Blame view

fs/exec.c 46.9 KB
457c89965   Thomas Gleixner   treewide: Add SPD...
1
  // SPDX-License-Identifier: GPL-2.0-only
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
  /*
   *  linux/fs/exec.c
   *
   *  Copyright (C) 1991, 1992  Linus Torvalds
   */
  
  /*
   * #!-checking implemented by tytso.
   */
  /*
   * Demand-loading implemented 01.12.91 - no need to read anything but
   * the header into memory. The inode of the executable is put into
   * "current->executable", and page faults do the actual loading. Clean.
   *
   * Once more I can proudly say that linux stood up to being changed: it
   * was less than 2 hours work to get demand-loading completely implemented.
   *
   * Demand loading changed July 1993 by Eric Youngdale.   Use mmap instead,
   * current->executable is only used by the procfs.  This allows a dispatch
   * table to check for several different types  of binary formats.  We keep
   * trying until we recognize the file or we run out of supported binary
613cc2b6f   Aleksa Sarai   fs: exec: apply C...
23
   * formats.
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
24
   */
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
25
26
  #include <linux/slab.h>
  #include <linux/file.h>
9f3acc314   Al Viro   [PATCH] split lin...
27
  #include <linux/fdtable.h>
ba92a43db   Hugh Dickins   exec: remove some...
28
  #include <linux/mm.h>
615d6e875   Davidlohr Bueso   mm: per-thread vm...
29
  #include <linux/vmacache.h>
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
30
31
  #include <linux/stat.h>
  #include <linux/fcntl.h>
ba92a43db   Hugh Dickins   exec: remove some...
32
  #include <linux/swap.h>
74aadce98   Neil Horman   core_pattern: all...
33
  #include <linux/string.h>
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
34
  #include <linux/init.h>
6e84f3152   Ingo Molnar   sched/headers: Pr...
35
  #include <linux/sched/mm.h>
f7ccbae45   Ingo Molnar   sched/headers: Pr...
36
  #include <linux/sched/coredump.h>
3f07c0144   Ingo Molnar   sched/headers: Pr...
37
  #include <linux/sched/signal.h>
6a3827d75   Ingo Molnar   sched/headers: Pr...
38
  #include <linux/sched/numa_balancing.h>
299300258   Ingo Molnar   sched/headers: Pr...
39
  #include <linux/sched/task.h>
ca5b172bd   Hugh Dickins   exec: include pag...
40
  #include <linux/pagemap.h>
cdd6c482c   Ingo Molnar   perf: Do the big ...
41
  #include <linux/perf_event.h>
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
42
43
44
45
46
  #include <linux/highmem.h>
  #include <linux/spinlock.h>
  #include <linux/key.h>
  #include <linux/personality.h>
  #include <linux/binfmts.h>
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
47
  #include <linux/utsname.h>
84d737866   Sukadev Bhattiprolu   [PATCH] add child...
48
  #include <linux/pid_namespace.h>
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
49
50
  #include <linux/module.h>
  #include <linux/namei.h>
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
51
52
53
  #include <linux/mount.h>
  #include <linux/security.h>
  #include <linux/syscalls.h>
8f0ab5147   Jay Lan   [PATCH] csa: conv...
54
  #include <linux/tsacct_kern.h>
9f46080c4   Matt Helsley   [PATCH] Process E...
55
  #include <linux/cn_proc.h>
473ae30bc   Al Viro   [PATCH] execve ar...
56
  #include <linux/audit.h>
6341c393f   Roland McGrath   tracehook: exec
57
  #include <linux/tracehook.h>
5f4123be3   Johannes Berg   remove CONFIG_KMO...
58
  #include <linux/kmod.h>
6110e3abb   Eric Paris   sys_execve and sy...
59
  #include <linux/fsnotify.h>
5ad4e53bd   Al Viro   Get rid of indire...
60
  #include <linux/fs_struct.h>
61be228a0   Neil Horman   exec: allow do_co...
61
  #include <linux/pipe_fs_i.h>
3d5992d2a   Ying Han   oom: add per-mm o...
62
  #include <linux/oom.h>
0e028465d   Oleg Nesterov   exec: unify do_ex...
63
  #include <linux/compat.h>
b44a7dfc6   Mimi Zohar   vfs: define a gen...
64
  #include <linux/vmalloc.h>
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
65

7c0f6ba68   Linus Torvalds   Replace <asm/uacc...
66
  #include <linux/uaccess.h>
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
67
  #include <asm/mmu_context.h>
b6a2fea39   Ollie Wild   mm: variable leng...
68
  #include <asm/tlb.h>
43d2b1132   KAMEZAWA Hiroyuki   tracepoint: add t...
69
70
  
  #include <trace/events/task.h>
a6f76f23d   David Howells   CRED: Make execve...
71
  #include "internal.h"
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
72

4ff16c25e   David Smith   tracepoint, vfs, ...
73
  #include <trace/events/sched.h>
d6e711448   Alan Cox   [PATCH] setuid co...
74
  int suid_dumpable = 0;
e4dc1b14d   Alexey Dobriyan   Use list_head in ...
75
  static LIST_HEAD(formats);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
76
  static DEFINE_RWLOCK(binfmt_lock);
8fc3dc5a3   Al Viro   __register_binfmt...
77
  void __register_binfmt(struct linux_binfmt * fmt, int insert)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
78
  {
8fc3dc5a3   Al Viro   __register_binfmt...
79
  	BUG_ON(!fmt);
92eaa565a   Oleg Nesterov   exec: kill ->load...
80
81
  	if (WARN_ON(!fmt->load_binary))
  		return;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
82
  	write_lock(&binfmt_lock);
74641f584   Ivan Kokshaysky   alpha: binfmt_aou...
83
84
  	insert ? list_add(&fmt->lh, &formats) :
  		 list_add_tail(&fmt->lh, &formats);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
85
  	write_unlock(&binfmt_lock);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
86
  }
74641f584   Ivan Kokshaysky   alpha: binfmt_aou...
87
  EXPORT_SYMBOL(__register_binfmt);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
88

f6b450d48   Alexey Dobriyan   Make unregister_b...
89
  void unregister_binfmt(struct linux_binfmt * fmt)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
90
  {
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
91
  	write_lock(&binfmt_lock);
e4dc1b14d   Alexey Dobriyan   Use list_head in ...
92
  	list_del(&fmt->lh);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
93
  	write_unlock(&binfmt_lock);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
94
95
96
97
98
99
100
101
  }
  
  EXPORT_SYMBOL(unregister_binfmt);
  
  static inline void put_binfmt(struct linux_binfmt * fmt)
  {
  	module_put(fmt->module);
  }
90f8572b0   Eric W. Biederman   vfs: Commit to ne...
102
103
104
105
106
  bool path_noexec(const struct path *path)
  {
  	return (path->mnt->mnt_flags & MNT_NOEXEC) ||
  	       (path->mnt->mnt_sb->s_iflags & SB_I_NOEXEC);
  }
69369a700   Josh Triplett   fs, kernel: permi...
107
  #ifdef CONFIG_USELIB
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
108
109
110
111
112
113
  /*
   * Note that a shared library must be both readable and executable due to
   * security reasons.
   *
   * Also note that we take the address to load from from the file itself.
   */
1e7bfb213   Heiko Carstens   [CVE-2009-0029] S...
114
  SYSCALL_DEFINE1(uselib, const char __user *, library)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
115
  {
72c2d5319   Al Viro   file->f_op is nev...
116
  	struct linux_binfmt *fmt;
964bd1836   Al Viro   [PATCH] get rid o...
117
  	struct file *file;
91a27b2a7   Jeff Layton   vfs: define struc...
118
  	struct filename *tmp = getname(library);
964bd1836   Al Viro   [PATCH] get rid o...
119
  	int error = PTR_ERR(tmp);
47c805dc2   Al Viro   switch do_filp_op...
120
121
  	static const struct open_flags uselib_flags = {
  		.open_flag = O_LARGEFILE | O_RDONLY | __FMODE_EXEC,
62fb4a155   Al Viro   don't carry MAY_O...
122
  		.acc_mode = MAY_READ | MAY_EXEC,
f9652e10c   Al Viro   allow build_open_...
123
124
  		.intent = LOOKUP_OPEN,
  		.lookup_flags = LOOKUP_FOLLOW,
47c805dc2   Al Viro   switch do_filp_op...
125
  	};
964bd1836   Al Viro   [PATCH] get rid o...
126

6e8341a11   Al Viro   Switch open_exec(...
127
128
  	if (IS_ERR(tmp))
  		goto out;
f9652e10c   Al Viro   allow build_open_...
129
  	file = do_filp_open(AT_FDCWD, tmp, &uselib_flags);
6e8341a11   Al Viro   Switch open_exec(...
130
131
132
  	putname(tmp);
  	error = PTR_ERR(file);
  	if (IS_ERR(file))
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
133
134
135
  		goto out;
  
  	error = -EINVAL;
496ad9aa8   Al Viro   new helper: file_...
136
  	if (!S_ISREG(file_inode(file)->i_mode))
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
137
  		goto exit;
30524472c   Al Viro   [PATCH] take noex...
138
  	error = -EACCES;
90f8572b0   Eric W. Biederman   vfs: Commit to ne...
139
  	if (path_noexec(&file->f_path))
6146f0d5e   Mimi Zohar   integrity: IMA hooks
140
  		goto exit;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
141

2a12a9d78   Eric Paris   fsnotify: pass a ...
142
  	fsnotify_open(file);
6110e3abb   Eric Paris   sys_execve and sy...
143

1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
144
  	error = -ENOEXEC;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
145

72c2d5319   Al Viro   file->f_op is nev...
146
147
148
149
150
151
  	read_lock(&binfmt_lock);
  	list_for_each_entry(fmt, &formats, lh) {
  		if (!fmt->load_shlib)
  			continue;
  		if (!try_module_get(fmt->module))
  			continue;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
152
  		read_unlock(&binfmt_lock);
72c2d5319   Al Viro   file->f_op is nev...
153
154
155
156
157
  		error = fmt->load_shlib(file);
  		read_lock(&binfmt_lock);
  		put_binfmt(fmt);
  		if (error != -ENOEXEC)
  			break;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
158
  	}
72c2d5319   Al Viro   file->f_op is nev...
159
  	read_unlock(&binfmt_lock);
6e8341a11   Al Viro   Switch open_exec(...
160
  exit:
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
161
162
163
  	fput(file);
  out:
    	return error;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
164
  }
69369a700   Josh Triplett   fs, kernel: permi...
165
  #endif /* #ifdef CONFIG_USELIB */
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
166

b6a2fea39   Ollie Wild   mm: variable leng...
167
  #ifdef CONFIG_MMU
ae6b585ee   Oleg Nesterov   exec: document ac...
168
169
170
171
172
173
  /*
   * The nascent bprm->mm is not visible until exec_mmap() but it can
   * use a lot of memory, account these pages in current->mm temporary
   * for oom_badness()->get_mm_rss(). Once exec succeeds or fails, we
   * change the counter back via acct_arg_size(0).
   */
0e028465d   Oleg Nesterov   exec: unify do_ex...
174
  static void acct_arg_size(struct linux_binprm *bprm, unsigned long pages)
3c77f8457   Oleg Nesterov   exec: make argv/e...
175
176
177
178
179
180
181
182
  {
  	struct mm_struct *mm = current->mm;
  	long diff = (long)(pages - bprm->vma_pages);
  
  	if (!mm || !diff)
  		return;
  
  	bprm->vma_pages = pages;
3c77f8457   Oleg Nesterov   exec: make argv/e...
183
  	add_mm_counter(mm, MM_ANONPAGES, diff);
3c77f8457   Oleg Nesterov   exec: make argv/e...
184
  }
0e028465d   Oleg Nesterov   exec: unify do_ex...
185
  static struct page *get_arg_page(struct linux_binprm *bprm, unsigned long pos,
b6a2fea39   Ollie Wild   mm: variable leng...
186
187
188
189
  		int write)
  {
  	struct page *page;
  	int ret;
9beae1ea8   Lorenzo Stoakes   mm: replace get_u...
190
  	unsigned int gup_flags = FOLL_FORCE;
b6a2fea39   Ollie Wild   mm: variable leng...
191
192
193
  
  #ifdef CONFIG_STACK_GROWSUP
  	if (write) {
d05f3169c   Michal Hocko   mm: make expand_d...
194
  		ret = expand_downwards(bprm->vma, pos);
b6a2fea39   Ollie Wild   mm: variable leng...
195
196
197
198
  		if (ret < 0)
  			return NULL;
  	}
  #endif
9beae1ea8   Lorenzo Stoakes   mm: replace get_u...
199
200
201
  
  	if (write)
  		gup_flags |= FOLL_WRITE;
1e9877902   Dave Hansen   mm/gup: Introduce...
202
203
204
205
  	/*
  	 * We are doing an exec().  'current' is the process
  	 * doing the exec and bprm->mm is the new process's mm.
  	 */
9beae1ea8   Lorenzo Stoakes   mm: replace get_u...
206
  	ret = get_user_pages_remote(current, bprm->mm, pos, 1, gup_flags,
5b56d49fc   Lorenzo Stoakes   mm: add locked pa...
207
  			&page, NULL, NULL);
b6a2fea39   Ollie Wild   mm: variable leng...
208
209
  	if (ret <= 0)
  		return NULL;
655c16a8c   Oleg Nesterov   exec: separate MM...
210
211
  	if (write)
  		acct_arg_size(bprm, vma_pages(bprm->vma));
b6a2fea39   Ollie Wild   mm: variable leng...
212
213
214
215
216
217
218
219
  
  	return page;
  }
  
  static void put_arg_page(struct page *page)
  {
  	put_page(page);
  }
b6a2fea39   Ollie Wild   mm: variable leng...
220
221
222
223
224
225
226
227
228
229
230
231
  static void free_arg_pages(struct linux_binprm *bprm)
  {
  }
  
  static void flush_arg_page(struct linux_binprm *bprm, unsigned long pos,
  		struct page *page)
  {
  	flush_cache_page(bprm->vma, pos, page_to_pfn(page));
  }
  
  static int __bprm_mm_init(struct linux_binprm *bprm)
  {
eaccbfa56   Luiz Fernando N. Capitulino   fs/exec.c:__bprm_...
232
  	int err;
b6a2fea39   Ollie Wild   mm: variable leng...
233
234
  	struct vm_area_struct *vma = NULL;
  	struct mm_struct *mm = bprm->mm;
490fc0538   Linus Torvalds   mm: make vm_area_...
235
  	bprm->vma = vma = vm_area_alloc(mm);
b6a2fea39   Ollie Wild   mm: variable leng...
236
  	if (!vma)
eaccbfa56   Luiz Fernando N. Capitulino   fs/exec.c:__bprm_...
237
  		return -ENOMEM;
bfd40eaff   Kirill A. Shutemov   mm: fix vma_is_an...
238
  	vma_set_anonymous(vma);
b6a2fea39   Ollie Wild   mm: variable leng...
239

f268dfe90   Michal Hocko   exec: make exec p...
240
241
242
243
  	if (down_write_killable(&mm->mmap_sem)) {
  		err = -EINTR;
  		goto err_free;
  	}
b6a2fea39   Ollie Wild   mm: variable leng...
244
245
246
247
248
249
250
  
