From patchwork Wed Jun 3 00:04:32 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Adhemerval Zanella Netto X-Patchwork-Id: 136340 X-Patchwork-Delegate: dj@redhat.com Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 764A34BA2E2C for ; Wed, 3 Jun 2026 00:13:29 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 764A34BA2E2C Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=linaro.org header.i=@linaro.org header.a=rsa-sha256 header.s=google header.b=KMNJb+G+ X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-yw1-x1129.google.com (mail-yw1-x1129.google.com [IPv6:2607:f8b0:4864:20::1129]) by sourceware.org (Postfix) with ESMTPS id 8E67E4BA2E24 for ; Wed, 3 Jun 2026 00:07:05 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 8E67E4BA2E24 Authentication-Results: sourceware.org; dmarc=pass (p=none dis=none) header.from=linaro.org Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=linaro.org ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 8E67E4BA2E24 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::1129 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1780445225; cv=none; b=aU0U/vsfq84GV0Gpmlt6+Y5/7sDqHjJUc4A9hXJGO0YDntBaR+vmxhW5ZvqbsoXtNTIddxX/HrZZyYVhjzEWsLk4Tge/d/wdFm7VOYAi42ZqCKHPV9x6h0wjQzKsB27CEU2zCv9fSBGBKkB5kFxooAVYu1FcGLI3o2v5eI/GupU= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1780445225; c=relaxed/simple; bh=hS/Dh+6ew+vM1b0sUOyHG/C1EXyyCg9cVg+le/cKGYY=; h=DKIM-Signature:From:To:Subject:Date:Message-ID:MIME-Version; b=JiESHRT/m11kDVc/Yv5WT406rbuEFMQ1wQHCJbckpKRq7VbQB8zytsfpvPtS0bwUsaNXex1bJwLXbtoXNx3Y5KepyBLwXfOD4NMBe0uHVAK/mZx+TquukWqAomMerjcGakAdD3Pq9f+Usl6rrwaDLqbNqtzpUNaQD5CujhPAd78= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=linaro.org header.i=@linaro.org header.a=rsa-sha256 header.s=google header.b=KMNJb+G+ DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 8E67E4BA2E24 Received: by mail-yw1-x1129.google.com with SMTP id 00721157ae682-7dca5a81be2so58934127b3.2 for ; Tue, 02 Jun 2026 17:07:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1780445225; x=1781050025; darn=sourceware.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=E0pOrCnJGqny7iPZLN9pAOcdvCmBRD3NPYUeDpXGMg8=; b=KMNJb+G+M6zYw35SeYQctzFIaK+MiqZOn2CLQ+1jX3VuDRc1yf9wx069c4vjcGmXTT 8I1KDe94+SDjfK460VmY5S9wFxZolTxdaZL+MZH56pFJLCmyTX5wAouwCnHHi67feuW1 RgH4vapmMTaq1LjQYEeuplVfzw6JgNA0m+WlfCWemNZy/Jh02auNEWM2hTW3eZF4gx0l K5LSvKC6MzPflY/muAGko1olHsr/giX34jGb5MSBUrfTPeeWCPC4XlsmwAPuxMl06CpG otmOWj9ctLifb7QyIY2lEzi+FEtyHM1Klr7HzQAM0S6qtBZulMfU9X8ybqclfsRpDaPH 2dOw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780445225; x=1781050025; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=E0pOrCnJGqny7iPZLN9pAOcdvCmBRD3NPYUeDpXGMg8=; b=ip4KYxHP3IqUMCBfwviPMM3nvMGTGd+ClOqDjlTKUcMIo48HdfJT6NftVBHQHXUc0I koDGFqPtbq1zFy917aEkV/xIWkb7Vo0KxX8h8uVQ04FC6xXVp9+Nkl7pkEDUresQ7sRw Dmg0kUmV771xkk8te61e2+h1gDmppuDJvI6lYEB6ao4SUv0dIoLoCT1pq1rZkw3foBFx de9x3V1o0Op3NXUmK4m0zBqx10KlTWQcSavI1ypFRg5kOH7FZtjz97yjByeUjmB7Tkxm 3ZrX8jq7M4UYeYtYUHXyJJM/CmtOhb24wKRzmb2G42wyQFrf88u9mD20AorTgjY6VMeE TGMQ== X-Gm-Message-State: AOJu0YzGKAHf7+COjI9fvd5+HDpxO+fyE1Lk6rq8Y8BGTElRzglpUhoH