1. 12 9月, 2017 1 次提交
  2. 07 9月, 2017 5 次提交
    • R
      work around incorrect EPERM from mmap syscall · da438ee1
      Rich Felker 提交于
      under some conditions, the mmap syscall wrongly fails with EPERM
      instead of ENOMEM when memory is exhausted; this is probably the
      result of the kernel trying to fit the allocation somewhere that
      crosses into the kernel range or below mmap_min_addr. in any case it's
      a conformance bug, so work around it. for now, only handle the case of
      anonymous mappings with no requested address; in other cases EPERM may
      be a legitimate error.
      
      this indirectly fixes the possibility of malloc failing with the wrong
      errno value.
      da438ee1
    • R
      fix glob descent into . and .. with GLOB_PERIOD · 8c4be3e2
      Rich Felker 提交于
      GLOB_PERIOD is a gnu extension, and GNU glob does not seem to honor it
      except in the last path component. it's not clear whether this a bug
      or intentional, but it seems reasonable that it should exclude the
      special entries . and .. when walking.
      
      changes based on report and analysis by Julien Ramseier.
      8c4be3e2
    • R
      don't treat numeric port strings as servent records in getservby*() · 565dbee2
      Rich Felker 提交于
      some applications use getservbyport to find port numbers that are not
      assigned to a service; if getservbyport always succeeds with a numeric
      string as the result, they fail to find any available ports.
      
      POSIX doesn't seem to mandate the behavior one way or another. it
      specifies an abstract service database, which an implementation could
      define to include numeric port strings, but it makes more sense to
      align behavior with traditional implementations.
      
      based on patch by A. Wilcox. the original patch only changed
      getservbyport[_r]. to maintain a consistent view of the "service
      database", I have also modified getservbyname[_r] to exclude numeric
      port strings.
      565dbee2
    • R
      fix signal masking race in pthread_create with priority attributes · 9e01be6e
      Rich Felker 提交于
      if the parent thread was able to set the new thread's priority before
      it reached the check for 'startlock', the new thread failed to restore
      its signal mask and thus ran with all signals blocked.
      
      concept for patch by Sergei, who reported the issue; unnecessary
      changes were removed and comments added since the whole 'startlock'
      thing is non-idiomatic and confusing. eventually it should be replaced
      with use of idiomatic synchronization primitives.
      9e01be6e
    • S
      make syscall.h consistent with linux · 822dddfb
      Szabolcs Nagy 提交于
      most of the found naming differences don't matter to musl, because
      internally it unifies the syscall names that vary across targets,
      but for external code the names should match the kernel uapi.
      
      aarch64:
      	__NR_fstatat is called __NR_newfstatat in linux.
      	__NR_or1k_atomic got mistakenly copied from or1k.
      arm:
      	__NR_arm_sync_file_range is an alias for __NR_sync_file_range2
      	__NR_fadvise64_64 is called __NR_arm_fadvise64_64 in linux,
      	the old non-arm name is kept too, it should not cause issues.
      	(powerpc has similar nonstandard fadvise and it uses the
      	normal name.)
      i386:
      	__NR_madvise1 was removed from linux in commit
      	303395ac3bf3e2cb488435537d416bc840438fcb 2011-11-11
      microblaze:
      	__NR_fadvise, __NR_fstatat, __NR_pread, __NR_pwrite
      	had different name in linux.
      mips:
      	__NR_fadvise, __NR_fstatat, __NR_pread, __NR_pwrite, __NR_select
      	had different name in linux.
      mipsn32:
      	__NR_fstatat is called __NR_newfstatat in linux.
      or1k:
      	__NR__llseek is called __NR_llseek in linux.
      	the old name is kept too because that's the name musl uses
      	internally.
      powerpc:
      	__NR_{get,set}res{gid,uid}32 was never present in powerpc linux.
      	__NR_timerfd was briefly defined in linux but then got renamed.
      822dddfb
  3. 05 9月, 2017 4 次提交
    • B
      handle whitespace before %% in scanf · 9255dad9
      Bartosz Brachaczek 提交于
      this is mandated by C and POSIX standards and is in accordance with
      glibc behavior.
      9255dad9
    • A
      fix OOB reads in Xbyte_memmem · 51bdcdc4
      Alexander Monakov 提交于
      Reported by Leah Neukirchen.
      51bdcdc4
    • A
      free allocations in clearenv · cc0dbd5f
      Alexander Monakov 提交于
      This aligns clearenv with the Linux man page by setting 'environ'
      rather than '*environ' to NULL, and stops it from leaking entries
      allocated by the libc.
      cc0dbd5f
    • A
      overhaul environment functions · 8e932792
      Alexander Monakov 提交于
      Rewrite environment access functions to slim down code, fix bugs and
      avoid invoking undefined behavior.
      