  	/*
  	 * Place the stack at the largest stack address the architecture
  	 * supports. Later, we'll move this to an appropriate place. We don't
  	 * use STACK_TOP because that can depend on attributes which aren't
  	 * configured yet.
  	 */
aacb3d17a   Michal Hocko   fs/exec.c: use BU...
251
  	BUILD_BUG_ON(VM_STACK_FLAGS & VM_STACK_INCOMPLETE_SETUP);
b6a2fea39   Ollie Wild   mm: variable leng...
252
253
  	vma->vm_end = STACK_TOP_MAX;
  	vma->vm_start = vma->vm_end - PAGE_SIZE;
d9104d1ca   Cyrill Gorcunov   mm: track vma cha...
254
  	vma->vm_flags = VM_SOFTDIRTY | VM_STACK_FLAGS | VM_STACK_INCOMPLETE_SETUP;
3ed75eb8f   Coly Li   setup vma->vm_pag...
255
  	vma->vm_page_prot = vm_get_page_prot(vma->vm_flags);
462e635e5   Tavis Ormandy   install_special_m...
256

b6a2fea39   Ollie Wild   mm: variable leng...
257
  	err = insert_vm_struct(mm, vma);
eaccbfa56   Luiz Fernando N. Capitulino   fs/exec.c:__bprm_...
258
  	if (err)
b6a2fea39   Ollie Wild   mm: variable leng...
259
  		goto err;
b6a2fea39   Ollie Wild   mm: variable leng...
260
261
  
  	mm->stack_vm = mm->total_vm = 1;
fe3d197f8   Dave Hansen   x86, mpx: On-dema...
262
  	arch_bprm_mm_init(mm, vma);
b6a2fea39   Ollie Wild   mm: variable leng...
263
  	up_write(&mm->mmap_sem);
b6a2fea39   Ollie Wild   mm: variable leng...
264
  	bprm->p = vma->vm_end - sizeof(void *);
b6a2fea39   Ollie Wild   mm: variable leng...
265
  	return 0;
b6a2fea39   Ollie Wild   mm: variable leng...
266
  err:
eaccbfa56   Luiz Fernando N. Capitulino   fs/exec.c:__bprm_...
267
  	up_write(&mm->mmap_sem);
f268dfe90   Michal Hocko   exec: make exec p...
268
  err_free:
eaccbfa56   Luiz Fernando N. Capitulino   fs/exec.c:__bprm_...
269
  	bprm->vma = NULL;
3928d4f5e   Linus Torvalds   mm: use helper fu...
270
  	vm_area_free(vma);
b6a2fea39   Ollie Wild   mm: variable leng...
271
272
273
274
275
276
277
278
279
  	return err;
  }
  
  static bool valid_arg_len(struct linux_binprm *bprm, long len)
  {
  	return len <= MAX_ARG_STRLEN;
  }
  
  #else
0e028465d   Oleg Nesterov   exec: unify do_ex...
280
  static inline void acct_arg_size(struct linux_binprm *bprm, unsigned long pages)
3c77f8457   Oleg Nesterov   exec: make argv/e...
281
282
  {
  }
0e028465d   Oleg Nesterov   exec: unify do_ex...
283
  static struct page *get_arg_page(struct linux_binprm *bprm, unsigned long pos,
b6a2fea39   Ollie Wild   mm: variable leng...
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
  		int write)
  {
  	struct page *page;
  
  	page = bprm->page[pos / PAGE_SIZE];
  	if (!page && write) {
  		page = alloc_page(GFP_HIGHUSER|__GFP_ZERO);
  		if (!page)
  			return NULL;
  		bprm->page[pos / PAGE_SIZE] = page;
  	}
  
  	return page;
  }
  
  static void put_arg_page(struct page *page)
  {
  }
  
  static void free_arg_page(struct linux_binprm *bprm, int i)
  {
  	if (bprm->page[i]) {
  		__free_page(bprm->page[i]);
  		bprm->page[i] = NULL;
  	}
  }
  
  static void free_arg_pages(struct linux_binprm *bprm)
  {
  	int i;
  
  	for (i = 0; i < MAX_ARG_PAGES; i++)
  		free_arg_page(bprm, i);
  }
  
  static void flush_arg_page(struct linux_binprm *bprm, unsigned long pos,
  		struct page *page)
  {
  }
  
  static int __bprm_mm_init(struct linux_binprm *bprm)
  {
  	bprm->p = PAGE_SIZE * MAX_ARG_PAGES - sizeof(void *);
  	return 0;
  }
  
  static bool valid_arg_len(struct linux_binprm *bprm, long len)
  {
  	return len <= bprm->p;
  }
  
  #endif /* CONFIG_MMU */
  
  /*
   * Create a new mm_struct and populate it with a temporary stack
   * vm_area_struct.  We don't have enough context at this point to set the stack
   * flags, permissions, and offset, so we use temporary values.  We'll update
   * them later in setup_arg_pages().
   */
9cc64ceaa   Yuanhan Liu   fs/exec.c: make b...
343
  static int bprm_mm_init(struct linux_binprm *bprm)
b6a2fea39   Ollie Wild   mm: variable leng...
344
345
346
347
348
349
350
351
  {
  	int err;
  	struct mm_struct *mm = NULL;
  
  	bprm->mm = mm = mm_alloc();
  	err = -ENOMEM;
  	if (!mm)
  		goto err;
c31dbb146   Kees Cook   exec: pin stack l...
352
353
354
355
  	/* Save current stack limit for all calculations made during exec. */
  	task_lock(current->group_leader);
  	bprm->rlim_stack = current->signal->rlim[RLIMIT_STACK];
  	task_unlock(current->group_leader);
b6a2fea39   Ollie Wild   mm: variable leng...
356
357
358
359
360
361
362
363
364
365
366
367
368
369
  	err = __bprm_mm_init(bprm);
  	if (err)
  		goto err;
  
  	return 0;
  
  err:
  	if (mm) {
  		bprm->mm = NULL;
  		mmdrop(mm);
  	}
  
  	return err;
  }
ba2d01629   Oleg Nesterov   exec: introduce s...
370
  struct user_arg_ptr {
0e028465d   Oleg Nesterov   exec: unify do_ex...
371
372
373
374
375
376
  #ifdef CONFIG_COMPAT
  	bool is_compat;
  #endif
  	union {
  		const char __user *const __user *native;
  #ifdef CONFIG_COMPAT
38b983b34   Al Viro   generic sys_execve()
377
  		const compat_uptr_t __user *compat;
0e028465d   Oleg Nesterov   exec: unify do_ex...
378
379
  #endif
  	} ptr;
ba2d01629   Oleg Nesterov   exec: introduce s...
380
381
382
  };
  
  static const char __user *get_user_arg_ptr(struct user_arg_ptr argv, int nr)
1d1dbf813   Oleg Nesterov   exec: introduce g...
383
  {
0e028465d   Oleg Nesterov   exec: unify do_ex...
384
385
386
387
388
389
390
391
  	const char __user *native;
  
  #ifdef CONFIG_COMPAT
  	if (unlikely(argv.is_compat)) {
  		compat_uptr_t compat;
  
  		if (get_user(compat, argv.ptr.compat + nr))
  			return ERR_PTR(-EFAULT);
1d1dbf813   Oleg Nesterov   exec: introduce g...
392

0e028465d   Oleg Nesterov   exec: unify do_ex...
393
394
395
396
397
  		return compat_ptr(compat);
  	}
  #endif
  
  	if (get_user(native, argv.ptr.native + nr))
1d1dbf813   Oleg Nesterov   exec: introduce g...
398
  		return ERR_PTR(-EFAULT);
0e028465d   Oleg Nesterov   exec: unify do_ex...
399
  	return native;
1d1dbf813   Oleg Nesterov   exec: introduce g...
400
  }
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
401
402
403
  /*
   * count() counts the number of strings in array ARGV.
   */
ba2d01629   Oleg Nesterov   exec: introduce s...
404
  static int count(struct user_arg_ptr argv, int max)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
405
406
  {
  	int i = 0;
0e028465d   Oleg Nesterov   exec: unify do_ex...
407
  	if (argv.ptr.native != NULL) {
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
408
  		for (;;) {
1d1dbf813   Oleg Nesterov   exec: introduce g...
409
  			const char __user *p = get_user_arg_ptr(argv, i);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
410

1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
411
412
  			if (!p)
  				break;
1d1dbf813   Oleg Nesterov   exec: introduce g...
413
414
415
  
  			if (IS_ERR(p))
  				return -EFAULT;
6d92d4f6a   Xi Wang   fs/exec.c: work a...
416
  			if (i >= max)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
417
  				return -E2BIG;
6d92d4f6a   Xi Wang   fs/exec.c: work a...
418
  			++i;
9aea5a65a   Roland McGrath   execve: make resp...
419
420
421
  
  			if (fatal_signal_pending(current))
  				return -ERESTARTNOHAND;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
422
423
424
425
426
  			cond_resched();
  		}
  	}
  	return i;
  }
655c16a8c   Oleg Nesterov   exec: separate MM...
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
  static int prepare_arg_pages(struct linux_binprm *bprm,
  			struct user_arg_ptr argv, struct user_arg_ptr envp)
  {
  	unsigned long limit, ptr_size;
  
  	bprm->argc = count(argv, MAX_ARG_STRINGS);
  	if (bprm->argc < 0)
  		return bprm->argc;
  
  	bprm->envc = count(envp, MAX_ARG_STRINGS);
  	if (bprm->envc < 0)
  		return bprm->envc;
  
  	/*
  	 * Limit to 1/4 of the max stack size or 3/4 of _STK_LIM
  	 * (whichever is smaller) for the argv+env strings.
  	 * This ensures that:
  	 *  - the remaining binfmt code will not run out of stack space,
  	 *  - the program will have a reasonable amount of stack left
  	 *    to work from.
  	 */
  	limit = _STK_LIM / 4 * 3;
  	limit = min(limit, bprm->rlim_stack.rlim_cur / 4);
  	/*
  	 * We've historically supported up to 32 pages (ARG_MAX)
  	 * of argument strings even with small stacks
  	 */
  	limit = max_t(unsigned long, limit, ARG_MAX);
  	/*
  	 * We must account for the size of all the argv and envp pointers to
  	 * the argv and envp strings, since they will also take up space in
  	 * the stack. They aren't stored until much later when we can't
  	 * signal to the parent that the child has run out of stack space.
  	 * Instead, calculate it here so it's possible to fail gracefully.
  	 */
  	ptr_size = (bprm->argc + bprm->envc) * sizeof(void *);
  	if (limit <= ptr_size)
  		return -E2BIG;
  	limit -= ptr_size;
  
  	bprm->argmin = bprm->p - limit;
  	return 0;
  }
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
470
  /*
b6a2fea39   Ollie Wild   mm: variable leng...
471
472
473
   * 'copy_strings()' copies argument/environment strings from the old
   * processes's memory to the new process's stack.  The call to get_user_pages()
   * ensures the destination page is created and not swapped out.
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
474
   */
ba2d01629   Oleg Nesterov   exec: introduce s...
475
  static int copy_strings(int argc, struct user_arg_ptr argv,
75c96f858   Adrian Bunk   [PATCH] make some...
476
  			struct linux_binprm *bprm)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
477
478
479
  {
  	struct page *kmapped_page = NULL;
  	char *kaddr = NULL;
b6a2fea39   Ollie Wild   mm: variable leng...
480
  	unsigned long kpos = 0;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
481
482
483
  	int ret;
  
  	while (argc-- > 0) {
d7627467b   David Howells   Make do_execve() ...
484
  		const char __user *str;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
485
486
  		int len;
  		unsigned long pos;
1d1dbf813   Oleg Nesterov   exec: introduce g...
487
488
489
  		ret = -EFAULT;
  		str = get_user_arg_ptr(argv, argc);
  		if (IS_ERR(str))
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
490
  			goto out;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
491

1d1dbf813   Oleg Nesterov   exec: introduce g...
492
493
494
495
496
497
  		len = strnlen_user(str, MAX_ARG_STRLEN);
  		if (!len)
  			goto out;
  
  		ret = -E2BIG;
  		if (!valid_arg_len(bprm, len))
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
498
  			goto out;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
499

b6a2fea39   Ollie Wild   mm: variable leng...
500
  		/* We're going to work our way backwords. */
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
501
  		pos = bprm->p;
b6a2fea39   Ollie Wild   mm: variable leng...
502
503
  		str += len;
  		bprm->p -= len;
655c16a8c   Oleg Nesterov   exec: separate MM...
504
505
506
507
  #ifdef CONFIG_MMU
  		if (bprm->p < bprm->argmin)
  			goto out;
  #endif
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
508
509
  
  		while (len > 0) {
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
510
  			int offset, bytes_to_copy;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
511

