[LibOS] Fix execve() corner cases

- Return EACCES if the file has no execute permission
- Return ENOEXEC if the file is not recognized as either ELF or
  shebang script
This commit is contained in:
Paweł Marczewski
2020-11-12 11:55:52 +01:00
parent 7ef9601501
commit ebe7715d3a
2 changed files with 21 additions and 20 deletions
+21 -12
View File
@@ -251,6 +251,11 @@ reopen:
__kernel_mode_t mode;
if ((ret = fs->d_ops->mode(dent, &mode)) < 0)
goto err;
/* Check if the file is executable. Currently just looks at the user bit. */
if (!(mode & S_IXUSR)) {
ret = -EACCES;
goto err;
}
}
struct shim_handle* exec = NULL;
@@ -331,20 +336,24 @@ reopen:
}
} while (!ended);
if (started) {
if (next) {
INIT_LIST_HEAD(next, list);
LISTP_ADD_TAIL(next, &new_shargs, list);
}
struct sharg* first = LISTP_FIRST_ENTRY(&new_shargs, struct sharg, list);
assert(first);
debug("detected as script: run by %s\n", first->arg);
file = first->arg;
LISTP_SPLICE(&new_shargs, &shargs, list, sharg);
if (!started) {
debug("file not recognized as ELF or shebang");
put_handle(exec);
goto reopen;
return -ENOEXEC;
}
if (next) {
INIT_LIST_HEAD(next, list);
LISTP_ADD_TAIL(next, &new_shargs, list);
}
struct sharg* first = LISTP_FIRST_ENTRY(&new_shargs, struct sharg, list);
assert(first);
debug("detected as script: run by %s\n", first->arg);
file = first->arg;
LISTP_SPLICE(&new_shargs, &shargs, list, sharg);
put_handle(exec);
goto reopen;
}
/* If `execve` is invoked concurrently by multiple threads, let only one succeed. */
-8
View File
@@ -265,14 +265,6 @@ skip = yes
[execve02]
skip = yes
# 5. exec on a "fake" file with no execute permission, Graphene tries to execute it anyway
[execve03]
must-pass =
1
2
3
4
# copy child
[execve04]
skip = yes