Upstream commit: fffc2df8a3e2c8cda2991063d23086360268b777 - i386: Provide GLIBC_ABI_GNU_TLS symbol version [BZ #33221] - i386: Update ___tls_get_addr to preserve vector registers - Extend struct r_debug to support multiple namespaces (RHEL-101985) - Fix a potential crash in the dynamic loader when processing specific symbol versions (RHEL-109683) - Signal la_objopen for ld.so with dlmopen (RHEL-109693) - Switch to main malloc after final ld.so self-relocation (RHEL-109703) - Prevent ld.so from asserting and crashing during audited library loads (RHEL-109702) - x86-64: Provide GLIBC_ABI_DT_X86_64_PLT symbol version (RHEL-109621) - x86-64, i386: Provide GLIBC_ABI_GNU2_TLS symbol version (RHEL-109625) - Ensure fallback initialization of ctype TLS data pointers to fix segfaults in programs using dlmopen or auditors (RHEL-72018) - Handle load segment gaps in _dl_find_object (RHEL-104854) - AArch64: Improve codegen in SVE log1p - AArch64: Optimize inverse trig functions - AArch64: Avoid memset ifunc in cpu-features.c [BZ #33112] Resolves: RHEL-109536 Resolves: RHEL-72018 Resolves: RHEL-101985 Resolves: RHEL-104854 Resolves: RHEL-109621 Resolves: RHEL-109625 Resolves: RHEL-109683 Resolves: RHEL-109693 Resolves: RHEL-109702 Resolves: RHEL-109703
243 lines
8.2 KiB
Diff
243 lines
8.2 KiB
Diff
commit 6917fde6f9623d0521a9f16c8f10c94ab0f2e4ba
|
|
Author: Florian Weimer <fweimer@redhat.com>
|
|
Date: Fri Oct 25 16:50:10 2024 +0200
|
|
|
|
elf: Run constructors on cyclic recursive dlopen (bug 31986)
|
|
|
|
This is conceptually similar to the reported bug, but does not
|
|
depend on auditing. The fix is simple: just complete execution
|
|
of the constructors. This exposed the fact that the link map
|
|
for statically linked executables does not have l_init_called
|
|
set, even though constructors have run.
|
|
|
|
Reviewed-by: Adhemerval Zanella <adhemerval.zanella@linaro.org>
|
|
(cherry picked from commit 9897ced8e78db5d813166a7ccccfd5a42c69ef20)
|
|
|
|
diff --git a/elf/Makefile b/elf/Makefile
|
|
index 3085a0844c6604fe..7690ee9edc0b0c9a 100644
|
|
--- a/elf/Makefile
|
|
+++ b/elf/Makefile
|
|
@@ -414,6 +414,7 @@ tests += \
|
|
tst-dlmopen1 \
|
|
tst-dlmopen3 \
|
|
tst-dlmopen4 \
|
|
+ tst-dlopen-recurse \
|
|
tst-dlopen-self \
|
|
tst-dlopen-tlsmodid \
|
|
tst-dlopen-tlsreinit1 \
|
|
@@ -858,6 +859,8 @@ modules-names += \
|
|
tst-dlmopen-twice-mod1 \
|
|
tst-dlmopen-twice-mod2 \
|
|
tst-dlmopen1mod \
|
|
+ tst-dlopen-recursemod1 \
|
|
+ tst-dlopen-recursemod2 \
|
|
tst-dlopen-sgid-mod \
|
|
tst-dlopen-tlsreinitmod1 \
|
|
tst-dlopen-tlsreinitmod2 \
|
|
@@ -3145,3 +3148,6 @@ $(objpfx)tst-dlopen-tlsreinit4.out: $(objpfx)tst-auditmod1.so
|
|
tst-dlopen-tlsreinit4-ENV = LD_AUDIT=$(objpfx)tst-auditmod1.so
|
|
|
|
$(objpfx)tst-dlopen-sgid.out: $(objpfx)tst-dlopen-sgid-mod.so
|
|
+
|
|
+$(objpfx)tst-dlopen-recurse.out: $(objpfx)tst-dlopen-recursemod1.so
|
|
+$(objpfx)tst-dlopen-recursemod1.so: $(objpfx)tst-dlopen-recursemod2.so
|
|
diff --git a/elf/dl-open.c b/elf/dl-open.c
|
|
index 8556e7bd2fb0b40e..5139d276e04a5d85 100644
|
|
--- a/elf/dl-open.c
|
|
+++ b/elf/dl-open.c
|
|
@@ -601,6 +601,14 @@ dl_open_worker_begin (void *a)
|
|
= _dl_debug_update (args->nsid)->r_state;
