2017-02-07 23:53:53 +00:00
|
|
|
With latest versions of glibc, a lot of apps failed on a PaX enabled
|
|
|
|
system with:
|
|
|
|
cannot enable executable stack as shared object requires: Permission denied
|
|
|
|
|
|
|
|
This is due to PaX 'exec-protecting' the stack, and ld.so then trying
|
|
|
|
to make the stack executable due to some libraries not containing the
|
|
|
|
PT_GNU_STACK section. Bug #32960. <azarah@gentoo.org> (12 Nov 2003).
|
|
|
|
|
|
|
|
Patch also NPTL. Bug #116086. <kevquinn@gentoo.org> (20 Dec 2005).
|
|
|
|
|
2017-12-02 20:44:39 +00:00
|
|
|
---
|
|
|
|
nptl/allocatestack.c | 3 ++-
|
|
|
|
sysdeps/unix/sysv/linux/dl-execstack.c | 19 ++++++++++++++++---
|
|
|
|
2 files changed, 18 insertions(+), 4 deletions(-)
|
|
|
|
|
|
|
|
--- a/nptl/allocatestack.c
|
|
|
|
+++ b/nptl/allocatestack.c
|
|
|
|
@@ -334,7 +334,8 @@
|
2017-02-07 23:53:53 +00:00
|
|
|
# error "Define either _STACK_GROWS_DOWN or _STACK_GROWS_UP"
|
|
|
|
#endif
|
|
|
|
if (mprotect (stack, len, PROT_READ | PROT_WRITE | PROT_EXEC) != 0)
|
|
|
|
- return errno;
|
|
|
|
+ if (errno != EACCES) /* PAX is enabled */
|
|
|
|
+ return errno;
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
2017-12-02 20:44:39 +00:00
|
|
|
--- a/sysdeps/unix/sysv/linux/dl-execstack.c
|
|
|
|
+++ b/sysdeps/unix/sysv/linux/dl-execstack.c
|
|
|
|
@@ -62,7 +62,10 @@
|
2017-02-07 23:53:53 +00:00
|
|
|
else
|
|
|
|
# endif
|
|
|
|
{
|
|
|
|
- result = errno;
|
|
|
|
+ if (errno == EACCES) /* PAX is enabled */
|
|
|
|
+ result = 0;
|
|
|
|
+ else
|
|
|
|
+ result = errno;
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
}
|
2017-12-02 20:44:39 +00:00
|
|
|
@@ -88,7 +91,12 @@
|
2017-02-07 23:53:53 +00:00
|
|
|
page -= size;
|
|
|
|
else
|
|
|
|
{
|
|
|
|
- if (errno != ENOMEM) /* Unexpected failure mode. */
|
|
|
|
+ if (errno == EACCES) /* PAX is enabled */
|
|
|
|
+ {
|
|
|
|
+ result = 0;
|
|
|
|
+ goto out;
|
|
|
|
+ }
|
|
|
|
+ else if (errno != ENOMEM) /* Unexpected failure mode. */
|
|
|
|
{
|
|
|
|
result = errno;
|
|
|
|
goto out;
|
2017-12-02 20:44:39 +00:00
|
|
|
@@ -114,7 +122,12 @@
|
2017-02-07 23:53:53 +00:00
|
|
|
page += size;
|
|
|
|
else
|
|
|
|
{
|
|
|
|
- if (errno != ENOMEM) /* Unexpected failure mode. */
|
|
|
|
+ if (errno == EACCES) /* PAX is enabled */
|
|
|
|
+ {
|
|
|
|
+ result = 0;
|
|
|
|
+ goto out;
|
|
|
|
+ }
|
|
|
|
+ else if (errno != ENOMEM) /* Unexpected failure mode. */
|
|
|
|
{
|
|
|
|
result = errno;
|
|
|
|
goto out;
|