Received: by 2002:ad5:474a:0:0:0:0:0 with SMTP id i10csp231604imu; Mon, 19 Nov 2018 21:27:06 -0800 (PST) X-Google-Smtp-Source: AJdET5dUWy6Lb8Q+zHeSdW9sJLhOmyJMTPULmNxV0offe2YWUnBDKqZIUFeJcpr21iW/YYWKxj7R X-Received: by 2002:a62:6181:: with SMTP id v123-v6mr761328pfb.117.1542691626075; Mon, 19 Nov 2018 21:27:06 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1542691626; cv=none; d=google.com; s=arc-20160816; b=Wl70R/6xY/1p4XhH7WxJEt2L5p4fSYS4Trh4dyzkZ72y/ubWoPo1f4zQUBOWfqHU00 by8da+8dfzXR7n8hicUO2/36HeP6klMTATIXctQ6tXL9y2dlavyYvDcKXJbHJsB1lEe8 ba8cezpaufqUHVcWQWsopd7kMcXY3poqZDvuRUgjeZClA8WtQTHaDbWYSDXsou3xrmY1 UQexJj1de3/8Zp1Zve7+LZ8cZ1jxmdrzlli+cYYkgRsn6MMF1Ly73sveSU22OdlEf14T esQzoDxjInSMY2SexkjNOU13AQ1svJzP4Y9a5fEVoUb01UysudHjrXPhtHwwgcqQ3F/u qiUA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :message-id:date:subject:cc:to:from:dkim-signature; bh=rhPoQZhqgkEYd2R0TR94fBIobE2oIUczJVXl8rOT65A=; b=EijnooM3/gEOw/5qXNE+uOCt9Bpj2DvzXh5A5L52Y97p95+3hMW+GhVSXjHf86QRd0 +QnfONeb0zKUl/8qffsJoEHdtWCvrDJoy1HqmWARrIIzzARVxsLmlrrb6DZb0EsjcqUt C75mE4tSCO+SYHcfa2621pZSHqwdqGjM6CdC2ANpHXSv1kZCXOEZ/94bklAYYvD7OQM+ 9N0k5s5qRN4JMY9DuptbF+WCZqhvSjIETDCSaqS1VxdrNNYStu8AW6lVJmDFz0DwmV3d oDu58v3MUrgOaMW+F9+z/g7ZDUN6PbWSoI9Wk0ICdxt5kHD4fv21mGYLSk/9zWKGtEIB R+gQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@joelfernandes.org header.s=google header.b=d0VOLtUk; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id j13si14102851pgi.227.2018.11.19.21.26.50; Mon, 19 Nov 2018 21:27:06 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@joelfernandes.org header.s=google header.b=d0VOLtUk; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1731068AbeKTPx0 (ORCPT + 99 others); Tue, 20 Nov 2018 10:53:26 -0500 Received: from mail-pl1-f196.google.com ([209.85.214.196]:35949 "EHLO mail-pl1-f196.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726794AbeKTPx0 (ORCPT ); Tue, 20 Nov 2018 10:53:26 -0500 Received: by mail-pl1-f196.google.com with SMTP id y6-v6so416859plt.3 for ; Mon, 19 Nov 2018 21:26:12 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=joelfernandes.org; s=google; h=from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=rhPoQZhqgkEYd2R0TR94fBIobE2oIUczJVXl8rOT65A=; b=d0VOLtUkBjUsWwJ2X8edrqI7xaMpeXVg2YL7CxPVLDyWuMqlVL4fj8yAHE+xG9IZWB 49okWuYT2X7C5NpJe5AjJQqAT6HGfIgHoCDJdB6L2zBwcDKBXsIqKRy9Z9kBBTqJQDNo Zjk7sg0hCinUvDgSYGHPVpQrBpcRqy1qz4ets= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=rhPoQZhqgkEYd2R0TR94fBIobE2oIUczJVXl8rOT65A=; b=V7luFFeVARRm5GAZNixvxWTraumlJvvPEdyyOMQvOwc5vF+IfH+2rK1n9GGwd1P0SU tdMR3z3MwzEAm1PRWWb6/yZ5icnnyNMCw5pq71EIHv1A6ZcsmFoVvLoCaNqi53/rMwYF Y+50ckI9nkuZuHeNIxMO+0Wx8GNe3fYwT3ZF7peERkyiHxjsZ1RKM7jJ78K3kcIAb6DU o7Xd2SA6iCKdN8Z36/voQIySuNwVG0dQgUw3rkyzwqkN2l8eRN2/TmaukwYoZyi2HyFA bGbQ/fV5KBO5nZ+iFx/URZG949de4CiBaANLDmMO3ufAikM2GXunQDmiRMalRjoGh+yP LzMA== X-Gm-Message-State: AA+aEWYsWQXqrI55YjLg9I5Y3PEFJGgQpB4r6ZzzRC3qlxA7KkJ4z6TM /c/sSQdw651rrwOZ17FCOTgHLQ== X-Received: by 2002:a17:902:66e5:: with SMTP id e92-v6mr772902plk.92.1542691572002; Mon, 19 Nov 2018 21:26:12 -0800 (PST) Received: from joelaf.mtv.corp.google.com ([2620:0:1000:1601:3aef:314f:b9ea:889f]) by smtp.gmail.com with ESMTPSA id p6sm20574271pfn.53.2018.11.19.21.26.10 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 19 Nov 2018 21:26:11 -0800 (PST) From: "Joel Fernandes (Google)" To: linux-man@vger.kernel.org Cc: "Joel Fernandes (Google)" , Andrew Morton , Andy Lutomirski , Hugh Dickins , Jann Horn , John Stultz , linux-api@vger.kernel.org, linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org, linux-mm@kvack.org, =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Matthew Wilcox , Mike Kravetz , Shuah Khan , Stephen Rothwell Subject: [PATCH -manpage 1/2] fcntl.2: Update manpage with new memfd F_SEAL_FUTURE_WRITE seal Date: Mon, 19 Nov 2018 21:25:44 -0800 Message-Id: <20181120052545.76560-1-joel@joelfernandes.org> X-Mailer: git-send-email 2.19.1.1215.g8438c0b245-goog MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org More details of the seal can be found in the LKML patch: https://lore.kernel.org/lkml/20181120052137.74317-1-joel@joelfernandes.org/T/#t Signed-off-by: Joel Fernandes (Google) --- man2/fcntl.2 | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/man2/fcntl.2 b/man2/fcntl.2 index 03533d65b49d..54772f94964c 100644 --- a/man2/fcntl.2 +++ b/man2/fcntl.2 @@ -1525,6 +1525,21 @@ Furthermore, if there are any asynchronous I/O operations .RB ( io_submit (2)) pending on the file, all outstanding writes will be discarded. +.TP +.BR F_SEAL_FUTURE_WRITE +If this seal is set, the contents of the file can be modified only from +existing writeable mappings that were created prior to the seal being set. +Any attempt to create a new writeable mapping on the memfd via +.BR mmap (2) +will fail with +.BR EPERM. +Also any attempts to write to the memfd via +.BR write (2) +will fail with +.BR EPERM. +This is useful in situations where existing writable mapped regions need to be +kept intact while preventing any future writes. For example, to share a +read-only memory buffer to other processes that only the sender can write to. .\" .SS File read/write hints Write lifetime hints can be used to inform the kernel about the relative -- 2.19.1.1215.g8438c0b245-goog