exec.c 47.0 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21
/*
 *  linux/fs/exec.c
 *
 *  Copyright (C) 1991, 1992  Linus Torvalds
 */

/*
 * #!-checking implemented by tytso.
 */
/*
 * Demand-loading implemented 01.12.91 - no need to read anything but
 * the header into memory. The inode of the executable is put into
 * "current->executable", and page faults do the actual loading. Clean.
 *
 * Once more I can proudly say that linux stood up to being changed: it
 * was less than 2 hours work to get demand-loading completely implemented.
 *
 * Demand loading changed July 1993 by Eric Youngdale.   Use mmap instead,
 * current->executable is only used by the procfs.  This allows a dispatch
 * table to check for several different types  of binary formats.  We keep
 * trying until we recognize the file or we run out of supported binary
22
 * formats.
L
Linus Torvalds 已提交
23 24 25 26
 */

#include <linux/slab.h>
#include <linux/file.h>
A
Al Viro 已提交
27
#include <linux/fdtable.h>
H
Hugh Dickins 已提交
28
#include <linux/mm.h>
D
Davidlohr Bueso 已提交
29
#include <linux/vmacache.h>
L
Linus Torvalds 已提交
30 31
#include <linux/stat.h>
#include <linux/fcntl.h>
H
Hugh Dickins 已提交
32
#include <linux/swap.h>
33
#include <linux/string.h>
L
Linus Torvalds 已提交
34
#include <linux/init.h>
35
#include <linux/sched/mm.h>
36
#include <linux/sched/coredump.h>
37
#include <linux/sched/signal.h>
38
#include <linux/sched/numa_balancing.h>
39
#include <linux/sched/task.h>
40
#include <linux/pagemap.h>
41
#include <linux/perf_event.h>
L
Linus Torvalds 已提交
42 43 44 45 46 47
#include <linux/highmem.h>
#include <linux/spinlock.h>
#include <linux/key.h>
#include <linux/personality.h>
#include <linux/binfmts.h>
#include <linux/utsname.h>
48
#include <linux/pid_namespace.h>
L
Linus Torvalds 已提交
49 50 51 52 53
#include <linux/module.h>
#include <linux/namei.h>
#include <linux/mount.h>
#include <linux/security.h>
#include <linux/syscalls.h>
54
#include <linux/tsacct_kern.h>
M
Matt Helsley 已提交
55
#include <linux/cn_proc.h>
A
Al Viro 已提交
56
#include <linux/audit.h>
R
Roland McGrath 已提交
57
#include <linux/tracehook.h>
J
Johannes Berg 已提交
58
#include <linux/kmod.h>
59
#include <linux/fsnotify.h>
60
#include <linux/fs_struct.h>
61
#include <linux/pipe_fs_i.h>
Y
Ying Han 已提交
62
#include <linux/oom.h>
63
#include <linux/compat.h>
64
#include <linux/vmalloc.h>
L
Linus Torvalds 已提交
65

66
#include <linux/uaccess.h>
L
Linus Torvalds 已提交
67
#include <asm/mmu_context.h>
68
#include <asm/tlb.h>
69 70

#include <trace/events/task.h>
71
#include "internal.h"
L
Linus Torvalds 已提交
72

73 74
#include <trace/events/sched.h>

A
Alan Cox 已提交
75 76
int suid_dumpable = 0;

A
Alexey Dobriyan 已提交
77
static LIST_HEAD(formats);
L
Linus Torvalds 已提交
78 79
static DEFINE_RWLOCK(binfmt_lock);

A
Al Viro 已提交
80
void __register_binfmt(struct linux_binfmt * fmt, int insert)
L
Linus Torvalds 已提交
81
{
A
Al Viro 已提交
82
	BUG_ON(!fmt);
83 84
	if (WARN_ON(!fmt->load_binary))
		return;
L
Linus Torvalds 已提交
85
	write_lock(&binfmt_lock);
I
Ivan Kokshaysky 已提交
86 87
	insert ? list_add(&fmt->lh, &formats) :
		 list_add_tail(&fmt->lh, &formats);
L
Linus Torvalds 已提交
88 89 90
	write_unlock(&binfmt_lock);
}

I
Ivan Kokshaysky 已提交
91
EXPORT_SYMBOL(__register_binfmt);
L
Linus Torvalds 已提交
92

93
void unregister_binfmt(struct linux_binfmt * fmt)
L
Linus Torvalds 已提交
94 95
{
	write_lock(&binfmt_lock);
A
Alexey Dobriyan 已提交
96
	list_del(&fmt->lh);
L
Linus Torvalds 已提交
97 98 99 100 101 102 103 104 105 106
	write_unlock(&binfmt_lock);
}

EXPORT_SYMBOL(unregister_binfmt);

static inline void put_binfmt(struct linux_binfmt * fmt)
{
	module_put(fmt->module);
}

107 108 109 110 111 112
bool path_noexec(const struct path *path)
{
	return (path->mnt->mnt_flags & MNT_NOEXEC) ||
	       (path->mnt->mnt_sb->s_iflags & SB_I_NOEXEC);
}

113
#ifdef CONFIG_USELIB
L
Linus Torvalds 已提交
114 115 116 117 118 119
/*
 * Note that a shared library must be both readable and executable due to
 * security reasons.
 *
 * Also note that we take the address to load from from the file itself.
 */
120
SYSCALL_DEFINE1(uselib, const char __user *, library)
L
Linus Torvalds 已提交
121
{
A
Al Viro 已提交
122
	struct linux_binfmt *fmt;
123
	struct file *file;
124
	struct filename *tmp = getname(library);
125
	int error = PTR_ERR(tmp);
126 127
	static const struct open_flags uselib_flags = {
		.open_flag = O_LARGEFILE | O_RDONLY | __FMODE_EXEC,
A
Al Viro 已提交
128
		.acc_mode = MAY_READ | MAY_EXEC,
129 130
		.intent = LOOKUP_OPEN,
		.lookup_flags = LOOKUP_FOLLOW,
131
	};
132

133 134 135
	if (IS_ERR(tmp))
		goto out;

136
	file = do_filp_open(AT_FDCWD, tmp, &uselib_flags);
137 138 139
	putname(tmp);
	error = PTR_ERR(file);
	if (IS_ERR(file))
L
Linus Torvalds 已提交
140 141 142
		goto out;

	error = -EINVAL;
A
Al Viro 已提交
143
	if (!S_ISREG(file_inode(file)->i_mode))
L
Linus Torvalds 已提交
144 145
		goto exit;

146
	error = -EACCES;
147
	if (path_noexec(&file->f_path))
L
Linus Torvalds 已提交
148 149
		goto exit;

150
	fsnotify_open(file);
151

L
Linus Torvalds 已提交
152 153
	error = -ENOEXEC;

A
Al Viro 已提交
154 155 156 157 158 159
	read_lock(&binfmt_lock);
	list_for_each_entry(fmt, &formats, lh) {
		if (!fmt->load_shlib)
			continue;
		if (!try_module_get(fmt->module))
			continue;
L
Linus Torvalds 已提交
160
		read_unlock(&binfmt_lock);
A
Al Viro 已提交
161 162 163 164 165
		error = fmt->load_shlib(file);
		read_lock(&binfmt_lock);
		put_binfmt(fmt);
		if (error != -ENOEXEC)
			break;
L
Linus Torvalds 已提交
166
	}
A
Al Viro 已提交
167
	read_unlock(&binfmt_lock);
168
exit:
L
Linus Torvalds 已提交
169 170 171 172
	fput(file);
out:
  	return error;
}
173
#endif /* #ifdef CONFIG_USELIB */
L
Linus Torvalds 已提交
174

175
#ifdef CONFIG_MMU
O
Oleg Nesterov 已提交
176 177 178 179 180 181
/*
 * The nascent bprm->mm is not visible until exec_mmap() but it can
 * use a lot of memory, account these pages in current->mm temporary
 * for oom_badness()->get_mm_rss(). Once exec succeeds or fails, we
 * change the counter back via acct_arg_size(0).
 */
182
static void acct_arg_size(struct linux_binprm *bprm, unsigned long pages)
183 184 185 186 187 188 189 190 191 192 193
{
	struct mm_struct *mm = current->mm;
	long diff = (long)(pages - bprm->vma_pages);

	if (!mm || !diff)
		return;

	bprm->vma_pages = pages;
	add_mm_counter(mm, MM_ANONPAGES, diff);
}

194
static struct page *get_arg_page(struct linux_binprm *bprm, unsigned long pos,
195 196 197 198
		int write)
{
	struct page *page;
	int ret;
199
	unsigned int gup_flags = FOLL_FORCE;
200 201 202

#ifdef CONFIG_STACK_GROWSUP
	if (write) {
203
		ret = expand_downwards(bprm->vma, pos);
204 205 206 207
		if (ret < 0)
			return NULL;
	}
#endif
208 209 210 211

	if (write)
		gup_flags |= FOLL_WRITE;

212 213 214 215
	/*
	 * We are doing an exec().  'current' is the process
	 * doing the exec and bprm->mm is the new process's mm.
	 */
216
	ret = get_user_pages_remote(current, bprm->mm, pos, 1, gup_flags,
217
			&page, NULL, NULL);
218 219 220
	if (ret <= 0)
		return NULL;

221 222
	if (write)
		acct_arg_size(bprm, vma_pages(bprm->vma));
223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243

	return page;
}

static void put_arg_page(struct page *page)
{
	put_page(page);
}

static void free_arg_pages(struct linux_binprm *bprm)
{
}

static void flush_arg_page(struct linux_binprm *bprm, unsigned long pos,
		struct page *page)
{
	flush_cache_page(bprm->vma, pos, page_to_pfn(page));
}

static int __bprm_mm_init(struct linux_binprm *bprm)
{
244
	int err;
245 246 247
	struct vm_area_struct *vma = NULL;
	struct mm_struct *mm = bprm->mm;