9aea5a65a   Roland McGrath   execve: make resp...
512
513
514
515
  			if (fatal_signal_pending(current)) {
  				ret = -ERESTARTNOHAND;
  				goto out;
  			}
7993bc1f4   Roland McGrath   execve: improve i...
516
  			cond_resched();
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
517
  			offset = pos % PAGE_SIZE;
b6a2fea39   Ollie Wild   mm: variable leng...
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
  			if (offset == 0)
  				offset = PAGE_SIZE;
  
  			bytes_to_copy = offset;
  			if (bytes_to_copy > len)
  				bytes_to_copy = len;
  
  			offset -= bytes_to_copy;
  			pos -= bytes_to_copy;
  			str -= bytes_to_copy;
  			len -= bytes_to_copy;
  
  			if (!kmapped_page || kpos != (pos & PAGE_MASK)) {
  				struct page *page;
  
  				page = get_arg_page(bprm, pos, 1);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
534
  				if (!page) {
b6a2fea39   Ollie Wild   mm: variable leng...
535
  					ret = -E2BIG;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
536
537
  					goto out;
  				}
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
538

b6a2fea39   Ollie Wild   mm: variable leng...
539
540
  				if (kmapped_page) {
  					flush_kernel_dcache_page(kmapped_page);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
541
  					kunmap(kmapped_page);
b6a2fea39   Ollie Wild   mm: variable leng...
542
543
  					put_arg_page(kmapped_page);
  				}
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
544
545
  				kmapped_page = page;
  				kaddr = kmap(kmapped_page);
b6a2fea39   Ollie Wild   mm: variable leng...
546
547
  				kpos = pos & PAGE_MASK;
  				flush_arg_page(bprm, kpos, kmapped_page);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
548
  			}
b6a2fea39   Ollie Wild   mm: variable leng...
549
  			if (copy_from_user(kaddr+offset, str, bytes_to_copy)) {
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
550
551
552
  				ret = -EFAULT;
  				goto out;
  			}
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
553
554
555
556
  		}
  	}
  	ret = 0;
  out:
b6a2fea39   Ollie Wild   mm: variable leng...
557
558
  	if (kmapped_page) {
  		flush_kernel_dcache_page(kmapped_page);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
559
  		kunmap(kmapped_page);
b6a2fea39   Ollie Wild   mm: variable leng...
560
561
  		put_arg_page(kmapped_page);
  	}
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
562
563
564
565
566
567
  	return ret;
  }
  
  /*
   * Like copy_strings, but get argv and its values from kernel memory.
   */
ba2d01629   Oleg Nesterov   exec: introduce s...
568
  int copy_strings_kernel(int argc, const char *const *__argv,
d7627467b   David Howells   Make do_execve() ...
569
  			struct linux_binprm *bprm)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
570
571
572
  {
  	int r;
  	mm_segment_t oldfs = get_fs();
ba2d01629   Oleg Nesterov   exec: introduce s...
573
  	struct user_arg_ptr argv = {
0e028465d   Oleg Nesterov   exec: unify do_ex...
574
  		.ptr.native = (const char __user *const  __user *)__argv,
ba2d01629   Oleg Nesterov   exec: introduce s...
575
  	};
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
576
  	set_fs(KERNEL_DS);
ba2d01629   Oleg Nesterov   exec: introduce s...
577
  	r = copy_strings(argc, argv, bprm);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
578
  	set_fs(oldfs);
ba2d01629   Oleg Nesterov   exec: introduce s...
579

1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
580
581
  	return r;
  }
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
582
583
584
  EXPORT_SYMBOL(copy_strings_kernel);
  
  #ifdef CONFIG_MMU
b6a2fea39   Ollie Wild   mm: variable leng...
585

1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
586
  /*
b6a2fea39   Ollie Wild   mm: variable leng...
587
588
589
   * During bprm_mm_init(), we create a temporary stack at STACK_TOP_MAX.  Once
   * the binfmt code determines where the new stack should reside, we shift it to
   * its final location.  The process proceeds as follows:
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
590
   *
b6a2fea39   Ollie Wild   mm: variable leng...
591
592
593
594
595
596
   * 1) Use shift to calculate the new vma endpoints.
   * 2) Extend vma to cover both the old and new ranges.  This ensures the
   *    arguments passed to subsequent functions are consistent.
   * 3) Move vma's page tables to the new range.
   * 4) Free up any cleared pgd range.
   * 5) Shrink the vma to cover only the new range.
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
597
   */
b6a2fea39   Ollie Wild   mm: variable leng...
598
  static int shift_arg_pages(struct vm_area_struct *vma, unsigned long shift)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
599
600
  {
  	struct mm_struct *mm = vma->vm_mm;
b6a2fea39   Ollie Wild   mm: variable leng...
601
602
603
604
605
  	unsigned long old_start = vma->vm_start;
  	unsigned long old_end = vma->vm_end;
  	unsigned long length = old_end - old_start;
  	unsigned long new_start = old_start - shift;
  	unsigned long new_end = old_end - shift;
d16dfc550   Peter Zijlstra   mm: mmu_gather re...
606
  	struct mmu_gather tlb;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
607

b6a2fea39   Ollie Wild   mm: variable leng...
608
  	BUG_ON(new_start > new_end);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
609

b6a2fea39   Ollie Wild   mm: variable leng...
610
611
612
613
614
615
616
617
618
619
  	/*
  	 * ensure there are no vmas between where we want to go
  	 * and where we are
  	 */
  	if (vma != find_vma(mm, new_start))
  		return -EFAULT;
  
  	/*
  	 * cover the whole range: [new_start, old_end)
  	 */
5beb49305   Rik van Riel   mm: change anon_v...
620
621
  	if (vma_adjust(vma, new_start, old_end, vma->vm_pgoff, NULL))
  		return -ENOMEM;
b6a2fea39   Ollie Wild   mm: variable leng...
622
623
624
625
626
627
  
  	/*
  	 * move the page tables downwards, on failure we rely on
  	 * process cleanup to remove whatever mess we made.
  	 */
  	if (length != move_page_tables(vma, old_start,
38a76013a   Michel Lespinasse   mm: avoid taking ...
628
  				       vma, new_start, length, false))
b6a2fea39   Ollie Wild   mm: variable leng...
629
630
631
  		return -ENOMEM;
  
  	lru_add_drain();
2b047252d   Linus Torvalds   Fix TLB gather vi...
632
  	tlb_gather_mmu(&tlb, mm, old_start, old_end);
b6a2fea39   Ollie Wild   mm: variable leng...
633
634
635
636
  	if (new_end > old_start) {
  		/*
  		 * when the old and new regions overlap clear from new_end.
  		 */
d16dfc550   Peter Zijlstra   mm: mmu_gather re...
637
  		free_pgd_range(&tlb, new_end, old_end, new_end,
6ee8630e0   Hugh Dickins   mm: allow arch co...
638
  			vma->vm_next ? vma->vm_next->vm_start : USER_PGTABLES_CEILING);
b6a2fea39   Ollie Wild   mm: variable leng...
639
640
641
642
643
644
645
  	} else {
  		/*
  		 * otherwise, clean from old_start; this is done to not touch
  		 * the address space in [new_end, old_start) some architectures
  		 * have constraints on va-space that make this illegal (IA64) -
  		 * for the others its just a little faster.
  		 */
d16dfc550   Peter Zijlstra   mm: mmu_gather re...
646
  		free_pgd_range(&tlb, old_start, old_end, new_end,
6ee8630e0   Hugh Dickins   mm: allow arch co...
647
  			vma->vm_next ? vma->vm_next->vm_start : USER_PGTABLES_CEILING);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
648
  	}
2b047252d   Linus Torvalds   Fix TLB gather vi...
649
  	tlb_finish_mmu(&tlb, old_start, old_end);
b6a2fea39   Ollie Wild   mm: variable leng...
650
651
  
  	/*
5beb49305   Rik van Riel   mm: change anon_v...
652
  	 * Shrink the vma to just the new range.  Always succeeds.
b6a2fea39   Ollie Wild   mm: variable leng...
653
654
655
656
  	 */
  	vma_adjust(vma, new_start, new_end, vma->vm_pgoff, NULL);
  
  	return 0;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
657
  }
b6a2fea39   Ollie Wild   mm: variable leng...
658
659
660
661
  /*
   * Finalizes the stack vm_area_struct. The flags and permissions are updated,
   * the stack is optionally relocated, and some extra space is added.
   */
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
662
663
664
665
  int setup_arg_pages(struct linux_binprm *bprm,
  		    unsigned long stack_top,
  		    int executable_stack)
  {
b6a2fea39   Ollie Wild   mm: variable leng...
666
667
  	unsigned long ret;
  	unsigned long stack_shift;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
668
  	struct mm_struct *mm = current->mm;
b6a2fea39   Ollie Wild   mm: variable leng...
669
670
671
672
  	struct vm_area_struct *vma = bprm->vma;
  	struct vm_area_struct *prev = NULL;
  	unsigned long vm_flags;
  	unsigned long stack_base;
803bf5ec2   Michael Neuling   fs/exec.c: restri...
673
674
675
  	unsigned long stack_size;
  	unsigned long stack_expand;
  	unsigned long rlim_stack;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
676
677
  
  #ifdef CONFIG_STACK_GROWSUP
d71f290b4   James Hogan   metag: Reduce max...
678
  	/* Limit stack size */
c31dbb146   Kees Cook   exec: pin stack l...
679
  	stack_base = bprm->rlim_stack.rlim_max;
d71f290b4   James Hogan   metag: Reduce max...
680
681
  	if (stack_base > STACK_SIZE_MAX)
  		stack_base = STACK_SIZE_MAX;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
682

d045c77c1   Helge Deller   parisc,metag: Fix...
683
684
  	/* Add space for stack randomization. */
  	stack_base += (STACK_RND_MASK << PAGE_SHIFT);
b6a2fea39   Ollie Wild   mm: variable leng...
685
686
687
  	/* Make sure we didn't let the argument array grow too large. */
  	if (vma->vm_end - vma->vm_start > stack_base)
  		return -ENOMEM;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
688

b6a2fea39   Ollie Wild   mm: variable leng...
689
  	stack_base = PAGE_ALIGN(stack_top - stack_base);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
690

b6a2fea39   Ollie Wild   mm: variable leng...
691
692
693
  	stack_shift = vma->vm_start - stack_base;
  	mm->arg_start = bprm->p - stack_shift;
  	bprm->p = vma->vm_end - stack_shift;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
694
  #else
b6a2fea39   Ollie Wild   mm: variable leng...
695
696
  	stack_top = arch_align_stack(stack_top);
  	stack_top = PAGE_ALIGN(stack_top);
1b528181b   Roland McGrath   setup_arg_pages: ...
697
698
699
700
  
  	if (unlikely(stack_top < mmap_min_addr) ||
  	    unlikely(vma->vm_end - vma->vm_start >= stack_top - mmap_min_addr))
  		return -ENOMEM;
b6a2fea39   Ollie Wild   mm: variable leng...
701
702
703
  	stack_shift = vma->vm_end - stack_top;
  
  	bprm->p -= stack_shift;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
704
  	mm->arg_start = bprm->p;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
705
  #endif
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
706
  	if (bprm->loader)
b6a2fea39   Ollie Wild   mm: variable leng...
707
708
  		bprm->loader -= stack_shift;
  	bprm->exec -= stack_shift;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
709

f268dfe90   Michal Hocko   exec: make exec p...
710
711
  	if (down_write_killable(&mm->mmap_sem))
  		return -EINTR;
96a8e13ed   Hugh Dickins   exec: fix stack e...
712
  	vm_flags = VM_STACK_FLAGS;
b6a2fea39   Ollie Wild   mm: variable leng...
713
714
715
716
717
718
719
720
721
722
723
  
  	/*
  	 * Adjust stack execute permissions; explicitly enable for
  	 * EXSTACK_ENABLE_X, disable for EXSTACK_DISABLE_X and leave alone
  	 * (arch default) otherwise.
  	 */
  	if (unlikely(executable_stack == EXSTACK_ENABLE_X))
  		vm_flags |= VM_EXEC;
  	else if (executable_stack == EXSTACK_DISABLE_X)
  		vm_flags &= ~VM_EXEC;
  	vm_flags |= mm->def_flags;
a8bef8ff6   Mel Gorman   mm: migration: av...
724
  	vm_flags |= VM_STACK_INCOMPLETE_SETUP;
b6a2fea39   Ollie Wild   mm: variable leng...
725
726
727
728
729
730
731
732
733
734
  
  	ret = mprotect_fixup(vma, &prev, vma->vm_start, vma->vm_end,
  			vm_flags);
  	if (ret)
  		goto out_unlock;
  	BUG_ON(prev != vma);
  
  	/* Move stack pages down in memory. */
  	if (stack_shift) {
  		ret = shift_arg_pages(vma, stack_shift);
fc63cf237   Anton Blanchard   exec: setup_arg_p...
735
736
  		if (ret)
  			goto out_unlock;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
737
  	}
a8bef8ff6   Mel Gorman   mm: migration: av...
738
739
  	/* mprotect_fixup is overkill to remove the temporary stack flags */
  	vma->vm_flags &= ~VM_STACK_INCOMPLETE_SETUP;
5ef097dd7   Michael Neuling   exec: create init...
740
  	stack_expand = 131072UL; /* randomly 32*4k (or 2*64k) pages */
803bf5ec2   Michael Neuling   fs/exec.c: restri...
741
742
743
744
745
  	stack_size = vma->vm_end - vma->vm_start;
  	/*
  	 * Align this down to a page boundary as expand_stack
  	 * will align it up.
  	 */
c31dbb146   Kees Cook   exec: pin stack l...
746
  	rlim_stack = bprm->rlim_stack.rlim_cur & PAGE_MASK;
b6a2fea39   Ollie Wild   mm: variable leng...
747
  #ifdef CONFIG_STACK_GROWSUP
803bf5ec2   Michael Neuling   fs/exec.c: restri...
748
749
750
751
  	if (stack_size + stack_expand > rlim_stack)
  		stack_base = vma->vm_start + rlim_stack;
  	else
  		stack_base = vma->vm_end + stack_expand;
b6a2fea39   Ollie Wild   mm: variable leng...
752
  #else
803bf5ec2   Michael Neuling   fs/exec.c: restri...
753
754
755
756
  	if (stack_size + stack_expand > rlim_stack)
  		stack_base = vma->vm_end - rlim_stack;
  	else
  		stack_base = vma->vm_start - stack_expand;
b6a2fea39   Ollie Wild   mm: variable leng...
757
  #endif
3af9e8592   Eric B Munson   perf: Add non-exe...
758
  	current->mm->start_stack = bprm->p;
b6a2fea39   Ollie Wild   mm: variable leng...
759
760
761
762
763
  	ret = expand_stack(vma, stack_base);
  	if (ret)
  		ret = -EFAULT;
  
  out_unlock:
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
764
  	up_write(&mm->mmap_sem);
fc63cf237   Anton Blanchard   exec: setup_arg_p...
765
  	return ret;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
766
  }
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
767
  EXPORT_SYMBOL(setup_arg_pages);
7e7ec6a93   Nicolas Pitre   elf_fdpic_transfe...
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
  #else
  
