicy
707 	 * to hold the policy upon return.  Caller should pass NULL @new to
708 	 * remove a policy and fall back to surrounding context--i.e. do not
709 	 * install a MPOL_DEFAULT policy, nor the task or system default
710 	 * mempolicy.
711 	 */
712 	int (*set_policy)(struct vm_area_struct *vma, struct mempolicy *new);
713 
714 	/*
715 	 * get_policy() op must add reference [mpol_get()] to any policy at
716 	 * (vma,addr) marked as MPOL_SHARED.  The shared policy infrastructure
717 	 * in mm/mempolicy.c will do this automatically.
718 	 * get_policy() must NOT add a ref if the policy at (vma,addr) is not
719 	 * marked as MPOL_SHARED. vma policies are protected by the mmap_lock.
720 	 * If no [shared/vma] mempolicy exists at the addr, get_policy() op
721 	 * must return NULL--i.e., do not "fallback" to task or system default
722 	 * policy.
723 	 */
724 	struct mempolicy *(*get_policy)(struct vm_area_struct *vma,
725 					unsigned long addr, pgoff_t *ilx);
726 #endif
727 #ifdef CONFIG_FIND_NORMAL_PAGE
728 	/*
729 	 * Called by vm_normal_page() for special PTEs in @vma at @addr. This
730 	 * allows for returning a "normal" page from vm_normal_page() even
731 	 * though the PTE indicates that the "struct page" either does not exist
732 	 * or should not be touched: "special".
733 	 *
734 	 * Do not add new users: this really only works when a "normal" page
735 	 * was mapped, but then the PTE got changed to something weird (+
736 	 * marked special) that would not make pte_pfn() identify the originally
737 	 * inserted page.
738 	 */
739 	struct page *(*find_normal_page)(struct vm_area_struct *vma,
740 					 unsigned long addr);
741 #endif /* CONFIG_FIND_NORMAL_PAGE */
742 };
743 
744 struct vm_unmapped_area_info {
745 #define VM_UNMAPPED_AREA_TOPDOWN 1
746 	unsigned long flags;
747 	unsigned long length;
748 	unsigned long low_limit;
749 	unsigned long high_limit;
750 	unsigned long align_mask;
751 	unsigned long align_offset;
752 	unsigned long start_gap;
753 };
754 
755 struct pagetable_move_control {
756 	struct vm_area_struct *old; /* Source VMA. */
757 	struct vm_area_struct *new; /* Destination VMA. */
758 	unsigned long old_addr; /* Address from which the move begins. */
759 	unsigned long old_end; /* Exclusive address at which old range ends. */
760 	unsigned long new_addr; /* Address to move page tables to. */
761 	unsigned long len_in; /* Bytes to remap specified by user. */
762 
763 	bool need_rmap_locks; /* Do rmap locks need to be taken? */
764 	bool for_stack; /* Is this an early temp stack being moved? */
765 };
766 
767 #define PAGETABLE_MOVE(name, old_, new_, old_addr_, new_addr_, len_)	\
768 	struct pagetable_move_control name = {				\
769 		.old = old_,						\
770 		.new = new_,						\
771 		.old_addr = old_addr_,					\
772 		.old_end = (old_addr_) + (len_),			\
773 		.new_addr = new_addr_,					\
774 		.len_in = len_,						\
775 	}
776 
777 static inline void vma_iter_invalidate(struct vma_iterator *vmi)
778 {
779 	mas_pause(&vmi->mas);
780 }
781 
782 static inline pgprot_t pgprot_modify(pgprot_t oldprot, pgprot_t newprot)
783 {
784 	return __pgprot(pgprot_val(oldprot) | pgprot_val(newprot));
785 }
786 
787 static inline pgprot_t vm_get_page_prot(vm_flags_t vm_flags)
788 {
789 	return __pgprot(vm_flags);
790 }
791 
792 static inline bool mm_flags_test(int flag, const struct mm_struct *mm)
793 {
794 	return test_bit(flag, ACCESS_PRIVATE(&mm->flags, __mm_flags));
795 }
796 
797 /*
798  * Copy value to the first system word of VMA flags, non-atomically.
799  *
800  * IMPORTANT: This does not overwrite bytes past the first system word. The
801  * caller must account for this.
802  */
803 static __always_inline void vma_flags_overwrite_word(vma_flags_t *flags,
804 		unsigned long value)
805 {
806 	unsigned long *bitmap = flags->__vma_flags;
807 
808 	bitmap[0] = value;
809 }
810 
811 /*
812  * Copy value to the first system word of VMA flags ONCE, non-atomically.
813  *
814  * IMPORTANT: This does not overwrite bytes past the first system word. The
815  * caller must account for this.
