Page MenuHomeFreeBSD

Relax restrictions on private mappings of POSIX shm objects.
ClosedPublic

Authored by markj on Apr 13 2020, 4:50 PM.
Tags
None
Referenced Files
F163255443: D24398.id.diff
Tue, Jul 21, 11:41 AM
Unknown Object (File)
Sat, Jul 18, 6:21 PM
Unknown Object (File)
Fri, Jul 17, 3:19 AM
Unknown Object (File)
Thu, Jul 16, 9:16 AM
Unknown Object (File)
Tue, Jul 14, 5:38 AM
Unknown Object (File)
Thu, Jul 9, 6:02 AM
Unknown Object (File)
Tue, Jul 7, 10:58 PM
Unknown Object (File)
Sat, Jul 4, 3:03 AM
Subscribers

Details

Summary

When we create a private mapping of an shm object, VM_PROT_WRITE should
always be included in maxprot regardless of permissions on the
underlying FD. Otherwise it is possible to open a shm object read-only,
map it with MAP_PRIVATE and PROT_WRITE, and violate the invariant in
vm_map_insert() that (prot & maxprot) == prot.

Test Plan

syzkaller generated a program that triggers the aforementioned
assertion failure:
http://syzkaller.backtrace.io:8080/report?id=ba93405590ed607e9b2d65025a44ff60dc6c4bcc

Diff Detail

Lint
Lint Passed
Unit
No Test Coverage
Build Status
Buildable 30464
Build 28221: arc lint + arc unit