248
	bprm->vma = vma = vm_area_alloc(mm);
249
	if (!vma)
250
		return -ENOMEM;
251
	vma_set_anonymous(vma);
252

253 254 255 256
	if (down_write_killable(&mm->mmap_sem)) {
		err = -EINTR;
		goto err_free;
	}
257 258 259 260 261 262 263

	/*
	 * Place the stack at the largest stack address the architecture
	 * supports. Later, we'll move this to an appropriate place. We don't
	 * use STACK_TOP because that can depend on attributes which aren't
	 * configured yet.
	 */
264
	BUILD_BUG_ON(VM_STACK_FLAGS & VM_STACK_INCOMPLETE_SETUP);
265 266
	vma->vm_end = STACK_TOP_MAX;
	vma->vm_start = vma->vm_end - PAGE_SIZE;
267
	vma->vm_flags = VM_SOFTDIRTY | VM_STACK_FLAGS | VM_STACK_INCOMPLETE_SETUP;
268
	vma->vm_page_prot = vm_get_page_prot(vma->vm_flags);
269

270
	err = insert_vm_struct(mm, vma);
271
	if (err)
272 273 274
		goto err;

	mm->stack_vm = mm->total_vm = 1;
275
	arch_bprm_mm_init(mm, vma);
276 277 278 279
	up_write(&mm->mmap_sem);
	bprm->p = vma->vm_end - sizeof(void *);
	return 0;
err:
280
	up_write(&mm->mmap_sem);
281
err_free:
282
	bprm->vma = NULL;
283
	vm_area_free(vma);
284 285 286 287 288 289 290 291 292 293
	return err;
}

static bool valid_arg_len(struct linux_binprm *bprm, long len)
{
	return len <= MAX_ARG_STRLEN;
}

#else

294
static inline void acct_arg_size(struct linux_binprm *bprm, unsigned long pages)
295 296 297
{
}

298
static struct page *get_arg_page(struct linux_binprm *bprm, unsigned long pos,
299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357
		int write)
{
	struct page *page;

	page = bprm->page[pos / PAGE_SIZE];
	if (!page && write) {
		page = alloc_page(GFP_HIGHUSER|__GFP_ZERO);
		if (!page)
			return NULL;
		bprm->page[pos / PAGE_SIZE] = page;
	}

	return page;
}

static void put_arg_page(struct page *page)
{
}

static void free_arg_page(struct linux_binprm *bprm, int i)
{
	if (bprm->page[i]) {
		__free_page(bprm->page[i]);
		bprm->page[i] = NULL;
	}
}

static void free_arg_pages(struct linux_binprm *bprm)
{
	int i;

	for (i = 0; i < MAX_ARG_PAGES; i++)
		free_arg_page(bprm, i);
}

static void flush_arg_page(struct linux_binprm *bprm, unsigned long pos,
		struct page *page)
{
}

static int __bprm_mm_init(struct linux_binprm *bprm)
{
	bprm->p = PAGE_SIZE * MAX_ARG_PAGES - sizeof(void *);
	return 0;
}

static bool valid_arg_len(struct linux_binprm *bprm, long len)
{
	return len <= bprm->p;
}

#endif /* CONFIG_MMU */

/*
 * Create a new mm_struct and populate it with a temporary stack
 * vm_area_struct.  We don't have enough context at this point to set the stack
 * flags, permissions, and offset, so we use temporary values.  We'll update
 * them later in setup_arg_pages().
 */
358
static int bprm_mm_init(struct linux_binprm *bprm)
359 360 361 362 363 364 365 366 367
{
	int err;
	struct mm_struct *mm = NULL;

	bprm->mm = mm = mm_alloc();
	err = -ENOMEM;
	if (!mm)
		goto err;

K
Kees Cook 已提交
368 369 370 371 372
	/* Save current stack limit for all calculations made during exec. */
	task_lock(current->group_leader);
	bprm->rlim_stack = current->signal->rlim[RLIMIT_STACK];
	task_unlock(current->group_leader);

373 374 375 376 377 378 379 380 381 382 383 384 385 386 387
	err = __bprm_mm_init(bprm);
	if (err)
		goto err;

	return 0;

err:
	if (mm) {
		bprm->mm = NULL;
		mmdrop(mm);
	}

	return err;
}

388
struct user_arg_ptr {
389 390 391 392 393 394
#ifdef CONFIG_COMPAT
	bool is_compat;
#endif
	union {
		const char __user *const __user *native;
#ifdef CONFIG_COMPAT
A
Al Viro 已提交
395
		const compat_uptr_t __user *compat;
396 397
#endif
	} ptr;
398 399 400
};

static const char __user *get_user_arg_ptr(struct user_arg_ptr argv, int nr)
401
{
402 403 404 405 406 407 408 409
	const char __user *native;

#ifdef CONFIG_COMPAT
	if (unlikely(argv.is_compat)) {
		compat_uptr_t compat;

		if (get_user(compat, argv.ptr.compat + nr))
			return ERR_PTR(-EFAULT);
410

411 412 413 414 415
		return compat_ptr(compat);
	}
#endif

	if (get_user(native, argv.ptr.native + nr))
416 417
		return ERR_PTR(-EFAULT);

418
	return native;
419 420
}

L
Linus Torvalds 已提交
421 422 423
/*
 * count() counts the number of strings in array ARGV.
 */
424
static int count(struct user_arg_ptr argv, int max)
L
Linus Torvalds 已提交
425 426 427
{
	int i = 0;

428
	if (argv.ptr.native != NULL) {
L
Linus Torvalds 已提交
429
		for (;;) {
430
			const char __user *p = get_user_arg_ptr(argv, i);
L
Linus Torvalds 已提交
431 432 433

			if (!p)
				break;
434 435 436 437

			if (IS_ERR(p))
				return -EFAULT;

438
			if (i >= max)
L
Linus Torvalds 已提交
439
				return -E2BIG;
440
			++i;
441 442 443

			if (fatal_signal_pending(current))
				return -ERESTARTNOHAND;
L
Linus Torvalds 已提交
444 445 446 447 448 449
			cond_resched();
		}
	}
	return i;
}

450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492 493
static int prepare_arg_pages(struct linux_binprm *bprm,
			struct user_arg_ptr argv, struct user_arg_ptr envp)
{
	unsigned long limit, ptr_size;

	bprm->argc = count(argv, MAX_ARG_STRINGS);
	if (bprm->argc < 0)
		return bprm->argc;

	bprm->envc = count(envp, MAX_ARG_STRINGS);
	if (bprm->envc < 0)
		return bprm->envc;

	/*
	 * Limit to 1/4 of the max stack size or 3/4 of _STK_LIM
	 * (whichever is smaller) for the argv+env strings.
	 * This ensures that:
	 *  - the remaining binfmt code will not run out of stack space,
	 *  - the program will have a reasonable amount of stack left
	 *    to work from.
	 */
	limit = _STK_LIM / 4 * 3;
	limit = min(limit, bprm->rlim_stack.rlim_cur / 4);
	/*
	 * We've historically supported up to 32 pages (ARG_MAX)
	 * of argument strings even with small stacks
	 */
	limit = max_t(unsigned long, limit, ARG_MAX);
	/*
	 * We must account for the size of all the argv and envp pointers to
	 * the argv and envp strings, since they will also take up space in
	 * the stack. They aren't stored until much later when we can't
	 * signal to the parent that the child has run out of stack space.
	 * Instead, calculate it here so it's possible to fail gracefully.
	 */
	ptr_size = (bprm->argc + bprm->envc) * sizeof(void *);
	if (limit <= ptr_size)
		return -E2BIG;
	limit -= ptr_size;

	bprm->argmin = bprm->p - limit;
	return 0;
}

L
Linus Torvalds 已提交
494
/*
495 496 497
 * 'copy_strings()' copies argument/environment strings from the old
 * processes's memory to the new process's stack.  The call to get_user_pages()
 * ensures the destination page is created and not swapped out.
L
Linus Torvalds 已提交
498
 */
499
static int copy_strings(int argc, struct user_arg_ptr argv,
A
Adrian Bunk 已提交
500
			struct linux_binprm *bprm)
L
Linus Torvalds 已提交
501 502 503
{
	struct page *kmapped_page = NULL;
	char *kaddr = NULL;
504
	unsigned long kpos = 0;
L
Linus Torvalds 已提交
505 506 507
	int ret;

	while (argc-- > 0) {
508
		const char __user *str;
L
Linus Torvalds 已提交
509 510 511
		int len;
		unsigned long pos;

512 513 514
		ret = -EFAULT;
		str = get_user_arg_ptr(argv, argc);
		if (IS_ERR(str))
L
Linus Torvalds 已提交
515 516
			goto out;

517 518 519 520 521 522
		len = strnlen_user(str, MAX_ARG_STRLEN);
		if (!len)
			goto out;

		ret = -E2BIG;
		if (!valid_arg_len(bprm, len))
L
Linus Torvalds 已提交
523 524
			goto out;

525
		/* We're going to work our way backwords. */
L
Linus Torvalds 已提交
526
		pos = bprm->p;
527 528
		str += len;
		bprm->p -= len;
529 530 531 532
#ifdef CONFIG_MMU
		if (bprm->p < bprm->argmin)
			goto out;
#endif
L
Linus Torvalds 已提交
533 534 535 536

		while (len > 0) {
			int offset, bytes_to_copy;

537 538 539 540
			if (fatal_signal_pending(current)) {
				ret = -ERESTARTNOHAND;
				goto out;
			}
541 542
			cond_resched();

L
Linus Torvalds 已提交
543
			offset = pos % PAGE_SIZE;
544 545 546 547 548 549 550 551 552 553 554 555 556 557 558 559
			if (offset == 0)
				offset = PAGE_SIZE;

			bytes_to_copy = offset;
			if (bytes_to_copy > len)
				bytes_to_copy = len;

			offset -= bytes_to_copy;
			pos -= bytes_to_copy;
			str -= bytes_to_copy;
			len -= bytes_to_copy;

			if (!kmapped_page || kpos != (pos & PAGE_MASK)) {
				struct page *page;

				page = get_arg_page(bprm, pos, 1);
L
Linus Torvalds 已提交
560
				if (!page) {
561
					ret = -E2BIG;
L
Linus Torvalds 已提交
562 563 564
					goto out;
				}