816  */
817 static __always_inline void vma_flags_overwrite_word_once(vma_flags_t *flags,
818 		unsigned long value)
819 {
820 	unsigned long *bitmap = flags->__vma_flags;
821 
822 	WRITE_ONCE(*bitmap, value);
823 }
824 
825 /* Update the first system word of VMA flags setting bits, non-atomically. */
826 static __always_inline void vma_flags_set_word(vma_flags_t *flags,
827 		unsigned long value)
828 {
829 	unsigned long *bitmap = flags->__vma_flags;
830 
831 	*bitmap |= value;
832 }
833 
834 /* Update the first system word of VMA flags clearing bits, non-atomically. */
835 static __always_inline void vma_flags_clear_word(vma_flags_t *flags,
836 		unsigned long value)
837 {
838 	unsigned long *bitmap = flags->__vma_flags;
839 
840 	*bitmap &= ~value;
841 }
842 
843 static __always_inline void vma_flags_clear_all(vma_flags_t *flags)
844 {
845 	bitmap_zero(ACCESS_PRIVATE(flags, __vma_flags), NUM_VMA_FLAG_BITS);
846 }
847 
848 /*
849  * Helper function which converts a vma_flags_t value to a legacy vm_flags_t
850  * value. This is only valid if the input flags value can be expressed in a
851  * system word.
852  *
853  * Will be removed once the conversion to VMA flags is complete.
854  */
855 static __always_inline vm_flags_t vma_flags_to_legacy(vma_flags_t flags)
856 {
857 	return (vm_flags_t)flags.__vma_flags[0];
858 }
859 
860 /*
861  * Helper function which converts a legacy vm_flags_t value to a vma_flags_t
862  * value.
863  *
864  * Will be removed once the conversion to VMA flags is complete.
865  */
866 static __always_inline vma_flags_t legacy_to_vma_flags(vm_flags_t flags)
867 {
868 	vma_flags_t ret = EMPTY_VMA_FLAGS;
869 
870 	vma_flags_overwrite_word(&ret, flags);
871 	return ret;
872 }
873 
874 static __always_inline void vma_flags_set_flag(vma_flags_t *flags,
875 		vma_flag_t bit)
876 {
877 	unsigned long *bitmap = ACCESS_PRIVATE(flags, __vma_flags);
878 
879 	__set_bit((__force int)bit, bitmap);
880 }
881 
882 /* Use when VMA is not part of the VMA tree and needs no locking */
883 static inline void vm_flags_init(struct vm_area_struct *vma,
884 				 vm_flags_t flags)
885 {
886 	vma_flags_clear_all(&vma->flags);
887 	vma_flags_overwrite_word(&vma->flags, flags);
888 }
889 
890 /*
891  * Use when VMA is part of the VMA tree and modifications need coordination
892  * Note: vm_flags_reset and vm_flags_reset_once do not lock the vma and
893  * it should be locked explicitly beforehand.
894  */
895 static inline void vm_flags_reset(struct vm_area_struct *vma,
896 				  vm_flags_t flags)
897 {
898 	vma_assert_write_locked(vma);
899 	vm_flags_init(vma, flags);
900 }
901 
902 static inline void vma_flags_reset_once(struct vm_area_struct *vma,
903 					vma_flags_t *flags)
904 {
905 	const unsigned long word = flags->__vma_flags[0];
906 
907 	/* It is assumed only the first system word must be written once. */
908 	vma_flags_overwrite_word_once(&vma->flags, word);
909 	/* The remainder can be copied normally. */
910 	if (NUM_VMA_FLAG_BITS > BITS_PER_LONG) {
911 		unsigned long *dst = &vma->flags.__vma_flags[1];
912 		const unsigned long *src = &flags->__vma_flags[1];
913 
914 		bitmap_copy(dst, src, NUM_VMA_FLAG_BITS - BITS_PER_LONG);
915 	}
916 }
917 
918 static inline void vm_flags_set(struct vm_area_struct *vma,
919 				vm_flags_t flags)
920 {
921 	vma_start_write(vma);
922 	vma_flags_set_word(&vma->flags, flags);
923 }
924 
925 static inline void vm_flags_clear(struct vm_area_struct *vma,
926 				  vm_flags_t flags)
927 {
928 	vma_start_write(vma);
929 	vma_flags_clear_word(&vma->flags, flags);
930 }
931 
932 static __always_inline vma_flags_t __mk_vma_flags(vma_flags_t flags,
933 		size_t count, const vma_flag_t *bits)
934 {
935 	int i;
936 
937 	for (i = 0; i < count; i++)
938 		vma_flags_set_flag(&flags, bits[i]);
939 	return flags;
940 }
941 
942 #define mk_vma_flags(...) __mk_vma_flags(EMPTY_VMA_FLAGS,			\
943 		COUNT_ARGS(__VA_ARGS__), (const vma_flag_t []){__VA_ARGS__})
944 
