From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mailman by lists.gnu.org with tmda-scanned (Exim 4.43) id 1JpjLa-0002L8-IN for qemu-devel@nongnu.org; Sat, 26 Apr 2008 08:17:42 -0400 Received: from exim by lists.gnu.org with spam-scanned (Exim 4.43) id 1JpjLZ-0002K2-Sw for qemu-devel@nongnu.org; Sat, 26 Apr 2008 08:17:42 -0400 Received: from [199.232.76.173] (port=41873 helo=monty-python.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1JpjLZ-0002Jr-N4 for qemu-devel@nongnu.org; Sat, 26 Apr 2008 08:17:41 -0400 Received: from savannah.gnu.org ([199.232.41.3] helo=sv.gnu.org) by monty-python.gnu.org with esmtps (TLS-1.0:RSA_AES_256_CBC_SHA1:32) (Exim 4.60) (envelope-from ) id 1JpjLZ-0008UB-HB for qemu-devel@nongnu.org; Sat, 26 Apr 2008 08:17:41 -0400 Received: from cvs.savannah.gnu.org ([199.232.41.69]) by sv.gnu.org with esmtp (Exim 4.63) (envelope-from ) id 1JpjLW-0007J6-MU for qemu-devel@nongnu.org; Sat, 26 Apr 2008 12:17:39 +0000 Received: from balrog by cvs.savannah.gnu.org with local (Exim 4.63) (envelope-from ) id 1JpjLU-0007IX-OB for qemu-devel@nongnu.org; Sat, 26 Apr 2008 12:17:37 +0000 MIME-Version: 1.0 Errors-To: balrog Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit From: Andrzej Zaborowski Message-Id: Date: Sat, 26 Apr 2008 12:17:36 +0000 Subject: [Qemu-devel] [4255] Teach mmap to not overwrite reserved pages and fix brk return value (Richard Purdie). Reply-To: qemu-devel@nongnu.org List-Id: qemu-devel.nongnu.org List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: qemu-devel@nongnu.org Revision: 4255 http://svn.sv.gnu.org/viewvc/?view=rev&root=qemu&revision=4255 Author: balrog Date: 2008-04-26 12:17:34 +0000 (Sat, 26 Apr 2008) Log Message: ----------- Teach mmap to not overwrite reserved pages and fix brk return value (Richard Purdie). Modified Paths: -------------- trunk/linux-user/mmap.c trunk/linux-user/syscall.c Modified: trunk/linux-user/mmap.c =================================================================== --- trunk/linux-user/mmap.c 2008-04-26 12:00:18 UTC (rev 4254) +++ trunk/linux-user/mmap.c 2008-04-26 12:17:34 UTC (rev 4255) @@ -259,13 +259,24 @@ host_start += offset - host_offset; start = h2g(host_start); } else { + int flg; + target_ulong addr; + if (start & ~TARGET_PAGE_MASK) { errno = EINVAL; return -1; } end = start + len; real_end = HOST_PAGE_ALIGN(end); - + + for(addr = real_start; addr < real_end; addr += TARGET_PAGE_SIZE) { + flg = page_get_flags(addr); + if (flg & PAGE_RESERVED) { + errno = ENXIO; + return -1; + } + } + /* worst case: we cannot map the file because the offset is not aligned, so we read it */ if (!(flags & MAP_ANONYMOUS) && Modified: trunk/linux-user/syscall.c =================================================================== --- trunk/linux-user/syscall.c 2008-04-26 12:00:18 UTC (rev 4254) +++ trunk/linux-user/syscall.c 2008-04-26 12:17:34 UTC (rev 4255) @@ -420,7 +420,7 @@ if (!new_brk) return target_brk; if (new_brk < target_original_brk) - return -TARGET_ENOMEM; + return target_brk; brk_page = HOST_PAGE_ALIGN(target_brk); @@ -435,12 +435,11 @@ mapped_addr = get_errno(target_mmap(brk_page, new_alloc_size, PROT_READ|PROT_WRITE, MAP_ANON|MAP_FIXED|MAP_PRIVATE, 0, 0)); - if (is_error(mapped_addr)) { - return mapped_addr; - } else { + + if (!is_error(mapped_addr)) target_brk = new_brk; - return target_brk; - } + + return target_brk; } static inline abi_long copy_from_user_fdset(fd_set *fds,