Re: [patch] remove MNT_NOEXEC check for PROT_EXEC mmaps

From: Stas Sergeev
Date: Sun Sep 24 2006 - 13:03:19 EST


Ulrich Drepper wrote:
The consensus has been to add the same checks to mprotect. They were
not left out intentionally.
I know, and as long as the mmap have these checks,
that would be at least consistent.
But could you please explain what does that solve
*besides* the problem, which looks like the
user-space problem to me? I tried my best to express
the negative sides of that approach, but what are
the positive ones?
If that approach forces people to avoid using "noexec"
where they previously used it for good, then I'd even
call it a regression.