945 #define append_vma_flags(flags, ...) __mk_vma_flags(flags,			\
946 		COUNT_ARGS(__VA_ARGS__), (const vma_flag_t []){__VA_ARGS__})
947 
948 static __always_inline int vma_flags_count(const vma_flags_t *flags)
949 {
950 	const unsigned long *bitmap = flags->__vma_flags;
951 
952 	return bitmap_weight(bitmap, NUM_VMA_FLAG_BITS);
953 }
954 
955 static __always_inline bool vma_flags_test(const vma_flags_t *flags,
956 		vma_flag_t bit)
957 {
958 	const unsigned long *bitmap = flags->__vma_flags;
959 
960 	return test_bit((__force int)bit, bitmap);
961 }
962 
963 static __always_inline vma_flags_t vma_flags_and_mask(const vma_flags_t *flags,
964 						      vma_flags_t to_and)
965 {
966 	vma_flags_t dst;
967 	unsigned long *bitmap_dst = dst.__vma_flags;
968 	const unsigned long *bitmap = flags->__vma_flags;
969 	const unsigned long *bitmap_to_and = to_and.__vma_flags;
970 
971 	bitmap_and(bitmap_dst, bitmap, bitmap_to_and, NUM_VMA_FLAG_BITS);
972 	return dst;
973 }
974 
975 #define vma_flags_and(flags, ...)		\
976 	vma_flags_and_mask(flags, mk_vma_flags(__VA_ARGS__))
977 
978 static __always_inline bool vma_flags_test_any_mask(const vma_flags_t *flags,
979 		vma_flags_t to_test)
980 {
981 	const unsigned long *bitmap = flags->__vma_flags;
982 	const unsigned long *bitmap_to_test = to_test.__vma_flags;
983 
984 	return bitmap_intersects(bitmap_to_test, bitmap, NUM_VMA_FLAG_BITS);
985 }
986 
987 #define vma_flags_test_any(flags, ...) \
988 	vma_flags_test_any_mask(flags, mk_vma_flags(__VA_ARGS__))
989 
990 static __always_inline bool vma_flags_test_all_mask(const vma_flags_t *flags,
991 		vma_flags_t to_test)
992 {
993 	const unsigned long *bitmap = flags->__vma_flags;
994 	const unsigned long *bitmap_to_test = to_test.__vma_flags;
995 
996 	return bitmap_subset(bitmap_to_test, bitmap, NUM_VMA_FLAG_BITS);
997 }
998 
999 #define vma_flags_test_all(flags, ...) \
1000 	vma_flags_test_all_mask(flags, mk_vma_flags(__VA_ARGS__))
1001 
1002 static __always_inline bool vma_flags_test_single_mask(const vma_flags_t *flags,
1003 						vma_flags_t flagmask)
1004 {
1005 	VM_WARN_ON_ONCE(vma_flags_count(&flagmask) > 1);
1006 
1007 	return vma_flags_test_any_mask(flags, flagmask);
1008 }
1009 
1010 static __always_inline void vma_flags_set_mask(vma_flags_t *flags, vma_flags_t to_set)
1011 {
1012 	unsigned long *bitmap = flags->__vma_flags;
1013 	const unsigned long *bitmap_to_set = to_set.__vma_flags;
1014 
1015 	bitmap_or(bitmap, bitmap, bitmap_to_set, NUM_VMA_FLAG_BITS);
1016 }
1017 
1018 #define vma_flags_set(flags, ...) \
1019 	vma_flags_set_mask(flags, mk_vma_flags(__VA_ARGS__))
1020 
1021 static __always_inline void vma_flags_clear_mask(vma_flags_t *flags, vma_flags_t to_clear)
1022 {
1023 	unsigned long *bitmap = flags->__vma_flags;
1024 	const unsigned long *bitmap_to_clear = to_clear.__vma_flags;
1025 
1026 	bitmap_andnot(bitmap, bitmap, bitmap_to_clear, NUM_VMA_FLAG_BITS);
1027 }
1028 
1029 #define vma_flags_clear(flags, ...) \
1030 	vma_flags_clear_mask(flags, mk_vma_flags(__VA_ARGS__))
1031 
1032 static __always_inline vma_flags_t vma_flags_diff_pair(const vma_flags_t *flags,
1033 		const vma_flags_t *flags_other)
1034 {
1035 	vma_flags_t dst;
1036 	const unsigned long *bitmap_other = flags_other->__vma_flags;
1037 	const unsigned long *bitmap = flags->__vma_flags;
1038 	unsigned long *bitmap_dst = dst.__vma_flags;
1039 
1040 	bitmap_xor(bitmap_dst, bitmap, bitmap_other, NUM_VMA_FLAG_BITS);
1041 	return dst;
1042 }
1043 
1044 static __always_inline bool vma_flags_same_pair(const vma_flags_t *flags,
1045 						const vma_flags_t *flags_other)
1046 {
1047 	const unsigned long *bitmap = flags->__vma_flags;
1048 	const unsigned long *bitmap_other = flags_other->__vma_flags;
1049 
1050 	return bitmap_equal(bitmap, bitmap_other, NUM_VMA_FLAG_BITS);
1051 }
1052 
1053 static __always_inline bool vma_flags_same_mask(const vma_flags_t *flags,
1054 						vma_flags_t flags_other)
1055 {
1056 	const unsigned long *bitmap = flags->__vma_flags;