      * avoid using int-typed iterators where size_t would be correct;
      * use strncmp instead of memcmp consistently;
      * tighten prologues by invoking __strchrnul;
      * handle NULL environ.
      
      putenv:
      * handle "=value" input via unsetenv too (will return -1/EINVAL);
      * rewrite and simplify __putenv; fix the leak caused by failure to
        deallocate entry added by preceding setenv when called from putenv.
      
      setenv:
      * move management of libc-allocated entries to this translation unit,
        and use no-op weak symbols in putenv/unsetenv;
      
      unsetenv:
      * rewrite; this fixes UB caused by testing a free'd pointer against
        NULL on entry to subsequent loops.
      
      Not changed:
      Failure to extend allocation tracking array (previously __env_map, now
      env_alloced) is ignored rather than causing to report -1/ENOMEM to the
      caller; the worst-case consequence is leaking this allocation when it
      is removed or replaced in a subsequent environment access.
      
      Initially UB in unsetenv was reported by Alexander Cherepanov.
      Using a weak alias to avoid pulling in malloc via unsetenv was
      suggested by Rich Felker.
      8e932792
  4. 02 9月, 2017 1 次提交
  5. 01 9月, 2017 1 次提交
    • R
      fix erroneous stop before input limit in mbsnrtowcs and wcsnrtombs · 11ddc314
      Rich Felker 提交于
      the value computed as an output limit that bounds the amount of input
      consumed below the input limit was incorrectly being used as the
      actual amount of input consumed. instead, compute the actual amount of
      input consumed as a difference of pointers before and after the
      conversion.
      
      patch by Mikhail Kremnyov.
      11ddc314
  6. 30 8月, 2017 10 次提交
  7. 12 8月, 2017 5 次提交
    • D
      fix signed overflow in ftok · 511b7042
      Daniel Sabogal 提交于
      511b7042
    • T
      fix build failure for sh4a due to missing colon in asm statement · 1698fe6c
      Thomas Petazzoni 提交于
      Due to a missing ":" in an asm() statement, the "memory" clobber is
      considered by gcc as an input operand and not a clobber, which causes a
      build failure.
      1698fe6c
    • R
      trap UB from attempts to join a detached thread · 80bf5952
      Rich Felker 提交于
      passing to pthread_join the id of a thread which is not joinable
      results in undefined behavior.
      
      in principle the check to trap does not necessarily work if
      pthread_detach was called after thread creation, since no effort is
      made here to synchronize access to t->detached, but the check is
      well-defined and harmless for callers which did not invoke UB, and
      likely to help catch erroneous code that would otherwise mysteriously
      hang.
      
      patch by William Pitcock.
      80bf5952
    • B
      ppc64: fix setjmp/longjmp handling of TOC pointer · e31c8c2d
      Bobby Bingham 提交于
      The TOC pointer is constant within a single dso, but needs to be saved
      and restored around cross-dso calls.  The PLT stub saves it to the
      caller's stack frame, and the linker adds code to the caller to restore
      it.
      
      With a local call, as within a single dso or with static linking, this
      doesn't happen and the TOC pointer is always in r2.  Therefore,
      setjmp/longjmp need to save/restore the TOC pointer from/to different
      locations depending on whether the call to setjmp was a local or non-local
      call.
      
      It is always safe for longjmp to restore to both r2 and the caller's stack.
      If the call to setjmp was local, and only r2 matters and the stack location
      will be ignored, but is required by the ABI to be reserved for the TOC
      pointer.  If the call was non-local, then only the stack location matters,
      and whatever is restored into r2 will be clobbered anyway when the caller
      reloads r2 from the stack.
      
