xref: /freebsd/lib/libsys/mprotect.2 (revision 8269e7673cf033aba67dab8264fe719920c70f87)
1*8269e767SBrooks Davis.\" Copyright (c) 1991, 1993
2*8269e767SBrooks Davis.\"	The Regents of the University of California.  All rights reserved.
3*8269e767SBrooks Davis.\"
4*8269e767SBrooks Davis.\" Redistribution and use in source and binary forms, with or without
5*8269e767SBrooks Davis.\" modification, are permitted provided that the following conditions
6*8269e767SBrooks Davis.\" are met:
7*8269e767SBrooks Davis.\" 1. Redistributions of source code must retain the above copyright
8*8269e767SBrooks Davis.\"    notice, this list of conditions and the following disclaimer.
9*8269e767SBrooks Davis.\" 2. Redistributions in binary form must reproduce the above copyright
10*8269e767SBrooks Davis.\"    notice, this list of conditions and the following disclaimer in the
11*8269e767SBrooks Davis.\"    documentation and/or other materials provided with the distribution.
12*8269e767SBrooks Davis.\" 3. Neither the name of the University nor the names of its contributors
13*8269e767SBrooks Davis.\"    may be used to endorse or promote products derived from this software
14*8269e767SBrooks Davis.\"    without specific prior written permission.
15*8269e767SBrooks Davis.\"
16*8269e767SBrooks Davis.\" THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
17*8269e767SBrooks Davis.\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
18*8269e767SBrooks Davis.\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
19*8269e767SBrooks Davis.\" ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
20*8269e767SBrooks Davis.\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
21*8269e767SBrooks Davis.\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
22*8269e767SBrooks Davis.\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
23*8269e767SBrooks Davis.\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
24*8269e767SBrooks Davis.\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
25*8269e767SBrooks Davis.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26*8269e767SBrooks Davis.\" SUCH DAMAGE.
27*8269e767SBrooks Davis.\"
28*8269e767SBrooks Davis.Dd September 7, 2021
29*8269e767SBrooks Davis.Dt MPROTECT 2
30*8269e767SBrooks Davis.Os
31*8269e767SBrooks Davis.Sh NAME
32*8269e767SBrooks Davis.Nm mprotect
33*8269e767SBrooks Davis.Nd control the protection of pages
34*8269e767SBrooks Davis.Sh LIBRARY
35*8269e767SBrooks Davis.Lb libc
36*8269e767SBrooks Davis.Sh SYNOPSIS
37*8269e767SBrooks Davis.In sys/mman.h
38*8269e767SBrooks Davis.Ft int
39*8269e767SBrooks Davis.Fn mprotect "void *addr" "size_t len" "int prot"
40*8269e767SBrooks Davis.Sh DESCRIPTION
41*8269e767SBrooks DavisThe
42*8269e767SBrooks Davis.Fn mprotect
43*8269e767SBrooks Davissystem call
44*8269e767SBrooks Davischanges the specified pages to have protection
45*8269e767SBrooks Davis.Fa prot .
46*8269e767SBrooks Davis.Pp
47*8269e767SBrooks DavisThe
48*8269e767SBrooks Davis.Fa prot
49*8269e767SBrooks Davisargument shall be
50*8269e767SBrooks Davis.Dv PROT_NONE
51*8269e767SBrooks Davis(no permissions at all)
52*8269e767SBrooks Davisor the bitwise
53*8269e767SBrooks Davis.Em or
54*8269e767SBrooks Davisof one or more of the following values:
55*8269e767SBrooks Davis.Pp
56*8269e767SBrooks Davis.Bl -tag -width ".Dv PROT_WRITE" -compact
57*8269e767SBrooks Davis.It Dv PROT_READ
58*8269e767SBrooks DavisThe pages can be read.
59*8269e767SBrooks Davis.It Dv PROT_WRITE
60*8269e767SBrooks DavisThe pages can be written.
