Re: [PATCH] RDMA/cxgb4: Do not allow userspace to write the status page

From: Leon Romanovsky

Date: Tue Sep 29 2026 - 15:09:59 EST



On Sat, 26 Sep 2026 19:26:11 +0800, Jiale Yao wrote:
> The device status page is shared by all userspace contexts and contains
> db_off, which the driver updates to control doorbell flow. The rdma-core
> provider maps it with PROT_READ, but c4iw_mmap() passes the requested page
> protection through when handling CXGB4_MMAP_CONTIG.
>
> A process can therefore request PROT_WRITE directly or later upgrade a
> read-only mapping with mprotect() because VM_MAYWRITE remains set. This
> lets userspace alter device-wide flow-control state seen by the kernel and
> other contexts.
>
> [...]

Applied, thanks!

[1/1] RDMA/cxgb4: Do not allow userspace to write the status page
https://git.kernel.org/rdma/rdma/c/1c5335a6902639

Best regards,
--
Leon Romanovsky <leon@xxxxxxxxxx>