1057 	const unsigned long *bitmap_other = flags_other.__vma_flags;
1058 
1059 	return bitmap_equal(bitmap, bitmap_other, NUM_VMA_FLAG_BITS);
1060 }
1061 
1062 #define vma_flags_same(flags, ...) \
1063 	vma_flags_same_mask(flags, mk_vma_flags(__VA_ARGS__))
1064 
1065 static __always_inline bool vma_test(const struct vm_area_struct *vma,
1066 		vma_flag_t bit)
1067 {
1068 	return vma_flags_test(&vma->flags, bit);
1069 }
1070 
1071 static __always_inline bool vma_test_any_mask(const struct vm_area_struct *vma,
1072 		vma_flags_t flags)
1073 {
1074 	return vma_flags_test_any_mask(&vma->flags, flags);
1075 }
1076 
1077 #define vma_test_any(vma, ...) \
1078 	vma_test_any_mask(vma, mk_vma_flags(__VA_ARGS__))
1079 
1080 static __always_inline bool vma_test_all_mask(const struct vm_area_struct *vma,
1081 		vma_flags_t flags)
1082 {
1083 	return vma_flags_test_all_mask(&vma->flags, flags);
1084 }
1085 
1086 #define vma_test_all(vma, ...) \
1087 	vma_test_all_mask(vma, mk_vma_flags(__VA_ARGS__))
1088 
1089 static __always_inline bool
1090 vma_test_single_mask(const struct vm_area_struct *vma, vma_flags_t flagmask)
1091 {
1092 	return vma_flags_test_single_mask(&vma->flags, flagmask);
1093 }
1094 
1095 static __always_inline void vma_set_flags_mask(struct vm_area_struct *vma,
1096 		vma_flags_t flags)
1097 {
1098 	vma_flags_set_mask(&vma->flags, flags);
1099 }
1100 
1101 #define vma_set_flags(vma, ...) \
1102 	vma_set_flags_mask(vma, mk_vma_flags(__VA_ARGS__))
1103 
1104 static __always_inline void vma_clear_flags_mask(struct vm_area_struct *vma,
1105 		vma_flags_t flags)
1106 {
1107 	vma_flags_clear_mask(&vma->flags, flags);
1108 }
1109 
1110 #define vma_clear_flags(vma, ...) \
1111 	vma_clear_flags_mask(vma, mk_vma_flags(__VA_ARGS__))
1112 
1113 static __always_inline bool vma_desc_test(const struct vm_area_desc *desc,
1114 		vma_flag_t bit)
1115 {
1116 	return vma_flags_test(&desc->vma_flags, bit);
1117 }
1118 
1119 static __always_inline bool vma_desc_test_any_mask(const struct vm_area_desc *desc,
1120 		vma_flags_t flags)
1121 {
1122 	return vma_flags_test_any_mask(&desc->vma_flags, flags);
1123 }
1124 
1125 #define vma_desc_test_any(desc, ...) \
1126 	vma_desc_test_any_mask(desc, mk_vma_flags(__VA_ARGS__))
1127 
1128 static __always_inline bool vma_desc_test_all_mask(const struct vm_area_desc *desc,
1129 		vma_flags_t flags)
1130 {
1131 	return vma_flags_test_all_mask(&desc->vma_flags, flags);
1132 }
1133 
1134 #define vma_desc_test_all(desc, ...) \
1135 	vma_desc_test_all_mask(desc, mk_vma_flags(__VA_ARGS__))
1136 
1137 static __always_inline void vma_desc_set_flags_mask(struct vm_area_desc *desc,
1138 		vma_flags_t flags)
1139 {
1140 	vma_flags_set_mask(&desc->vma_flags, flags);
1141 }
1142 
1143 #define vma_desc_set_flags(desc, ...) \
1144 	vma_desc_set_flags_mask(desc, mk_vma_flags(__VA_ARGS__))
1145 
1146 static __always_inline void vma_desc_clear_flags_mask(struct vm_area_desc *desc,
1147 		vma_flags_t flags)
1148 {
1149 	vma_flags_clear_mask(&desc->vma_flags, flags);
1150 }
1151 
1152 #define vma_desc_clear_flags(desc, ...) \
1153 	vma_desc_clear_flags_mask(desc, mk_vma_flags(__VA_ARGS__))
1154 
1155 static inline bool is_shared_maywrite(const vma_flags_t *flags)
1156 {
1157 	return vma_flags_test_all(flags, VMA_SHARED_BIT, VMA_MAYWRITE_BIT);
1158 }
1159 
1160 static inline bool vma_is_shared_maywrite(struct vm_area_struct *vma)
1161 {
1162 	return is_shared_maywrite(&vma->flags);
1163 }
1164 
1165 static inline bool vma_flags_is_cow_mapping(const vma_flags_t *flags)
1166 {
1167 	return vma_flags_test(flags, VMA_MAYWRITE_BIT) &&
1168 		!vma_flags_test(flags, VMA_SHARED_BIT);
1169 }
1170 
1171 static inline bool vma_is_cow_mapping(const struct vm_area_struct *vma)
1172 {
1173 	return vma_flags_is_cow_mapping(&vma->flags);
1174 }
1175 
1176 static inline struct vm_area_struct *vma_next(struct vma_iterator *vmi)
1177 {
1178 	/*
1179 	 * Uses mas_find() to get the first VMA when the iterator starts.