|
|
assert (r_state == RT_CONSISTENT);
|
|
|
|
+ /* Do not return without calling the (supposedly new) map's
|
|
+ constructor. This case occurs if a dependency of a directly
|
|
+ opened map has a constructor that calls dlopen again on the
|
|
+ initially opened map. The new map is initialized last, so
|
|
+ checking only it is enough. */
|
|
+ if (!new->l_init_called)
|
|
+ _dl_catch_exception (NULL, call_dl_init, args);
|
|
+
|
|
return;
|
|
}
|
|
|
|
diff --git a/elf/dl-support.c b/elf/dl-support.c
|
|
index 451932dd03e971b8..94e8197c632c11c8 100644
|
|
--- a/elf/dl-support.c
|
|
+++ b/elf/dl-support.c
|
|
@@ -99,6 +99,7 @@ static struct link_map _dl_main_map =
|
|
.l_used = 1,
|
|
.l_tls_offset = NO_TLS_OFFSET,
|
|
.l_serial = 1,
|
|
+ .l_init_called = 1,
|
|
};
|
|
|
|
/* Namespace information. */
|
|
diff --git a/elf/tst-dlopen-recurse.c b/elf/tst-dlopen-recurse.c
|
|
new file mode 100644
|
|
index 0000000000000000..c7fb379d373c6e77
|
|
--- /dev/null
|
|
+++ b/elf/tst-dlopen-recurse.c
|
|
@@ -0,0 +1,34 @@
|
|
+/* Test that recursive dlopen runs constructors before return (bug 31986).
|
|
+ Copyright (C) 2024 Free Software Foundation, Inc.
|
|
+ This file is part of the GNU C Library.
|
|
+
|
|
+ The GNU C Library is free software; you can redistribute it and/or
|
|
+ modify it under the terms of the GNU Lesser General Public
|
|
+ License as published by the Free Software Foundation; either
|
|
+ version 2.1 of the License, or (at your option) any later version.
|
|
+
|
|
+ The GNU C Library is distributed in the hope that it will be useful,
|
|
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
|
+ Lesser General Public License for more details.
|
|
+
|
|
+ You should have received a copy of the GNU Lesser General Public
|
|
+ License along with the GNU C Library; if not, see
|
|
+ <https://www.gnu.org/licenses/>. */
|
|
+
|
|
+#include <stdio.h>
|
|
+#include <support/check.h>
|
|
+#include <support/xdlfcn.h>
|
|
+
|
|
+static int
|
|
+do_test (void)
|
|
+{
|
|
+ void *handle = xdlopen ("tst-dlopen-recursemod1.so", RTLD_NOW);
|
|
+ int *status = dlsym (handle, "recursemod1_status");
|
|
+ printf ("info: recursemod1_status == %d (from main)\n", *status);
|
|
+ TEST_COMPARE (*status, 2);
|
|
+ xdlclose (handle);
|
|
+ return 0;
|
|
+}
|
|
+
|
|
+#include <support/test-driver.c>
|
|
diff --git a/elf/tst-dlopen-recursemod1.c b/elf/tst-dlopen-recursemod1.c
|
|
new file mode 100644
|
|
index 0000000000000000..5e0cc0eb8c32d6d4
|
|
--- /dev/null
|
|
+++ b/elf/tst-dlopen-recursemod1.c
|
|
@@ -0,0 +1,50 @@
|
|
+/* Directly opened test module that gets recursively opened again.
|
|
+ Copyright (C) 2024 Free Software Foundation, Inc.
|
|
+ This file is part of the GNU C Library.
|
|
+
|
|
+ The GNU C Library is free software; you can redistribute it and/or
|
|
+ modify it under the terms of the GNU Lesser General Public
|
|
+ License as published by the Free Software Foundation; either
|
|
+ version 2.1 of the License, or (at your option) any later version.
|
|
+
|
|
+ The GNU C Library is distributed in the hope that it will be useful,
|
|
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
|
+ Lesser General Public License for more details.
