1. 03 11月, 2015 3 次提交
    • D
      prevent allocs than PTRDIFF_MAX via mremap · f9ecb6bf
      Daniel Micay 提交于
      It's quite feasible for this to happen via MREMAP_MAYMOVE.
      f9ecb6bf
    • R
      use explicit __cp_cancel label in cancellable syscall asm for all archs · 36e8b6a2
      Rich Felker 提交于
      previously, only archs that needed to do stack cleanup defined a
      __cp_cancel label for acting on cancellation in their syscall asm, and
      a default definition was provided by a weak alias to __cancel, the C
      function. this resulted in wrong codegen for arm on gcc versions
      affected by pr 68178 and possibly similar issues (like pr 66609) on
      other archs, and also created an inconsistency where the __cp_begin
      and __cp_end labels were treated as const data but __cp_cancel was
      treated as a function. this in turn caused incorrect code generation
      on archs where function pointers point to function descriptors rather
      than code (for now, only sh/fdpic).
      36e8b6a2
    • R
      properly access mcontext_t program counter in cancellation handler · cb1bf2f3
      Rich Felker 提交于
      using the actual mcontext_t definition rather than an overlaid pointer
      array both improves correctness/readability and eliminates some ugly
      hacks for archs with 64-bit registers bit 32-bit program counter.
      
      also fix UB due to comparison of pointers not in a common array
      object.
      cb1bf2f3
  2. 29 10月, 2015 1 次提交
    • R
      fix missing bss handling in FDPIC ELF loader · fead7e3f
      Rich Felker 提交于
      when a library being loaded has bss (i.e. data segment with
      p_memsz>p_filesz), this region needs to be zeroed with a combination
      of memset and/or mmap. the regular ELF loader always did this but the
      FDPIC code path omitted it, leading to objects in bss having
      uninitialized/junk contents.
      fead7e3f
  3. 27 10月, 2015 2 次提交
    • H
      getnameinfo: make size check not fail for bigger sizes · 6eada2ed
      Hauke Mehrtens 提交于
      getnameinfo() compares the size of the given struct sockaddr with
      sizeof(struct sockaddr_in) and sizeof(struct sockaddr_in6) depending on
      the net family. When you add a sockaddr of size sizeof(struct
      sockaddr_storage) this function will fail because the size of the
      sockaddr is too big. Change the check that it only fails if the size is
      too small, but make it work when it is too big for example when someone
      calls this function with a struct sockaddr_storage and its size.
      This fixes a problem with IoTivity 1.0.0 and musl.
      
      glibc and bionic are only failing if it is smaller, net/freebsd
      implemented the != check.
      Signed-off-by: NHauke Mehrtens <hauke@hauke-m.de>
      6eada2ed
    • R
      safely handle failure to open hosts, services, resolv.conf files · 2683e267
      Rich Felker 提交于
      previously, transient failures like fd exhaustion or other
      resource-related errors were treated the same as non-existence of
      these files, leading to fallbacks or false-negative results. in
      particular:
      
      - failure to open hosts resulted in fallback to dns, possibly yielding
        EAI_NONAME for a hostname that should be defined locally, or an
        unwanted result from dns that the hosts file was intended to
        replace.
      
      - failure to open services resulted in EAI_SERVICE.
      
      - failure to open resolv.conf resulted in querying localhost rather
        than the configured nameservers.
      
      now, only permanent errors trigger the fallback behaviors above; all
      other errors are reportable to the caller as EAI_SYSTEM.
      2683e267
  4. 25 10月, 2015 1 次提交
    • R
      fix single-byte overflow of malloc'd buffer in getdelim · b114190b
      Rich Felker 提交于
      the buffer enlargement logic here accounted for the terminating null
      byte, but not for the possibility of hitting the delimiter in the
      buffer-refill code path that uses getc_unlocked, in which case two
      additional bytes (the delimiter and the null termination) are written
      without another chance to enlarge the buffer.
      
