linux-user/mmap.c: handle invalid len maps correctly
I've slightly re-organised the check to more closely match the sequence that the kernel uses in do_mmap(). We check for both the zero case (EINVAL) and the overflow length case (ENOMEM). Signed-off-by: Alex Bennée <alex.bennee@linaro.org> Cc: umarcor <1783362@bugs.launchpad.net> Reviewed-by: Laurent Vivier <laurent@vivier.eu> Message-Id: <20180730134321.19898-2-alex.bennee@linaro.org> Signed-off-by: Laurent Vivier <laurent@vivier.eu>
This commit is contained in:
parent
6d9dd5fb9d
commit
38138fab93
@ -391,14 +391,23 @@ abi_long target_mmap(abi_ulong start, abi_ulong len, int prot,
|
|||||||
}
|
}
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
|
if (!len) {
|
||||||
|
errno = EINVAL;
|
||||||
|
goto fail;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Also check for overflows... */
|
||||||
|
len = TARGET_PAGE_ALIGN(len);
|
||||||
|
if (!len) {
|
||||||
|
errno = ENOMEM;
|
||||||
|
goto fail;
|
||||||
|
}
|
||||||
|
|
||||||
if (offset & ~TARGET_PAGE_MASK) {
|
if (offset & ~TARGET_PAGE_MASK) {
|
||||||
errno = EINVAL;
|
errno = EINVAL;
|
||||||
goto fail;
|
goto fail;
|
||||||
}
|
}
|
||||||
|
|
||||||
len = TARGET_PAGE_ALIGN(len);
|
|
||||||
if (len == 0)
|
|
||||||
goto the_end;
|
|
||||||
real_start = start & qemu_host_page_mask;
|
real_start = start & qemu_host_page_mask;
|
||||||
host_offset = offset & qemu_host_page_mask;
|
host_offset = offset & qemu_host_page_mask;
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user