  /*
   * Transfer the program arguments and environment from the holding pages
   * onto the stack. The provided stack pointer is adjusted accordingly.
   */
  int transfer_args_to_stack(struct linux_binprm *bprm,
  			   unsigned long *sp_location)
  {
  	unsigned long index, stop, sp;
  	int ret = 0;
  
  	stop = bprm->p >> PAGE_SHIFT;
  	sp = *sp_location;
  
  	for (index = MAX_ARG_PAGES - 1; index >= stop; index--) {
  		unsigned int offset = index == stop ? bprm->p & ~PAGE_MASK : 0;
  		char *src = kmap(bprm->page[index]) + offset;
  		sp -= PAGE_SIZE - offset;
  		if (copy_to_user((void *) sp, src, PAGE_SIZE - offset) != 0)
  			ret = -EFAULT;
  		kunmap(bprm->page[index]);
  		if (ret)
  			goto out;
  	}
  
  	*sp_location = sp;
  
  out:
  	return ret;
  }
  EXPORT_SYMBOL(transfer_args_to_stack);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
800
  #endif /* CONFIG_MMU */
51f39a1f0   David Drysdale   syscalls: impleme...
801
  static struct file *do_open_execat(int fd, struct filename *name, int flags)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
802
  {
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
803
  	struct file *file;
e56b6a5dd   Christoph Hellwig   Re: [PATCH 3/6] v...
804
  	int err;
51f39a1f0   David Drysdale   syscalls: impleme...
805
  	struct open_flags open_exec_flags = {
47c805dc2   Al Viro   switch do_filp_op...
806
  		.open_flag = O_LARGEFILE | O_RDONLY | __FMODE_EXEC,
62fb4a155   Al Viro   don't carry MAY_O...
807
  		.acc_mode = MAY_EXEC,
f9652e10c   Al Viro   allow build_open_...
808
809
  		.intent = LOOKUP_OPEN,
  		.lookup_flags = LOOKUP_FOLLOW,
47c805dc2   Al Viro   switch do_filp_op...
810
  	};
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
811

51f39a1f0   David Drysdale   syscalls: impleme...
812
813
814
815
816
817
818
819
  	if ((flags & ~(AT_SYMLINK_NOFOLLOW | AT_EMPTY_PATH)) != 0)
  		return ERR_PTR(-EINVAL);
  	if (flags & AT_SYMLINK_NOFOLLOW)
  		open_exec_flags.lookup_flags &= ~LOOKUP_FOLLOW;
  	if (flags & AT_EMPTY_PATH)
  		open_exec_flags.lookup_flags |= LOOKUP_EMPTY;
  
  	file = do_filp_open(fd, name, &open_exec_flags);
6e8341a11   Al Viro   Switch open_exec(...
820
  	if (IS_ERR(file))
e56b6a5dd   Christoph Hellwig   Re: [PATCH 3/6] v...
821
822
823
  		goto out;
  
  	err = -EACCES;
496ad9aa8   Al Viro   new helper: file_...
824
  	if (!S_ISREG(file_inode(file)->i_mode))
6e8341a11   Al Viro   Switch open_exec(...
825
  		goto exit;
e56b6a5dd   Christoph Hellwig   Re: [PATCH 3/6] v...
826

90f8572b0   Eric W. Biederman   vfs: Commit to ne...
827
  	if (path_noexec(&file->f_path))
6e8341a11   Al Viro   Switch open_exec(...
828
  		goto exit;
e56b6a5dd   Christoph Hellwig   Re: [PATCH 3/6] v...
829
830
  
  	err = deny_write_access(file);
6e8341a11   Al Viro   Switch open_exec(...
831
832
  	if (err)
  		goto exit;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
833

51f39a1f0   David Drysdale   syscalls: impleme...
834
835
  	if (name->name[0] != '\0')
  		fsnotify_open(file);
6e8341a11   Al Viro   Switch open_exec(...
836
  out:
e56b6a5dd   Christoph Hellwig   Re: [PATCH 3/6] v...
837
  	return file;
6e8341a11   Al Viro   Switch open_exec(...
838
839
  exit:
  	fput(file);
e56b6a5dd   Christoph Hellwig   Re: [PATCH 3/6] v...
840
841
  	return ERR_PTR(err);
  }
c4ad8f98b   Linus Torvalds   execve: use 'stru...
842
843
844
  
  struct file *open_exec(const char *name)
  {
516891041   Paul Moore   fs: create proper...
845
846
847
848
849
850
851
852
  	struct filename *filename = getname_kernel(name);
  	struct file *f = ERR_CAST(filename);
  
  	if (!IS_ERR(filename)) {
  		f = do_open_execat(AT_FDCWD, filename, 0);
  		putname(filename);
  	}
  	return f;
c4ad8f98b   Linus Torvalds   execve: use 'stru...
853
  }
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
854
  EXPORT_SYMBOL(open_exec);
b44a7dfc6   Mimi Zohar   vfs: define a gen...
855
  int kernel_read_file(struct file *file, void **buf, loff_t *size,
bc8ca5b92   Mimi Zohar   vfs: define kerne...
856
  		     loff_t max_size, enum kernel_read_file_id id)
b44a7dfc6   Mimi Zohar   vfs: define a gen...
857
858
859
860
861
862
863
  {
  	loff_t i_size, pos;
  	ssize_t bytes = 0;
  	int ret;
  
  	if (!S_ISREG(file_inode(file)->i_mode) || max_size < 0)
  		return -EINVAL;
7bd698b3c   Kees Cook   exec: Set file un...
864
  	ret = deny_write_access(file);
39eeb4fb9   Mimi Zohar   security: define ...
865
866
  	if (ret)
  		return ret;
7bd698b3c   Kees Cook   exec: Set file un...
867
  	ret = security_kernel_read_file(file, id);
39d637af5   Dmitry Kasatkin   vfs: forbid write...
868
  	if (ret)
7bd698b3c   Kees Cook   exec: Set file un...
869
  		goto out;
39d637af5   Dmitry Kasatkin   vfs: forbid write...
870

b44a7dfc6   Mimi Zohar   vfs: define a gen...
871
  	i_size = i_size_read(file_inode(file));
39d637af5   Dmitry Kasatkin   vfs: forbid write...
872
873
874
875
  	if (i_size <= 0) {
  		ret = -EINVAL;
  		goto out;
  	}
691115c35   Eric Biggers   vfs: require i_si...
876
877
878
879
  	if (i_size > SIZE_MAX || (max_size > 0 && i_size > max_size)) {
  		ret = -EFBIG;
  		goto out;
  	}
b44a7dfc6   Mimi Zohar   vfs: define a gen...
880

a098ecd2f   Stephen Boyd   firmware: support...
881
882
  	if (id != READING_FIRMWARE_PREALLOC_BUFFER)
  		*buf = vmalloc(i_size);
39d637af5   Dmitry Kasatkin   vfs: forbid write...
883
884
885
886
  	if (!*buf) {
  		ret = -ENOMEM;
  		goto out;
  	}
b44a7dfc6   Mimi Zohar   vfs: define a gen...
887
888
889
  
  	pos = 0;
  	while (pos < i_size) {
bdd1d2d3d   Christoph Hellwig   fs: fix kernel_re...
890
  		bytes = kernel_read(file, *buf + pos, i_size - pos, &pos);
b44a7dfc6   Mimi Zohar   vfs: define a gen...
891
892
  		if (bytes < 0) {
  			ret = bytes;
f612acfae   YueHaibing   exec: Fix mem lea...
893
  			goto out_free;
b44a7dfc6   Mimi Zohar   vfs: define a gen...
894
895
896
897
  		}
  
  		if (bytes == 0)
  			break;
b44a7dfc6   Mimi Zohar   vfs: define a gen...
898
899
900
901
  	}
  
  	if (pos != i_size) {
  		ret = -EIO;
39d637af5   Dmitry Kasatkin   vfs: forbid write...
902
  		goto out_free;
b44a7dfc6   Mimi Zohar   vfs: define a gen...
903
  	}
bc8ca5b92   Mimi Zohar   vfs: define kerne...
904
  	ret = security_kernel_post_read_file(file, *buf, i_size, id);
b44a7dfc6   Mimi Zohar   vfs: define a gen...
905
906
  	if (!ret)
  		*size = pos;
39d637af5   Dmitry Kasatkin   vfs: forbid write...
907
  out_free:
b44a7dfc6   Mimi Zohar   vfs: define a gen...
908
  	if (ret < 0) {
a098ecd2f   Stephen Boyd   firmware: support...
909
910
911
912
  		if (id != READING_FIRMWARE_PREALLOC_BUFFER) {
  			vfree(*buf);
  			*buf = NULL;
  		}
b44a7dfc6   Mimi Zohar   vfs: define a gen...
913
  	}
39d637af5   Dmitry Kasatkin   vfs: forbid write...
914
915
916
  
  out:
  	allow_write_access(file);
b44a7dfc6   Mimi Zohar   vfs: define a gen...
917
918
919
  	return ret;
  }
  EXPORT_SYMBOL_GPL(kernel_read_file);
711aab1db   Mimi Zohar   vfs: constify pat...
920
  int kernel_read_file_from_path(const char *path, void **buf, loff_t *size,
09596b94f   Mimi Zohar   vfs: define kerne...
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
  			       loff_t max_size, enum kernel_read_file_id id)
  {
  	struct file *file;
  	int ret;
  
  	if (!path || !*path)
  		return -EINVAL;
  
  	file = filp_open(path, O_RDONLY, 0);
  	if (IS_ERR(file))
  		return PTR_ERR(file);
  
  	ret = kernel_read_file(file, buf, size, max_size, id);
  	fput(file);
  	return ret;
  }
  EXPORT_SYMBOL_GPL(kernel_read_file_from_path);
b844f0ecb   Mimi Zohar   vfs: define kerne...
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
  int kernel_read_file_from_fd(int fd, void **buf, loff_t *size, loff_t max_size,
  			     enum kernel_read_file_id id)
  {
  	struct fd f = fdget(fd);
  	int ret = -EBADF;
  
  	if (!f.file)
  		goto out;
  
  	ret = kernel_read_file(f.file, buf, size, max_size, id);
  out:
  	fdput(f);
  	return ret;
  }
  EXPORT_SYMBOL_GPL(kernel_read_file_from_fd);
3dc20cb28   Al Viro   new helper: read_...
953
954
  ssize_t read_code(struct file *file, unsigned long addr, loff_t pos, size_t len)
  {
ec6955798   Al Viro   read_code(): go t...
955
  	ssize_t res = vfs_read(file, (void __user *)addr, len, &pos);
3dc20cb28   Al Viro   new helper: read_...
956
957
958
959
960
  	if (res > 0)
  		flush_icache_range(addr, addr + len);
  	return res;
  }
  EXPORT_SYMBOL(read_code);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
961
962
963
  static int exec_mmap(struct mm_struct *mm)
  {
  	struct task_struct *tsk;
615d6e875   Davidlohr Bueso   mm: per-thread vm...
964
  	struct mm_struct *old_mm, *active_mm;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
965
966
967
968
  
  	/* Notify parent that we're no longer interested in the old VM */
  	tsk = current;
  	old_mm = current->mm;
7d7e93588   Thomas Gleixner   exit/exec: Sepera...
969
  	exec_mm_release(tsk, old_mm);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
970
971
  
  	if (old_mm) {
4fe7efdbd   Konstantin Khlebnikov   mm: correctly syn...
972
  		sync_mm_rss(old_mm);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
973
974
975
976
  		/*
  		 * Make sure that if there is a core dump in progress
  		 * for the old mm, we get out and die instead of going
  		 * through with the exec.  We must hold mmap_sem around
999d9fc16   Oleg Nesterov   coredump: move mm...
977
  		 * checking core_state and changing tsk->mm.
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
978
979
  		 */
  		down_read(&old_mm->mmap_sem);
999d9fc16   Oleg Nesterov   coredump: move mm...
980
  		if (unlikely(old_mm->core_state)) {
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
981
982
983
984
985
986
  			up_read(&old_mm->mmap_sem);
  			return -EINTR;
  		}
  	}
  	task_lock(tsk);
  	active_mm = tsk->active_mm;
227a4aadc   Mathieu Desnoyers   sched/membarrier:...
987
  	membarrier_exec_mmap(mm);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
988
989
990
  	tsk->mm = mm;
  	tsk->active_mm = mm;
  	activate_mm(active_mm, mm);
615d6e875   Davidlohr Bueso   mm: per-thread vm...
991
992
  	tsk->mm->vmacache_seqnum = 0;
  	vmacache_flush(tsk);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
993
  	task_unlock(tsk);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
994
995
  	if (old_mm) {
  		up_read(&old_mm->mmap_sem);
7dddb12c6   Eric Sesterhenn   BUG_ON() Conversi...
996
  		BUG_ON(active_mm != old_mm);
701085b21   Oleg Nesterov   exec: move de_thr...
997
  		setmax_mm_hiwater_rss(&tsk->signal->maxrss, old_mm);
31a78f23b   Balbir Singh   mm owner: fix rac...
998
  		mm_update_next_owner(old_mm);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
999
1000
1001
1002
1003
1004
1005
1006
1007
1008
1009
1010
1011
  		mmput(old_mm);
  		return 0;
  	}
  	mmdrop(active_mm);
  	return 0;
  }
  
  /*
   * This function makes sure the current process has its own signal table,
   * so that flush_signal_handlers can later reset the handlers without
   * disturbing other processes.  (Other processes might share the signal
   * table via the CLONE_SIGHAND option to clone().)
   */
858119e15   Arjan van de Ven   [PATCH] Unlinline...
1012
  static int de_thread(struct task_struct *tsk)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1013
1014
  {
  	struct signal_struct *sig = tsk->signal;
b2c903b87   Oleg Nesterov   exec: simplify th...
1015
  	struct sighand_struct *oldsighand = tsk->sighand;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1016
  	spinlock_t *lock = &oldsighand->siglock;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1017

aafe6c2a2   Eric W. Biederman   [PATCH] de_thread...
1018
  	if (thread_group_empty(tsk))
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1019
1020
1021
1022
  		goto no_thread_group;
  