565 566
				if (kmapped_page) {
					flush_kernel_dcache_page(kmapped_page);
L
Linus Torvalds 已提交
567
					kunmap(kmapped_page);
568 569
					put_arg_page(kmapped_page);
				}
L
Linus Torvalds 已提交
570 571
				kmapped_page = page;
				kaddr = kmap(kmapped_page);
572 573
				kpos = pos & PAGE_MASK;
				flush_arg_page(bprm, kpos, kmapped_page);
L
Linus Torvalds 已提交
574
			}
575
			if (copy_from_user(kaddr+offset, str, bytes_to_copy)) {
L
Linus Torvalds 已提交
576 577 578 579 580 581 582
				ret = -EFAULT;
				goto out;
			}
		}
	}
	ret = 0;
out:
583 584
	if (kmapped_page) {
		flush_kernel_dcache_page(kmapped_page);
L
Linus Torvalds 已提交
585
		kunmap(kmapped_page);
586 587
		put_arg_page(kmapped_page);
	}
L
Linus Torvalds 已提交
588 589 590 591 592 593
	return ret;
}

/*
 * Like copy_strings, but get argv and its values from kernel memory.
 */
594
int copy_strings_kernel(int argc, const char *const *__argv,
595
			struct linux_binprm *bprm)
L
Linus Torvalds 已提交
596 597 598
{
	int r;
	mm_segment_t oldfs = get_fs();
599
	struct user_arg_ptr argv = {
600
		.ptr.native = (const char __user *const  __user *)__argv,
601 602
	};

L
Linus Torvalds 已提交
603
	set_fs(KERNEL_DS);
604
	r = copy_strings(argc, argv, bprm);
L
Linus Torvalds 已提交
605
	set_fs(oldfs);
606

L
Linus Torvalds 已提交
607 608 609 610 611
	return r;
}
EXPORT_SYMBOL(copy_strings_kernel);

#ifdef CONFIG_MMU
612

L
Linus Torvalds 已提交
613
/*
614 615 616
 * During bprm_mm_init(), we create a temporary stack at STACK_TOP_MAX.  Once
 * the binfmt code determines where the new stack should reside, we shift it to
 * its final location.  The process proceeds as follows:
L
Linus Torvalds 已提交
617
 *
618 619 620 621 622 623
 * 1) Use shift to calculate the new vma endpoints.
 * 2) Extend vma to cover both the old and new ranges.  This ensures the
 *    arguments passed to subsequent functions are consistent.
 * 3) Move vma's page tables to the new range.
 * 4) Free up any cleared pgd range.
 * 5) Shrink the vma to cover only the new range.
L
Linus Torvalds 已提交
624
 */
625
static int shift_arg_pages(struct vm_area_struct *vma, unsigned long shift)
L
Linus Torvalds 已提交
626 627
{
	struct mm_struct *mm = vma->vm_mm;
628 629 630 631 632
	unsigned long old_start = vma->vm_start;
	unsigned long old_end = vma->vm_end;
	unsigned long length = old_end - old_start;
	unsigned long new_start = old_start - shift;
	unsigned long new_end = old_end - shift;
P
Peter Zijlstra 已提交
633
	struct mmu_gather tlb;
L
Linus Torvalds 已提交
634

635
	BUG_ON(new_start > new_end);
L
Linus Torvalds 已提交
636

637 638 639 640 641 642 643 644 645 646
	/*
	 * ensure there are no vmas between where we want to go
	 * and where we are
	 */
	if (vma != find_vma(mm, new_start))
		return -EFAULT;

	/*
	 * cover the whole range: [new_start, old_end)
	 */
647 648
	if (vma_adjust(vma, new_start, old_end, vma->vm_pgoff, NULL))
		return -ENOMEM;
649 650 651 652 653 654

	/*
	 * move the page tables downwards, on failure we rely on
	 * process cleanup to remove whatever mess we made.
	 */
	if (length != move_page_tables(vma, old_start,
655
				       vma, new_start, length, false))
656 657 658
		return -ENOMEM;

	lru_add_drain();
659
	tlb_gather_mmu(&tlb, mm, old_start, old_end);
660 661 662 663
	if (new_end > old_start) {
		/*
		 * when the old and new regions overlap clear from new_end.
		 */
P
Peter Zijlstra 已提交
664
		free_pgd_range(&tlb, new_end, old_end, new_end,
665
			vma->vm_next ? vma->vm_next->vm_start : USER_PGTABLES_CEILING);
666 667 668 669 670 671 672
	} else {
		/*
		 * otherwise, clean from old_start; this is done to not touch
		 * the address space in [new_end, old_start) some architectures
		 * have constraints on va-space that make this illegal (IA64) -
		 * for the others its just a little faster.
		 */
P
Peter Zijlstra 已提交
673
		free_pgd_range(&tlb, old_start, old_end, new_end,
674
			vma->vm_next ? vma->vm_next->vm_start : USER_PGTABLES_CEILING);
L
Linus Torvalds 已提交
675
	}
676
	tlb_finish_mmu(&tlb, old_start, old_end);
677 678

	/*
679
	 * Shrink the vma to just the new range.  Always succeeds.
680 681 682 683
	 */
	vma_adjust(vma, new_start, new_end, vma->vm_pgoff, NULL);

	return 0;
L
Linus Torvalds 已提交
684 685
}

686 687 688 689
/*
 * Finalizes the stack vm_area_struct. The flags and permissions are updated,
 * the stack is optionally relocated, and some extra space is added.
 */
L
Linus Torvalds 已提交
690 691 692 693
int setup_arg_pages(struct linux_binprm *bprm,
		    unsigned long stack_top,
		    int executable_stack)
{
694 695
	unsigned long ret;
	unsigned long stack_shift;
L
Linus Torvalds 已提交
696
	struct mm_struct *mm = current->mm;
697 698 699 700
	struct vm_area_struct *vma = bprm->vma;
	struct vm_area_struct *prev = NULL;
	unsigned long vm_flags;
	unsigned long stack_base;
701 702 703
	unsigned long stack_size;
	unsigned long stack_expand;
	unsigned long rlim_stack;
L
Linus Torvalds 已提交
704 705

#ifdef CONFIG_STACK_GROWSUP
706
	/* Limit stack size */
K
Kees Cook 已提交
707
	stack_base = bprm->rlim_stack.rlim_max;
708 709
	if (stack_base > STACK_SIZE_MAX)
		stack_base = STACK_SIZE_MAX;
L
Linus Torvalds 已提交
710

711 712 713
	/* Add space for stack randomization. */
	stack_base += (STACK_RND_MASK << PAGE_SHIFT);

714 715 716
	/* Make sure we didn't let the argument array grow too large. */
	if (vma->vm_end - vma->vm_start > stack_base)
		return -ENOMEM;
L
Linus Torvalds 已提交
717

718
	stack_base = PAGE_ALIGN(stack_top - stack_base);
L
Linus Torvalds 已提交
719

720 721 722
	stack_shift = vma->vm_start - stack_base;
	mm->arg_start = bprm->p - stack_shift;
	bprm->p = vma->vm_end - stack_shift;
L
Linus Torvalds 已提交
723
#else
724 725
	stack_top = arch_align_stack(stack_top);
	stack_top = PAGE_ALIGN(stack_top);
726 727 728 729 730

	if (unlikely(stack_top < mmap_min_addr) ||
	    unlikely(vma->vm_end - vma->vm_start >= stack_top - mmap_min_addr))
		return -ENOMEM;

731 732 733
	stack_shift = vma->vm_end - stack_top;

	bprm->p -= stack_shift;
L
Linus Torvalds 已提交
734 735 736 737
	mm->arg_start = bprm->p;
#endif

	if (bprm->loader)
738 739
		bprm->loader -= stack_shift;
	bprm->exec -= stack_shift;
L
Linus Torvalds 已提交
740

741 742 743
	if (down_write_killable(&mm->mmap_sem))
		return -EINTR;

744
	vm_flags = VM_STACK_FLAGS;
745 746 747 748 749 750 751 752 753 754 755

	/*
	 * Adjust stack execute permissions; explicitly enable for
	 * EXSTACK_ENABLE_X, disable for EXSTACK_DISABLE_X and leave alone
	 * (arch default) otherwise.
	 */
	if (unlikely(executable_stack == EXSTACK_ENABLE_X))
		vm_flags |= VM_EXEC;
	else if (executable_stack == EXSTACK_DISABLE_X)
		vm_flags &= ~VM_EXEC;
	vm_flags |= mm->def_flags;
756
	vm_flags |= VM_STACK_INCOMPLETE_SETUP;
757 758 759 760 761 762 763 764 765 766

	ret = mprotect_fixup(vma, &prev, vma->vm_start, vma->vm_end,
			vm_flags);
	if (ret)
		goto out_unlock;
	BUG_ON(prev != vma);

	/* Move stack pages down in memory. */
	if (stack_shift) {
		ret = shift_arg_pages(vma, stack_shift);
767 768
		if (ret)
			goto out_unlock;
L
Linus Torvalds 已提交
769 770
	}

771 772 773
	/* mprotect_fixup is overkill to remove the temporary stack flags */
	vma->vm_flags &= ~VM_STACK_INCOMPLETE_SETUP;