      this patch and the corresponding bug report are by Felix Janda.
      b114190b
  5. 23 10月, 2015 2 次提交
    • R
      prevent user CFLAGS overrides from exposing executable stack · bc0c4841
      Rich Felker 提交于
      the option to suppress executable stack tagging was placed in CFLAGS,
      which is treated as optional and overridable by the build system. if a
      user replaces CFLAGS after configure has run, it could get lost,
      resulting in a libc.so that's flagged as needing executable stack,
      which would cause the kernel to map the initial stack as executable.
      
      move -Wa,--noexecstack to CFLAGS_C99FSE, the make variable used for
      mandatory compiler options.
      bc0c4841
    • R
      fix breakage when user overrides CFLAGS on the make command line · be76cdcf
      Rich Felker 提交于
      these per-target CFLAGS adjustments are mandatory additions to the
      command line for building the affected targets, not part of the
      user-provided CFLAGS for tuning. my intent was always that the
      variable append operations would take place after user settings, but
      when a variable is set on the command line, it overrides all
      definitions in the makefile, including target-specific ones.
      
      based on patch by Szabolcs Nagy.
      be76cdcf
  6. 20 10月, 2015 1 次提交
  7. 19 10月, 2015 1 次提交
  8. 16 10月, 2015 6 次提交
    • B
      add missing memory barrier to pthread_join · 53cd8c5a
      Bobby Bingham 提交于
      POSIX requires pthread_join to synchronize memory on success.  The
      futex wait inside __timedwait_cp cannot handle this because it's not
      called in all cases.  Also, in the case of a spurious wake, tid can
      become zero between the wake and when the joining thread checks it.
      53cd8c5a
    • R
      fix dladdr treatment of function descriptors for fdpic · bde0b4b9
      Rich Felker 提交于
      when determining which module an address belongs to, all function
      descriptor ranges must be checked first, in case the allocated memory
      falls inside another module's memory range.
      
      dladdr itself must also check addresses against function descriptors
      before doing a best-match search against the symbol table. even when
      doing the latter (e.g. for code addresses obtained from mcontext_t),
      also check whether the best-match was a function, and if so, replace
      the result with a function descriptor address. which is the nominal
      "base address" of the function and which the caller needs if it
      intends to subsequently call the matching function.
      bde0b4b9
    • R
      fix visibility mismatch in dynamic linker stage 2 function definition · bc9b6ea0
      Rich Felker 提交于
      since commits 2907afb8 and
      6fc30c24, __dls2 is no longer called
      via symbol lookup, but instead uses relative addressing that needs to
      be resolved at link time. on some linker versions, and/or if
      -Bsymbolic-functions is not used, the linker may leave behind a
      dynamic relocation, which is not suitable for bootstrapping the
      dynamic linker, if the reference to __dls2 is marked hidden but the
      definition is not actually hidden. correcting the definition to use
      hidden visibility fixes the problem.
      
      the static-PIE entry point rcrt1 was likewise affected and is also
      fixed by this patch.
      bc9b6ea0
    • R
      suppress sh assembler rejection of instructions based on isa level · 79789980
      Rich Felker 提交于
      we need access to all instructions in order for runtime selection of
      atomic model to work correctly. without this patch, some versions of
      gcc instruct gas to reject instructions outside the target isa level.
      79789980
    • R
      prevent reordering of or1k and powerpc thread pointer loads · 92637bb0
      Rich Felker 提交于
      other archs use asm for the thread pointer load, so making that asm
      volatile is sufficient to inform the compiler that it has a "side
      effect" (crashing or giving the wrong result if the thread pointer was
      not yet initialized) that prevents reordering. however, powerpc and
      or1k have dedicated general purpose registers for the thread pointer
      and did not need to use any asm to access it; instead, "local register
      variables with a specified register" were used. however, there is no
      specification for ordering constraints on this type of usage, and
      presumably use of the thread pointer could be reordered across its
      initialization.
      
