From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mailman by lists.gnu.org with tmda-scanned (Exim 4.43) id 1L9kay-0001pZ-0k for qemu-devel@nongnu.org; Mon, 08 Dec 2008 13:12:36 -0500 Received: from exim by lists.gnu.org with spam-scanned (Exim 4.43) id 1L9kaw-0001pJ-IO for qemu-devel@nongnu.org; Mon, 08 Dec 2008 13:12:34 -0500 Received: from [199.232.76.173] (port=41580 helo=monty-python.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1L9kaw-0001pG-Af for qemu-devel@nongnu.org; Mon, 08 Dec 2008 13:12:34 -0500 Received: from savannah.gnu.org ([199.232.41.3]:38521 helo=sv.gnu.org) by monty-python.gnu.org with esmtps (TLS-1.0:RSA_AES_256_CBC_SHA1:32) (Exim 4.60) (envelope-from ) id 1L9kaw-0003bi-33 for qemu-devel@nongnu.org; Mon, 08 Dec 2008 13:12:34 -0500 Received: from cvs.savannah.gnu.org ([199.232.41.69]) by sv.gnu.org with esmtp (Exim 4.63) (envelope-from ) id 1L9kav-0001ZK-PT for qemu-devel@nongnu.org; Mon, 08 Dec 2008 18:12:33 +0000 Received: from aurel32 by cvs.savannah.gnu.org with local (Exim 4.63) (envelope-from ) id 1L9kav-0001ZE-AR for qemu-devel@nongnu.org; Mon, 08 Dec 2008 18:12:33 +0000 MIME-Version: 1.0 Errors-To: aurel32 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit From: Aurelien Jarno Message-Id: Date: Mon, 08 Dec 2008 18:12:33 +0000 Subject: [Qemu-devel] [5958] linux-user: mmap: add check if requested memory area fits target address space Reply-To: qemu-devel@nongnu.org List-Id: qemu-devel.nongnu.org List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: qemu-devel@nongnu.org Revision: 5958 http://svn.sv.gnu.org/viewvc/?view=rev&root=qemu&revision=5958 Author: aurel32 Date: 2008-12-08 18:12:33 +0000 (Mon, 08 Dec 2008) Log Message: ----------- linux-user: mmap: add check if requested memory area fits target address space Signed-off-by: Kirill A. Shutemov Acked-by: Edgar E. Iglesias Signed-off-by: Aurelien Jarno Modified Paths: -------------- trunk/linux-user/mmap.c Modified: trunk/linux-user/mmap.c =================================================================== --- trunk/linux-user/mmap.c 2008-12-08 18:12:26 UTC (rev 5957) +++ trunk/linux-user/mmap.c 2008-12-08 18:12:33 UTC (rev 5958) @@ -382,6 +382,16 @@ end = start + len; real_end = HOST_PAGE_ALIGN(end); + /* + * Test if requested memory area fits target address space + * It can fail only on 64-bit host with 32-bit target. + * On any other target/host host mmap() handles this error correctly. + */ + if ((unsigned long)start + len - 1 > (abi_ulong) -1) { + errno = EINVAL; + goto fail; + } + for(addr = real_start; addr < real_end; addr += TARGET_PAGE_SIZE) { flg = page_get_flags(addr); if (flg & PAGE_RESERVED) {