mirror of
https://github.com/netbirdio/gvisor.git
synced 2026-05-22 17:12:49 -07:00
memmap.Mappable.Translate() is passed a hostarch.AccessType indicating what permissions are *immediately* required; it returns permissions in memmap.Translation.Perms that are granted *to MM* until invalidation. MM ensures that the permissions granted to the application are the intersection of those granted by Translate, and those granted by VMA permissions; see determination of pma.effectivePerms in mm.MemoryManager.getPMAsInternalLocked(). This mechanism is used to avoid marking pages dirty in the sentry's page cache for gofer-backed files until PROT_WRITE pages are actually written to; see gofer.dentry.Translate(). In most other cases, granting all supported permissions (to MM) up-front avoids a redundant page fault for pages that are touched first for reading, and later for writing. Also: - Prevent PROT_WRITE mappings of erofs files at mmap()/mprotect() time, rather than raising SIGBUS when writing to such mappings. - Map nvproxy.frontendFD with PlatformEffectPopulate. This is the original goal of this CL; however, before this rest of this CL, MM.MMap() => MM.populateVMAAndUnlock() => MM.getPMAsLocked(at=hostarch.NoAccess) => MM.getPMAsInternalLocked(at=hostarch.NoAccess) => nvproxy.frontendFD.Translate(at=hostarch.NoAccess) returns Translations with no permissions, causing MM.mapASLocked() to no-op. PiperOrigin-RevId: 679360594