From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mailman by lists.gnu.org with tmda-scanned (Exim 4.43) id 1L7pu7-0007yY-DL for qemu-devel@nongnu.org; Wed, 03 Dec 2008 06:28:27 -0500 Received: from exim by lists.gnu.org with spam-scanned (Exim 4.43) id 1L7ptx-0007qJ-6C for qemu-devel@nongnu.org; Wed, 03 Dec 2008 06:28:21 -0500 Received: from [199.232.76.173] (port=33373 helo=monty-python.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1L7ptw-0007pg-Fm for qemu-devel@nongnu.org; Wed, 03 Dec 2008 06:28:16 -0500 Received: from ug-out-1314.google.com ([66.249.92.169]:10731) by monty-python.gnu.org with esmtp (Exim 4.60) (envelope-from ) id 1L7ptt-0004Dk-P8 for qemu-devel@nongnu.org; Wed, 03 Dec 2008 06:28:14 -0500 Received: by ug-out-1314.google.com with SMTP id 29so3354924ugc.36 for ; Wed, 03 Dec 2008 03:27:47 -0800 (PST) From: "Kirill A. Shutemov" Date: Wed, 3 Dec 2008 13:29:43 +0200 Message-Id: <1228303789-25653-8-git-send-email-kirill@shutemov.name> In-Reply-To: <1228303789-25653-7-git-send-email-kirill@shutemov.name> References: <1228303789-25653-1-git-send-email-kirill@shutemov.name> <1228303789-25653-2-git-send-email-kirill@shutemov.name> <1228303789-25653-3-git-send-email-kirill@shutemov.name> <1228303789-25653-4-git-send-email-kirill@shutemov.name> <1228303789-25653-5-git-send-email-kirill@shutemov.name> <1228303789-25653-6-git-send-email-kirill@shutemov.name> <1228303789-25653-7-git-send-email-kirill@shutemov.name> Subject: [Qemu-devel] [PATCH] mmap: add check if requested memory area fits target address space Reply-To: qemu-devel@nongnu.org List-Id: qemu-devel.nongnu.org List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: qemu-devel@nongnu.org Cc: "Kirill A. Shutemov" Signed-off-by: Kirill A. Shutemov --- linux-user/mmap.c | 10 ++++++++++ 1 files changed, 10 insertions(+), 0 deletions(-) diff --git a/linux-user/mmap.c b/linux-user/mmap.c index d96917d..52e2dc8 100644 --- a/linux-user/mmap.c +++ b/linux-user/mmap.c @@ -389,6 +389,16 @@ abi_long target_mmap(abi_ulong start, abi_ulong len, int prot, end = start + len; real_end = HOST_PAGE_ALIGN(end); + /* + * Test if requested memory area fits target address space + * It can fail only on 64-bit host with 32-bit target. + * On any other target/host host mmap() handles this error correctly. + */ + if ((unsigned long)start + len - 1 > (abi_ulong) -1) { + errno = EINVAL; + goto fail; + } + for(addr = real_start; addr < real_end; addr += TARGET_PAGE_SIZE) { flg = page_get_flags(addr); if (flg & PAGE_RESERVED) { -- 1.6.0.2.GIT