Stas Sergeev wrote: > Exactly. So why such a "middle-ground" solution is currently > there? I can: > 1. mprotect() the existing mapping to PROT_EXEC and bypass the > checks (but you can easily restrict that by patching mprotect()). The consensus has been to add the same checks to mprotect. They were not left out intentionally. -- ➧ Ulrich Drepper ➧ Red Hat, Inc. ➧ 444 Castro St ➧ Mountain View, CA ❖