61*8269e767SBrooks Davis.It Dv PROT_EXEC
62*8269e767SBrooks DavisThe pages can be executed.
63*8269e767SBrooks Davis.El
64*8269e767SBrooks Davis.Pp
65*8269e767SBrooks DavisIn addition to these standard protection flags,
66*8269e767SBrooks Davisthe
67*8269e767SBrooks Davis.Fx
68*8269e767SBrooks Davisimplementation of
69*8269e767SBrooks Davis.Fn mprotect
70*8269e767SBrooks Davisprovides the ability to set the maximum protection of a region
71*8269e767SBrooks Davis(which prevents
72*8269e767SBrooks Davis.Nm
73*8269e767SBrooks Davisfrom adding to the permissions later).
74*8269e767SBrooks DavisThis is accomplished by bitwise
75*8269e767SBrooks Davis.Em or Ns 'ing
76*8269e767SBrooks Davisone or more
77*8269e767SBrooks Davis.Dv PROT_
78*8269e767SBrooks Davisvalues wrapped in the
79*8269e767SBrooks Davis.Dv PROT_MAX()
80*8269e767SBrooks Davismacro into the
81*8269e767SBrooks Davis.Fa prot
82*8269e767SBrooks Davisargument.
83*8269e767SBrooks Davis.Sh RETURN VALUES
84*8269e767SBrooks Davis.Rv -std mprotect
85*8269e767SBrooks Davis.Sh ERRORS
86*8269e767SBrooks DavisThe
87*8269e767SBrooks Davis.Fn mprotect
88*8269e767SBrooks Davissystem call will fail if:
89*8269e767SBrooks Davis.Bl -tag -width Er
90*8269e767SBrooks Davis.It Bq Er EACCES
91*8269e767SBrooks DavisThe calling process was not allowed to change
92*8269e767SBrooks Davisthe protection to the value specified by
93*8269e767SBrooks Davisthe
94*8269e767SBrooks Davis.Fa prot
95*8269e767SBrooks Davisargument.
96*8269e767SBrooks Davis.It Bq Er EINVAL
97*8269e767SBrooks DavisThe virtual address range specified by the
98*8269e767SBrooks Davis.Fa addr
99*8269e767SBrooks Davisand
100*8269e767SBrooks Davis.Fa len
101*8269e767SBrooks Davisarguments is not valid.
102*8269e767SBrooks Davis.It Bq Er EINVAL
103*8269e767SBrooks DavisThe
104*8269e767SBrooks Davis.Fa prot
105*8269e767SBrooks Davisargument contains unhandled bits.
106*8269e767SBrooks Davis.It Bq Er ENOTSUP
107*8269e767SBrooks DavisThe
108*8269e767SBrooks Davis.Fa prot
109*8269e767SBrooks Davisargument contains permissions which are not a subset of the specified
110*8269e767SBrooks Davismaximum permissions.
111*8269e767SBrooks Davis.El
112*8269e767SBrooks Davis.Sh SEE ALSO
113*8269e767SBrooks Davis.Xr madvise 2 ,
114*8269e767SBrooks Davis.Xr mincore 2 ,
115*8269e767SBrooks Davis.Xr msync 2 ,
116*8269e767SBrooks Davis.Xr munmap 2
117*8269e767SBrooks Davis.Sh HISTORY
118*8269e767SBrooks DavisThe
119*8269e767SBrooks Davis.Fn mprotect
120*8269e767SBrooks Davissystem call was first documented in
121*8269e767SBrooks Davis.Bx 4.2
122*8269e767SBrooks Davisand first appeared in
123*8269e767SBrooks Davis.Bx 4.4 .
124*8269e767SBrooks Davis.Pp
125*8269e767SBrooks DavisThe
126*8269e767SBrooks Davis.Dv PROT_MAX
127*8269e767SBrooks Davisfunctionality was introduced in
128*8269e767SBrooks Davis.Fx 13 .
129