      to impose an ordering, I have added empty volatile asm blocks that
      produce the "local register variable with a specified register" as
      an output constraint.
      92637bb0
    • R
      mark arm thread-pointer-loading inline asm as volatile · 74483c59
      Rich Felker 提交于
      this builds on commits a603a75a and
      0ba35d69 to ensure that a compiler
      cannot conclude that it's valid to reorder the asm to a point before
      the thread pointer is set up, or to treat the inline function as if it
      were declared with attribute((const)).
      
      other archs already use volatile asm for thread pointer loading.
      74483c59
  9. 15 10月, 2015 4 次提交
  10. 14 10月, 2015 4 次提交
  11. 09 10月, 2015 4 次提交
    • R
      fix integer overflows in time_t/struct tm conversion code · c82d3bad
      Rich Felker 提交于
      as found and reported by Brian Mastenbrook, the expressions
      400*qc_cycles and years+100 in __secs_to_tm were both subject to
      integer overflow for extreme values of the input t.
      
      this patch by Szabolcs Nagy fixes the code by switching to larger
      types, and matches the original intent I had in mind when writing this
      code.
      c82d3bad
    • R
      fix open_[w]memstream behavior when no writes take place · 7b9f57f2
      Rich Felker 提交于
      the specification for these functions requires that the buffer/size
      exposed to the caller be valid after any successful call to fflush or
      fclose on the stream. the implementation's approach is to update them
      only at flush time, but that misses the case where fflush or fclose is
      called without any writes having taken place, in which case the write
      flushing callback will not be called.
      
      to fix both the observable bug and the desired invariant, setup empty
      buffers at open time and fail the open operation if no memory is
      available.
      7b9f57f2
    • A
      fix instruction matching errors in i386 CFI generation · dc979514
      Alex Dowad 提交于
      fdiv and fmul instructions were wrongly matched by the rules for
      integer div and mul instructions, leading to incorrect conclusions
      about register values being clobbered.
      dc979514
    • A
      factor common awk functions for CFI generation scripts into new file · 0650a059
      Alex Dowad 提交于
      There is a lot which could be common between i386 and x86_64, but none
      of it will be useful for any other arch. These should be useful for
      all archs, however.
      0650a059
  12. 02 10月, 2015 1 次提交
    • R
      make nl_langinfo(CODESET) always return "ASCII" in byte-based C locale · 2d51c4ad
      Rich Felker 提交于
      commit 844212d9, which did not make it
      into any releases, changed nl_langinfo(CODESET) to always return
      "UTF-8", even in the byte-based C locale. this was problematic because
      application software was found to use the string match for "UTF-8" to
      activate its own UTF-8 processing. this both undermines the byte-based
      functionality of the C locale, and if mixed with with calls to the
      standard multibyte functions, which happened in practice, could result
      in severe mis-handling of input.
      
      the motive for the previous change was that, to avoid widespread
      compatibility problems, the string returned by nl_langinfo(CODESET)
      needs to be accepted by iconv and by third-party character conversion
      code. thus, the only remaining choice is "ASCII". this choice
      accurately represents the intent that high bytes do not have
      individual meaning in the C locale, but it does mean that iconv, when
      passed nl_langinfo(CODESET) in the C locale, will produce errors in
      cases where mbrtowc would have succeeded. for reference, glibc behaves
      similarly in this regard, so I don't think it will be a problem.
      2d51c4ad
  13. 01 10月, 2015 1 次提交
  14. 29 9月, 2015 1 次提交
    • R
      eliminate protected-visibility data in libc.so with vis.h preinclude · f3a53f09
      Rich Felker 提交于
      some newer binutils versions print scary warnings about protected data
      because most gcc versions fail to produce the right address
      references/relocations for such data that might be subject to copy
      relocations. originally vis.h explicitly assigned default visibility
      to all public data symbols to avoid this issue, but commit
      b8dda24f removed this treatment for
      stdin/out/err to work around a gcc 3.x bug, and since they don't
      actually need it (because taking their addresses is not valid C).
      
