Fix Python availability claim: included in ESXi 6.x+, not all versions

This commit is contained in:
NK
2026-03-25 00:54:33 +01:00
parent 3ed50ef292
commit f3b4c2269a
2 changed files with 2 additions and 2 deletions
+1 -1
View File
@@ -23,7 +23,7 @@ esxcli system settings advanced set -o /User/execInstalledOnly -i 0
When `execInstalledOnly` is set to 1 (default on ESXi 7.0+), unsigned binaries cannot be executed directly. The included Python loader (`tools/vmkatz_loader.py`, bundled in the ESXi release archive) bypasses this by loading vmkatz into anonymous memory pages — ESXi allows `PROT_EXEC` on anonymous mappings while blocking `execve` on unsigned files.
Python is VIB-signed on all ESXi versions and can execute normally.
Python is included in ESXi 6.x and later (used internally by VMware hostd/CIM providers) and can execute normally regardless of VIB settings.
```bash
# Upload both files
+1 -1
View File
@@ -6,7 +6,7 @@ Bypasses execInstalledOnly (VIB protection) by loading the vmkatz static
binary into anonymous mmap pages with PROT_EXEC. ESXi VMkernel allows
PROT_EXEC on anonymous mappings but blocks execve on unsigned binaries.
Python is VIB-signed on ESXi, so it can execute normally.
Python is included in ESXi 6.x+ and executes regardless of VIB settings.
We parse the ELF, map segments, apply relocations, build a proper
initial stack (argc/argv/envp/auxv), and jump to _start.