  	/*
  	 * Kill all other threads in the thread group.
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1023
  	 */
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1024
  	spin_lock_irq(lock);
ed5d2cac1   Oleg Nesterov   exec: rework the ...
1025
  	if (signal_group_exit(sig)) {
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1026
1027
1028
1029
1030
  		/*
  		 * Another group action in progress, just
  		 * return so that the signal is processed.
  		 */
  		spin_unlock_irq(lock);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1031
1032
  		return -EAGAIN;
  	}
d344193a0   Oleg Nesterov   exit: avoid sig->...
1033

ed5d2cac1   Oleg Nesterov   exec: rework the ...
1034
  	sig->group_exit_task = tsk;
d344193a0   Oleg Nesterov   exit: avoid sig->...
1035
1036
1037
  	sig->notify_count = zap_other_threads(tsk);
  	if (!thread_group_leader(tsk))
  		sig->notify_count--;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1038

d344193a0   Oleg Nesterov   exit: avoid sig->...
1039
  	while (sig->notify_count) {
d5bbd43d5   Oleg Nesterov   exec: make de_thr...
1040
  		__set_current_state(TASK_KILLABLE);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1041
  		spin_unlock_irq(lock);
a72173ecf   Rafael J. Wysocki   Revert "exec: mak...
1042
  		schedule();
08d405c8b   Davidlohr Bueso   fs/: remove calle...
1043
  		if (__fatal_signal_pending(tsk))
d5bbd43d5   Oleg Nesterov   exec: make de_thr...
1044
  			goto killed;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1045
1046
  		spin_lock_irq(lock);
  	}
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1047
1048
1049
1050
1051
1052
1053
  	spin_unlock_irq(lock);
  
  	/*
  	 * At this point all other threads have exited, all we have to
  	 * do is to wait for the thread group leader to become inactive,
  	 * and to assume its PID:
  	 */
aafe6c2a2   Eric W. Biederman   [PATCH] de_thread...
1054
  	if (!thread_group_leader(tsk)) {
8187926bd   Oleg Nesterov   posix-timers: sim...
1055
  		struct task_struct *leader = tsk->group_leader;
6db840fa7   Oleg Nesterov   exec: RT sub-thre...
1056

6db840fa7   Oleg Nesterov   exec: RT sub-thre...
1057
  		for (;;) {
780de9dd2   Ingo Molnar   sched/headers, cg...
1058
  			cgroup_threadgroup_change_begin(tsk);
6db840fa7   Oleg Nesterov   exec: RT sub-thre...
1059
  			write_lock_irq(&tasklist_lock);
dfcce791f   Kirill Tkhai   fs/exec.c:de_thre...
1060
1061
1062
1063
1064
  			/*
  			 * Do this under tasklist_lock to ensure that
  			 * exit_notify() can't miss ->group_exit_task
  			 */
  			sig->notify_count = -1;
6db840fa7   Oleg Nesterov   exec: RT sub-thre...
1065
1066
  			if (likely(leader->exit_state))
  				break;
d5bbd43d5   Oleg Nesterov   exec: make de_thr...
1067
  			__set_current_state(TASK_KILLABLE);
6db840fa7   Oleg Nesterov   exec: RT sub-thre...
1068
  			write_unlock_irq(&tasklist_lock);
780de9dd2   Ingo Molnar   sched/headers, cg...
1069
  			cgroup_threadgroup_change_end(tsk);
a72173ecf   Rafael J. Wysocki   Revert "exec: mak...
1070
  			schedule();
08d405c8b   Davidlohr Bueso   fs/: remove calle...
1071
  			if (__fatal_signal_pending(tsk))
d5bbd43d5   Oleg Nesterov   exec: make de_thr...
1072
  				goto killed;
6db840fa7   Oleg Nesterov   exec: RT sub-thre...
1073
  		}
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1074

f5e902817   Roland McGrath   [PATCH] process a...
1075
1076
1077
1078
1079
1080
1081
1082
1083
1084
  		/*
  		 * The only record we have of the real-time age of a
  		 * process, regardless of execs it's done, is start_time.
  		 * All the past CPU time is accumulated in signal_struct
  		 * from sister threads now dead.  But in this non-leader
  		 * exec, nothing survives from the original leader thread,
  		 * whose birth marks the true age of this process now.
  		 * When we take on its identity by switching to its PID, we
  		 * also take its birthdate (always earlier than our own).
  		 */
aafe6c2a2   Eric W. Biederman   [PATCH] de_thread...
1085
  		tsk->start_time = leader->start_time;
266b7a021   Oleg Nesterov   fs/exec.c:de_thre...
1086
  		tsk->real_start_time = leader->real_start_time;
f5e902817   Roland McGrath   [PATCH] process a...
1087

bac0abd61   Pavel Emelyanov   Isolate some expl...
1088
1089
  		BUG_ON(!same_thread_group(leader, tsk));
  		BUG_ON(has_group_leader_pid(tsk));
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1090
1091
1092
1093
1094
1095
  		/*
  		 * An exec() starts a new thread group with the
  		 * TGID of the previous thread group. Rehash the
  		 * two threads with a switched PID, and release
  		 * the former thread group leader:
  		 */
d73d65293   Eric W. Biederman   [PATCH] pidhash: ...
1096
1097
  
  		/* Become a process group leader with the old leader's pid.
c18258c6f   Eric W. Biederman   [PATCH] pid: Impl...
1098
1099
  		 * The old leader becomes a thread of the this thread group.
  		 * Note: The old leader also uses this pid until release_task
d73d65293   Eric W. Biederman   [PATCH] pidhash: ...
1100
1101
  		 *       is called.  Odd but simple and correct.
  		 */
aafe6c2a2   Eric W. Biederman   [PATCH] de_thread...
1102
  		tsk->pid = leader->pid;
3f4185483   Oleg Nesterov   fs/exec.c:de_thre...
1103
  		change_pid(tsk, PIDTYPE_PID, task_pid(leader));
6883f81aa   Eric W. Biederman   pid: Implement PI...
1104
  		transfer_pid(leader, tsk, PIDTYPE_TGID);
aafe6c2a2   Eric W. Biederman   [PATCH] de_thread...
1105
1106
  		transfer_pid(leader, tsk, PIDTYPE_PGID);
  		transfer_pid(leader, tsk, PIDTYPE_SID);
9cd80bbb0   Oleg Nesterov   do_wait() optimiz...
1107

aafe6c2a2   Eric W. Biederman   [PATCH] de_thread...
1108
  		list_replace_rcu(&leader->tasks, &tsk->tasks);
9cd80bbb0   Oleg Nesterov   do_wait() optimiz...
1109
  		list_replace_init(&leader->sibling, &tsk->sibling);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1110

aafe6c2a2   Eric W. Biederman   [PATCH] de_thread...
1111
1112
  		tsk->group_leader = tsk;
  		leader->group_leader = tsk;
de12a7878   Eric W. Biederman   [PATCH] de_thread...
1113

aafe6c2a2   Eric W. Biederman   [PATCH] de_thread...
1114
  		tsk->exit_signal = SIGCHLD;
087806b12   Oleg Nesterov   redefine thread_g...
1115
  		leader->exit_signal = -1;
962b564cf   Oleg Nesterov   [PATCH] fix do_wa...
1116
1117
1118
  
  		BUG_ON(leader->exit_state != EXIT_ZOMBIE);
  		leader->exit_state = EXIT_DEAD;
eac1b5e57   Oleg Nesterov   ptrace: do_wait(t...
1119
1120
1121
1122
1123
1124
1125
1126
  
  		/*
  		 * We are going to release_task()->ptrace_unlink() silently,
  		 * the tracer can sleep in do_wait(). EXIT_DEAD guarantees
  		 * the tracer wont't block again waiting for this thread.
  		 */
  		if (unlikely(leader->ptrace))
  			__wake_up_parent(leader, leader->parent);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1127
  		write_unlock_irq(&tasklist_lock);
780de9dd2   Ingo Molnar   sched/headers, cg...
1128
  		cgroup_threadgroup_change_end(tsk);
8187926bd   Oleg Nesterov   posix-timers: sim...
1129
1130
  
  		release_task(leader);
ed5d2cac1   Oleg Nesterov   exec: rework the ...
1131
  	}
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1132

6db840fa7   Oleg Nesterov   exec: RT sub-thre...
1133
1134
  	sig->group_exit_task = NULL;
  	sig->notify_count = 0;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1135
1136
  
  no_thread_group:
e63682534   Oleg Nesterov   exit_signal: simp...
1137
1138
  	/* we have changed execution domain */
  	tsk->exit_signal = SIGCHLD;
baa73d9e4   Nicolas Pitre   posix-timers: Mak...
1139
  #ifdef CONFIG_POSIX_TIMERS
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1140
  	exit_itimers(sig);
cbaffba12   Oleg Nesterov   posix timers: dis...
1141
  	flush_itimer_signals();
baa73d9e4   Nicolas Pitre   posix-timers: Mak...
1142
  #endif
329f7dba5   Oleg Nesterov   [PATCH] fix de_th...
1143

d036bda7d   Elena Reshetova   sched/core: Conve...
1144
  	if (refcount_read(&oldsighand->count) != 1) {
b2c903b87   Oleg Nesterov   exec: simplify th...
1145
  		struct sighand_struct *newsighand;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1146
  		/*
b2c903b87   Oleg Nesterov   exec: simplify th...
1147
1148
  		 * This ->sighand is shared with the CLONE_SIGHAND
  		 * but not CLONE_THREAD task, switch to the new one.
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1149
  		 */
b2c903b87   Oleg Nesterov   exec: simplify th...
1150
1151
1152
  		newsighand = kmem_cache_alloc(sighand_cachep, GFP_KERNEL);
  		if (!newsighand)
  			return -ENOMEM;
d036bda7d   Elena Reshetova   sched/core: Conve...
1153
  		refcount_set(&newsighand->count, 1);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1154
1155
1156
1157
1158
  		memcpy(newsighand->action, oldsighand->action,
  		       sizeof(newsighand->action));
  
  		write_lock_irq(&tasklist_lock);
  		spin_lock(&oldsighand->siglock);
aafe6c2a2   Eric W. Biederman   [PATCH] de_thread...
1159
  		rcu_assign_pointer(tsk->sighand, newsighand);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1160
1161
  		spin_unlock(&oldsighand->siglock);
  		write_unlock_irq(&tasklist_lock);
fba2afaae   Davide Libenzi   signal/timer/even...
1162
  		__cleanup_sighand(oldsighand);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1163
  	}
aafe6c2a2   Eric W. Biederman   [PATCH] de_thread...
1164
  	BUG_ON(!thread_group_leader(tsk));
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1165
  	return 0;
d5bbd43d5   Oleg Nesterov   exec: make de_thr...
1166
1167
1168
1169
1170
1171
1172
1173
  
  killed:
  	/* protects against exit_notify() and __exit_signal() */
  	read_lock(&tasklist_lock);
  	sig->group_exit_task = NULL;
  	sig->notify_count = 0;
  	read_unlock(&tasklist_lock);
  	return -EAGAIN;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1174
  }
0840a90d9   Oleg Nesterov   exec: simplify ->...
1175

3756f6401   Arnd Bergmann   exec: avoid gcc-8...
1176
  char *__get_task_comm(char *buf, size_t buf_size, struct task_struct *tsk)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1177
  {
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1178
  	task_lock(tsk);
3756f6401   Arnd Bergmann   exec: avoid gcc-8...
1179
  	strncpy(buf, tsk->comm, buf_size);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1180
  	task_unlock(tsk);
59714d65d   Andrew Morton   get_task_comm(): ...
1181
  	return buf;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1182
  }
3756f6401   Arnd Bergmann   exec: avoid gcc-8...
1183
  EXPORT_SYMBOL_GPL(__get_task_comm);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1184

6a6d27de3   Al Viro   take close-on-exe...
1185
1186
1187
1188
  /*
   * These functions flushes out all traces of the currently running executable
   * so that a new one can be started
   */
82b897782   Adrian Hunter   perf: Differentia...
1189
  void __set_task_comm(struct task_struct *tsk, const char *buf, bool exec)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1190
1191
  {
  	task_lock(tsk);
43d2b1132   KAMEZAWA Hiroyuki   tracepoint: add t...
1192
  	trace_task_rename(tsk, buf);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1193
1194
  	strlcpy(tsk->comm, buf, sizeof(tsk->comm));
  	task_unlock(tsk);
82b897782   Adrian Hunter   perf: Differentia...
1195
  	perf_event_comm(tsk, exec);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1196
  }
a9208e42b   Kees Cook   exec: Correct com...
1197
1198
1199
1200
1201
1202
  /*
   * Calling this is the point of no return. None of the failures will be
   * seen by userspace since either the process is already taking a fatal
   * signal (via de_thread() or coredump), or will have SEGV raised
   * (after exec_mmap()) by search_binary_handlers (see below).
   */
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1203
1204
  int flush_old_exec(struct linux_binprm * bprm)
  {
221af7f87   Linus Torvalds   Split 'flush_old_...
1205
  	int retval;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1206
1207
1208
1209
1210
1211
1212
1213
  
  	/*
  	 * Make sure we have a private signal table and that
  	 * we are unassociated from the previous thread group.
  	 */
  	retval = de_thread(current);
  	if (retval)
  		goto out;
6e399cd14   Davidlohr Bueso   prctl: avoid usin...
1214
1215
1216
1217
1218
  	/*
  	 * Must be called _before_ exec_mmap() as bprm->mm is
  	 * not visibile until then. This also enables the update
  	 * to be lockless.
  	 */
925d1c401   Matt Helsley   procfs task exe s...
1219
  	set_mm_exe_file(bprm->mm, bprm->file);
6e399cd14   Davidlohr Bueso   prctl: avoid usin...
1220

