eb7712
From 1bcf4b3aaf39cedd42bb5b34a81c6044b8a02d5a Mon Sep 17 00:00:00 2001
eb7712
From: =?UTF-8?q?Nikola=20Forr=C3=B3?= <nforro@redhat.com>
eb7712
Date: Tue, 19 Jun 2018 13:13:18 +0200
eb7712
Subject: [PATCH] madvise.2: document MADV_WIPEONFORK and MADV_KEEPONFORK
eb7712
---
eb7712
 man-pages/en/man2/madvise.2 | 39 +++++++++++++++++++++++++++++++++++++
eb7712
 man-pages/man2/madvise.2    | 39 +++++++++++++++++++++++++++++++++++++
eb7712
 2 files changed, 78 insertions(+)
eb7712
eb7712
diff --git a/man-pages/en/man2/madvise.2 b/man-pages/en/man2/madvise.2
eb7712
index 4e693da..8a1c46d 100644
eb7712
--- a/man-pages/en/man2/madvise.2
eb7712
+++ b/man-pages/en/man2/madvise.2
eb7712
@@ -265,6 +265,33 @@ file (see
eb7712
 .BR MADV_DODUMP " (since Linux 3.4)"
eb7712
 Undo the effect of an earlier
eb7712
 .BR MADV_DONTDUMP .
eb7712
+.TP
eb7712
+.BR MADV_WIPEONFORK " (since Linux 4.14)"
eb7712
+.\" commit d2cd9ede6e193dd7d88b6d27399e96229a551b19
eb7712
+Present the child process with zero-filled memory in this range after a
eb7712
+.BR fork (2).
eb7712
+This is useful in forking servers in order to ensure
eb7712
+that sensitive per-process data
eb7712
+(for example, PRNG seeds, cryptographic secrets, and so on)
eb7712
+is not handed to child processes.
eb7712
+.IP
eb7712
+The
eb7712
+.B MADV_WIPEONFORK
eb7712
+operation can be applied only to private anonymous pages (see
eb7712
+.BR mmap (2)).
eb7712
+.IP
eb7712
+Within the child created by
eb7712
+.BR fork (2),
eb7712
+the
eb7712
+.B MADV_WIPEONFORK
eb7712
+setting remains in place on the specified address range.
eb7712
+This setting is cleared during
eb7712
+.BR execve (2).
eb7712
+.TP
eb7712
+.BR MADV_KEEPONFORK " (since Linux 4.14)"
eb7712
+.\" commit d2cd9ede6e193dd7d88b6d27399e96229a551b19
eb7712
+Undo the effect of an earlier
eb7712
+.BR MADV_WIPEONFORK .
eb7712
 .SH RETURN VALUE
eb7712
 On success
eb7712
 .BR madvise ()
eb7712
@@ -308,6 +335,18 @@ but the kernel was not configured with
eb7712
 .BR CONFIG_KSM .
eb7712
 .RE
eb7712
 .TP
eb7712
+.B EINVAL
eb7712
+.I advice
eb7712
+is
eb7712
+.BR MADV_FREE
eb7712
+or
eb7712
+.BR MADV_WIPEONFORK
eb7712
+but the specified address range includes file, Huge TLB,
eb7712
+.BR MAP_SHARED ,
eb7712
+or
eb7712
+.BR VM_PFNMAP
eb7712
+ranges.
eb7712
+.TP
eb7712
 .B EIO
eb7712
 (for
eb7712
 .BR MADV_WILLNEED )
eb7712
diff --git a/man-pages/man2/madvise.2 b/man-pages/man2/madvise.2
eb7712
index 4e693da..8a1c46d 100644
eb7712
--- a/man-pages/man2/madvise.2
eb7712
+++ b/man-pages/man2/madvise.2
eb7712
@@ -265,6 +265,33 @@ file (see
eb7712
 .BR MADV_DODUMP " (since Linux 3.4)"
eb7712
 Undo the effect of an earlier
eb7712
 .BR MADV_DONTDUMP .
eb7712
+.TP
eb7712
+.BR MADV_WIPEONFORK " (since Linux 4.14)"
eb7712
+.\" commit d2cd9ede6e193dd7d88b6d27399e96229a551b19
eb7712
+Present the child process with zero-filled memory in this range after a
eb7712
+.BR fork (2).
eb7712
+This is useful in forking servers in order to ensure
eb7712
+that sensitive per-process data
eb7712
+(for example, PRNG seeds, cryptographic secrets, and so on)
eb7712
+is not handed to child processes.
eb7712
+.IP
eb7712
+The
eb7712
+.B MADV_WIPEONFORK
eb7712
+operation can be applied only to private anonymous pages (see
eb7712
+.BR mmap (2)).
eb7712
+.IP
eb7712
+Within the child created by
eb7712
+.BR fork (2),
eb7712
+the
eb7712
+.B MADV_WIPEONFORK
eb7712
+setting remains in place on the specified address range.
eb7712
+This setting is cleared during
eb7712
+.BR execve (2).
eb7712
+.TP
eb7712
+.BR MADV_KEEPONFORK " (since Linux 4.14)"
eb7712
+.\" commit d2cd9ede6e193dd7d88b6d27399e96229a551b19
eb7712
+Undo the effect of an earlier
eb7712
+.BR MADV_WIPEONFORK .
eb7712
 .SH RETURN VALUE
eb7712
 On success
eb7712
 .BR madvise ()
eb7712
@@ -308,6 +335,18 @@ but the kernel was not configured with
eb7712
 .BR CONFIG_KSM .
eb7712
 .RE
eb7712
 .TP
eb7712
+.B EINVAL
eb7712
+.I advice
eb7712
+is
eb7712
+.BR MADV_FREE
eb7712
+or
eb7712
+.BR MADV_WIPEONFORK
eb7712
+but the specified address range includes file, Huge TLB,
eb7712
+.BR MAP_SHARED ,
eb7712
+or
eb7712
+.BR VM_PFNMAP
eb7712
+ranges.
eb7712
+.TP
eb7712
 .B EIO
eb7712
 (for
eb7712
 .BR MADV_WILLNEED )
eb7712
-- 
eb7712
2.17.1
eb7712