      instead, a check for the gcc 3.x bug is added to the configure check
      for vis.h preinclude support; this feature will simply be disabled
      when using a buggy version of gcc.
      f3a53f09
  15. 25 9月, 2015 2 次提交
    • R
      avoid attempting to lookup IP literals as hostnames · 2a6e1f0f
      Rich Felker 提交于
      previously, __lookup_ipliteral only checked its argument against the
      requested address family, so IPv4 literals passed through to
      __lookup_name if the caller asked for only IPv6 results, and likewise
      for IPv6 literals when the caller asked for only IPv4. this resulted
      in spurious DNS lookups that reportedly even succeeded with some
      nameservers.
      
      now, __lookup_ipliteral attempts to parse its argument as both IPv4
      and IPv6, and returns an error (to stop further search) rather than 0
      (no results yet) if the form of the argument mismatches the requested
      address family.
      
      based on patch by Julien Ramseier.
      2a6e1f0f
    • R
      make getaddrinfo return error if both host and service name are null · 06bcf9bc
      Rich Felker 提交于
      this case is specified as a mandatory ("shall fail") error.
      
      based on patch by Julien Ramseier.
      06bcf9bc
  16. 24 9月, 2015 4 次提交
    • R
      fix localeconv field value for unavailable values · b4d94ba4
      Rich Felker 提交于
      per ISO C, CHAR_MAX, not -1, is the value used to indicate that a char
      field in struct lconv is unavailable.
      
      patch by Julien Ramseier.
      b4d94ba4
    • S
      avoid reading uninitialized memory in __map_file · bd275378
      Szabolcs Nagy 提交于
      The value of *size is not relevant in case of failure, but it's
      better not to copy garbage from the stack into it.
      (The compiler cannot see through the syscall, so optimization
      was not affected by the unspecified value).
      bd275378
    • S
      regcomp: propagate allocation failures · 4260dfe1
      Szabolcs Nagy 提交于
      The error code of an allocating function was not checked in tre_add_tag.
      4260dfe1
    • R
      fix signal return for sh/fdpic · b61df229
      Rich Felker 提交于
      the restorer function pointer provided in the kernel sigaction
      structure is interpreted by the kernel as a raw code address, not a
      function descriptor.
      
      this commit moves the declarations of the __restore and __restore_rt
      symbols to ksigaction.h so that arch versions of the file can override
      them, and introduces a version for sh which declares them as objects
      rather than functions.
      
      an alternate solution would have been defining SA_RESTORER to 0 so
      that the functions are not used, but this both requires executable
      stack (since the sh kernel does not have a vdso page with permanent
      restorer functions) and crashes on qemu user-level emulation.
      b61df229
  17. 23 9月, 2015 2 次提交
    • R
      fix dlsym RTLD_NEXT behavior for fdpic · 6c5cad2a
      Rich Felker 提交于
      lookup the dso an address falls in based on the loadmap and not just a
      base/length. fix the main app's fake loadmap used when loaded by a
      non-fdpic-aware loader so that it does not cover the whole memory
      space.
      
      function descriptor addresses are also matched for future use by
      dladdr, but reverse lookups of function descriptors via dladdr have
      not been implemented yet. some revisions may be needed in the future
      once reclaim_gaps supports fdpic, so that function descriptors
      allocated in reclaimed heap space do not get detected as belonging to
      the module whose gaps they were allocated in.
      6c5cad2a
    • R
      fix dlsym lookup of function symbols on fdpic · d47d9a50
      Rich Felker 提交于
      previously these resolved to the code address rather than the address
      of the function descriptor.
      
      the conditions for accepting or rejecting symbols are quite
      inconsistent between the different points in the dynamic linker code
      where such decisions are made. this commit attempts to be at least as
      correct as anything already there, but does not improve consistency.
      it has been tested to correctly avoid symbols that are merely
      references to functions defined in other modules, at least in simple
      usage, but at some point all symbol lookup logic should be reviewed
      and refactored/unified.
      d47d9a50