Module Name:    src
Committed By:   reinoud
Date:           Thu Aug 25 19:14:08 UTC 2011

Modified Files:
        src/sys/kern: kern_exec.c

Log Message:
On a verbose kernel boot show why executables are denied due to their start
adresses. This will hardly ever occure in real-life.


To generate a diff of this commit:
cvs rdiff -u -r1.317 -r1.318 src/sys/kern/kern_exec.c

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: src/sys/kern/kern_exec.c
diff -u src/sys/kern/kern_exec.c:1.317 src/sys/kern/kern_exec.c:1.318
--- src/sys/kern/kern_exec.c:1.317	Mon Aug  8 12:08:53 2011
+++ src/sys/kern/kern_exec.c	Thu Aug 25 19:14:07 2011
@@ -1,4 +1,4 @@
-/*	$NetBSD: kern_exec.c,v 1.317 2011/08/08 12:08:53 manu Exp $	*/
+/*	$NetBSD: kern_exec.c,v 1.318 2011/08/25 19:14:07 reinoud Exp $	*/
 
 /*-
  * Copyright (c) 2008 The NetBSD Foundation, Inc.
@@ -59,7 +59,7 @@
  */
 
 #include <sys/cdefs.h>
-__KERNEL_RCSID(0, "$NetBSD: kern_exec.c,v 1.317 2011/08/08 12:08:53 manu Exp $");
+__KERNEL_RCSID(0, "$NetBSD: kern_exec.c,v 1.318 2011/08/25 19:14:07 reinoud Exp $");
 
 #include "opt_ktrace.h"
 #include "opt_modular.h"
@@ -370,8 +370,17 @@
 		newerror = (*execsw[i]->es_makecmds)(l, epp);
 
 		if (!newerror) {
-			/* Seems ok: check that entry point is sane */
+			/* Seems ok: check that entry point is not too high */
 			if (epp->ep_entry > VM_MAXUSER_ADDRESS) {
+				aprint_verbose("check_exec: rejecting due to "
+					"too high entry address\n");
+				error = ENOEXEC;
+				break;
+			}
+			/* Seems ok: check that entry point is not too low */
+			if (epp->ep_entry < VM_MIN_ADDRESS) {
+				aprint_verbose("check_exec: rejecting due to "
+					"too low entry address\n");
 				error = ENOEXEC;
 				break;
 			}
@@ -380,6 +389,8 @@
 			if ((epp->ep_tsize > MAXTSIZ) ||
 			    (epp->ep_dsize > (u_quad_t)l->l_proc->p_rlimit
 						    [RLIMIT_DATA].rlim_cur)) {
+				aprint_debug("check_exec: rejecting due to "
+					"limits\n");
 				error = ENOMEM;
 				break;
 			}

Reply via email to