1180 	 * Calling mas_next() could skip the first entry.
1181 	 */
1182 	return mas_find(&vmi->mas, ULONG_MAX);
1183 }
1184 
1185 static inline bool vma_is_attached(struct vm_area_struct *vma)
1186 {
1187 	return refcount_read(&vma->vm_refcnt);
1188 }
1189 
1190 /*
1191  * WARNING: to avoid racing with vma_mark_attached()/vma_mark_detached(), these
1192  * assertions should be made either under mmap_write_lock or when the object
1193  * has been isolated under mmap_write_lock, ensuring no competing writers.
1194  */
1195 static inline void vma_assert_attached(struct vm_area_struct *vma)
1196 {
1197 	WARN_ON_ONCE(!vma_is_attached(vma));
1198 }
1199 
1200 static inline void vma_assert_detached(struct vm_area_struct *vma)
1201 {
1202 	WARN_ON_ONCE(vma_is_attached(vma));
1203 }
1204 
1205 static inline void vma_assert_write_locked(struct vm_area_struct *);
1206 static inline void vma_mark_attached(struct vm_area_struct *vma)
1207 {
1208 	vma_assert_write_locked(vma);
1209 	vma_assert_detached(vma);
1210 	refcount_set_release(&vma->vm_refcnt, 1);
1211 }
1212 
1213 static inline void vma_mark_detached(struct vm_area_struct *vma)
1214 {
1215 	vma_assert_write_locked(vma);
1216 	vma_assert_attached(vma);
1217 	/* We are the only writer, so no need to use vma_refcount_put(). */
1218 	if (unlikely(!refcount_dec_and_test(&vma->vm_refcnt))) {
1219 		/*
1220 		 * Reader must have temporarily raised vm_refcnt but it will
1221 		 * drop it without using the vma since vma is write-locked.
1222 		 */
1223 	}
1224 }
1225 
1226 static inline void vma_init(struct vm_area_struct *vma, struct mm_struct *mm)
1227 {
1228 	memset(vma, 0, sizeof(*vma));
1229 	vma->vm_mm = mm;
1230 	vma->vm_ops = &vma_dummy_vm_ops;
1231 	INIT_LIST_HEAD(&vma->anon_vma_chain);
1232 	vma->vm_lock_seq = UINT_MAX;
1233 }
1234 
1235 /*
1236  * These are defined in vma.h, but sadly vm_stat_account() is referenced by
1237  * kernel/fork.c, so we have to these broadly available there, and temporarily
1238  * define them here to resolve the dependency cycle.
1239  */
1240 #define is_exec_mapping(flags) \
1241 	((flags & (VM_EXEC | VM_WRITE | VM_STACK)) == VM_EXEC)
1242 
1243 #define is_stack_mapping(flags) \
1244 	(((flags & VM_STACK) == VM_STACK) || (flags & VM_SHADOW_STACK))
1245 
1246 #define is_data_mapping(flags) \
1247 	((flags & (VM_WRITE | VM_SHARED | VM_STACK)) == VM_WRITE)
1248 
1249 static inline void vm_stat_account(struct mm_struct *mm, vm_flags_t flags,
1250 				   long npages)
1251 {
1252 	WRITE_ONCE(mm->total_vm, READ_ONCE(mm->total_vm)+npages);
1253 
1254 	if (is_exec_mapping(flags))
1255 		mm->exec_vm += npages;
1256 	else if (is_stack_mapping(flags))
1257 		mm->stack_vm += npages;
1258 	else if (is_data_mapping(flags))
1259 		mm->data_vm += npages;
1260 }
1261 
1262 #undef is_exec_mapping
1263 #undef is_stack_mapping
1264 #undef is_data_mapping
1265 
1266 static inline void vm_unacct_memory(long pages)
1267 {
1268 	vm_acct_memory(-pages);
1269 }
1270 
1271 static inline void mapping_allow_writable(struct address_space *mapping)
1272 {
1273 	atomic_inc(&mapping->i_mmap_writable);
1274 }
1275 
1276 static inline
1277 struct vm_area_struct *vma_find(struct vma_iterator *vmi, unsigned long max)
1278 {
1279 	return mas_find(&vmi->mas, max - 1);
1280 }
1281 
1282 static inline int vma_iter_clear_gfp(struct vma_iterator *vmi,
1283 			unsigned long start, unsigned long end, gfp_t gfp)
1284 {
1285 	__mas_set_range(&vmi->mas, start, end - 1);
1286 	mas_store_gfp(&vmi->mas, NULL, gfp);
1287 	if (unlikely(mas_is_err(&vmi->mas)))
1288 		return -ENOMEM;
1289 
1290 	return 0;
1291 }
1292 
1293 static inline void vma_set_anonymous(struct vm_area_struct *vma)
1294 {
1295 	vma->vm_ops = NULL;
1296 }
1297 
