Linux RDMA and InfiniBand development
 help / color / mirror / Atom feed
* [PATCH] RDMA/cxgb4: Do not allow userspace to write the status page
@ 2026-09-26 11:26 Jiale Yao
  2026-09-26 11:32 ` sashiko-bot
  2026-09-29 19:05 ` Leon Romanovsky
  0 siblings, 2 replies; 3+ messages in thread
From: Jiale Yao @ 2026-09-26 11:26 UTC (permalink / raw)
  To: Potnuri Bharat Teja, Jason Gunthorpe, Leon Romanovsky,
	David S. Miller, Steve Wise, linux-rdma, linux-kernel
  Cc: Jiale Yao

The device status page is shared by all userspace contexts and contains
db_off, which the driver updates to control doorbell flow. The rdma-core
provider maps it with PROT_READ, but c4iw_mmap() passes the requested page
protection through when handling CXGB4_MMAP_CONTIG.

A process can therefore request PROT_WRITE directly or later upgrade a
read-only mapping with mprotect() because VM_MAYWRITE remains set. This
lets userspace alter device-wide flow-control state seen by the kernel and
other contexts.

Reject initially writable mappings and clear VM_MAYWRITE before mapping the
page. This preserves the existing read-only userspace ABI.

Fixes: 05eb23893c2c ("cxgb4/iw_cxgb4: Doorbell Drop Avoidance Bug Fixes")
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/infiniband/hw/cxgb4/provider.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/drivers/infiniband/hw/cxgb4/provider.c b/drivers/infiniband/hw/cxgb4/provider.c
index ebe3170a641c..11c2a891f934 100644
--- a/drivers/infiniband/hw/cxgb4/provider.c
+++ b/drivers/infiniband/hw/cxgb4/provider.c
@@ -171,6 +171,11 @@ static int c4iw_mmap(struct ib_ucontext *context, struct vm_area_struct *vma)
 					 len, t4_pgprot_wc(vma->vm_page_prot));
 		break;
 	case CXGB4_MMAP_CONTIG:
+		if (vma->vm_flags & VM_WRITE) {
+			ret = -EPERM;
+			break;
+		}
+		vm_flags_clear(vma, VM_MAYWRITE);
 		ret = io_remap_pfn_range(vma, vma->vm_start,
 					 addr >> PAGE_SHIFT,
 					 len, vma->vm_page_prot);
-- 
2.34.1


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH] RDMA/cxgb4: Do not allow userspace to write the status page
  2026-09-26 11:26 [PATCH] RDMA/cxgb4: Do not allow userspace to write the status page Jiale Yao
@ 2026-09-26 11:32 ` sashiko-bot
  2026-09-29 19:05 ` Leon Romanovsky
  1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-09-26 11:32 UTC (permalink / raw)
  To: Jiale Yao; +Cc: linux-rdma

> The device status page is shared by all userspace contexts and contains
> db_off, which the driver updates to control doorbell flow. The rdma-core
> provider maps it with PROT_READ, but c4iw_mmap() passes the requested page
> protection through when handling CXGB4_MMAP_CONTIG.
> 
> A process can therefore request PROT_WRITE directly or later upgrade a
> read-only mapping with mprotect() because VM_MAYWRITE remains set. This
> lets userspace alter device-wide flow-control state seen by the kernel and
> other contexts.
> 
> Reject initially writable mappings and clear VM_MAYWRITE before mapping the
> page. This preserves the existing read-only userspace ABI.
> 
> Fixes: 05eb23893c2c ("cxgb4/iw_cxgb4: Doorbell Drop Avoidance Bug Fixes")
> Signed-off-by: Jiale Yao <yaojiale02@163.com>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260926112611.3214382-1-yaojiale02@163.com?part=1


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] RDMA/cxgb4: Do not allow userspace to write the status page
  2026-09-26 11:26 [PATCH] RDMA/cxgb4: Do not allow userspace to write the status page Jiale Yao
  2026-09-26 11:32 ` sashiko-bot
@ 2026-09-29 19:05 ` Leon Romanovsky
  1 sibling, 0 replies; 3+ messages in thread
From: Leon Romanovsky @ 2026-09-29 19:05 UTC (permalink / raw)
  To: Potnuri Bharat Teja, Jason Gunthorpe, David S. Miller, Steve Wise,
	linux-rdma, linux-kernel, Jiale Yao


On Sat, 26 Sep 2026 19:26:11 +0800, Jiale Yao wrote:
> The device status page is shared by all userspace contexts and contains
> db_off, which the driver updates to control doorbell flow. The rdma-core
> provider maps it with PROT_READ, but c4iw_mmap() passes the requested page
> protection through when handling CXGB4_MMAP_CONTIG.
> 
> A process can therefore request PROT_WRITE directly or later upgrade a
> read-only mapping with mprotect() because VM_MAYWRITE remains set. This
> lets userspace alter device-wide flow-control state seen by the kernel and
> other contexts.
> 
> [...]

Applied, thanks!

[1/1] RDMA/cxgb4: Do not allow userspace to write the status page
      https://git.kernel.org/rdma/rdma/c/1c5335a6902639

Best regards,
-- 
Leon Romanovsky <leon@kernel.org>


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-29 19:05 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-26 11:26 [PATCH] RDMA/cxgb4: Do not allow userspace to write the status page Jiale Yao
2026-09-26 11:32 ` sashiko-bot
2026-09-29 19:05 ` Leon Romanovsky

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox