yann@1625: With latest versions of glibc, a lot of apps failed on a PaX enabled yann@1625: system with: yann@1625: cannot enable executable stack as shared object requires: Permission denied yann@1625: yann@1625: This is due to PaX 'exec-protecting' the stack, and ld.so then trying yann@1625: to make the stack executable due to some libraries not containing the yann@1625: PT_GNU_STACK section. Bug #32960. (12 Nov 2003). yann@1625: yann@1625: Patch also NPTL. Bug #116086. (20 Dec 2005). yann@1625: yann@1625: diff -durN glibc-2.10.1.orig/nptl/allocatestack.c glibc-2.10.1/nptl/allocatestack.c yann@1625: --- glibc-2.10.1.orig/nptl/allocatestack.c 2009-01-29 21:34:16.000000000 +0100 yann@1625: +++ glibc-2.10.1/nptl/allocatestack.c 2009-11-13 00:50:33.000000000 +0100 yann@1625: @@ -326,7 +326,8 @@ yann@1625: # error "Define either _STACK_GROWS_DOWN or _STACK_GROWS_UP" yann@1625: #endif yann@1625: if (mprotect (stack, len, PROT_READ | PROT_WRITE | PROT_EXEC) != 0) yann@1625: - return errno; yann@1625: + if (errno != EACCES) /* PAX is enabled */ yann@1625: + return errno; yann@1625: yann@1625: return 0; yann@1625: } yann@1625: diff -durN glibc-2.10.1.orig/sysdeps/unix/sysv/linux/dl-execstack.c glibc-2.10.1/sysdeps/unix/sysv/linux/dl-execstack.c yann@1625: --- glibc-2.10.1.orig/sysdeps/unix/sysv/linux/dl-execstack.c 2006-01-08 09:21:15.000000000 +0100 yann@1625: +++ glibc-2.10.1/sysdeps/unix/sysv/linux/dl-execstack.c 2009-11-13 00:50:33.000000000 +0100 yann@1625: @@ -63,7 +63,10 @@ yann@1625: else yann@1625: # endif yann@1625: { yann@1625: - result = errno; yann@1625: + if (errno == EACCES) /* PAX is enabled */ yann@1625: + result = 0; yann@1625: + else yann@1625: + result = errno; yann@1625: goto out; yann@1625: } yann@1625: } yann@1625: @@ -89,7 +92,12 @@ yann@1625: page -= size; yann@1625: else yann@1625: { yann@1625: - if (errno != ENOMEM) /* Unexpected failure mode. */ yann@1625: + if (errno == EACCES) /* PAX is enabled */ yann@1625: + { yann@1625: + result = 0; yann@1625: + goto out; yann@1625: + } yann@1625: + else if (errno != ENOMEM) /* Unexpected failure mode. */ yann@1625: { yann@1625: result = errno; yann@1625: goto out; yann@1625: @@ -115,7 +123,12 @@ yann@1625: page += size; yann@1625: else yann@1625: { yann@1625: - if (errno != ENOMEM) /* Unexpected failure mode. */ yann@1625: + if (errno == EACCES) /* PAX is enabled */ yann@1625: + { yann@1625: + result = 0; yann@1625: + goto out; yann@1625: + } yann@1625: + else if (errno != ENOMEM) /* Unexpected failure mode. */ yann@1625: { yann@1625: result = errno; yann@1625: goto out;