1298 /* Declared in vma.h. */
1299 static inline void compat_set_vma_from_desc(struct vm_area_struct *vma,
1300 		struct vm_area_desc *desc);
1301 
1302 static inline void compat_set_desc_from_vma(struct vm_area_desc *desc,
1303 			      const struct file *file,
1304 			      const struct vm_area_struct *vma)
1305 {
1306 	memset(desc, 0, sizeof(*desc));
1307 
1308 	desc->mm = vma->vm_mm;
1309 	desc->file = (struct file *)file;
1310 	desc->start = vma->vm_start;
1311 	desc->end = vma->vm_end;
1312 
1313 	desc->pgoff = vma->vm_pgoff;
1314 	desc->vm_file = vma->vm_file;
1315 	desc->vma_flags = vma->flags;
1316 	desc->page_prot = vma->vm_page_prot;
1317 	desc->vm_ops = vma->vm_ops;
1318 
1319 	/* Default. */
1320 	desc->action.type = MMAP_NOTHING;
1321 }
1322 
1323 static inline unsigned long vma_pages(const struct vm_area_struct *vma)
1324 {
1325 	return (vma->vm_end - vma->vm_start) >> PAGE_SHIFT;
1326 }
1327 
1328 static inline pgoff_t vma_start_pgoff(const struct vm_area_struct *vma)
1329 {
1330 	return vma->vm_pgoff;
1331 }
1332 
1333 static inline pgoff_t vma_end_pgoff(const struct vm_area_struct *vma)
1334 {
1335 	return vma_start_pgoff(vma) + vma_pages(vma);
1336 }
1337 
1338 static inline pgoff_t vma_start_anon_pgoff(const struct vm_area_struct *vma)
1339 {
1340 	pgoff_t pgoff = 0;
1341 
1342 #ifdef CONFIG_64BIT
1343 	pgoff += vma->__vm_anon_pgoff_hi;
1344 	pgoff <<= 32;
1345 #endif
1346 	pgoff += vma->__vm_anon_pgoff_lo;
1347 	return pgoff;
1348 }
1349 
1350 static inline pgoff_t vma_end_anon_pgoff(const struct vm_area_struct *vma)
1351 {
1352 	return vma_start_anon_pgoff(vma) + vma_pages(vma);
1353 }
1354 
1355 static inline pgoff_t vma_last_anon_pgoff(const struct vm_area_struct *vma)
1356 {
1357 	return vma_end_anon_pgoff(vma) - 1;
1358 }
1359 
1360 static inline int vfs_mmap_prepare(struct file *file, struct vm_area_desc *desc)
1361 {
1362 	return file->f_op->mmap_prepare(desc);
1363 }
1364 
1365 static inline int __compat_vma_mmap(struct vm_area_desc *desc,
1366 		struct vm_area_struct *vma)
1367 {
1368 	int err;
1369 
1370 	/* Perform any preparatory tasks for mmap action. */
1371 	err = mmap_action_prepare(desc);
1372 	if (err)
1373 		return err;
1374 	/* Update the VMA from the descriptor. */
1375 	compat_set_vma_from_desc(vma, desc);
1376 	/* Complete any specified mmap actions. */
1377 	return mmap_action_complete(vma, &desc->action, /*is_compat=*/true);
1378 }
1379 
1380 static inline int compat_vma_mmap(struct file *file, struct vm_area_struct *vma)
1381 {
1382 	struct vm_area_desc desc;
1383 	struct mmap_action *action;
1384 	int err;
1385 
1386 	compat_set_desc_from_vma(&desc, file, vma);
1387 	err = vfs_mmap_prepare(file, &desc);
1388 	if (err)
1389 		return err;
1390 	action = &desc.action;
1391 
1392 	/* being invoked from .mmmap means we don't have to enforce this. */
1393 	action->hide_from_rmap_until_complete = false;
1394 
1395 	return __compat_vma_mmap(&desc, vma);
1396 }
1397 
1398 static inline void vma_iter_init(struct vma_iterator *vmi,
1399 		struct mm_struct *mm, unsigned long addr)
1400 {
1401 	mas_init(&vmi->mas, &mm->mm_mt, addr);
1402 }
1403 
1404 static inline void mmap_assert_locked(struct mm_struct *);
1405 static inline struct vm_area_struct *find_vma_intersection(struct mm_struct *mm,
1406 						unsigned long start_addr,
1407 						unsigned long end_addr)
1408 {
1409 	unsigned long index = start_addr;
1410 
1411 	mmap_assert_locked(mm);
1412 	return mt_find(&mm->mm_mt, &index, end_addr - 1);
1413 }
1414 
1415 static inline
1416 struct vm_area_struct *vma_lookup(struct mm_struct *mm, unsigned long addr)
1417 {
1418 	return mtree_load(&mm->mm_mt, addr);
1419 }
1420 
1421 static inline struct vm_area_struct *vma_prev(struct vma_iterator *vmi)
