Received: by 2002:ac0:950c:0:0:0:0:0 with SMTP id f12csp4192959imc; Thu, 14 Mar 2019 14:50:33 -0700 (PDT) X-Google-Smtp-Source: APXvYqxDJ/1/9Ol0Tt8JYjPGixAl6unoyOKVuZj52i7xgaefmBIx40R3sYTx+kVQ2vHMeTW3KpbQ X-Received: by 2002:a17:902:ab8e:: with SMTP id f14mr574504plr.84.1552600233519; Thu, 14 Mar 2019 14:50:33 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1552600233; cv=none; d=google.com; s=arc-20160816; b=F9ERiJlhhyh/E2fyCxiNgGm7t7tk0xO4Vvwn/nVOGY3XyfcwiEpsMGA4Zyx++WhSjg 5yWISwLcMPMk63fBXsLO1nA9hwKH97hg1FHPsZopt5sE1LCp3q0J3OCdeFG/lJgQ1wqc 10Sh4ztGR12yTIWvkbU+uY8Q38ELYU8pAQQxipAEBe4sdOlUIRBQWlEjTStvq5+JFK0w CJaNfilArzYoctckwKRNseDR5QzccyeeOhbTLPVgO3ZOACYrGIr2mrkXrE21/rkBV3tl sxApeiT/lBSvInGVuEy58eKoGMqBnDyms+JLsLymNSYx9IHoaiAQLx9Q8O4YBywmowMu wW7g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :dkim-signature; bh=R07u5PMAtEqJ4n0ZpRT11CGSzmXWRh5bYhsMopnK+pw=; b=nqW/II9edTVEWe9tXazwF9icG/4sbZAdD5/BDUkIw36NIJ6q/HyvuTndBm9XA5EKIB FL/MiTFxxZ8k0/mkToTbYmbFHwFzQ+d+7VPogzh5kp9A99KA+9bRf4/t2bru5IdZD+ce B6dJLXmucxwYzGOkLBJrWzlCNNPNz5AiP6A41J4TpQZrEObuA7NtgjieAGEa4i6CQeCp CafTYhMMnlhkYBhvEYQGxpe6tw9fitPSTxqX9GQ9Gqu8eCxoE+pS+MkRKJ8QaLJmXDWr 3HUMv2nM+rWGVgL6HGCe1uv0CjUvGw/Bl7p1Sm5rlWWL110r4otRFcEaKCEBjMB5nZ0C kU8Q== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@joelfernandes.org header.s=google header.b=FOT6Xd0x; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id e16si108249pgv.436.2019.03.14.14.50.16; Thu, 14 Mar 2019 14:50:33 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@joelfernandes.org header.s=google header.b=FOT6Xd0x; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1728016AbfCNVtB (ORCPT + 99 others); Thu, 14 Mar 2019 17:49:01 -0400 Received: from mail-qk1-f193.google.com ([209.85.222.193]:33383 "EHLO mail-qk1-f193.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1727915AbfCNVs7 (ORCPT ); Thu, 14 Mar 2019 17:48:59 -0400 Received: by mail-qk1-f193.google.com with SMTP id x9so4345049qkf.0 for ; Thu, 14 Mar 2019 14:48:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=joelfernandes.org; s=google; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=R07u5PMAtEqJ4n0ZpRT11CGSzmXWRh5bYhsMopnK+pw=; b=FOT6Xd0x/fkezE5hgpcd1utWlgralYJufRguBUibbEQEo07fzk8ZY1sZ4ZwS0efX+X MLfYwKLXkP0j9jVr08bvHJNhkbFwWd+Hc7WdwdwydtBVnJlZvk3O7FnLzugM2exCGtoD vhPZIzrBcO93Vjv4XFZgy9cxZUjBw3uGxCkyA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=R07u5PMAtEqJ4n0ZpRT11CGSzmXWRh5bYhsMopnK+pw=; b=XARsJMBLvK1kFbVtTdQ5fBbTxOjNpKN893so1iuMUPJmUkPEGKJ3GxXPpBZpOfHRYs FRjfBHMGLB7tPGISgPThlSEd65RUBj370nfARz2bRTsHiIac80D6pyUMftcr/wSmGFVA Aj0Bo8XDXn+WSq+dSnSy5rzTIbNbGdK/nc11ubxTZEp9pXilX8MoLtZg5L3Gka14oZ13 orlXxKh8Ji6akyG5r+9wZ1SQr2aOVM3mqJ928rdDeQeJm4EVgfTPa+eGTiRzpvvv2azS FZsy1TWNPHsVfTWiJhX29r12L60AmHRvBy1UNnGNDzBtS7EDd+CA1iWkIhEDOpSGTR+r DS/w== X-Gm-Message-State: APjAAAXflE0zIBzC6ltXzh4tlL6DjpnNFHLhgGz/JNFVgNd3ztKC/5H0 HkTLFYOKsanlVu9/zTjKQF6P/JwH484= X-Received: by 2002:a37:50d5:: with SMTP id e204mr428340qkb.26.1552600138133; Thu, 14 Mar 2019 14:48:58 -0700 (PDT) Received: from joelaf.cam.corp.google.com ([2620:0:1004:1100:cca9:fccc:8667:9bdc]) by smtp.gmail.com with ESMTPSA id o19sm96827qkl.65.2019.03.14.14.48.56 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 14 Mar 2019 14:48:57 -0700 (PDT) From: "Joel Fernandes (Google)" To: linux-kernel@vger.kernel.org, mtk.manpages@gmail.com Cc: "Joel Fernandes (Google)" , Andrew Morton , Andy Lutomirski , dancol@google.com, Jann Horn , John Stultz , kernel-team@android.com, linux-api@vger.kernel.org, linux-man@vger.kernel.org, linux-mm@kvack.org, Matthew Wilcox , Mike Kravetz , Shuah Khan , Stephen Rothwell Subject: [PATCH -manpage 1/2] fcntl.2: Update manpage with new memfd F_SEAL_FUTURE_WRITE seal Date: Thu, 14 Mar 2019 17:48:43 -0400 Message-Id: <20190314214844.207430-2-joel@joelfernandes.org> X-Mailer: git-send-email 2.21.0.360.g471c308f928-goog In-Reply-To: <20190314214844.207430-1-joel@joelfernandes.org> References: <20190314214844.207430-1-joel@joelfernandes.org> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org More details of the seal can be found in the LKML patch: https://lore.kernel.org/lkml/20181120052137.74317-1-joel@joelfernandes.org/T/#t Signed-off-by: Joel Fernandes (Google) --- man2/fcntl.2 | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/man2/fcntl.2 b/man2/fcntl.2 index fce4f4c2b3bd..e01e2c075b5b 100644 --- a/man2/fcntl.2 +++ b/man2/fcntl.2 @@ -1525,6 +1525,21 @@ Furthermore, if there are any asynchronous I/O operations .RB ( io_submit (2)) pending on the file, all outstanding writes will be discarded. +.TP +.BR F_SEAL_FUTURE_WRITE +If this seal is set, the contents of the file can be modified only from +existing writeable mappings that were created prior to the seal being set. +Any attempt to create a new writeable mapping on the memfd via +.BR mmap (2) +will fail with +.BR EPERM. +Also any attempts to write to the memfd via +.BR write (2) +will fail with +.BR EPERM. +This is useful in situations where existing writable mapped regions need to be +kept intact while preventing any future writes. For example, to share a +read-only memory buffer to other processes that only the sender can write to. .\" .SS File read/write hints Write lifetime hints can be used to inform the kernel about the relative -- 2.21.0.360.g471c308f928-goog