mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH 2.6] fix mprotect() with len=(size_t)(-1) to return -ENOMEM
@ 2005-03-14  9:55 Gordon Jin
  2005-03-14 10:08 ` Arjan van de Ven
  2005-03-15  3:04 ` [PATCH 2.6] fix mmap() return value to conform POSIX Gordon Jin
  0 siblings, 2 replies; 4+ messages in thread
From: Gordon Jin @ 2005-03-14  9:55 UTC (permalink / raw)
  To: akpm; +Cc: linux-kernel, michael.fu

This patch fixes a corner case in sys_mprotect(): 

Case: len is so large that will overflow to 0 after page alignment.
E.g. len=(size_t)(-1), i.e. 0xff...ff.
Expected result: POSIX spec says it should return -ENOMEM.
Current result: len is aligned to 0, then treated the same as len=0 and
return success.

--- linux-2.6.11.3/mm/mprotect.c.orig	2005-03-14 13:40:28.000000000
-0800
+++ linux-2.6.11.3/mm/mprotect.c	2005-03-14 13:42:41.000000000 -0800
@@ -232,14 +232,14 @@ sys_mprotect(unsigned long start, size_t
 
 	if (start & ~PAGE_MASK)
 		return -EINVAL;
+	if (!len)
+		return 0;
 	len = PAGE_ALIGN(len);
 	end = start + len;
-	if (end < start)
+	if (end <= start)
 		return -ENOMEM;
 	if (prot & ~(PROT_READ | PROT_WRITE | PROT_EXEC | PROT_SEM))
 		return -EINVAL;
-	if (end == start)
-		return 0;
 	/*
 	 * Does the application expect PROT_READ to imply PROT_EXEC:
 	 */



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2005-03-15  3:09 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2005-03-14  9:55 [PATCH 2.6] fix mprotect() with len=(size_t)(-1) to return -ENOMEM Gordon Jin
2005-03-14 10:08 ` Arjan van de Ven
2005-03-14 21:58   ` Ingo Oeser
2005-03-15  3:04 ` [PATCH 2.6] fix mmap() return value to conform POSIX Gordon Jin

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®