774
	stack_expand = 131072UL; /* randomly 32*4k (or 2*64k) pages */
775 776 777 778 779
	stack_size = vma->vm_end - vma->vm_start;
	/*
	 * Align this down to a page boundary as expand_stack
	 * will align it up.
	 */
K
Kees Cook 已提交
780
	rlim_stack = bprm->rlim_stack.rlim_cur & PAGE_MASK;
781
#ifdef CONFIG_STACK_GROWSUP
782 783 784 785
	if (stack_size + stack_expand > rlim_stack)
		stack_base = vma->vm_start + rlim_stack;
	else
		stack_base = vma->vm_end + stack_expand;
786
#else
787 788 789 790
	if (stack_size + stack_expand > rlim_stack)
		stack_base = vma->vm_end - rlim_stack;
	else
		stack_base = vma->vm_start - stack_expand;
791
#endif
792
	current->mm->start_stack = bprm->p;
793 794 795 796 797
	ret = expand_stack(vma, stack_base);
	if (ret)
		ret = -EFAULT;

out_unlock:
L
Linus Torvalds 已提交
798
	up_write(&mm->mmap_sem);
799
	return ret;
L
Linus Torvalds 已提交
800 801 802
}
EXPORT_SYMBOL(setup_arg_pages);

803 804 805 806 807 808 809 810 811 812 813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834 835
#else

/*
 * Transfer the program arguments and environment from the holding pages
 * onto the stack. The provided stack pointer is adjusted accordingly.
 */
int transfer_args_to_stack(struct linux_binprm *bprm,
			   unsigned long *sp_location)
{
	unsigned long index, stop, sp;
	int ret = 0;

	stop = bprm->p >> PAGE_SHIFT;
	sp = *sp_location;

	for (index = MAX_ARG_PAGES - 1; index >= stop; index--) {
		unsigned int offset = index == stop ? bprm->p & ~PAGE_MASK : 0;
		char *src = kmap(bprm->page[index]) + offset;
		sp -= PAGE_SIZE - offset;
		if (copy_to_user((void *) sp, src, PAGE_SIZE - offset) != 0)
			ret = -EFAULT;
		kunmap(bprm->page[index]);
		if (ret)
			goto out;
	}

	*sp_location = sp;

out:
	return ret;
}
EXPORT_SYMBOL(transfer_args_to_stack);

L
Linus Torvalds 已提交
836 837
#endif /* CONFIG_MMU */

838
static struct file *do_open_execat(int fd, struct filename *name, int flags)
L
Linus Torvalds 已提交
839 840
{
	struct file *file;
841
	int err;
842
	struct open_flags open_exec_flags = {
843
		.open_flag = O_LARGEFILE | O_RDONLY | __FMODE_EXEC,
A
Al Viro 已提交
844
		.acc_mode = MAY_EXEC,
845 846
		.intent = LOOKUP_OPEN,
		.lookup_flags = LOOKUP_FOLLOW,
847
	};
L
Linus Torvalds 已提交
848

849 850 851 852 853 854 855 856
	if ((flags & ~(AT_SYMLINK_NOFOLLOW | AT_EMPTY_PATH)) != 0)
		return ERR_PTR(-EINVAL);
	if (flags & AT_SYMLINK_NOFOLLOW)
		open_exec_flags.lookup_flags &= ~LOOKUP_FOLLOW;
	if (flags & AT_EMPTY_PATH)
		open_exec_flags.lookup_flags |= LOOKUP_EMPTY;

	file = do_filp_open(fd, name, &open_exec_flags);
857
	if (IS_ERR(file))
858 859 860
		goto out;

	err = -EACCES;
A
Al Viro 已提交
861
	if (!S_ISREG(file_inode(file)->i_mode))
862
		goto exit;
863

864
	if (path_noexec(&file->f_path))
865
		goto exit;
866 867

	err = deny_write_access(file);
868 869
	if (err)
		goto exit;
L
Linus Torvalds 已提交
870

871 872 873
	if (name->name[0] != '\0')
		fsnotify_open(file);

874
out:
875 876
	return file;

877 878
exit:
	fput(file);
879 880
	return ERR_PTR(err);
}
881 882 883

struct file *open_exec(const char *name)
{
884 885 886 887 888 889 890 891
	struct filename *filename = getname_kernel(name);
	struct file *f = ERR_CAST(filename);

	if (!IS_ERR(filename)) {
		f = do_open_execat(AT_FDCWD, filename, 0);
		putname(filename);
	}
	return f;
892
}
L
Linus Torvalds 已提交
893 894
EXPORT_SYMBOL(open_exec);

895
int kernel_read_file(struct file *file, void **buf, loff_t *size,
896
		     loff_t max_size, enum kernel_read_file_id id)
897 898 899 900 901 902 903 904
{
	loff_t i_size, pos;
	ssize_t bytes = 0;
	int ret;

	if (!S_ISREG(file_inode(file)->i_mode) || max_size < 0)
		return -EINVAL;

905
	ret = deny_write_access(file);
906 907 908
	if (ret)
		return ret;

909
	ret = security_kernel_read_file(file, id);
910
	if (ret)
911
		goto out;
912

913
	i_size = i_size_read(file_inode(file));
914 915 916 917
	if (i_size <= 0) {
		ret = -EINVAL;
		goto out;
	}
918 919 920 921
	if (i_size > SIZE_MAX || (max_size > 0 && i_size > max_size)) {
		ret = -EFBIG;
		goto out;
	}
922

923 924
	if (id != READING_FIRMWARE_PREALLOC_BUFFER)
		*buf = vmalloc(i_size);
925 926 927 928
	if (!*buf) {
		ret = -ENOMEM;
		goto out;
	}
929 930 931

	pos = 0;
	while (pos < i_size) {
932
		bytes = kernel_read(file, *buf + pos, i_size - pos, &pos);
933 934 935 936 937 938 939 940 941 942 943
		if (bytes < 0) {
			ret = bytes;
			goto out;
		}

		if (bytes == 0)
			break;
	}

	if (pos != i_size) {
		ret = -EIO;
944
		goto out_free;
945 946
	}

947
	ret = security_kernel_post_read_file(file, *buf, i_size, id);
948 949 950
	if (!ret)
		*size = pos;

951
out_free:
952
	if (ret < 0) {
953 954 955 956
		if (id != READING_FIRMWARE_PREALLOC_BUFFER) {
			vfree(*buf);
			*buf = NULL;
		}
957
	}
958 959 960

out:
	allow_write_access(file);
961 962 963 964
	return ret;
}
EXPORT_SYMBOL_GPL(kernel_read_file);

965
int kernel_read_file_from_path(const char *path, void **buf, loff_t *size,
966 967 968 969 970 971 972 973 974 975 976 977 978 979 980 981 982 983
			       loff_t max_size, enum kernel_read_file_id id)
{
	struct file *file;
	int ret;

	if (!path || !*path)
		return -EINVAL;

	file = filp_open(path, O_RDONLY, 0);
	if (IS_ERR(file))
		return PTR_ERR(file);

	ret = kernel_read_file(file, buf, size, max_size, id);
	fput(file);
	return ret;
}
EXPORT_SYMBOL_GPL(kernel_read_file_from_path);

984 985 986 987 988 989 990 991 992 993 994 995 996 997 998 999
int kernel_read_file_from_fd(int fd, void **buf, loff_t *size, loff_t max_size,
			     enum kernel_read_file_id id)
{
	struct fd f = fdget(fd);
	int ret = -EBADF;

	if (!f.file)
		goto out;

	ret = kernel_read_file(f.file, buf, size, max_size, id);
out:
	fdput(f);
	return ret;
}
EXPORT_SYMBOL_GPL(kernel_read_file_from_fd);

A
Al Viro 已提交
1000 1001
ssize_t read_code(struct file *file, unsigned long addr, loff_t pos, size_t len)
{
1002
	ssize_t res = vfs_read(file, (void __user *)addr, len, &pos);
A
Al Viro 已提交
1003 1004 1005 1006 1007 1008
	if (res > 0)
		flush_icache_range(addr, addr + len);
	return res;
}
EXPORT_SYMBOL(read_code);

L
Linus Torvalds 已提交
1009 1010 1011
static int exec_mmap(struct mm_struct *mm)
{
	struct task_struct *tsk;
D
Davidlohr Bueso 已提交
1012
	struct mm_struct *old_mm, *active_mm;
L
Linus Torvalds 已提交
1013 1014 1015 1016 1017 1018 1019

	/* Notify parent that we're no longer interested in the old VM */
	tsk = current;
	old_mm = current->mm;
	mm_release(tsk, old_mm);

	if (old_mm) {
1020
		sync_mm_rss(old_mm);
L
Linus Torvalds 已提交
1021 1022 1023 1024
		/*
		 * Make sure that if there is a core dump in progress
		 * for the old mm, we get out and die instead of going
		 * through with the exec.  We must hold mmap_sem around
1025
		 * checking core_state and changing tsk->mm.
L
Linus Torvalds 已提交
1026 1027
		 */
		down_read(&old_mm->mmap_sem);
1028
		if (unlikely(old_mm->core_state)) {
L
Linus Torvalds 已提交
1029 1030 1031 1032 1033 1034 1035 1036 1037
			up_read(&old_mm->mmap_sem);
			return -EINTR;
		}
	}
	task_lock(tsk);
	active_mm = tsk->active_mm;
	tsk->mm = mm;
	tsk->active_mm = mm;
	activate_mm(active_mm, mm);
D
Davidlohr Bueso 已提交
1038 1039
	tsk->mm->vmacache_seqnum = 0;
	vmacache_flush(tsk);
L
Linus Torvalds 已提交
1040 1041 1042
	task_unlock(tsk);
	if (old_mm) {
		up_read(&old_mm->mmap_sem);
1043
		BUG_ON(active_mm != old_mm);
1044
		setmax_mm_hiwater_rss(&tsk->signal->maxrss, old_mm);
1045
		mm_update_next_owner(old_mm);
L
Linus Torvalds 已提交
1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058
		mmput(old_mm);
		return 0;
	}
	mmdrop(active_mm);
	return 0;
}

/*
 * This function makes sure the current process has its own signal table,
 * so that flush_signal_handlers can later reset the handlers without
 * disturbing other processes.  (Other processes might share the signal
 * table via the CLONE_SIGHAND option to clone().)
 */
1059
static int de_thread(struct task_struct *tsk)
L
Linus Torvalds 已提交
1060 1061
{
	struct signal_struct *sig = tsk->signal;
1062
	struct sighand_struct *oldsighand = tsk->sighand;
L
Linus Torvalds 已提交
1063 1064
	spinlock_t *lock = &oldsighand->siglock;