1422 {
1423 	return mas_prev(&vmi->mas, 0);
1424 }
1425 
1426 static inline void vma_iter_set(struct vma_iterator *vmi, unsigned long addr)
1427 {
1428 	mas_set(&vmi->mas, addr);
1429 }
1430 
1431 static inline bool vma_is_anonymous(const struct vm_area_struct *vma)
1432 {
1433 	return !vma->vm_ops;
1434 }
1435 
1436 /* Defined in vma.h, so temporarily define here to avoid circular dependency. */
1437 #define vma_iter_load(vmi) \
1438 	mas_walk(&(vmi)->mas)
1439 
1440 static inline struct vm_area_struct *
1441 find_vma_prev(struct mm_struct *mm, unsigned long addr,
1442 			struct vm_area_struct **pprev)
1443 {
1444 	struct vm_area_struct *vma;
1445 	VMA_ITERATOR(vmi, mm, addr);
1446 
1447 	vma = vma_iter_load(&vmi);
1448 	*pprev = vma_prev(&vmi);
1449 	if (!vma)
1450 		vma = vma_next(&vmi);
1451 	return vma;
1452 }
1453 
1454 #undef vma_iter_load
1455 
1456 static inline void vma_iter_free(struct vma_iterator *vmi)
1457 {
1458 	mas_destroy(&vmi->mas);
1459 }
1460 
1461 static inline
1462 struct vm_area_struct *vma_iter_next_range(struct vma_iterator *vmi)
1463 {
1464 	return mas_next_range(&vmi->mas, ULONG_MAX);
1465 }
1466 
1467 bool vma_wants_writenotify(struct vm_area_struct *vma, pgprot_t vm_page_prot);
1468 
1469 /* Update vma->vm_page_prot to reflect vma->vm_flags. */
1470 static inline void vma_set_page_prot(struct vm_area_struct *vma)
1471 {
1472 	vm_flags_t vm_flags = vma->vm_flags;
1473 	pgprot_t vm_page_prot;
1474 
1475 	/* testing: we inline vm_pgprot_modify() to avoid clash with vma.h. */
1476 	vm_page_prot = pgprot_modify(vma->vm_page_prot, vm_get_page_prot(vm_flags));
1477 
1478 	if (vma_wants_writenotify(vma, vm_page_prot)) {
1479 		vm_flags &= ~VM_SHARED;
1480 		/* testing: we inline vm_pgprot_modify() to avoid clash with vma.h. */
1481 		vm_page_prot = pgprot_modify(vm_page_prot, vm_get_page_prot(vm_flags));
1482 	}
1483 	/* remove_protection_ptes reads vma->vm_page_prot without mmap_lock */
1484 	WRITE_ONCE(vma->vm_page_prot, vm_page_prot);
1485 }
1486 
1487 static inline unsigned long stack_guard_start_gap(struct vm_area_struct *vma)
1488 {
1489 	if (vma->vm_flags & VM_GROWSDOWN)
1490 		return stack_guard_gap;
1491 
1492 	/* See reasoning around the VM_SHADOW_STACK definition */
1493 	if (vma->vm_flags & VM_SHADOW_STACK)
1494 		return PAGE_SIZE;
1495 
1496 	return 0;
1497 }
1498 
1499 static inline unsigned long vm_start_gap(struct vm_area_struct *vma)
1500 {
1501 	unsigned long gap = stack_guard_start_gap(vma);
1502 	unsigned long vm_start = vma->vm_start;
1503 
1504 	vm_start -= gap;
1505 	if (vm_start > vma->vm_start)
1506 		vm_start = 0;
1507 	return vm_start;
1508 }
1509 
1510 static inline unsigned long vm_end_gap(struct vm_area_struct *vma)
1511 {
1512 	unsigned long vm_end = vma->vm_end;
1513 
1514 	if (vma->vm_flags & VM_GROWSUP) {
1515 		vm_end += stack_guard_gap;
1516 		if (vm_end < vma->vm_end)
1517 			vm_end = -PAGE_SIZE;
1518 	}
1519 	return vm_end;
1520 }
1521 
1522 static inline bool vma_is_accessible(struct vm_area_struct *vma)
1523 {
1524 	return vma->vm_flags & VM_ACCESS_FLAGS;
1525 }
1526 
1527 static inline bool mlock_future_ok(const struct mm_struct *mm,
1528 		vm_flags_t vm_flags, unsigned long bytes)
1529 {
1530 	unsigned long locked_pages, limit_pages;
1531 
1532 	if (!(vm_flags & VM_LOCKED) || capable(CAP_IPC_LOCK))
1533 		return true;
1534 
1535 	locked_pages = bytes >> PAGE_SHIFT;
1536 	locked_pages += mm->locked_vm;
1537 
1538 	limit_pages = rlimit(RLIMIT_MEMLOCK);
1539 	limit_pages >>= PAGE_SHIFT;
1540 
1541 	return locked_pages <= limit_pages;
1542 }
1543 
1544 static inline int mapping_map_writable(struct address_space *mapping)
1545 {
1546 	return atomic_inc_unless_negative(&mapping->i_mmap_writable) ?
1547 		0 : -EPERM;
1548 }
1549 
1550 /* Did the driver provide valid mmap hook configuration? */
1551 static inline bool can_mmap_file(struct file *file)
1552 {
1553 	bool has_mmap = file->f_op->mmap;
1554 	bool has_mmap_prepare = file->f_op->mmap_prepare;
1555 
1556 	/* Hooks are mutually exclusive. */
1557 	if (WARN_ON_ONCE(has_mmap && has_mmap_prepare))
1558 		return false;
1559 	if (!has_mmap && !has_mmap_prepare)
1560 		return false;
1561 
1562 	return true;
1563 }
1564 
1565 static inline int vfs_mmap(struct file *file, struct vm_area_struct *vma)
1566 {
1567 	if (file->f_op->mmap_prepare)
1568 		return compat_vma_mmap(file, vma);
1569 
1570 	return file->f_op->mmap(file, vma);
1571 }
1572 
1573 static inline void vma_set_file(struct vm_area_struct *vma, struct file *file)
1574 {
1575 	/* Changing an anonymous vma with this is illegal */
1576 	get_file(file);
1577 	swap(vma->vm_file, file);
1578 	fput(file);
1579 }
1580 
1581 extern int sysctl_max_map_count;
1582 static inline int get_sysctl_max_map_count(void)
1583 {
1584 	return READ_ONCE(sysctl_max_map_count);
1585 }
1586 
1587 #ifndef pgtable_supports_soft_dirty
1588 #define pgtable_supports_soft_dirty()	IS_ENABLED(CONFIG_MEM_SOFT_DIRTY)
1589 #endif
1590 
1591 static inline pgprot_t vma_flags_to_page_prot(vma_flags_t vma_flags)
1592 {
1593 	const vm_flags_t vm_flags = vma_flags_to_legacy(vma_flags);
1594 
1595 	return vm_get_page_prot(vm_flags);
1596 }
1597 
1598 static inline pgoff_t linear_page_delta(const struct vm_area_struct *vma,
1599 					const unsigned long address)
1600 {
1601 	return (address - vma->vm_start) >> PAGE_SHIFT;
1602 }
1603 
1604 static inline pgoff_t linear_page_index(const struct vm_area_struct *vma,
1605 					const unsigned long address)
1606 {
1607 	pgoff_t pgoff;
1608 
1609 	pgoff = linear_page_delta(vma, address);
1610 	pgoff += vma_start_pgoff(vma);
1611 	return pgoff;
1612 }
1613 
1614 static inline void vma_assert_can_modify(struct vm_area_struct *vma)
1615 {
1616 	if (vma_is_attached(vma))
1617 		vma_assert_write_locked(vma);
1618 }
1619 
1620 static inline pgprot_t vma_get_page_prot(const struct vm_area_struct *vma)
1621 {
1622 	return vma_flags_to_page_prot(vma->flags);
1623 }
1624 
1625 static inline pgoff_t __linear_anon_page_index(const struct vm_area_struct *vma,
1626 					       const unsigned long address)
1627 {
1628 	pgoff_t pgoff;
1629 
1630 	pgoff = linear_page_delta(vma, address);
1631 	pgoff += vma_start_anon_pgoff(vma);
1632 	return pgoff;
1633 }
1634 
1635 static inline pgoff_t linear_anon_page_index(const struct vm_area_struct *vma,
1636 		const unsigned long address)
1637 {
1638 	const pgoff_t pgoff = __linear_anon_page_index(vma, address);
1639 
1640 	VM_WARN_ON_ONCE(!vma_is_cow_mapping(vma));
1641 	/* Account for MAP_PRIVATE-/dev/zero which is only semi-anonymous. */
1642 	if (vma_is_anonymous(vma) && !vma->vm_file)
1643 		VM_WARN_ON_ONCE(pgoff != linear_page_index(vma, address));
1644 
1645 	return pgoff;
1646 }
1647