Re: [PATCH rdma-next] RDMA/bnxt_re: Clear VM_MAYWRITE on read-only mmap of driver pages

Selvin Xavier <[email protected]>
Newsgroups org.kernel.vger.linux-rdma,org.kernel.vger.linux-kernel
Message-ID <CA+sbYW0i0YQZO4wQRGXS9LEVGMmRtEhuAJYOZems2KmfCUfUCQ@mail.gmail.com>
On Wed, Jul 22, 2026 at 6:26 PM Leon Romanovsky <[email protected]> wrote:
>
> From: Leon Romanovsky <[email protected]>
>
> bnxt_re_mmap() rejects an initially writable mapping of the DBR pacing page
> and the toggle page, but leaves VM_MAYWRITE set on the accepted read-only
> mapping. A later mprotect(PROT_READ | PROT_WRITE) therefore passes the mm
> permission check and upgrades the inserted PTEs, letting userspace write
> these driver-owned pages: the DBR pacing parameters maintained under
> rdev->pacing.dbq_lock, and the CQ/SRQ toggle state written from the NQ
> tasklet.
>
> Clear VM_MAYWRITE before vm_insert_page() so the mapping can never be made
> writable, making any such mprotect() fail with -EACCES while the read-only
> mapping continues to work.
>
> Fixes: ea222485788208 ("RDMA/bnxt_re: Update alloc_page uapi for pacing")
> Signed-off-by: Leon Romanovsky <[email protected]>
> ---
>  drivers/infiniband/hw/bnxt_re/ib_verbs.c | 13 ++++++++-----
>  1 file changed, 8 insertions(+), 5 deletions(-)
>
> diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.c b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
> index adc693736769..dcfb1b0ebc22 100644
> --- a/drivers/infiniband/hw/bnxt_re/ib_verbs.c
> +++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
> @@ -4984,12 +4984,15 @@ int bnxt_re_mmap(struct ib_ucontext *ib_uctx, struct vm_area_struct *vma)
>                 break;
>         case BNXT_RE_MMAP_DBR_PAGE:
>         case BNXT_RE_MMAP_TOGGLE_PAGE:
> -               /* Driver doesn't expect write access for user space */
> -               if (vma->vm_flags & VM_WRITE)
> +               /* Reject writable mappings and prevent mprotect() upgrades. */
> +               if (vma->vm_flags & VM_WRITE) {
>                         ret = -EFAULT;
> -               else
> -                       ret = vm_insert_page(vma, vma->vm_start,
> -                                            virt_to_page((void *)bnxt_entry->mem_offset));
> +                       break;
> +               }
> +
> +               vm_flags_clear(vma, VM_MAYWRITE);
> +               ret = vm_insert_page(vma, vma->vm_start,
> +                                    virt_to_page((void *)bnxt_entry->mem_offset));
Same change was done as part of my series which cleaned up the toggle
page for CQ/SRQ.
https://lore.kernel.org/linux-rdma/[email protected]/
Do you want to take this and abandon my patch? I am okay with that. I
can rebase my series
once this gets merged.

Thanks,
Selvin

>                 break;
>         default:
>                 ret = -EINVAL;
>
> ---
> base-commit: 0e8e94c15091041ea8910cbfcade5a9c7cfe3f90
> change-id: 20260722-missing-vma-write-protection-enforce-2e99624c35dc
>
> Best regards,
> --
> Leon Romanovsky <[email protected]>
>
smime.p7s (application/pkcs7-signature, 5.3 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.