1065
	if (thread_group_empty(tsk))
L
Linus Torvalds 已提交
1066 1067 1068 1069 1070 1071
		goto no_thread_group;

	/*
	 * Kill all other threads in the thread group.
	 */
	spin_lock_irq(lock);
1072
	if (signal_group_exit(sig)) {
L
Linus Torvalds 已提交
1073 1074 1075 1076 1077 1078 1079
		/*
		 * Another group action in progress, just
		 * return so that the signal is processed.
		 */
		spin_unlock_irq(lock);
		return -EAGAIN;
	}
1080

1081
	sig->group_exit_task = tsk;
1082 1083 1084
	sig->notify_count = zap_other_threads(tsk);
	if (!thread_group_leader(tsk))
		sig->notify_count--;
L
Linus Torvalds 已提交
1085

1086
	while (sig->notify_count) {
O
Oleg Nesterov 已提交
1087
		__set_current_state(TASK_KILLABLE);
L
Linus Torvalds 已提交
1088
		spin_unlock_irq(lock);
1089
		schedule();
O
Oleg Nesterov 已提交
1090 1091
		if (unlikely(__fatal_signal_pending(tsk)))
			goto killed;
L
Linus Torvalds 已提交
1092 1093 1094 1095 1096 1097 1098 1099 1100
		spin_lock_irq(lock);
	}
	spin_unlock_irq(lock);

	/*
	 * At this point all other threads have exited, all we have to
	 * do is to wait for the thread group leader to become inactive,
	 * and to assume its PID:
	 */
1101
	if (!thread_group_leader(tsk)) {
1102
		struct task_struct *leader = tsk->group_leader;
1103 1104

		for (;;) {
1105
			cgroup_threadgroup_change_begin(tsk);
1106
			write_lock_irq(&tasklist_lock);
1107 1108 1109 1110 1111
			/*
			 * Do this under tasklist_lock to ensure that
			 * exit_notify() can't miss ->group_exit_task
			 */
			sig->notify_count = -1;
1112 1113
			if (likely(leader->exit_state))
				break;
O
Oleg Nesterov 已提交
1114
			__set_current_state(TASK_KILLABLE);
1115
			write_unlock_irq(&tasklist_lock);
1116
			cgroup_threadgroup_change_end(tsk);
1117
			schedule();
O
Oleg Nesterov 已提交
1118 1119
			if (unlikely(__fatal_signal_pending(tsk)))
				goto killed;
1120
		}
L
Linus Torvalds 已提交
1121

1122 1123 1124 1125 1126 1127 1128 1129 1130 1131
		/*
		 * The only record we have of the real-time age of a
		 * process, regardless of execs it's done, is start_time.
		 * All the past CPU time is accumulated in signal_struct
		 * from sister threads now dead.  But in this non-leader
		 * exec, nothing survives from the original leader thread,
		 * whose birth marks the true age of this process now.
		 * When we take on its identity by switching to its PID, we
		 * also take its birthdate (always earlier than our own).
		 */
1132
		tsk->start_time = leader->start_time;
1133
		tsk->real_start_time = leader->real_start_time;
1134

1135 1136
		BUG_ON(!same_thread_group(leader, tsk));
		BUG_ON(has_group_leader_pid(tsk));
L
Linus Torvalds 已提交
1137 1138 1139 1140 1141 1142
		/*
		 * An exec() starts a new thread group with the
		 * TGID of the previous thread group. Rehash the
		 * two threads with a switched PID, and release
		 * the former thread group leader:
		 */
1143 1144

		/* Become a process group leader with the old leader's pid.
1145 1146
		 * The old leader becomes a thread of the this thread group.
		 * Note: The old leader also uses this pid until release_task
1147 1148
		 *       is called.  Odd but simple and correct.
		 */
1149
		tsk->pid = leader->pid;
1150
		change_pid(tsk, PIDTYPE_PID, task_pid(leader));
E
Eric W. Biederman 已提交
1151
		transfer_pid(leader, tsk, PIDTYPE_TGID);
1152 1153
		transfer_pid(leader, tsk, PIDTYPE_PGID);
		transfer_pid(leader, tsk, PIDTYPE_SID);
1154

1155
		list_replace_rcu(&leader->tasks, &tsk->tasks);
1156
		list_replace_init(&leader->sibling, &tsk->sibling);
L
Linus Torvalds 已提交
1157

1158 1159
		tsk->group_leader = tsk;
		leader->group_leader = tsk;
1160

1161
		tsk->exit_signal = SIGCHLD;
1162
		leader->exit_signal = -1;
1163 1164 1165

		BUG_ON(leader->exit_state != EXIT_ZOMBIE);
		leader->exit_state = EXIT_DEAD;
1166 1167 1168 1169 1170 1171 1172 1173

		/*
		 * We are going to release_task()->ptrace_unlink() silently,
		 * the tracer can sleep in do_wait(). EXIT_DEAD guarantees
		 * the tracer wont't block again waiting for this thread.
		 */
		if (unlikely(leader->ptrace))
			__wake_up_parent(leader, leader->parent);
L
Linus Torvalds 已提交
1174
		write_unlock_irq(&tasklist_lock);
1175
		cgroup_threadgroup_change_end(tsk);
1176 1177

		release_task(leader);
1178
	}
L
Linus Torvalds 已提交
1179

1180 1181
	sig->group_exit_task = NULL;
	sig->notify_count = 0;
L
Linus Torvalds 已提交
1182 1183

no_thread_group:
1184 1185 1186
	/* we have changed execution domain */
	tsk->exit_signal = SIGCHLD;

1187
#ifdef CONFIG_POSIX_TIMERS
L
Linus Torvalds 已提交
1188
	exit_itimers(sig);
1189
	flush_itimer_signals();
1190
#endif
1191

1192 1193
	if (atomic_read(&oldsighand->count) != 1) {
		struct sighand_struct *newsighand;
L
Linus Torvalds 已提交
1194
		/*
1195 1196
		 * This ->sighand is shared with the CLONE_SIGHAND
		 * but not CLONE_THREAD task, switch to the new one.
L
Linus Torvalds 已提交
1197
		 */
1198 1199 1200 1201
		newsighand = kmem_cache_alloc(sighand_cachep, GFP_KERNEL);
		if (!newsighand)
			return -ENOMEM;

L
Linus Torvalds 已提交
1202 1203 1204 1205 1206 1207
		atomic_set(&newsighand->count, 1);
		memcpy(newsighand->action, oldsighand->action,
		       sizeof(newsighand->action));

		write_lock_irq(&tasklist_lock);
		spin_lock(&oldsighand->siglock);
1208
		rcu_assign_pointer(tsk->sighand, newsighand);
L
Linus Torvalds 已提交
1209 1210 1211
		spin_unlock(&oldsighand->siglock);
		write_unlock_irq(&tasklist_lock);

1212
		__cleanup_sighand(oldsighand);
L
Linus Torvalds 已提交
1213 1214
	}

1215
	BUG_ON(!thread_group_leader(tsk));
L
Linus Torvalds 已提交
1216
	return 0;
O
Oleg Nesterov 已提交
1217 1218 1219 1220 1221 1222 1223 1224

killed:
	/* protects against exit_notify() and __exit_signal() */
	read_lock(&tasklist_lock);
	sig->group_exit_task = NULL;
	sig->notify_count = 0;
	read_unlock(&tasklist_lock);
	return -EAGAIN;
L
Linus Torvalds 已提交
1225
}
O
Oleg Nesterov 已提交
1226

1227
char *__get_task_comm(char *buf, size_t buf_size, struct task_struct *tsk)
L
Linus Torvalds 已提交
1228 1229
{
	task_lock(tsk);
1230
	strncpy(buf, tsk->comm, buf_size);
L
Linus Torvalds 已提交
1231
	task_unlock(tsk);
1232
	return buf;
L
Linus Torvalds 已提交
1233
}
1234
EXPORT_SYMBOL_GPL(__get_task_comm);
L
Linus Torvalds 已提交
1235

1236 1237 1238 1239 1240
/*
 * These functions flushes out all traces of the currently running executable
 * so that a new one can be started
 */

1241
void __set_task_comm(struct task_struct *tsk, const char *buf, bool exec)
L
Linus Torvalds 已提交
1242 1243
{
	task_lock(tsk);
1244
	trace_task_rename(tsk, buf);
L
Linus Torvalds 已提交
1245 1246
	strlcpy(tsk->comm, buf, sizeof(tsk->comm));
	task_unlock(tsk);
1247
	perf_event_comm(tsk, exec);
L
Linus Torvalds 已提交
1248 1249
}

1250 1251 1252 1253 1254 1255
/*
 * Calling this is the point of no return. None of the failures will be
 * seen by userspace since either the process is already taking a fatal
 * signal (via de_thread() or coredump), or will have SEGV raised
 * (after exec_mmap()) by search_binary_handlers (see below).
 */
L
Linus Torvalds 已提交
1256 1257
int flush_old_exec(struct linux_binprm * bprm)
{
1258
	int retval;
L
Linus Torvalds 已提交
1259 1260 1261 1262 1263 1264 1265 1266 1267

	/*
	 * Make sure we have a private signal table and that
	 * we are unassociated from the previous thread group.
	 */
	retval = de_thread(current);
	if (retval)
		goto out;

1268 1269 1270 1271 1272
	/*
	 * Must be called _before_ exec_mmap() as bprm->mm is
	 * not visibile until then. This also enables the update
	 * to be lockless.
	 */
M
Matt Helsley 已提交
1273
	set_mm_exe_file(bprm->mm, bprm->file);
1274

