[PATCH rdma-next] RDMA/bnxt_re: Clear VM_MAYWRITE on read-only mmap of driver pages

Leon Romanovsky <[email protected]>
Newsgroups org.kernel.vger.linux-rdma,org.kernel.vger.linux-kernel
Message-ID <20260722-missing-vma-write-protection-enforce-v1-1-567cd8499e23@nvidia.com>
From: Leon Romanovsky <[email protected]>

bnxt_re_mmap() rejects an initially writable mapping of the DBR pacing page
and the toggle page, but leaves VM_MAYWRITE set on the accepted read-only
mapping. A later mprotect(PROT_READ | PROT_WRITE) therefore passes the mm
permission check and upgrades the inserted PTEs, letting userspace write
these driver-owned pages: the DBR pacing parameters maintained under
rdev->pacing.dbq_lock, and the CQ/SRQ toggle state written from the NQ
tasklet.

Clear VM_MAYWRITE before vm_insert_page() so the mapping can never be made
writable, making any such mprotect() fail with -EACCES while the read-only
mapping continues to work.

Fixes: ea222485788208 ("RDMA/bnxt_re: Update alloc_page uapi for pacing")
Signed-off-by: Leon Romanovsky <[email protected]>
---
 drivers/infiniband/hw/bnxt_re/ib_verbs.c | 13 ++++++++-----
 1 file changed, 8 insertions(+), 5 deletions(-)

diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.c b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
index adc693736769..dcfb1b0ebc22 100644
--- a/drivers/infiniband/hw/bnxt_re/ib_verbs.c
+++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
@@ -4984,12 +4984,15 @@ int bnxt_re_mmap(struct ib_ucontext *ib_uctx, struct vm_area_struct *vma)
 		break;
 	case BNXT_RE_MMAP_DBR_PAGE:
 	case BNXT_RE_MMAP_TOGGLE_PAGE:
-		/* Driver doesn't expect write access for user space */
-		if (vma->vm_flags & VM_WRITE)
+		/* Reject writable mappings and prevent mprotect() upgrades. */
+		if (vma->vm_flags & VM_WRITE) {
 			ret = -EFAULT;
-		else
-			ret = vm_insert_page(vma, vma->vm_start,
-					     virt_to_page((void *)bnxt_entry->mem_offset));
+			break;
+		}
+
+		vm_flags_clear(vma, VM_MAYWRITE);
+		ret = vm_insert_page(vma, vma->vm_start,
+				     virt_to_page((void *)bnxt_entry->mem_offset));
 		break;
 	default:
 		ret = -EINVAL;

---
base-commit: 0e8e94c15091041ea8910cbfcade5a9c7cfe3f90
change-id: 20260722-missing-vma-write-protection-enforce-2e99624c35dc

Best regards,
--  
Leon Romanovsky <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.