* [PATCH] RDMA/cxgb4: Do not allow userspace to write the status page
@ 2026-09-26 11:26 Jiale Yao
2026-09-26 11:32 ` sashiko-bot
2026-09-29 19:05 ` Leon Romanovsky
0 siblings, 2 replies; 3+ messages in thread
From: Jiale Yao @ 2026-09-26 11:26 UTC (permalink / raw)
To: Potnuri Bharat Teja, Jason Gunthorpe, Leon Romanovsky,
David S. Miller, Steve Wise, linux-rdma, linux-kernel
Cc: Jiale Yao
The device status page is shared by all userspace contexts and contains
db_off, which the driver updates to control doorbell flow. The rdma-core
provider maps it with PROT_READ, but c4iw_mmap() passes the requested page
protection through when handling CXGB4_MMAP_CONTIG.
A process can therefore request PROT_WRITE directly or later upgrade a
read-only mapping with mprotect() because VM_MAYWRITE remains set. This
lets userspace alter device-wide flow-control state seen by the kernel and
other contexts.
Reject initially writable mappings and clear VM_MAYWRITE before mapping the
page. This preserves the existing read-only userspace ABI.
Fixes: 05eb23893c2c ("cxgb4/iw_cxgb4: Doorbell Drop Avoidance Bug Fixes")
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/infiniband/hw/cxgb4/provider.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/drivers/infiniband/hw/cxgb4/provider.c b/drivers/infiniband/hw/cxgb4/provider.c
index ebe3170a641c..11c2a891f934 100644
--- a/drivers/infiniband/hw/cxgb4/provider.c
+++ b/drivers/infiniband/hw/cxgb4/provider.c
@@ -171,6 +171,11 @@ static int c4iw_mmap(struct ib_ucontext *context, struct vm_area_struct *vma)
len, t4_pgprot_wc(vma->vm_page_prot));
break;
case CXGB4_MMAP_CONTIG:
+ if (vma->vm_flags & VM_WRITE) {
+ ret = -EPERM;
+ break;
+ }
+ vm_flags_clear(vma, VM_MAYWRITE);
ret = io_remap_pfn_range(vma, vma->vm_start,
addr >> PAGE_SHIFT,
len, vma->vm_page_prot);
--
2.34.1
^ permalink raw reply related [flat|nested] 3+ messages in thread* Re: [PATCH] RDMA/cxgb4: Do not allow userspace to write the status page
2026-09-26 11:26 [PATCH] RDMA/cxgb4: Do not allow userspace to write the status page Jiale Yao
@ 2026-09-26 11:32 ` sashiko-bot
2026-09-29 19:05 ` Leon Romanovsky
1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-09-26 11:32 UTC (permalink / raw)
To: Jiale Yao; +Cc: linux-rdma
> The device status page is shared by all userspace contexts and contains
> db_off, which the driver updates to control doorbell flow. The rdma-core
> provider maps it with PROT_READ, but c4iw_mmap() passes the requested page
> protection through when handling CXGB4_MMAP_CONTIG.
>
> A process can therefore request PROT_WRITE directly or later upgrade a
> read-only mapping with mprotect() because VM_MAYWRITE remains set. This
> lets userspace alter device-wide flow-control state seen by the kernel and
> other contexts.
>
> Reject initially writable mappings and clear VM_MAYWRITE before mapping the
> page. This preserves the existing read-only userspace ABI.
>
> Fixes: 05eb23893c2c ("cxgb4/iw_cxgb4: Doorbell Drop Avoidance Bug Fixes")
> Signed-off-by: Jiale Yao <yaojiale02@163.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260926112611.3214382-1-yaojiale02@163.com?part=1
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [PATCH] RDMA/cxgb4: Do not allow userspace to write the status page
2026-09-26 11:26 [PATCH] RDMA/cxgb4: Do not allow userspace to write the status page Jiale Yao
2026-09-26 11:32 ` sashiko-bot
@ 2026-09-29 19:05 ` Leon Romanovsky
1 sibling, 0 replies; 3+ messages in thread
From: Leon Romanovsky @ 2026-09-29 19:05 UTC (permalink / raw)
To: Potnuri Bharat Teja, Jason Gunthorpe, David S. Miller, Steve Wise,
linux-rdma, linux-kernel, Jiale Yao
On Sat, 26 Sep 2026 19:26:11 +0800, Jiale Yao wrote:
> The device status page is shared by all userspace contexts and contains
> db_off, which the driver updates to control doorbell flow. The rdma-core
> provider maps it with PROT_READ, but c4iw_mmap() passes the requested page
> protection through when handling CXGB4_MMAP_CONTIG.
>
> A process can therefore request PROT_WRITE directly or later upgrade a
> read-only mapping with mprotect() because VM_MAYWRITE remains set. This
> lets userspace alter device-wide flow-control state seen by the kernel and
> other contexts.
>
> [...]
Applied, thanks!
[1/1] RDMA/cxgb4: Do not allow userspace to write the status page
https://git.kernel.org/rdma/rdma/c/1c5335a6902639
Best regards,
--
Leon Romanovsky <leon@kernel.org>
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-29 19:05 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-26 11:26 [PATCH] RDMA/cxgb4: Do not allow userspace to write the status page Jiale Yao
2026-09-26 11:32 ` sashiko-bot
2026-09-29 19:05 ` Leon Romanovsky
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox