]> git.proxmox.com Git - pve-kernel.git/blame - patches/kernel/0012-revert-memfd-improve-userspace-warnings-for-missing-.patch
cherry-pick 6.5.11 stable release
[pve-kernel.git] / patches / kernel / 0012-revert-memfd-improve-userspace-warnings-for-missing-.patch
CommitLineData
8f06837c
TL
1From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
2From: Thomas Lamprecht <t.lamprecht@proxmox.com>
3Date: Mon, 6 Nov 2023 10:17:02 +0100
4Subject: [PATCH] revert "memfd: improve userspace warnings for missing
5 exec-related flags".
6
7This warning is telling userspace developers to pass MFD_EXEC and
8MFD_NOEXEC_SEAL to memfd_create(). Commit 434ed3350f57 ("memfd: improve
9userspace warnings for missing exec-related flags") made the warning more
10frequent and visible in the hope that this would accelerate the fixing of
11errant userspace.
12
13But the overall effect is to generate far too much dmesg noise.
14
15Fixes: 434ed3350f57 ("memfd: improve userspace warnings for missing exec-related flags")
16Reported-by: Damian Tometzki <dtometzki@fedoraproject.org>
17Closes: https://lkml.kernel.org/r/ZPFzCSIgZ4QuHsSC@fedora.fritz.box
18Cc: Aleksa Sarai <cyphar@cyphar.com>
19Cc: Christian Brauner <brauner@kernel.org>
20Cc: Daniel Verkamp <dverkamp@chromium.org>
21Cc: Jeff Xu <jeffxu@google.com>
22Cc: Kees Cook <keescook@chromium.org>
23Cc: Shuah Khan <shuah@kernel.org>
24Cc: <stable@vger.kernel.org>
25Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
26 (cherry picked from commit 2562d67b1bdf91c7395b0225d60fdeb26b4bc5a0)
27Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
28---
29 mm/memfd.c | 2 +-
30 1 file changed, 1 insertion(+), 1 deletion(-)
31
32diff --git a/mm/memfd.c b/mm/memfd.c
33index 2dba2cb6f0d0..1c077e98e116 100644
34--- a/mm/memfd.c
35+++ b/mm/memfd.c
36@@ -282,7 +282,7 @@ static int check_sysctl_memfd_noexec(unsigned int *flags)
37 }
38
39 if (!(*flags & MFD_NOEXEC_SEAL) && sysctl >= MEMFD_NOEXEC_SCOPE_NOEXEC_ENFORCED) {
40- pr_err_ratelimited(
41+ pr_warn_once(
42 "%s[%d]: memfd_create() requires MFD_NOEXEC_SEAL with vm.memfd_noexec=%d\n",
43 current->comm, task_pid_nr(current), sysctl);
44 return -EACCES;