1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1221
  	/*
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1222
1223
  	 * Release all of the old mmap stuff
  	 */
3c77f8457   Oleg Nesterov   exec: make argv/e...
1224
  	acct_arg_size(bprm, 0);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1225
1226
  	retval = exec_mmap(bprm->mm);
  	if (retval)
fd8328be8   Al Viro   [PATCH] sanitize ...
1227
  		goto out;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1228

a9208e42b   Kees Cook   exec: Correct com...
1229
1230
1231
1232
1233
1234
1235
  	/*
  	 * After clearing bprm->mm (to mark that current is using the
  	 * prepared mm now), we have nothing left of the original
  	 * process. If anything from here on returns an error, the check
  	 * in search_binary_handler() will SEGV current.
  	 */
  	bprm->mm = NULL;
7ab02af42   Linus Torvalds   Fix 'flush_old_ex...
1236

dac853ae8   Mathias Krause   exec: delay addre...
1237
  	set_fs(USER_DS);
b88fae644   Zhang Yi   exec: avoid propa...
1238
1239
  	current->flags &= ~(PF_RANDOMIZE | PF_FORKNOEXEC | PF_KTHREAD |
  					PF_NOFREEZE | PF_NO_SETAFFINITY);
7ab02af42   Linus Torvalds   Fix 'flush_old_ex...
1240
1241
  	flush_thread();
  	current->personality &= ~bprm->per_clear;
613cc2b6f   Aleksa Sarai   fs: exec: apply C...
1242
1243
1244
1245
1246
1247
1248
  	/*
  	 * We have to apply CLOEXEC before we change whether the process is
  	 * dumpable (in setup_new_exec) to avoid a race with a process in userspace
  	 * trying to access the should-be-closed file descriptors of a process
  	 * undergoing exec(2).
  	 */
  	do_close_on_exec(current->files);
221af7f87   Linus Torvalds   Split 'flush_old_...
1249
1250
1251
1252
1253
1254
  	return 0;
  
  out:
  	return retval;
  }
  EXPORT_SYMBOL(flush_old_exec);
1b5d783c9   Al Viro   consolidate BINPR...
1255
1256
  void would_dump(struct linux_binprm *bprm, struct file *file)
  {
f84df2a6f   Eric W. Biederman   exec: Ensure mm->...
1257
1258
1259
  	struct inode *inode = file_inode(file);
  	if (inode_permission(inode, MAY_READ) < 0) {
  		struct user_namespace *old, *user_ns;
1b5d783c9   Al Viro   consolidate BINPR...
1260
  		bprm->interp_flags |= BINPRM_FLAGS_ENFORCE_NONDUMP;
f84df2a6f   Eric W. Biederman   exec: Ensure mm->...
1261
1262
1263
1264
1265
1266
1267
1268
1269
1270
1271
1272
  
  		/* Ensure mm->user_ns contains the executable */
  		user_ns = old = bprm->mm->user_ns;
  		while ((user_ns != &init_user_ns) &&
  		       !privileged_wrt_inode_uidgid(user_ns, inode))
  			user_ns = user_ns->parent;
  
  		if (old != user_ns) {
  			bprm->mm->user_ns = get_user_ns(user_ns);
  			put_user_ns(old);
  		}
  	}
1b5d783c9   Al Viro   consolidate BINPR...
1273
1274
  }
  EXPORT_SYMBOL(would_dump);
221af7f87   Linus Torvalds   Split 'flush_old_...
1275
1276
  void setup_new_exec(struct linux_binprm * bprm)
  {
46d98eb4e   Kees Cook   commoncap: Refact...
1277
1278
1279
1280
1281
1282
  	/*
  	 * Once here, prepare_binrpm() will not be called any more, so
  	 * the final state of setuid/setgid/fscaps can be merged into the
  	 * secureexec flag.
  	 */
  	bprm->secureexec |= bprm->cap_elevated;
64701dee4   Kees Cook   exec: Use sane st...
1283
  	if (bprm->secureexec) {
fe8993b3a   Kees Cook   exec: Consolidate...
1284
1285
  		/* Make sure parent cannot signal privileged process. */
  		current->pdeath_signal = 0;
64701dee4   Kees Cook   exec: Use sane st...
1286
1287
1288
1289
1290
  		/*
  		 * For secureexec, reset the stack limit to sane default to
  		 * avoid bad behavior from the prior rlimits. This has to
  		 * happen before arch_pick_mmap_layout(), which examines
  		 * RLIMIT_STACK, but after the point of no return to avoid
779f4e1c6   Kees Cook   Revert "exec: avo...
1291
  		 * needing to clean up the change on failure.
64701dee4   Kees Cook   exec: Use sane st...
1292
  		 */
c31dbb146   Kees Cook   exec: pin stack l...
1293
1294
  		if (bprm->rlim_stack.rlim_cur > _STK_LIM)
  			bprm->rlim_stack.rlim_cur = _STK_LIM;
64701dee4   Kees Cook   exec: Use sane st...
1295
  	}
c31dbb146   Kees Cook   exec: pin stack l...
1296
  	arch_pick_mmap_layout(current->mm, &bprm->rlim_stack);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1297

1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1298
  	current->sas_ss_sp = current->sas_ss_size = 0;
e816c201a   Kees Cook   exec: Weaken dump...
1299
1300
1301
1302
1303
  	/*
  	 * Figure out dumpability. Note that this checking only of current
  	 * is wrong, but userspace depends on it. This should be testing
  	 * bprm->secureexec instead.
  	 */
473d89639   Kees Cook   exec: Consolidate...
1304
  	if (bprm->interp_flags & BINPRM_FLAGS_ENFORCE_NONDUMP ||
e816c201a   Kees Cook   exec: Weaken dump...
1305
1306
  	    !(uid_eq(current_euid(), current_uid()) &&
  	      gid_eq(current_egid(), current_gid())))
6c5d52382   Kawai, Hidehiro   coredump masking:...
1307
  		set_dumpable(current->mm, suid_dumpable);
473d89639   Kees Cook   exec: Consolidate...
1308
1309
  	else
  		set_dumpable(current->mm, SUID_DUMP_USER);
d6e711448   Alan Cox   [PATCH] setuid co...
1310

e9ea1e7f5   Kyle Huey   x86/arch_prctl: A...
1311
  	arch_setup_new_exec();
e041e328c   Peter Zijlstra   perf: Fix perf_ev...
1312
  	perf_event_exec();
82b897782   Adrian Hunter   perf: Differentia...
1313
  	__set_task_comm(current, kbasename(bprm->filename), true);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1314

0551fbd29   Benjamin Herrenschmidt   [PATCH] Add mm->t...
1315
1316
1317
1318
1319
  	/* Set the new mm task size. We have to do that late because it may
  	 * depend on TIF_32BIT which is only updated in flush_thread() on
  	 * some architectures like powerpc
  	 */
  	current->mm->task_size = TASK_SIZE;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1320
1321
  	/* An exec changes our domain. We are no longer part of the thread
  	   group */
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1322
  	current->self_exec_id++;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1323
  	flush_signal_handlers(current, 0);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1324
  }
221af7f87   Linus Torvalds   Split 'flush_old_...
1325
  EXPORT_SYMBOL(setup_new_exec);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1326

b83838313   Kees Cook   exec: introduce f...
1327
1328
1329
  /* Runs immediately before start_thread() takes over. */
  void finalize_exec(struct linux_binprm *bprm)
  {
c31dbb146   Kees Cook   exec: pin stack l...
1330
1331
1332
1333
  	/* Store any stack rlimit changes before starting thread. */
  	task_lock(current->group_leader);
  	current->signal->rlim[RLIMIT_STACK] = bprm->rlim_stack;
  	task_unlock(current->group_leader);
b83838313   Kees Cook   exec: introduce f...
1334
1335
  }
  EXPORT_SYMBOL(finalize_exec);
a6f76f23d   David Howells   CRED: Make execve...
1336
  /*
a2a8474c3   Oleg Nesterov   exec: do not slee...
1337
1338
1339
1340
1341
   * Prepare credentials and lock ->cred_guard_mutex.
   * install_exec_creds() commits the new creds and drops the lock.
   * Or, if exec fails before, free_bprm() should release ->cred and
   * and unlock.
   */
4addd2640   Chanho Min   exec: make prepar...
1342
  static int prepare_bprm_creds(struct linux_binprm *bprm)
a2a8474c3   Oleg Nesterov   exec: do not slee...
1343
  {
9b1bf12d5   KOSAKI Motohiro   signals: move cre...
1344
  	if (mutex_lock_interruptible(&current->signal->cred_guard_mutex))
a2a8474c3   Oleg Nesterov   exec: do not slee...
1345
1346
1347
1348
1349
  		return -ERESTARTNOINTR;
  
  	bprm->cred = prepare_exec_creds();
  	if (likely(bprm->cred))
  		return 0;
9b1bf12d5   KOSAKI Motohiro   signals: move cre...
1350
  	mutex_unlock(&current->signal->cred_guard_mutex);
a2a8474c3   Oleg Nesterov   exec: do not slee...
1351
1352
  	return -ENOMEM;
  }
c4ad8f98b   Linus Torvalds   execve: use 'stru...
1353
  static void free_bprm(struct linux_binprm *bprm)
a2a8474c3   Oleg Nesterov   exec: do not slee...
1354
1355
1356
  {
  	free_arg_pages(bprm);
  	if (bprm->cred) {
9b1bf12d5   KOSAKI Motohiro   signals: move cre...
1357
  		mutex_unlock(&current->signal->cred_guard_mutex);
a2a8474c3   Oleg Nesterov   exec: do not slee...
1358
1359
  		abort_creds(bprm->cred);
  	}
63e46b95e   Oleg Nesterov   exec: move the fi...
1360
1361
1362
1363
  	if (bprm->file) {
  		allow_write_access(bprm->file);
  		fput(bprm->file);
  	}
b66c59840   Kees Cook   exec: do not leav...
1364
1365
1366
  	/* If a binfmt changed the interp, free it. */
  	if (bprm->interp != bprm->filename)
  		kfree(bprm->interp);
a2a8474c3   Oleg Nesterov   exec: do not slee...
1367
1368
  	kfree(bprm);
  }
c2315c187   Oleg Nesterov   exec: load_script...
1369
  int bprm_change_interp(const char *interp, struct linux_binprm *bprm)
b66c59840   Kees Cook   exec: do not leav...
1370
1371
1372
1373
1374
1375
1376
1377
1378
1379
  {
  	/* If a binfmt changed the interp, free it first. */
  	if (bprm->interp != bprm->filename)
  		kfree(bprm->interp);
  	bprm->interp = kstrdup(interp, GFP_KERNEL);
  	if (!bprm->interp)
  		return -ENOMEM;
  	return 0;
  }
  EXPORT_SYMBOL(bprm_change_interp);
a2a8474c3   Oleg Nesterov   exec: do not slee...
1380
  /*
a6f76f23d   David Howells   CRED: Make execve...
1381
1382
1383
1384
1385
1386
1387
1388
   * install the new credentials for this executable
   */
  void install_exec_creds(struct linux_binprm *bprm)
  {
  	security_bprm_committing_creds(bprm);
  
  	commit_creds(bprm->cred);
  	bprm->cred = NULL;
2976b10f0   Stephane Eranian   perf: Disable mon...
1389
1390
1391
1392
1393
1394
1395
1396
1397
  
  	/*
  	 * Disable monitoring for regular users
  	 * when executing setuid binaries. Must
  	 * wait until new credentials are committed
  	 * by commit_creds() above
  	 */
  	if (get_dumpable(current->mm) != SUID_DUMP_USER)
  		perf_event_exit_task(current);
a2a8474c3   Oleg Nesterov   exec: do not slee...
1398
1399
  	/*
  	 * cred_guard_mutex must be held at least to this point to prevent
a6f76f23d   David Howells   CRED: Make execve...
1400
  	 * ptrace_attach() from altering our determination of the task's
a2a8474c3   Oleg Nesterov   exec: do not slee...
1401
1402
  	 * credentials; any time after this it may be unlocked.
  	 */
a6f76f23d   David Howells   CRED: Make execve...
1403
  	security_bprm_committed_creds(bprm);
9b1bf12d5   KOSAKI Motohiro   signals: move cre...
1404
  	mutex_unlock(&current->signal->cred_guard_mutex);
a6f76f23d   David Howells   CRED: Make execve...
1405
1406
1407
1408
1409
  }
  EXPORT_SYMBOL(install_exec_creds);
  
  /*
   * determine how safe it is to execute the proposed program
9b1bf12d5   KOSAKI Motohiro   signals: move cre...
1410
   * - the caller must hold ->cred_guard_mutex to protect against
c2e1f2e30   Kees Cook   seccomp: implemen...
1411
   *   PTRACE_ATTACH or seccomp thread-sync
a6f76f23d   David Howells   CRED: Make execve...
1412
   */
9e00cdb09   Oleg Nesterov   exec:check_unsafe...
1413
  static void check_unsafe_exec(struct linux_binprm *bprm)
a6f76f23d   David Howells   CRED: Make execve...
1414
  {
0bf2f3aec   David Howells   CRED: Fix SUID ex...
1415
  	struct task_struct *p = current, *t;
f1191b50e   Al Viro   check_unsafe_exec...
1416
  	unsigned n_fs;
a6f76f23d   David Howells   CRED: Make execve...
1417

9227dd2a8   Eric W. Biederman   exec: Remove LSM_...
1418
1419
  	if (p->ptrace)
  		bprm->unsafe |= LSM_UNSAFE_PTRACE;
a6f76f23d   David Howells   CRED: Make execve...
1420

259e5e6c7   Andy Lutomirski   Add PR_{GET,SET}_...
1421
1422
1423
1424
  	/*
  	 * This isn't strictly necessary, but it makes it harder for LSMs to
  	 * mess up.
  	 */
1d4457f99   Kees Cook   sched: move no_ne...
1425
  	if (task_no_new_privs(current))
259e5e6c7   Andy Lutomirski   Add PR_{GET,SET}_...
1426
  		bprm->unsafe |= LSM_UNSAFE_NO_NEW_PRIVS;
83f62a2ea   Oleg Nesterov   exec:check_unsafe...
1427
  	t = p;
0bf2f3aec   David Howells   CRED: Fix SUID ex...
1428
  	n_fs = 1;
2a4419b5b   Nick Piggin   fs: fs_struct rwl...
1429
  	spin_lock(&p->fs->lock);
437f7fdb6   Oleg Nesterov   check_unsafe_exec...
1430
  	rcu_read_lock();
83f62a2ea   Oleg Nesterov   exec:check_unsafe...
1431
  	while_each_thread(p, t) {
0bf2f3aec   David Howells   CRED: Fix SUID ex...
1432
1433
  		if (t->fs == p->fs)
  			n_fs++;
0bf2f3aec   David Howells   CRED: Fix SUID ex...
1434
  	}
437f7fdb6   Oleg Nesterov   check_unsafe_exec...
1435
  	rcu_read_unlock();
0bf2f3aec   David Howells   CRED: Fix SUID ex...
1436

