ANDROID: BACKPORT: KVM: arm64: Let modules specify arbitrary permissions for host pages Currently pKVM modules can only restrict the host stage-2 permissions of some pages with no way of relaxing them later on. Also, modules lack the ability to unmap pages from the host without mapping them in the hypervisor as they only have access to the host-to-hyp-donation path. In order to give modules more flexibility, make the hyp_protect_host_page() function a lot more generic by allowing it to relax permissions as well as "map" with !R!W!X. BACKPORT: Bring in the 'final' version of module_change_host_page_prot() ignoring the IOMMU stuff Bug: 458241298 Signed-off-by: Quentin Perret <qperret@google.com> Signed-off-by: Fuad Tabba <tabba@google.com> Change-Id: Id6751fe147ea8b86a416a1c3326a2d75f04b623d (cherry picked from commit 1d6cfb19388aaca36a2e3ebf4fa68610313d6b7c) [tabba@: Carry-rebased onto the base's owner-PTE encoding. The base annotates non-host owners with the typed KVM_HOST_INVALID_PTE_TYPE_DONATION (owner in [3:1], meta in [59:4]) via host_stage2_set_owner_metadata_locked(), not A17's kvm_init_invalid_leaf_owner()/KVM_INVALID_PTE_OWNER_MASK. So rather than introduce A17's __host_stage2_set_owner_locked(), extend host_stage2_set_owner_metadata_locked() with the two capabilities 1d6cfb19 adds: an is_memory flag (skip vmemmap page-state tracking for MMIO, which has no hyp_vmemmap) and a nopage_state OR'd into PKVM_NOPAGE. Existing HYP/GUEST callers pass (is_memory=true, nopage_state=0), preserving behaviour. module_change_host_page_prot() routes its PKVM_ID_PROTECTED owner-set through it with nopage_state=PKVM_MODULE_OWNED_PAGE. PKVM_ID_PROTECTED slots into the base's enum; the host-fault guard in host_stage2_adjust_range() denies the host any annotated page regardless of owner value, so module-owned pages inherit host isolation.] Signed-off-by: Fuad Tabba <tabba@google.com> Change-Id: I1b9056b0ee2dd72e6a516ca06703b411d1574682
BEST: Make all of your changes to upstream Linux. If appropriate, backport to the stable releases. These patches will be merged automatically in the corresponding common kernels. If the patch is already in upstream Linux, post a backport of the patch that conforms to the patch requirements below.
EXPORT_SYMBOL_GPL() require an in-tree modular driver that uses the symbol -- so include the new driver or changes to an existing driver in the same patchset as the export.LESS GOOD: Develop your patches out-of-tree (from an upstream Linux point-of-view). Unless these are fixing an Android-specific bug, these are very unlikely to be accepted unless they have been coordinated with kernel-team@android.com. If you want to proceed, post a patch that conforms to the patch requirements below.
scripts/checkpatch.plUPSTREAM:, BACKPORT:, FROMGIT:, FROMLIST:, or ANDROID:.Change-Id: tag (see https://gerrit-review.googlesource.com/Documentation/user-changeid.html)Bug: tag.Signed-off-by: tag by the author and the submitterAdditional requirements are listed below based on patch type
UPSTREAM:, BACKPORT:UPSTREAM:.(cherry picked from commit ...) lineBug:, Change-Id:, etc.) at the end to keep the chronological order. important patch from upstream
This is the detailed description of the important patch
Signed-off-by: Fred Jones <fred.jones@foo.org>
- then Joe Smith would upload the patch for the common kernel as
UPSTREAM: important patch from upstream
This is the detailed description of the important patch
Signed-off-by: Fred Jones <fred.jones@foo.org>
Bug: 135791357
Change-Id: I4caaaa566ea080fa148c5e768bb1a0b6f7201c01
(cherry picked from commit c31e73121f4c1ec41143423ac6ce3ce6dafdcec1)
Signed-off-by: Joe Smith <joe.smith@foo.org>
BACKPORT: instead of UPSTREAM:.UPSTREAM:(cherry picked from commit ...) line BACKPORT: important patch from upstream
This is the detailed description of the important patch
Signed-off-by: Fred Jones <fred.jones@foo.org>
Bug: 135791357
Change-Id: I4caaaa566ea080fa148c5e768bb1a0b6f7201c01
(cherry picked from commit c31e73121f4c1ec41143423ac6ce3ce6dafdcec1)
[joe: Resolved minor conflict in drivers/foo/bar.c ]
Signed-off-by: Joe Smith <joe.smith@foo.org>
FROMGIT:, FROMLIST:,FROMGIT:(cherry picked from commit <sha1> <repo> <branch>). This must be a branch on a tree which is normally merged into Linus‘s tree and is not rebased. For example, don’t use linux-next which is rebased and never directly merged into Linus‘s tree, but you can use SHAs from net or net-next, which are merged into Linus’s tree at various points in the release.BACKPORT: FROMGIT: important patch from upstream
This is the detailed description of the important patch
Signed-off-by: Fred Jones <fred.jones@foo.org>
- then Joe Smith would upload the patch for the common kernel as
FROMGIT: important patch from upstream
This is the detailed description of the important patch
Signed-off-by: Fred Jones <fred.jones@foo.org>
Bug: 135791357
(cherry picked from commit 878a2fd9de10b03d11d2f622250285c7e63deace
https://git.kernel.org/pub/scm/linux/kernel/git/foo/bar.git test-branch)
Change-Id: I4caaaa566ea080fa148c5e768bb1a0b6f7201c01
Signed-off-by: Joe Smith <joe.smith@foo.org>
FROMLIST:Link: tag with a link to the submittal on lore.kernel.orgBug: tag with the Android bug (required for patches not accepted into a maintainer tree)BACKPORT: FROMLIST: FROMLIST: important patch from upstream
This is the detailed description of the important patch
Signed-off-by: Fred Jones <fred.jones@foo.org>
Bug: 135791357
Link: https://lore.kernel.org/lkml/20190619171517.GA17557@someone.com/
Change-Id: I4caaaa566ea080fa148c5e768bb1a0b6f7201c01
Signed-off-by: Joe Smith <joe.smith@foo.org>
FROMLIST: tag to try to hide this fact. Use the ANDROID: tag as described below as this must be considered as an Android-specific submission, not an upstream submission as the community will not accept these changes as-is.ANDROID:ANDROID:Fixes: tag that cites the patch with the bug ANDROID: fix android-specific bug in foobar.c
This is the detailed description of the important fix
Fixes: 1234abcd2468 ("foobar: add cool feature")
Change-Id: I4caaaa566ea080fa148c5e768bb1a0b6f7201c01
Signed-off-by: Joe Smith <joe.smith@foo.org>
ANDROID:Bug: tag with the Android bug (required for android-specific features)git revert Revert "ANDROID: fix android-specific bug in foobar.c"
This reverts commit a57a7913f53e34c8a8d905444b126b3316146e69.
Reason for revert: Breaks a lot of internal tests
Additional modifications: Resolved merge conflicts
Bug: 135791357
Change-Id: I4caaaa566ea080fa148c5e768bb1a0b6f7201c01
Signed-off-by: Joe Smith <joe.smith@foo.org>