L
Linus Torvalds 已提交
1275 1276 1277
	/*
	 * Release all of the old mmap stuff
	 */
1278
	acct_arg_size(bprm, 0);
L
Linus Torvalds 已提交
1279 1280
	retval = exec_mmap(bprm->mm);
	if (retval)
1281
		goto out;
L
Linus Torvalds 已提交
1282

1283 1284 1285 1286 1287 1288 1289
	/*
	 * After clearing bprm->mm (to mark that current is using the
	 * prepared mm now), we have nothing left of the original
	 * process. If anything from here on returns an error, the check
	 * in search_binary_handler() will SEGV current.
	 */
	bprm->mm = NULL;
1290

1291
	set_fs(USER_DS);
1292 1293
	current->flags &= ~(PF_RANDOMIZE | PF_FORKNOEXEC | PF_KTHREAD |
					PF_NOFREEZE | PF_NO_SETAFFINITY);
1294 1295 1296
	flush_thread();
	current->personality &= ~bprm->per_clear;

1297 1298 1299 1300 1301 1302 1303
	/*
	 * We have to apply CLOEXEC before we change whether the process is
	 * dumpable (in setup_new_exec) to avoid a race with a process in userspace
	 * trying to access the should-be-closed file descriptors of a process
	 * undergoing exec(2).
	 */
	do_close_on_exec(current->files);
1304 1305 1306 1307 1308 1309 1310
	return 0;

out:
	return retval;
}
EXPORT_SYMBOL(flush_old_exec);

1311 1312
void would_dump(struct linux_binprm *bprm, struct file *file)
{
1313 1314 1315
	struct inode *inode = file_inode(file);
	if (inode_permission(inode, MAY_READ) < 0) {
		struct user_namespace *old, *user_ns;
1316
		bprm->interp_flags |= BINPRM_FLAGS_ENFORCE_NONDUMP;
1317 1318 1319 1320 1321 1322 1323 1324 1325 1326 1327 1328

		/* Ensure mm->user_ns contains the executable */
		user_ns = old = bprm->mm->user_ns;
		while ((user_ns != &init_user_ns) &&
		       !privileged_wrt_inode_uidgid(user_ns, inode))
			user_ns = user_ns->parent;

		if (old != user_ns) {
			bprm->mm->user_ns = get_user_ns(user_ns);
			put_user_ns(old);
		}
	}
1329 1330 1331
}
EXPORT_SYMBOL(would_dump);

1332 1333
void setup_new_exec(struct linux_binprm * bprm)
{
1334 1335 1336 1337 1338 1339 1340
	/*
	 * Once here, prepare_binrpm() will not be called any more, so
	 * the final state of setuid/setgid/fscaps can be merged into the
	 * secureexec flag.
	 */
	bprm->secureexec |= bprm->cap_elevated;

1341
	if (bprm->secureexec) {
1342 1343 1344
		/* Make sure parent cannot signal privileged process. */
		current->pdeath_signal = 0;

1345 1346 1347 1348 1349
		/*
		 * For secureexec, reset the stack limit to sane default to
		 * avoid bad behavior from the prior rlimits. This has to
		 * happen before arch_pick_mmap_layout(), which examines
		 * RLIMIT_STACK, but after the point of no return to avoid
1350
		 * needing to clean up the change on failure.
1351
		 */
K
Kees Cook 已提交
1352 1353
		if (bprm->rlim_stack.rlim_cur > _STK_LIM)
			bprm->rlim_stack.rlim_cur = _STK_LIM;
1354 1355
	}

K
Kees Cook 已提交
1356
	arch_pick_mmap_layout(current->mm, &bprm->rlim_stack);
L
Linus Torvalds 已提交
1357 1358 1359

	current->sas_ss_sp = current->sas_ss_size = 0;

1360 1361 1362 1363 1364
	/*
	 * Figure out dumpability. Note that this checking only of current
	 * is wrong, but userspace depends on it. This should be testing
	 * bprm->secureexec instead.
	 */
K
Kees Cook 已提交
1365
	if (bprm->interp_flags & BINPRM_FLAGS_ENFORCE_NONDUMP ||
1366 1367
	    !(uid_eq(current_euid(), current_uid()) &&
	      gid_eq(current_egid(), current_gid())))
1368
		set_dumpable(current->mm, suid_dumpable);
K
Kees Cook 已提交
1369 1370
	else
		set_dumpable(current->mm, SUID_DUMP_USER);
A
Alan Cox 已提交
1371

1372
	arch_setup_new_exec();
1373
	perf_event_exec();
1374
	__set_task_comm(current, kbasename(bprm->filename), true);
L
Linus Torvalds 已提交
1375

1376 1377 1378 1379 1380 1381
	/* Set the new mm task size. We have to do that late because it may
	 * depend on TIF_32BIT which is only updated in flush_thread() on
	 * some architectures like powerpc
	 */
	current->mm->task_size = TASK_SIZE;

L
Linus Torvalds 已提交
1382 1383 1384 1385 1386
	/* An exec changes our domain. We are no longer part of the thread
	   group */
	current->self_exec_id++;
	flush_signal_handlers(current, 0);
}
1387
EXPORT_SYMBOL(setup_new_exec);
L
Linus Torvalds 已提交
1388

1389 1390 1391
/* Runs immediately before start_thread() takes over. */
void finalize_exec(struct linux_binprm *bprm)
{
K
Kees Cook 已提交
1392 1393 1394 1395
	/* Store any stack rlimit changes before starting thread. */
	task_lock(current->group_leader);
	current->signal->rlim[RLIMIT_STACK] = bprm->rlim_stack;
	task_unlock(current->group_leader);
1396 1397 1398
}
EXPORT_SYMBOL(finalize_exec);

1399 1400 1401 1402 1403 1404 1405 1406
/*
 * Prepare credentials and lock ->cred_guard_mutex.
 * install_exec_creds() commits the new creds and drops the lock.
 * Or, if exec fails before, free_bprm() should release ->cred and
 * and unlock.
 */
int prepare_bprm_creds(struct linux_binprm *bprm)
{
1407
	if (mutex_lock_interruptible(&current->signal->cred_guard_mutex))
1408 1409 1410 1411 1412 1413
		return -ERESTARTNOINTR;

	bprm->cred = prepare_exec_creds();
	if (likely(bprm->cred))
		return 0;

1414
	mutex_unlock(&current->signal->cred_guard_mutex);
1415 1416 1417
	return -ENOMEM;
}

1418
static void free_bprm(struct linux_binprm *bprm)
1419 1420 1421
{
	free_arg_pages(bprm);
	if (bprm->cred) {
1422
		mutex_unlock(&current->signal->cred_guard_mutex);
1423 1424
		abort_creds(bprm->cred);
	}
1425 1426 1427 1428
	if (bprm->file) {
		allow_write_access(bprm->file);
		fput(bprm->file);
	}
1429 1430 1431
	/* If a binfmt changed the interp, free it. */
	if (bprm->interp != bprm->filename)
		kfree(bprm->interp);
1432 1433 1434
	kfree(bprm);
}

1435
int bprm_change_interp(const char *interp, struct linux_binprm *bprm)
1436 1437 1438 1439 1440 1441 1442 1443 1444 1445 1446
{
	/* If a binfmt changed the interp, free it first. */
	if (bprm->interp != bprm->filename)
		kfree(bprm->interp);
	bprm->interp = kstrdup(interp, GFP_KERNEL);
	if (!bprm->interp)
		return -ENOMEM;
	return 0;
}
EXPORT_SYMBOL(bprm_change_interp);

1447 1448 1449 1450 1451 1452 1453 1454 1455
/*
 * install the new credentials for this executable
 */
void install_exec_creds(struct linux_binprm *bprm)
{
	security_bprm_committing_creds(bprm);

	commit_creds(bprm->cred);
	bprm->cred = NULL;
1456 1457 1458 1459 1460 1461 1462 1463 1464

	/*
	 * Disable monitoring for regular users
	 * when executing setuid binaries. Must
	 * wait until new credentials are committed
	 * by commit_creds() above
	 */
	if (get_dumpable(current->mm) != SUID_DUMP_USER)
		perf_event_exit_task(current);
1465 1466
	/*
	 * cred_guard_mutex must be held at least to this point to prevent
1467
	 * ptrace_attach() from altering our determination of the task's
1468 1469
	 * credentials; any time after this it may be unlocked.
	 */
1470
	security_bprm_committed_creds(bprm);
1471
	mutex_unlock(&current->signal->cred_guard_mutex);
1472 1473 1474 1475 1476
}
EXPORT_SYMBOL(install_exec_creds);

/*
 * determine how safe it is to execute the proposed program
1477
 * - the caller must hold ->cred_guard_mutex to protect against
1478
 *   PTRACE_ATTACH or seccomp thread-sync
1479
 */
1480
static void check_unsafe_exec(struct linux_binprm *bprm)
1481
{
D
David Howells 已提交
1482
	struct task_struct *p = current, *t;
1483
	unsigned n_fs;
1484

1485 1486
	if (p->ptrace)
		bprm->unsafe |= LSM_UNSAFE_PTRACE;
1487

1488 1489 1490 1491
	/*
	 * This isn't strictly necessary, but it makes it harder for LSMs to
	 * mess up.
	 */
1492
	if (task_no_new_privs(current))
1493 1494
		bprm->unsafe |= LSM_UNSAFE_NO_NEW_PRIVS;

1495
	t = p;
D
David Howells 已提交
1496
	n_fs = 1;
N
Nick Piggin 已提交
1497
	spin_lock(&p->fs->lock);
1498
	rcu_read_lock();
1499
	while_each_thread(p, t) {
D
David Howells 已提交
1500 1501 1502
		if (t->fs == p->fs)
			n_fs++;
	}
1503
	rcu_read_unlock();
D
David Howells 已提交
1504

1505
	if (p->fs->users > n_fs)
1506
		bprm->unsafe |= LSM_UNSAFE_SHARE;
1507 1508
	else
		p->fs->in_exec = 1;
N
Nick Piggin 已提交
1509
	spin_unlock(&p->fs->lock);
1510 1511
}

