sem_open: Avoid uninitialized result for non-existent files (RHEL-119392)

Resolves: RHEL-119392
This commit is contained in:
Frédéric Bérat 2025-10-07 11:19:51 +02:00
parent ac4d98ccf5
commit fd242e7aae
2 changed files with 126 additions and 0 deletions

84
glibc-RHEL-119392-1.patch Normal file
View File

@ -0,0 +1,84 @@
commit f745d78e2628cd5b13ca119ae0c0e21d08ad1906
Author: Joseph Myers <josmyers@redhat.com>
Date: Fri Nov 8 01:53:48 2024 +0000
Avoid uninitialized result in sem_open when file does not exist
A static analyzer apparently reported an uninitialized use of the
variable result in sem_open in the case where the file is required to
exist but does not exist.
The report appears to be correct; set result to SEM_FAILED in that
case, and add a test for it.
Note: the test passes for me even without the sem_open fix, I guess
because result happens to get value SEM_FAILED (i.e. 0) when
uninitialized.
Tested for x86_64.
diff --git a/sysdeps/pthread/Makefile b/sysdeps/pthread/Makefile
index 0d9e232acec2ed39..449478a847ad2292 100644
--- a/sysdeps/pthread/Makefile
+++ b/sysdeps/pthread/Makefile
@@ -256,6 +256,7 @@ tests += \
tst-sem14 \
tst-sem15 \
tst-sem16 \
+ tst-sem17 \
tst-setuid3 \
tst-signal1 \
tst-signal2 \
diff --git a/sysdeps/pthread/sem_open.c b/sysdeps/pthread/sem_open.c
index e41236157a5d1b0a..dab734191a8ca208 100644
--- a/sysdeps/pthread/sem_open.c
+++ b/sysdeps/pthread/sem_open.c
@@ -76,6 +76,7 @@ __sem_open (const char *name, int oflag, ...)
goto try_create;
/* Return. errno is already set. */
+ result = SEM_FAILED;
}
else
/* Check whether we already have this semaphore mapped and
diff --git a/sysdeps/pthread/tst-sem17.c b/sysdeps/pthread/tst-sem17.c
new file mode 100644
index 0000000000000000..c3f05d196f4ef17a
--- /dev/null
+++ b/sysdeps/pthread/tst-sem17.c
@@ -0,0 +1,35 @@
+/* Test sem_open with missing file.
+ Copyright (C) 2024 Free Software Foundation, Inc.
+ This file is part of the GNU C Library.
+
+ The GNU C Library is free software; you can redistribute it and/or
+ modify it under the terms of the GNU Lesser General Public
+ License as published by the Free Software Foundation; either
+ version 2.1 of the License, or (at your option) any later version.
+
+ The GNU C Library is distributed in the hope that it will be useful,
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+ Lesser General Public License for more details.
+
+ You should have received a copy of the GNU Lesser General Public
+ License along with the GNU C Library; if not, see
+ <https://www.gnu.org/licenses/>. */
+
+#include <errno.h>
+#include <semaphore.h>
+
+#include <support/check.h>
+
+int
+do_test (void)
+{
+ sem_unlink ("/glibc-tst-sem17");
+ errno = 0;
+ sem_t *s = sem_open ("/glibc-tst-sem17", 0);
+ TEST_VERIFY (s == SEM_FAILED);
+ TEST_COMPARE (errno, ENOENT);
+ return 0;
+}
+
+#include <support/test-driver.c>

42
glibc-RHEL-119392-2.patch Normal file
View File

@ -0,0 +1,42 @@
commit c7dcf594f4c52fa7e2cc76918c8aa9abb98e9625
Author: Joseph Myers <josmyers@redhat.com>
Date: Fri Nov 8 17:08:09 2024 +0000
Rename new tst-sem17 test to tst-sem18
As noted by Adhemerval, we already have a tst-sem17 in nptl.
Tested for x86_64.
diff --git a/sysdeps/pthread/Makefile b/sysdeps/pthread/Makefile
index 449478a847ad2292..aef323296d7926f6 100644
--- a/sysdeps/pthread/Makefile
+++ b/sysdeps/pthread/Makefile
@@ -256,7 +256,7 @@ tests += \
tst-sem14 \
tst-sem15 \
tst-sem16 \
- tst-sem17 \
+ tst-sem18 \
tst-setuid3 \
tst-signal1 \
tst-signal2 \
diff --git a/sysdeps/pthread/tst-sem17.c b/sysdeps/pthread/tst-sem18.c
similarity index 92%
rename from sysdeps/pthread/tst-sem17.c
rename to sysdeps/pthread/tst-sem18.c
index c3f05d196f4ef17a..1be207bcbeeb56f1 100644
--- a/sysdeps/pthread/tst-sem17.c
+++ b/sysdeps/pthread/tst-sem18.c
@@ -24,9 +24,9 @@
int
do_test (void)
{
- sem_unlink ("/glibc-tst-sem17");
+ sem_unlink ("/glibc-tst-sem18");
errno = 0;
- sem_t *s = sem_open ("/glibc-tst-sem17", 0);
+ sem_t *s = sem_open ("/glibc-tst-sem18", 0);
TEST_VERIFY (s == SEM_FAILED);
TEST_COMPARE (errno, ENOENT);
return 0;