Re: [PATCH rdma-next] RDMA/bnxt_re: Clear VM_MAYWRITE on read-only mmap of driver pages

Leon Romanovsky <[email protected]>
Newsgroups org.kernel.vger.linux-rdma,org.kernel.vger.linux-kernel
Message-ID <20260722162233.GZ110966@unreal>
On Wed, Jul 22, 2026 at 07:05:52PM +0530, Selvin Xavier wrote:
> On Wed, Jul 22, 2026 at 6:26 PM Leon Romanovsky <[email protected]> wrote:
> >
> > From: Leon Romanovsky <[email protected]>
> >
> > bnxt_re_mmap() rejects an initially writable mapping of the DBR pacing page
> > and the toggle page, but leaves VM_MAYWRITE set on the accepted read-only
> > mapping. A later mprotect(PROT_READ | PROT_WRITE) therefore passes the mm
> > permission check and upgrades the inserted PTEs, letting userspace write
> > these driver-owned pages: the DBR pacing parameters maintained under
> > rdev->pacing.dbq_lock, and the CQ/SRQ toggle state written from the NQ
> > tasklet.
> >
> > Clear VM_MAYWRITE before vm_insert_page() so the mapping can never be made
> > writable, making any such mprotect() fail with -EACCES while the read-only
> > mapping continues to work.
> >
> > Fixes: ea222485788208 ("RDMA/bnxt_re: Update alloc_page uapi for pacing")
> > Signed-off-by: Leon Romanovsky <[email protected]>
> > ---
> >  drivers/infiniband/hw/bnxt_re/ib_verbs.c | 13 ++++++++-----
> >  1 file changed, 8 insertions(+), 5 deletions(-)
> >
> > diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.c b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
> > index adc693736769..dcfb1b0ebc22 100644
> > --- a/drivers/infiniband/hw/bnxt_re/ib_verbs.c
> > +++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
> > @@ -4984,12 +4984,15 @@ int bnxt_re_mmap(struct ib_ucontext *ib_uctx, struct vm_area_struct *vma)
> >                 break;
> >         case BNXT_RE_MMAP_DBR_PAGE:
> >         case BNXT_RE_MMAP_TOGGLE_PAGE:
> > -               /* Driver doesn't expect write access for user space */
> > -               if (vma->vm_flags & VM_WRITE)
> > +               /* Reject writable mappings and prevent mprotect() upgrades. */
> > +               if (vma->vm_flags & VM_WRITE) {
> >                         ret = -EFAULT;
> > -               else
> > -                       ret = vm_insert_page(vma, vma->vm_start,
> > -                                            virt_to_page((void *)bnxt_entry->mem_offset));
> > +                       break;
> > +               }
> > +
> > +               vm_flags_clear(vma, VM_MAYWRITE);
> > +               ret = vm_insert_page(vma, vma->vm_start,
> > +                                    virt_to_page((void *)bnxt_entry->mem_offset));
> Same change was done as part of my series which cleaned up the toggle
> page for CQ/SRQ.
> https://lore.kernel.org/linux-rdma/[email protected]/
> Do you want to take this and abandon my patch? I am okay with that. I
> can rebase my series
> once this gets merged.

I took your patch as you posted before me and added Fixes line.

Thanks

> 
> Thanks,
> Selvin
> 
> >                 break;
> >         default:
> >                 ret = -EINVAL;
> >
> > ---
> > base-commit: 0e8e94c15091041ea8910cbfcade5a9c7cfe3f90
> > change-id: 20260722-missing-vma-write-protection-enforce-2e99624c35dc
> >
> > Best regards,
> > --
> > Leon Romanovsky <[email protected]>
> >
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.