1512 1513 1514 1515 1516 1517 1518
static void bprm_fill_uid(struct linux_binprm *bprm)
{
	struct inode *inode;
	unsigned int mode;
	kuid_t uid;
	kgid_t gid;

1519 1520 1521 1522 1523 1524
	/*
	 * Since this can be called multiple times (via prepare_binprm),
	 * we must clear any previous work done when setting set[ug]id
	 * bits from any earlier bprm->file uses (for example when run
	 * first for a setuid script then again for its interpreter).
	 */
1525 1526 1527
	bprm->cred->euid = current_euid();
	bprm->cred->egid = current_egid();

1528
	if (!mnt_may_suid(bprm->file->f_path.mnt))
1529 1530 1531 1532 1533
		return;

	if (task_no_new_privs(current))
		return;

1534
	inode = bprm->file->f_path.dentry->d_inode;
1535 1536 1537 1538 1539
	mode = READ_ONCE(inode->i_mode);
	if (!(mode & (S_ISUID|S_ISGID)))
		return;

	/* Be careful if suid/sgid is set */
A
Al Viro 已提交
1540
	inode_lock(inode);
1541 1542 1543 1544 1545

	/* reload atomically mode/uid/gid now that lock held */
	mode = inode->i_mode;
	uid = inode->i_uid;
	gid = inode->i_gid;
A
Al Viro 已提交
1546
	inode_unlock(inode);
1547 1548 1549 1550 1551 1552 1553 1554 1555 1556 1557 1558 1559 1560 1561 1562 1563

	/* We ignore suid/sgid if there are no mappings for them in the ns */
	if (!kuid_has_mapping(bprm->cred->user_ns, uid) ||
		 !kgid_has_mapping(bprm->cred->user_ns, gid))
		return;

	if (mode & S_ISUID) {
		bprm->per_clear |= PER_CLEAR_ON_SETID;
		bprm->cred->euid = uid;
	}

	if ((mode & (S_ISGID | S_IXGRP)) == (S_ISGID | S_IXGRP)) {
		bprm->per_clear |= PER_CLEAR_ON_SETID;
		bprm->cred->egid = gid;
	}
}

1564 1565
/*
 * Fill the binprm structure from the inode.
L
Linus Torvalds 已提交
1566
 * Check permissions, then read the first 128 (BINPRM_BUF_SIZE) bytes
1567 1568
 *
 * This may be called multiple times for binary chains (scripts for example).
L
Linus Torvalds 已提交
1569 1570 1571 1572
 */
int prepare_binprm(struct linux_binprm *bprm)
{
	int retval;
1573
	loff_t pos = 0;
L
Linus Torvalds 已提交
1574

1575
	bprm_fill_uid(bprm);
L
Linus Torvalds 已提交
1576 1577

	/* fill in binprm security blob */
1578
	retval = security_bprm_set_creds(bprm);
L
Linus Torvalds 已提交
1579 1580
	if (retval)
		return retval;
1581
	bprm->called_set_creds = 1;
L
Linus Torvalds 已提交
1582

1583
	memset(bprm->buf, 0, BINPRM_BUF_SIZE);
1584
	return kernel_read(bprm->file, bprm->buf, BINPRM_BUF_SIZE, &pos);
L
Linus Torvalds 已提交
1585 1586 1587 1588
}

EXPORT_SYMBOL(prepare_binprm);

N
Nick Piggin 已提交
1589 1590 1591 1592 1593
/*
 * Arguments are '\0' separated strings found at the location bprm->p
 * points to; chop off the first by relocating brpm->p to right after
 * the first '\0' encountered.
 */
1594
int remove_arg_zero(struct linux_binprm *bprm)
L
Linus Torvalds 已提交
1595
{
1596 1597 1598 1599
	int ret = 0;
	unsigned long offset;
	char *kaddr;
	struct page *page;
N
Nick Piggin 已提交
1600

1601 1602
	if (!bprm->argc)
		return 0;
L
Linus Torvalds 已提交
1603

1604 1605 1606 1607 1608 1609 1610
	do {
		offset = bprm->p & ~PAGE_MASK;
		page = get_arg_page(bprm, bprm->p, 0);
		if (!page) {
			ret = -EFAULT;
			goto out;
		}
1611
		kaddr = kmap_atomic(page);
N
Nick Piggin 已提交
1612

1613 1614 1615
		for (; offset < PAGE_SIZE && kaddr[offset];
				offset++, bprm->p++)
			;
N
Nick Piggin 已提交
1616

1617
		kunmap_atomic(kaddr);
1618 1619
		put_arg_page(page);
	} while (offset == PAGE_SIZE);
N
Nick Piggin 已提交
1620

1621 1622 1623
	bprm->p++;
	bprm->argc--;
	ret = 0;
N
Nick Piggin 已提交
1624

1625 1626
out:
	return ret;
L
Linus Torvalds 已提交
1627 1628 1629
}
EXPORT_SYMBOL(remove_arg_zero);

1630
#define printable(c) (((c)=='\t') || ((c)=='\n') || (0x20<=(c) && (c)<=0x7e))
L
Linus Torvalds 已提交
1631 1632 1633
/*
 * cycle the list of binary formats handler, until one recognizes the image
 */
1634
int search_binary_handler(struct linux_binprm *bprm)
L
Linus Torvalds 已提交
1635
{
1636
	bool need_retry = IS_ENABLED(CONFIG_MODULES);
L
Linus Torvalds 已提交
1637
	struct linux_binfmt *fmt;
1638
	int retval;
L
Linus Torvalds 已提交
1639

1640
	/* This allows 4 levels of binfmt rewrites before failing hard. */
1641
	if (bprm->recursion_depth > 5)
1642 1643
		return -ELOOP;

L
Linus Torvalds 已提交
1644 1645 1646 1647 1648
	retval = security_bprm_check(bprm);
	if (retval)
		return retval;

	retval = -ENOENT;
1649 1650 1651 1652 1653 1654 1655 1656
 retry:
	read_lock(&binfmt_lock);
	list_for_each_entry(fmt, &formats, lh) {
		if (!try_module_get(fmt->module))
			continue;
		read_unlock(&binfmt_lock);
		bprm->recursion_depth++;
		retval = fmt->load_binary(bprm);
1657 1658
		read_lock(&binfmt_lock);
		put_binfmt(fmt);
1659
		bprm->recursion_depth--;
1660 1661 1662 1663 1664 1665 1666 1667
		if (retval < 0 && !bprm->mm) {
			/* we got to flush_old_exec() and failed after it */
			read_unlock(&binfmt_lock);
			force_sigsegv(SIGSEGV, current);
			return retval;
		}
		if (retval != -ENOEXEC || !bprm->file) {
			read_unlock(&binfmt_lock);
1668
			return retval;
L
Linus Torvalds 已提交
1669 1670
		}
	}
1671 1672
	read_unlock(&binfmt_lock);

1673
	if (need_retry) {
1674 1675 1676
		if (printable(bprm->buf[0]) && printable(bprm->buf[1]) &&
		    printable(bprm->buf[2]) && printable(bprm->buf[3]))
			return retval;
1677 1678
		if (request_module("binfmt-%04x", *(ushort *)(bprm->buf + 2)) < 0)
			return retval;
1679 1680 1681 1682
		need_retry = false;
		goto retry;
	}

L
Linus Torvalds 已提交
1683 1684 1685 1686
	return retval;
}
EXPORT_SYMBOL(search_binary_handler);

1687 1688 1689 1690 1691 1692 1693 1694 1695 1696 1697 1698 1699
static int exec_binprm(struct linux_binprm *bprm)
{
	pid_t old_pid, old_vpid;
	int ret;

	/* Need to fetch pid before load_binary changes it */
	old_pid = current->pid;
	rcu_read_lock();
	old_vpid = task_pid_nr_ns(current, task_active_pid_ns(current->parent));
	rcu_read_unlock();

	ret = search_binary_handler(bprm);
	if (ret >= 0) {
1700
		audit_bprm(bprm);
1701 1702
		trace_sched_process_exec(current, old_pid, bprm);
		ptrace_event(PTRACE_EVENT_EXEC, old_vpid);
1703
		proc_exec_connector(current);
1704 1705 1706 1707 1708
	}

	return ret;
}

L
Linus Torvalds 已提交
1709 1710 1711
/*
 * sys_execve() executes a new program.
 */
1712 1713 1714 1715
static int __do_execve_file(int fd, struct filename *filename,
			    struct user_arg_ptr argv,
			    struct user_arg_ptr envp,
			    int flags, struct file *file)
L
Linus Torvalds 已提交
1716
{
1717
	char *pathbuf = NULL;
L
Linus Torvalds 已提交
1718
	struct linux_binprm *bprm;
1719
	struct files_struct *displaced;
L
Linus Torvalds 已提交
1720
	int retval;
1721

1722 1723 1724
	if (IS_ERR(filename))
		return PTR_ERR(filename);

1725 1726 1727 1728 1729 1730 1731
	/*
	 * We move the actual failure in case of RLIMIT_NPROC excess from
	 * set*uid() to execve() because too many poorly written programs
	 * don't check setuid() return code.  Here we additionally recheck
	 * whether NPROC limit is still exceeded.
	 */
	if ((current->flags & PF_NPROC_EXCEEDED) &&
1732
	    atomic_read(&current_user()->processes) > rlimit(RLIMIT_NPROC)) {
1733 1734 1735 1736 1737 1738 1739
		retval = -EAGAIN;
		goto out_ret;
	}

	/* We're below the limit (still or again), so we don't want to make
	 * further execve() calls fail. */
	current->flags &= ~PF_NPROC_EXCEEDED;
L
Linus Torvalds 已提交
1740

1741
	retval = unshare_files(&displaced);
1742 1743 1744
	if (retval)
		goto out_ret;

L
Linus Torvalds 已提交
1745
	retval = -ENOMEM;
1746
	bprm = kzalloc(sizeof(*bprm), GFP_KERNEL);
L
Linus Torvalds 已提交
1747
	if (!bprm)
1748
		goto out_files;
L
Linus Torvalds 已提交
1749