9e00cdb09   Oleg Nesterov   exec:check_unsafe...
1437
  	if (p->fs->users > n_fs)
a6f76f23d   David Howells   CRED: Make execve...
1438
  		bprm->unsafe |= LSM_UNSAFE_SHARE;
9e00cdb09   Oleg Nesterov   exec:check_unsafe...
1439
1440
  	else
  		p->fs->in_exec = 1;
2a4419b5b   Nick Piggin   fs: fs_struct rwl...
1441
  	spin_unlock(&p->fs->lock);
a6f76f23d   David Howells   CRED: Make execve...
1442
  }
8b01fc86b   Jann Horn   fs: take i_mutex ...
1443
1444
1445
1446
1447
1448
  static void bprm_fill_uid(struct linux_binprm *bprm)
  {
  	struct inode *inode;
  	unsigned int mode;
  	kuid_t uid;
  	kgid_t gid;
cb6fd68fd   Kees Cook   exec: clarify rea...
1449
1450
1451
1452
1453
1454
  	/*
  	 * Since this can be called multiple times (via prepare_binprm),
  	 * we must clear any previous work done when setting set[ug]id
  	 * bits from any earlier bprm->file uses (for example when run
  	 * first for a setuid script then again for its interpreter).
  	 */
8b01fc86b   Jann Horn   fs: take i_mutex ...
1455
1456
  	bprm->cred->euid = current_euid();
  	bprm->cred->egid = current_egid();
380cf5ba6   Andy Lutomirski   fs: Treat foreign...
1457
  	if (!mnt_may_suid(bprm->file->f_path.mnt))
8b01fc86b   Jann Horn   fs: take i_mutex ...
1458
1459
1460
1461
  		return;
  
  	if (task_no_new_privs(current))
  		return;
fea6d2a61   Vivek Goyal   vfs: Use upper fi...
1462
  	inode = bprm->file->f_path.dentry->d_inode;
8b01fc86b   Jann Horn   fs: take i_mutex ...
1463
1464
1465
1466
1467
  	mode = READ_ONCE(inode->i_mode);
  	if (!(mode & (S_ISUID|S_ISGID)))
  		return;
  
  	/* Be careful if suid/sgid is set */
5955102c9   Al Viro   wrappers for ->i_...
1468
  	inode_lock(inode);
8b01fc86b   Jann Horn   fs: take i_mutex ...
1469
1470
1471
1472
1473
  
  	/* reload atomically mode/uid/gid now that lock held */
  	mode = inode->i_mode;
  	uid = inode->i_uid;
  	gid = inode->i_gid;
5955102c9   Al Viro   wrappers for ->i_...
1474
  	inode_unlock(inode);
8b01fc86b   Jann Horn   fs: take i_mutex ...
1475
1476
1477
1478
1479
1480
1481
1482
1483
1484
1485
1486
1487
1488
1489
1490
  
  	/* We ignore suid/sgid if there are no mappings for them in the ns */
  	if (!kuid_has_mapping(bprm->cred->user_ns, uid) ||
  		 !kgid_has_mapping(bprm->cred->user_ns, gid))
  		return;
  
  	if (mode & S_ISUID) {
  		bprm->per_clear |= PER_CLEAR_ON_SETID;
  		bprm->cred->euid = uid;
  	}
  
  	if ((mode & (S_ISGID | S_IXGRP)) == (S_ISGID | S_IXGRP)) {
  		bprm->per_clear |= PER_CLEAR_ON_SETID;
  		bprm->cred->egid = gid;
  	}
  }
9e00cdb09   Oleg Nesterov   exec:check_unsafe...
1491
1492
  /*
   * Fill the binprm structure from the inode.
6eb3c3d0a   Oleg Nesterov   exec: increase BI...
1493
   * Check permissions, then read the first BINPRM_BUF_SIZE bytes
a6f76f23d   David Howells   CRED: Make execve...
1494
1495
   *
   * This may be called multiple times for binary chains (scripts for example).
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1496
1497
1498
   */
  int prepare_binprm(struct linux_binprm *bprm)
  {
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1499
  	int retval;
bdd1d2d3d   Christoph Hellwig   fs: fix kernel_re...
1500
  	loff_t pos = 0;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1501

8b01fc86b   Jann Horn   fs: take i_mutex ...
1502
  	bprm_fill_uid(bprm);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1503
1504
  
  	/* fill in binprm security blob */
a6f76f23d   David Howells   CRED: Make execve...
1505
  	retval = security_bprm_set_creds(bprm);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1506
1507
  	if (retval)
  		return retval;
ddb4a1442   Kees Cook   exec: Rename bprm...
1508
  	bprm->called_set_creds = 1;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1509

a6f76f23d   David Howells   CRED: Make execve...
1510
  	memset(bprm->buf, 0, BINPRM_BUF_SIZE);
bdd1d2d3d   Christoph Hellwig   fs: fix kernel_re...
1511
  	return kernel_read(bprm->file, bprm->buf, BINPRM_BUF_SIZE, &pos);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1512
1513
1514
  }
  
  EXPORT_SYMBOL(prepare_binprm);
4fc75ff48   Nick Piggin   exec: fix remove_...
1515
1516
1517
1518
1519
  /*
   * Arguments are '\0' separated strings found at the location bprm->p
   * points to; chop off the first by relocating brpm->p to right after
   * the first '\0' encountered.
   */
b6a2fea39   Ollie Wild   mm: variable leng...
1520
  int remove_arg_zero(struct linux_binprm *bprm)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1521
  {
b6a2fea39   Ollie Wild   mm: variable leng...
1522
1523
1524
1525
  	int ret = 0;
  	unsigned long offset;
  	char *kaddr;
  	struct page *page;
4fc75ff48   Nick Piggin   exec: fix remove_...
1526

b6a2fea39   Ollie Wild   mm: variable leng...
1527
1528
  	if (!bprm->argc)
  		return 0;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1529

b6a2fea39   Ollie Wild   mm: variable leng...
1530
1531
1532
1533
1534
1535
1536
  	do {
  		offset = bprm->p & ~PAGE_MASK;
  		page = get_arg_page(bprm, bprm->p, 0);
  		if (!page) {
  			ret = -EFAULT;
  			goto out;
  		}
e8e3c3d66   Cong Wang   fs: remove the se...
1537
  		kaddr = kmap_atomic(page);
4fc75ff48   Nick Piggin   exec: fix remove_...
1538

b6a2fea39   Ollie Wild   mm: variable leng...
1539
1540
1541
  		for (; offset < PAGE_SIZE && kaddr[offset];
  				offset++, bprm->p++)
  			;
4fc75ff48   Nick Piggin   exec: fix remove_...
1542

e8e3c3d66   Cong Wang   fs: remove the se...
1543
  		kunmap_atomic(kaddr);
b6a2fea39   Ollie Wild   mm: variable leng...
1544
  		put_arg_page(page);
b6a2fea39   Ollie Wild   mm: variable leng...
1545
  	} while (offset == PAGE_SIZE);
4fc75ff48   Nick Piggin   exec: fix remove_...
1546

b6a2fea39   Ollie Wild   mm: variable leng...
1547
1548
1549
  	bprm->p++;
  	bprm->argc--;
  	ret = 0;
4fc75ff48   Nick Piggin   exec: fix remove_...
1550

b6a2fea39   Ollie Wild   mm: variable leng...
1551
1552
  out:
  	return ret;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1553
  }
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1554
  EXPORT_SYMBOL(remove_arg_zero);
cb7b6b1cb   Oleg Nesterov   exec: cleanup the...
1555
1556
  #define printable(c) (((c)=='\t') || ((c)=='
  ') || (0x20<=(c) && (c)<=0x7e))
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1557
1558
1559
  /*
   * cycle the list of binary formats handler, until one recognizes the image
   */
3c456bfc4   Al Viro   get rid of pt_reg...
1560
  int search_binary_handler(struct linux_binprm *bprm)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1561
  {
cb7b6b1cb   Oleg Nesterov   exec: cleanup the...
1562
  	bool need_retry = IS_ENABLED(CONFIG_MODULES);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1563
  	struct linux_binfmt *fmt;
cb7b6b1cb   Oleg Nesterov   exec: cleanup the...
1564
  	int retval;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1565

d74026986   Kees Cook   exec: use -ELOOP ...
1566
  	/* This allows 4 levels of binfmt rewrites before failing hard. */
131b2f9f1   Oleg Nesterov   exec: kill "int d...
1567
  	if (bprm->recursion_depth > 5)
d74026986   Kees Cook   exec: use -ELOOP ...
1568
  		return -ELOOP;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1569
1570
1571
  	retval = security_bprm_check(bprm);
  	if (retval)
  		return retval;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1572
  	retval = -ENOENT;
cb7b6b1cb   Oleg Nesterov   exec: cleanup the...
1573
1574
1575
1576
1577
1578
   retry:
  	read_lock(&binfmt_lock);
  	list_for_each_entry(fmt, &formats, lh) {
  		if (!try_module_get(fmt->module))
  			continue;
  		read_unlock(&binfmt_lock);
d53ddd018   Alexey Dobriyan   fs/exec.c: move -...
1579

cb7b6b1cb   Oleg Nesterov   exec: cleanup the...
1580
1581
  		bprm->recursion_depth++;
  		retval = fmt->load_binary(bprm);
d53ddd018   Alexey Dobriyan   fs/exec.c: move -...
1582
  		bprm->recursion_depth--;
19d860a14   Al Viro   handle suicide on...
1583
1584
  		read_lock(&binfmt_lock);
  		put_binfmt(fmt);
19d860a14   Al Viro   handle suicide on...
1585
1586
1587
  		if (retval < 0 && !bprm->mm) {
  			/* we got to flush_old_exec() and failed after it */
  			read_unlock(&binfmt_lock);
cb44c9a0a   Eric W. Biederman   signal: Remove ta...
1588
  			force_sigsegv(SIGSEGV);
19d860a14   Al Viro   handle suicide on...
1589
1590
1591
1592
  			return retval;
  		}
  		if (retval != -ENOEXEC || !bprm->file) {
  			read_unlock(&binfmt_lock);
cb7b6b1cb   Oleg Nesterov   exec: cleanup the...
1593
  			return retval;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1594
  		}
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1595
  	}
cb7b6b1cb   Oleg Nesterov   exec: cleanup the...
1596
  	read_unlock(&binfmt_lock);
19d860a14   Al Viro   handle suicide on...
1597
  	if (need_retry) {
cb7b6b1cb   Oleg Nesterov   exec: cleanup the...
1598
1599
1600
  		if (printable(bprm->buf[0]) && printable(bprm->buf[1]) &&
  		    printable(bprm->buf[2]) && printable(bprm->buf[3]))
  			return retval;
4e0621a07   Oleg Nesterov   exec: don't retry...
1601
1602
  		if (request_module("binfmt-%04x", *(ushort *)(bprm->buf + 2)) < 0)
  			return retval;
cb7b6b1cb   Oleg Nesterov   exec: cleanup the...
1603
1604
1605
  		need_retry = false;
  		goto retry;
  	}
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1606
1607
  	return retval;
  }
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1608
  EXPORT_SYMBOL(search_binary_handler);
5d1baf3b6   Oleg Nesterov   exec: introduce e...
1609
1610
1611
1612
1613
1614
1615
1616
1617
1618
1619
1620
1621
  static int exec_binprm(struct linux_binprm *bprm)
  {
  	pid_t old_pid, old_vpid;
  	int ret;
  
  	/* Need to fetch pid before load_binary changes it */
  	old_pid = current->pid;
  	rcu_read_lock();
  	old_vpid = task_pid_nr_ns(current, task_active_pid_ns(current->parent));
  	rcu_read_unlock();
  
  	ret = search_binary_handler(bprm);
  	if (ret >= 0) {
3eaded86a   Linus Torvalds   Merge git://git.i...
1622
  		audit_bprm(bprm);
5d1baf3b6   Oleg Nesterov   exec: introduce e...
1623
1624
  		trace_sched_process_exec(current, old_pid, bprm);
  		ptrace_event(PTRACE_EVENT_EXEC, old_vpid);
9beb266f2   Oleg Nesterov   exec: proc_exec_c...
1625
  		proc_exec_connector(current);
5d1baf3b6   Oleg Nesterov   exec: introduce e...
1626
1627
1628
1629
  	}
  
  	return ret;
  }
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1630
1631
1632
  /*
   * sys_execve() executes a new program.
   */
449325b52   Alexei Starovoitov   umh: introduce fo...
1633
1634
1635
1636
  static int __do_execve_file(int fd, struct filename *filename,
  			    struct user_arg_ptr argv,
  			    struct user_arg_ptr envp,
  			    int flags, struct file *file)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1637
  {
51f39a1f0   David Drysdale   syscalls: impleme...
1638
  	char *pathbuf = NULL;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1639
  	struct linux_binprm *bprm;
3b1253880   Al Viro   [PATCH] sanitize ...
1640
  	struct files_struct *displaced;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1641
  	int retval;
72fa59970   Vasiliy Kulikov   move RLIMIT_NPROC...
1642

c4ad8f98b   Linus Torvalds   execve: use 'stru...
1643
1644
  	if (IS_ERR(filename))
  		return PTR_ERR(filename);
72fa59970   Vasiliy Kulikov   move RLIMIT_NPROC...
1645
1646
1647
1648
1649
1650
1651
  	/*
  	 * We move the actual failure in case of RLIMIT_NPROC excess from
  	 * set*uid() to execve() because too many poorly written programs
  	 * don't check setuid() return code.  Here we additionally recheck
  	 * whether NPROC limit is still exceeded.
  	 */
  	if ((current->flags & PF_NPROC_EXCEEDED) &&
bd9d43f47   Oleg Nesterov   fs/exec.c: do_exe...
1652
  	    atomic_read(&current_user()->processes) > rlimit(RLIMIT_NPROC)) {
72fa59970   Vasiliy Kulikov   move RLIMIT_NPROC...
1653
1654
1655
1656
1657
1658
1659
  		retval = -EAGAIN;
  		goto out_ret;
  	}
  
  	/* We're below the limit (still or again), so we don't want to make
  	 * further execve() calls fail. */
  	current->flags &= ~PF_NPROC_EXCEEDED;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1660