|
|
+
|
|
+ You should have received a copy of the GNU Lesser General Public
|
|
+ License along with the GNU C Library; if not, see
|
|
+ <https://www.gnu.org/licenses/>. */
|
|
+
|
|
+#include <stdio.h>
|
|
+#include <stdlib.h>
|
|
+#include <support/xdlfcn.h>
|
|
+
|
|
+int recursemod1_status;
|
|
+
|
|
+/* Force linking against st-dlopen-recursemod2.so. Also allows
|
|
+ checking for relocation. */
|
|
+extern int recursemod2_status;
|
|
+int *force_recursemod2_reference = &recursemod2_status;
|
|
+
|
|
+static void __attribute__ ((constructor))
|
|
+init (void)
|
|
+{
|
|
+ ++recursemod1_status;
|
|
+ printf ("info: tst-dlopen-recursemod1.so constructor called (status %d)\n",
|
|
+ recursemod1_status);
|
|
+}
|
|
+
|
|
+static void __attribute__ ((destructor))
|
|
+fini (void)
|
|
+{
|
|
+ /* The recursemod1_status variable was incremented in the
|
|
+ tst-dlopen-recursemod2.so constructor. */
|
|
+ printf ("info: tst-dlopen-recursemod1.so destructor called (status %d)\n",
|
|
+ recursemod1_status);
|
|
+ if (recursemod1_status != 2)
|
|
+ {
|
|
+ puts ("error: recursemod1_status == 2 expected");
|
|
+ exit (1);
|
|
+ }
|
|
+}
|
|
diff --git a/elf/tst-dlopen-recursemod2.c b/elf/tst-dlopen-recursemod2.c
|
|
new file mode 100644
|
|
index 0000000000000000..edd2f2526b877810
|
|
--- /dev/null
|
|
+++ b/elf/tst-dlopen-recursemod2.c
|
|
@@ -0,0 +1,66 @@
|
|
+/* Indirectly opened module that recursively opens the directly opened module.
|
|
+ Copyright (C) 2024 Free Software Foundation, Inc.
|
|
+ This file is part of the GNU C Library.
|
|
+
|
|
+ The GNU C Library is free software; you can redistribute it and/or
|
|
+ modify it under the terms of the GNU Lesser General Public
|
|
+ License as published by the Free Software Foundation; either
|
|
+ version 2.1 of the License, or (at your option) any later version.
|
|
+
|
|
+ The GNU C Library is distributed in the hope that it will be useful,
|
|
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
|
+ Lesser General Public License for more details.
|
|
+
|
|
+ You should have received a copy of the GNU Lesser General Public
|
|
+ License along with the GNU C Library; if not, see
|
|
+ <https://www.gnu.org/licenses/>. */
|
|
+
|
|
+#include <dlfcn.h>
|
|
+#include <stdio.h>
|
|
+#include <stdlib.h>
|
|
+
|
|
+int recursemod2_status;
|
|
+
|
|
+static void __attribute__ ((constructor))
|
|
+init (void)
|
|
+{
|
|
+ ++recursemod2_status;
|
|
+ printf ("info: tst-dlopen-recursemod2.so constructor called (status %d)\n",
|
|
+ recursemod2_status);
|
|
+ void *handle = dlopen ("tst-dlopen-recursemod1.so", RTLD_NOW);
|
|
+ if (handle == NULL)
|
|
+ {
|
|
+ printf ("error: dlopen: %s\n", dlerror ());
|
|
+ exit (1);
|
|
+ }
|
|
+ int *status = dlsym (handle, "recursemod1_status");
|
|
+ if (status == NULL)
|
|
+ {
|
|
+ printf ("error: dlsym: %s\n", dlerror ());
|
|
+ exit (1);
|
|
+ }
|
|
+ printf ("info: recursemod1_status == %d\n", *status);
|
|
+ if (*status != 1)
|
|
+ {
|
|
+ puts ("error: recursemod1_status == 1 expected");
|
|
+ exit (1);
|
|
+ }
|
|
+ ++*status;
|
|
+ printf ("info: recursemod1_status == %d\n", *status);
|
|
+
|
|
+ int **mod2_status = dlsym (handle, "force_recursemod2_reference");
|
|
+ if (mod2_status == NULL || *mod2_status != &recursemod2_status)
|
|
+ {
|
|
+ puts ("error: invalid recursemod2_status address in"
|
|
+ " tst-dlopen-recursemod1.so");
|
|
+ exit (1);
|
|
+ }
|
|
+}
|
|
+
|
|
+static void __attribute__ ((destructor))
|
|
+fini (void)
|
|
+{
|
|
+ printf ("info: tst-dlopen-recursemod2.so destructor called (status %d)\n",
|
|
+ recursemod2_status);
|
|
+}
|