      A little extra care is required for sigsetjmp, because it uses setjmp
      internally.  After the second return from this setjmp call, r2 will contain
      the caller's TOC pointer instead of libc's TOC pointer.  We need to save
      and restore the correct libc pointer before we can tail call to
      __sigsetjmp_tail.
      e31c8c2d
    • L
      qsort: add a short comment about the algorithm · 52cf5c18
      Leah Neukirchen 提交于
      52cf5c18
  8. 11 8月, 2017 1 次提交
    • R
      disable global visibility override hack (vis.h) by default · dc2f368e
      Rich Felker 提交于
      neither current compilers nor linkers treat protected visibility the
      way I expected, as having fixed source-level semantics rather than
      being dependent on target-specific ABI details, and change seems
      unlikely. while the use here does not actually depend on the specific
      semantics, at least some versions of some linkers, especially lld,
      refuse to allow linking to a libc.so where the symbols have protected
      visibility. this cannot be detected at configure-time because linking
      libc.so itself works fine, and because even if we could test linking
      an application against libc.so successfully, we could not justifiably
      assume that the same linker used to link libc.so would also be used
      later to link applications.
      
      disable the vis.h hack by default at the configure level, but add an
      explicit "auto" option to request the old configure-time detection
      rather than just removing it. this leaves it easy to evaluate whether
      it actually resulted in significant size or performance benefits while
      ensuring that out-of-the-box builds are not unlinkable for some users.
      
      fortunately, preliminary evaluation suggests that at least x86_64,
      arm, and aarch64 don't suffer at all from the change, and impact on
      other archs is low. if low is not low enough, it should not be hard to
      analyze where the significant PLT call ABI costs are present and
      mitigate them without the hack.
      dc2f368e
  9. 01 8月, 2017 1 次提交
    • R
      add _NL_LOCALE_NAME extension to nl_langinfo · 947d330f
      Rich Felker 提交于
      since setlocale(cat, NULL) is required to return the setting for the
      global locale, there is no standard mechanism to obtain the name of
      the currently active thread-local locale set by uselocale. this makes
      it impossible for application/library software to load appropriate
      translations, etc. unless using the gettext implementation provided by
      libc, which has privileged access to libc internals.
      
      to fill this gap, glibc introduced the _NL_LOCALE_NAME macro which can
      be used with nl_langinfo to obtain the name. GNU gettext/gnulib code
      already use this functionality on glibc, and can easily be adapted to
      make use of it on non-glibc systems if it's available; for other
      systems they poke at locale implementation internals, which we want to
      avoid. this patch provides a compatible interface to the one glibc
      introduced.
      947d330f
  10. 05 7月, 2017 8 次提交
  11. 04 7月, 2017 2 次提交
    • R
      fix regression in dlopen promotion from RTLD_LOCAL to RTLD_GLOBAL · 43c423af
      Rich Felker 提交于
      commit 4ff234f6 inadvertently removed
      the logic to do this when changing the representation of global
      status.
      43c423af
    • R
      ldso: avoid spurious & possible erroneous work for libs with no deps · 66b53cfa
      Rich Felker 提交于
      a null pointer for a library's deps list was ambiguous: it could
      indicate either no dependencies or that the dependency list had not
      yet been populated. inability to distinguish could lead to spurious
      work when dlopen is called multiple times on a library with no deps,
      and due to related bugs, could actually cause other libraries to
      falsely appear as dependencies, translating into false positives for
      dlsym.
      
      avoid the problem by always initializing the deps pointer, pointing to
      an empty list if there are no deps. rather than wasting memory and
      introducing another failure path by allocating an empty list per
      library, simply share a global dummy list.
      
      further fixes will be needed for related bugs, and much of this code
      may end up being replaced.
      66b53cfa
  12. 24 6月, 2017 1 次提交
    • R
      powerpc64: add single-instruction math functions · 94f74419
      Rich Felker 提交于
      while the official elfv2 abi for "powerpc64le" sets power8 as the
      baseline isa, we use it for both little and big endian powerpc64
      targets and need to maintain compatibility with pre-power8 models. the
      instructions for sqrt, fabs, and fma are in the baseline isa; support
      for the rest is conditional via predefined isa-level macros.
      
      patch by David Edelsohn.
      94f74419