3b1253880   Al Viro   [PATCH] sanitize ...
1661
  	retval = unshare_files(&displaced);
fd8328be8   Al Viro   [PATCH] sanitize ...
1662
1663
  	if (retval)
  		goto out_ret;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1664
  	retval = -ENOMEM;
11b0b5abb   Oliver Neukum   [PATCH] use kzall...
1665
  	bprm = kzalloc(sizeof(*bprm), GFP_KERNEL);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1666
  	if (!bprm)
fd8328be8   Al Viro   [PATCH] sanitize ...
1667
  		goto out_files;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1668

a2a8474c3   Oleg Nesterov   exec: do not slee...
1669
1670
  	retval = prepare_bprm_creds(bprm);
  	if (retval)
a6f76f23d   David Howells   CRED: Make execve...
1671
  		goto out_free;
498052bba   Al Viro   New locking/refco...
1672

9e00cdb09   Oleg Nesterov   exec:check_unsafe...
1673
  	check_unsafe_exec(bprm);
a2a8474c3   Oleg Nesterov   exec: do not slee...
1674
  	current->in_execve = 1;
a6f76f23d   David Howells   CRED: Make execve...
1675

449325b52   Alexei Starovoitov   umh: introduce fo...
1676
1677
  	if (!file)
  		file = do_open_execat(fd, filename, flags);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1678
1679
  	retval = PTR_ERR(file);
  	if (IS_ERR(file))
498052bba   Al Viro   New locking/refco...
1680
  		goto out_unmark;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1681
1682
  
  	sched_exec();
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1683
  	bprm->file = file;
449325b52   Alexei Starovoitov   umh: introduce fo...
1684
1685
1686
  	if (!filename) {
  		bprm->filename = "none";
  	} else if (fd == AT_FDCWD || filename->name[0] == '/') {
51f39a1f0   David Drysdale   syscalls: impleme...
1687
1688
1689
  		bprm->filename = filename->name;
  	} else {
  		if (filename->name[0] == '\0')
0ee931c4e   Michal Hocko   mm: treewide: rem...
1690
  			pathbuf = kasprintf(GFP_KERNEL, "/dev/fd/%d", fd);
51f39a1f0   David Drysdale   syscalls: impleme...
1691
  		else
0ee931c4e   Michal Hocko   mm: treewide: rem...
1692
  			pathbuf = kasprintf(GFP_KERNEL, "/dev/fd/%d/%s",
51f39a1f0   David Drysdale   syscalls: impleme...
1693
1694
1695
1696
1697
1698
1699
1700
1701
1702
1703
1704
1705
1706
1707
  					    fd, filename->name);
  		if (!pathbuf) {
  			retval = -ENOMEM;
  			goto out_unmark;
  		}
  		/*
  		 * Record that a name derived from an O_CLOEXEC fd will be
  		 * inaccessible after exec. Relies on having exclusive access to
  		 * current->files (due to unshare_files above).
  		 */
  		if (close_on_exec(fd, rcu_dereference_raw(current->files->fdt)))
  			bprm->interp_flags |= BINPRM_FLAGS_PATH_INACCESSIBLE;
  		bprm->filename = pathbuf;
  	}
  	bprm->interp = bprm->filename;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1708

b6a2fea39   Ollie Wild   mm: variable leng...
1709
1710
  	retval = bprm_mm_init(bprm);
  	if (retval)
63e46b95e   Oleg Nesterov   exec: move the fi...
1711
  		goto out_unmark;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1712

655c16a8c   Oleg Nesterov   exec: separate MM...
1713
1714
  	retval = prepare_arg_pages(bprm, argv, envp);
  	if (retval < 0)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1715
1716
1717
1718
1719
1720
1721
1722
1723
1724
1725
1726
1727
1728
1729
1730
1731
1732
  		goto out;
  
  	retval = prepare_binprm(bprm);
  	if (retval < 0)
  		goto out;
  
  	retval = copy_strings_kernel(1, &bprm->filename, bprm);
  	if (retval < 0)
  		goto out;
  
  	bprm->exec = bprm->p;
  	retval = copy_strings(bprm->envc, envp, bprm);
  	if (retval < 0)
  		goto out;
  
  	retval = copy_strings(bprm->argc, argv, bprm);
  	if (retval < 0)
  		goto out;
f84df2a6f   Eric W. Biederman   exec: Ensure mm->...
1733
  	would_dump(bprm, bprm->file);
5d1baf3b6   Oleg Nesterov   exec: introduce e...
1734
  	retval = exec_binprm(bprm);
a6f76f23d   David Howells   CRED: Make execve...
1735
1736
  	if (retval < 0)
  		goto out;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1737

a6f76f23d   David Howells   CRED: Make execve...
1738
  	/* execve succeeded */
498052bba   Al Viro   New locking/refco...
1739
  	current->fs->in_exec = 0;
f9ce1f1cd   Kentaro Takeda   Add in_execve fla...
1740
  	current->in_execve = 0;
d7822b1e2   Mathieu Desnoyers   rseq: Introduce r...
1741
  	rseq_execve(current);
a6f76f23d   David Howells   CRED: Make execve...
1742
  	acct_update_integrals(current);
16d51a590   Jann Horn   sched/fair: Don't...
1743
  	task_numa_free(current, false);
a6f76f23d   David Howells   CRED: Make execve...
1744
  	free_bprm(bprm);
51f39a1f0   David Drysdale   syscalls: impleme...
1745
  	kfree(pathbuf);
449325b52   Alexei Starovoitov   umh: introduce fo...
1746
1747
  	if (filename)
  		putname(filename);
a6f76f23d   David Howells   CRED: Make execve...
1748
1749
1750
  	if (displaced)
  		put_files_struct(displaced);
  	return retval;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1751

a6f76f23d   David Howells   CRED: Make execve...
1752
  out:
3c77f8457   Oleg Nesterov   exec: make argv/e...
1753
1754
1755
1756
  	if (bprm->mm) {
  		acct_arg_size(bprm, 0);
  		mmput(bprm->mm);
  	}
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1757

498052bba   Al Viro   New locking/refco...
1758
  out_unmark:
9e00cdb09   Oleg Nesterov   exec:check_unsafe...
1759
  	current->fs->in_exec = 0;
f9ce1f1cd   Kentaro Takeda   Add in_execve fla...
1760
  	current->in_execve = 0;
a6f76f23d   David Howells   CRED: Make execve...
1761
1762
  
  out_free:
08a6fac1c   Al Viro   [PATCH] get rid o...
1763
  	free_bprm(bprm);
51f39a1f0   David Drysdale   syscalls: impleme...
1764
  	kfree(pathbuf);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1765

fd8328be8   Al Viro   [PATCH] sanitize ...
1766
  out_files:
3b1253880   Al Viro   [PATCH] sanitize ...
1767
1768
  	if (displaced)
  		reset_files_struct(displaced);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1769
  out_ret:
449325b52   Alexei Starovoitov   umh: introduce fo...
1770
1771
  	if (filename)
  		putname(filename);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1772
1773
  	return retval;
  }
449325b52   Alexei Starovoitov   umh: introduce fo...
1774
1775
1776
1777
1778
1779
1780
1781
1782
1783
1784
1785
1786
1787
1788
  static int do_execveat_common(int fd, struct filename *filename,
  			      struct user_arg_ptr argv,
  			      struct user_arg_ptr envp,
  			      int flags)
  {
  	return __do_execve_file(fd, filename, argv, envp, flags, NULL);
  }
  
  int do_execve_file(struct file *file, void *__argv, void *__envp)
  {
  	struct user_arg_ptr argv = { .ptr.native = __argv };
  	struct user_arg_ptr envp = { .ptr.native = __envp };
  
  	return __do_execve_file(AT_FDCWD, NULL, argv, envp, 0, file);
  }
c4ad8f98b   Linus Torvalds   execve: use 'stru...
1789
  int do_execve(struct filename *filename,
ba2d01629   Oleg Nesterov   exec: introduce s...
1790
  	const char __user *const __user *__argv,
da3d4c5fa   Al Viro   get rid of pt_reg...
1791
  	const char __user *const __user *__envp)
ba2d01629   Oleg Nesterov   exec: introduce s...
1792
  {
0e028465d   Oleg Nesterov   exec: unify do_ex...
1793
1794
  	struct user_arg_ptr argv = { .ptr.native = __argv };
  	struct user_arg_ptr envp = { .ptr.native = __envp };
51f39a1f0   David Drysdale   syscalls: impleme...
1795
1796
1797
1798
1799
1800
1801
1802
1803
1804
1805
1806
  	return do_execveat_common(AT_FDCWD, filename, argv, envp, 0);
  }
  
  int do_execveat(int fd, struct filename *filename,
  		const char __user *const __user *__argv,
  		const char __user *const __user *__envp,
  		int flags)
  {
  	struct user_arg_ptr argv = { .ptr.native = __argv };
  	struct user_arg_ptr envp = { .ptr.native = __envp };
  
  	return do_execveat_common(fd, filename, argv, envp, flags);
0e028465d   Oleg Nesterov   exec: unify do_ex...
1807
1808
1809
  }
  
  #ifdef CONFIG_COMPAT
c4ad8f98b   Linus Torvalds   execve: use 'stru...
1810
  static int compat_do_execve(struct filename *filename,
38b983b34   Al Viro   generic sys_execve()
1811
  	const compat_uptr_t __user *__argv,
d03d26e58   Al Viro   make compat_do_ex...
1812
  	const compat_uptr_t __user *__envp)
0e028465d   Oleg Nesterov   exec: unify do_ex...
1813
1814
1815
1816
1817
1818
1819
1820
1821
  {
  	struct user_arg_ptr argv = {
  		.is_compat = true,
  		.ptr.compat = __argv,
  	};
  	struct user_arg_ptr envp = {
  		.is_compat = true,
  		.ptr.compat = __envp,
  	};
51f39a1f0   David Drysdale   syscalls: impleme...
1822
1823
1824
1825
1826
1827
1828
1829
1830
1831
1832
1833
1834
1835
1836
1837
1838
  	return do_execveat_common(AT_FDCWD, filename, argv, envp, 0);
  }
  
  static int compat_do_execveat(int fd, struct filename *filename,
  			      const compat_uptr_t __user *__argv,
  			      const compat_uptr_t __user *__envp,
  			      int flags)
  {
  	struct user_arg_ptr argv = {
  		.is_compat = true,
  		.ptr.compat = __argv,
  	};
  	struct user_arg_ptr envp = {
  		.is_compat = true,
  		.ptr.compat = __envp,
  	};
  	return do_execveat_common(fd, filename, argv, envp, flags);
ba2d01629   Oleg Nesterov   exec: introduce s...
1839
  }
0e028465d   Oleg Nesterov   exec: unify do_ex...
1840
  #endif
ba2d01629   Oleg Nesterov   exec: introduce s...
1841

964ee7df9   Oleg Nesterov   exec: fix set_bin...
1842
  void set_binfmt(struct linux_binfmt *new)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1843
  {
801460d0c   Hiroshi Shimamoto   task_struct clean...
1844
1845
1846
1847
  	struct mm_struct *mm = current->mm;
  
  	if (mm->binfmt)
  		module_put(mm->binfmt->module);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1848

801460d0c   Hiroshi Shimamoto   task_struct clean...
1849
  	mm->binfmt = new;
964ee7df9   Oleg Nesterov   exec: fix set_bin...
1850
1851
  	if (new)
  		__module_get(new->module);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1852
  }
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
1853
  EXPORT_SYMBOL(set_binfmt);
6c5d52382   Kawai, Hidehiro   coredump masking:...
1854
  /*
7288e1187   Oleg Nesterov   coredump: kill MM...
1855
   * set_dumpable stores three-value SUID_DUMP_* into mm->flags.
6c5d52382   Kawai, Hidehiro   coredump masking:...
1856
1857
1858
   */
  void set_dumpable(struct mm_struct *mm, int value)
  {
7288e1187   Oleg Nesterov   coredump: kill MM...
1859
1860
  	if (WARN_ON((unsigned)value > SUID_DUMP_ROOT))
  		return;
26e152252   Vineet Gupta   fs/exec.c: replac...
1861
  	set_mask_bits(&mm->flags, MMF_DUMPABLE_MASK, value);
6c5d52382   Kawai, Hidehiro   coredump masking:...
1862
  }
6c5d52382   Kawai, Hidehiro   coredump masking:...
1863

38b983b34   Al Viro   generic sys_execve()
1864
1865
1866
1867
1868
  SYSCALL_DEFINE3(execve,
  		const char __user *, filename,
  		const char __user *const __user *, argv,
  		const char __user *const __user *, envp)
  {
c4ad8f98b   Linus Torvalds   execve: use 'stru...
1869
  	return do_execve(getname(filename), argv, envp);
38b983b34   Al Viro   generic sys_execve()
1870
  }
51f39a1f0   David Drysdale   syscalls: impleme...
1871
1872
1873
1874
1875
1876
1877
1878
1879
1880
1881
1882
1883
  
  SYSCALL_DEFINE5(execveat,
  		int, fd, const char __user *, filename,
  		const char __user *const __user *, argv,
  		const char __user *const __user *, envp,
  		int, flags)
  {
  	int lookup_flags = (flags & AT_EMPTY_PATH) ? LOOKUP_EMPTY : 0;
  
  	return do_execveat(fd,
  			   getname_flags(filename, lookup_flags, NULL),
  			   argv, envp, flags);
  }
38b983b34   Al Viro   generic sys_execve()
1884
  #ifdef CONFIG_COMPAT
625b1d7e8   Heiko Carstens   fs/compat: conver...
1885
1886
1887
  COMPAT_SYSCALL_DEFINE3(execve, const char __user *, filename,
  	const compat_uptr_t __user *, argv,
  	const compat_uptr_t __user *, envp)
38b983b34   Al Viro   generic sys_execve()
1888
  {
c4ad8f98b   Linus Torvalds   execve: use 'stru...
1889
  	return compat_do_execve(getname(filename), argv, envp);
38b983b34   Al Viro   generic sys_execve()
1890
  }
51f39a1f0   David Drysdale   syscalls: impleme...
1891
1892
1893
1894
1895
1896
1897
1898
1899
1900
1901
1902
1903
  
  COMPAT_SYSCALL_DEFINE5(execveat, int, fd,
  		       const char __user *, filename,
  		       const compat_uptr_t __user *, argv,
  		       const compat_uptr_t __user *, envp,
  		       int,  flags)
  {
  	int lookup_flags = (flags & AT_EMPTY_PATH) ? LOOKUP_EMPTY : 0;
  
  	return compat_do_execveat(fd,
  				  getname_flags(filename, lookup_flags, NULL),
  				  argv, envp, flags);
  }
38b983b34   Al Viro   generic sys_execve()
1904
  #endif