This looks to me like you're copying the contents of an ELF binary from userspace memory into a kernel keyring, and then immediately copying it back from the kernel keyring to userspace memory, followed by userland exec the usual way. What's the point of the keyring steps, rather than just doing userland exec alone?
The keyring separates staging from execution, payload can be written by a different process at a different time with no file, no memfd, no open fd in /proc/pid/fd, by the time the loader runs, the payload only exists in kernel memory, direct userland exec still needs to read from somewhere visible
3 comments