1750 1751
	retval = prepare_bprm_creds(bprm);
	if (retval)
1752
		goto out_free;
A
Al Viro 已提交
1753

1754
	check_unsafe_exec(bprm);
1755
	current->in_execve = 1;
1756

1757 1758
	if (!file)
		file = do_open_execat(fd, filename, flags);
L
Linus Torvalds 已提交
1759 1760
	retval = PTR_ERR(file);
	if (IS_ERR(file))
A
Al Viro 已提交
1761
		goto out_unmark;
L
Linus Torvalds 已提交
1762 1763 1764 1765

	sched_exec();

	bprm->file = file;
1766 1767 1768
	if (!filename) {
		bprm->filename = "none";
	} else if (fd == AT_FDCWD || filename->name[0] == '/') {
1769 1770 1771
		bprm->filename = filename->name;
	} else {
		if (filename->name[0] == '\0')
1772
			pathbuf = kasprintf(GFP_KERNEL, "/dev/fd/%d", fd);
1773
		else
1774
			pathbuf = kasprintf(GFP_KERNEL, "/dev/fd/%d/%s",
1775 1776 1777 1778 1779 1780 1781 1782 1783 1784 1785 1786 1787 1788 1789
					    fd, filename->name);
		if (!pathbuf) {
			retval = -ENOMEM;
			goto out_unmark;
		}
		/*
		 * Record that a name derived from an O_CLOEXEC fd will be
		 * inaccessible after exec. Relies on having exclusive access to
		 * current->files (due to unshare_files above).
		 */
		if (close_on_exec(fd, rcu_dereference_raw(current->files->fdt)))
			bprm->interp_flags |= BINPRM_FLAGS_PATH_INACCESSIBLE;
		bprm->filename = pathbuf;
	}
	bprm->interp = bprm->filename;
L
Linus Torvalds 已提交
1790

1791 1792
	retval = bprm_mm_init(bprm);
	if (retval)
1793
		goto out_unmark;
L
Linus Torvalds 已提交
1794

1795 1796
	retval = prepare_arg_pages(bprm, argv, envp);
	if (retval < 0)
L
Linus Torvalds 已提交
1797 1798 1799 1800 1801 1802 1803 1804 1805 1806 1807 1808 1809 1810 1811 1812 1813 1814 1815
		goto out;

	retval = prepare_binprm(bprm);
	if (retval < 0)
		goto out;

	retval = copy_strings_kernel(1, &bprm->filename, bprm);
	if (retval < 0)
		goto out;

	bprm->exec = bprm->p;
	retval = copy_strings(bprm->envc, envp, bprm);
	if (retval < 0)
		goto out;

	retval = copy_strings(bprm->argc, argv, bprm);
	if (retval < 0)
		goto out;

1816 1817
	would_dump(bprm, bprm->file);

1818
	retval = exec_binprm(bprm);
1819 1820
	if (retval < 0)
		goto out;
L
Linus Torvalds 已提交
1821

1822
	/* execve succeeded */
A
Al Viro 已提交
1823
	current->fs->in_exec = 0;
1824
	current->in_execve = 0;
1825
	membarrier_execve(current);
1826
	rseq_execve(current);
1827
	acct_update_integrals(current);
1828
	task_numa_free(current);
1829
	free_bprm(bprm);
1830
	kfree(pathbuf);
1831 1832
	if (filename)
		putname(filename);
1833 1834 1835
	if (displaced)
		put_files_struct(displaced);
	return retval;
L
Linus Torvalds 已提交
1836

1837
out:
1838 1839 1840 1841
	if (bprm->mm) {
		acct_arg_size(bprm, 0);
		mmput(bprm->mm);
	}
L
Linus Torvalds 已提交
1842

A
Al Viro 已提交
1843
out_unmark:
1844
	current->fs->in_exec = 0;
1845
	current->in_execve = 0;
1846 1847

out_free:
1848
	free_bprm(bprm);
1849
	kfree(pathbuf);
L
Linus Torvalds 已提交
1850

1851
out_files:
1852 1853
	if (displaced)
		reset_files_struct(displaced);
L
Linus Torvalds 已提交
1854
out_ret:
1855 1856
	if (filename)
		putname(filename);
L
Linus Torvalds 已提交
1857 1858 1859
	return retval;
}

1860 1861 1862 1863 1864 1865 1866 1867 1868 1869 1870 1871 1872 1873 1874 1875
static int do_execveat_common(int fd, struct filename *filename,
			      struct user_arg_ptr argv,
			      struct user_arg_ptr envp,
			      int flags)
{
	return __do_execve_file(fd, filename, argv, envp, flags, NULL);
}

int do_execve_file(struct file *file, void *__argv, void *__envp)
{
	struct user_arg_ptr argv = { .ptr.native = __argv };
	struct user_arg_ptr envp = { .ptr.native = __envp };

	return __do_execve_file(AT_FDCWD, NULL, argv, envp, 0, file);
}

1876
int do_execve(struct filename *filename,
1877
	const char __user *const __user *__argv,
1878
	const char __user *const __user *__envp)
1879
{
1880 1881
	struct user_arg_ptr argv = { .ptr.native = __argv };
	struct user_arg_ptr envp = { .ptr.native = __envp };
1882 1883 1884 1885 1886 1887 1888 1889 1890 1891 1892 1893
	return do_execveat_common(AT_FDCWD, filename, argv, envp, 0);
}

int do_execveat(int fd, struct filename *filename,
		const char __user *const __user *__argv,
		const char __user *const __user *__envp,
		int flags)
{
	struct user_arg_ptr argv = { .ptr.native = __argv };
	struct user_arg_ptr envp = { .ptr.native = __envp };

	return do_execveat_common(fd, filename, argv, envp, flags);
1894 1895 1896
}

#ifdef CONFIG_COMPAT
1897
static int compat_do_execve(struct filename *filename,
A
Al Viro 已提交
1898
	const compat_uptr_t __user *__argv,
1899
	const compat_uptr_t __user *__envp)
1900 1901 1902 1903 1904 1905 1906 1907 1908
{
	struct user_arg_ptr argv = {
		.is_compat = true,
		.ptr.compat = __argv,
	};
	struct user_arg_ptr envp = {
		.is_compat = true,
		.ptr.compat = __envp,
	};
1909 1910 1911 1912 1913 1914 1915 1916 1917 1918 1919 1920 1921 1922 1923 1924 1925
	return do_execveat_common(AT_FDCWD, filename, argv, envp, 0);
}

static int compat_do_execveat(int fd, struct filename *filename,
			      const compat_uptr_t __user *__argv,
			      const compat_uptr_t __user *__envp,
			      int flags)
{
	struct user_arg_ptr argv = {
		.is_compat = true,
		.ptr.compat = __argv,
	};
	struct user_arg_ptr envp = {
		.is_compat = true,
		.ptr.compat = __envp,
	};
	return do_execveat_common(fd, filename, argv, envp, flags);
1926
}
1927
#endif
1928

1929
void set_binfmt(struct linux_binfmt *new)
L
Linus Torvalds 已提交
1930
{
1931 1932 1933 1934
	struct mm_struct *mm = current->mm;

	if (mm->binfmt)
		module_put(mm->binfmt->module);
L
Linus Torvalds 已提交
1935

1936
	mm->binfmt = new;
1937 1938
	if (new)
		__module_get(new->module);
L
Linus Torvalds 已提交
1939 1940 1941
}
EXPORT_SYMBOL(set_binfmt);

1942
/*
1943
 * set_dumpable stores three-value SUID_DUMP_* into mm->flags.
1944 1945 1946
 */
void set_dumpable(struct mm_struct *mm, int value)
{
1947 1948
	unsigned long old, new;

1949 1950 1951
	if (WARN_ON((unsigned)value > SUID_DUMP_ROOT))
		return;

1952
	do {
1953
		old = READ_ONCE(mm->flags);
1954
		new = (old & ~MMF_DUMPABLE_MASK) | value;
1955
	} while (cmpxchg(&mm->flags, old, new) != old);
1956 1957
}

A
Al Viro 已提交
1958 1959 1960 1961 1962
SYSCALL_DEFINE3(execve,
		const char __user *, filename,
		const char __user *const __user *, argv,
		const char __user *const __user *, envp)
{
1963
	return do_execve(getname(filename), argv, envp);
A
Al Viro 已提交
1964
}
1965 1966 1967 1968 1969 1970 1971 1972 1973 1974 1975 1976 1977 1978

SYSCALL_DEFINE5(execveat,
		int, fd, const char __user *, filename,
		const char __user *const __user *, argv,
		const char __user *const __user *, envp,
		int, flags)
{
	int lookup_flags = (flags & AT_EMPTY_PATH) ? LOOKUP_EMPTY : 0;

	return do_execveat(fd,
			   getname_flags(filename, lookup_flags, NULL),
			   argv, envp, flags);
}

A
Al Viro 已提交
1979
#ifdef CONFIG_COMPAT
1980 1981 1982
COMPAT_SYSCALL_DEFINE3(execve, const char __user *, filename,
	const compat_uptr_t __user *, argv,
	const compat_uptr_t __user *, envp)
A
Al Viro 已提交
1983
{
1984
	return compat_do_execve(getname(filename), argv, envp);
A
Al Viro 已提交
1985
}
1986 1987 1988 1989 1990 1991 1992 1993 1994 1995 1996 1997 1998

COMPAT_SYSCALL_DEFINE5(execveat, int, fd,
		       const char __user *, filename,
		       const compat_uptr_t __user *, argv,
		       const compat_uptr_t __user *, envp,
		       int,  flags)
{
	int lookup_flags = (flags & AT_EMPTY_PATH) ? LOOKUP_EMPTY : 0;

	return compat_do_execveat(fd,
				  getname_flags(filename, lookup_flags, NULL),
				  argv, envp, flags);
}
A
Al Viro 已提交
1999
#endif