cborwfpE3sXzLPFNhhmo+0IsT9ckxxwKY6C81YXFM7IBnigyEEC6WpFGB882kd454VT4rfRGcfc bf/Ya X-Gm-Gg: Acq92OEwZZQ8BPLxuf9E5L6VAiMfrBoeQiMQOCx8vrlHQkfbgrSzrL1C5hYt+ON/Y4R YCJJTFhA0CLL7TjYgsDdNMWXBm7z1hEOBpiUjN88Re0cFt7oq53DlOYOvLLSHBYA9hdZG3DK8zC v8LLCLAGxXTxiwiXMl/PCV5NOB0iL5gJ/X0DvVBtNmUXg7nj+myKDOHik4UJRjjqvnSfNdsOK31 YbcSpLeg4egSKJRPccYtv9Xlqj+BJWxcFbebf61zI0pLBD4q2GjeqvPB1Darg9vpAhZYnydjZsm gmURPvZHKXF/HfEWScP/T3nF5oMDMCuKgUzSV19bbs+pOzBNwjlEN32xHMYUxlbyWXSAerGRnj6 SfHZdsCvymolD84JgKNFMsdWcEsHdVLLx0dfB5ZPujyMEcWZU8pQTolJHD5nrS+SGUxt3rWKceX frx23SJ8l8vxCpUzFkV5ZNCLRODp6ka8awRT4DRZo379zzCg== X-Received: by 2002:a05:690c:6001:b0:7bd:73f3:7a8d with SMTP id 00721157ae682-7ea4c1bb51cmr10106627b3.42.1780445224769; Tue, 02 Jun 2026 17:07:04 -0700 (PDT) Received: from mandiga.. ([2804:1b3:a7c2:efc6:8f41:550d:2b14:9278]) by smtp.gmail.com with ESMTPSA id 00721157ae682-7ea23a9946bsm7332207b3.37.2026.06.02.17.07.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 02 Jun 2026 17:07:04 -0700 (PDT) From: Adhemerval Zanella To: libc-alpha@sourceware.org Cc: Anderson Nascimento , Carlos O'Donell Subject: [PATCH 1/8] elf: Propagate the pointer guard to ld.so loaded via static dlopen (BZ 34196) Date: Tue, 2 Jun 2026 21:04:32 -0300 Message-ID: <20260603000656.3287796-2-adhemerval.zanella@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260603000656.3287796-1-adhemerval.zanella@linaro.org> References: <20260603000656.3287796-1-adhemerval.zanella@linaro.org> MIME-Version: 1.0 X-Spam-Status: No, score=-11.5 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, KAM_SHORT, KAM_STOCKGEN, RCVD_IN_DNSWL_BLOCKED, SPF_HELO_NONE, SPF_PASS, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org The static-dlopen does not initialize the pointer guard for ABIs that define THREAD_SET_POINTER_GUARD. Besides not properly guard the pointer if a libc.so symbol is called, this can leads to setjmp failures (a jmp_buf set up by the loaded ibc.so.6 cannot be restored by the static program's __longjmp, and vice versa). Seed the just-mapped loader's __pointer_chk_guard from the program's __pointer_chk_guard_local in __rtld_static_init, next to the other runtime values copied there. Checked on aarch64-linux-gnu, x86_64-linux-gnu, and i686-linux-gnu. --- elf/Makefile | 6 +++ elf/rtld_static_init.c | 12 +++++ elf/tst-ptrguard-static-dlopen-mod.c | 29 +++++++++++ elf/tst-ptrguard-static-dlopen.c | 51 +++++++++++++++++++ .../tst-ptrguard-static-dlopen.script | 1 + 5 files changed, 99 insertions(+) create mode 100644 elf/tst-ptrguard-static-dlopen-mod.c create mode 100644 elf/tst-ptrguard-static-dlopen.c create mode 100644 elf/tst-ptrguard-static-dlopen.root/tst-ptrguard-static-dlopen.script diff --git a/elf/Makefile b/elf/Makefile index bdf9a786d54..a940b3045e5 100644 --- a/elf/Makefile +++ b/elf/Makefile @@ -270,6 +270,7 @@ tests-static-normal := \ tst-env-setuid-static \ tst-getauxval-static \ tst-linkall-static \ + tst-ptrguard-static-dlopen \ tst-single_threaded-pthread-static \ tst-single_threaded-static \ tst-tls-allocation-failure-static \ @@ -576,6 +577,7 @@ tests-container += \ tst-dlopen-tlsmodid-container \ tst-pldd \ tst-preload-pthread-libc \ + tst-ptrguard-static-dlopen \ tst-rootdir \ # tests-container @@ -1013,6 +1015,7 @@ modules-names += \ tst-null-argv-lib \ tst-p_alignmod-base \ tst-p_alignmod3 \ + tst-ptrguard-static-dlopen-mod \ tst-recursive-tlsmallocmod \ tst-recursive-tlsmod0 \ tst-recursive-tlsmod1 \ @@ -3177,6 +3180,9 @@ $(objpfx)tst-tls21mod.so: $(tst-tls-many-dynamic-modules:%=$(objpfx)%.so) $(objpfx)tst-getauxval-static.out: $(objpfx)tst-auxvalmod.so tst-getauxval-static-ENV = LD_LIBRARY_PATH=$(objpfx):$(common-objpfx) +$(objpfx)tst-ptrguard-static-dlopen.out: \ + $(objpfx)tst-ptrguard-static-dlopen-mod.so + $(objpfx)tst-dlmopen-gethostbyname.out: $(objpfx)tst-dlmopen-gethostbyname-mod.so $(objpfx)tst-ro-dynamic: $(objpfx)tst-ro-dynamic-mod.so diff --git a/elf/rtld_static_init.c b/elf/rtld_static_init.c index 04eb1c6fcc4..a428542e57e 100644 --- a/elf/rtld_static_init.c +++ b/elf/rtld_static_init.c @@ -81,5 +81,17 @@ __rtld_static_init (struct link_map *map) dl->_dl_find_object = _dl_find_object; dl->_dl_readonly_area = _dl_readonly_area; +#ifndef THREAD_SET_POINTER_GUARD + extern uintptr_t __pointer_chk_guard_local attribute_hidden; + const ElfW(Sym) *guard_sym + = _dl_lookup_direct (map, "__pointer_chk_guard", + 0x69f99cab, /* dl_new_hash output. */ + "GLIBC_PRIVATE", + 0x0963cf85); /* _dl_elf_hash output. */ + if (guard_sym != NULL) + *(uintptr_t *) DL_SYMBOL_ADDRESS (map, guard_sym) + = __pointer_chk_guard_local; +#endif + __rtld_static_init_arch (map, dl); } diff --git a/elf/tst-ptrguard-static-dlopen-mod.c b/elf/tst-ptrguard-static-dlopen-mod.c new file mode 100644 index 00000000000..1b98e24d038 --- /dev/null +++ b/elf/tst-ptrguard-static-dlopen-mod.c @@ -0,0 +1,29 @@ +/* Shared object for the static-dlopen pointer guard test. + Copyright (C) 2026 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#include + +static jmp_buf jb; +void (*do_longjmp) (jmp_buf); + +void +foo (void) +{ + if (setjmp (jb) == 0) + do_longjmp (jb); +} diff --git a/elf/tst-ptrguard-static-dlopen.c b/elf/tst-ptrguard-static-dlopen.c new file mode 100644 index 00000000000..5e4337b11cd --- /dev/null +++ b/elf/tst-ptrguard-static-dlopen.c @@ -0,0 +1,51 @@ +/* Test that the pointer guard is propagated to ld.so via static dlopen. + Copyright (C) 2026 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +/* A statically linked program dlopens a shared object; the object's setjmp + uses the just-mapped libc.so's pointer guard while the longjmp below uses + the program's guard. Unless __rtld_static_init propagates the guard to + the loaded loader the two differ, and the setjmp/longjmp round-trip jumps + to a corrupt address and crashes. */ + +#include +#include +#include + +static void +call_longjmp (jmp_buf jb) +{ + longjmp (jb, 1); +} + +static int +do_test (void) +{ + void *h = xdlopen ("tst-ptrguard-static-dlopen-mod.so", RTLD_NOW); + void (*foo) (void) = xdlsym (h, "foo"); + void (**do_longjmp) (jmp_buf) = xdlsym (h, "do_longjmp"); + *do_longjmp = call_longjmp; + + /* foo () sets the jump buffer and calls back into call_longjmp; a + mismatched guard makes the return jump fault. */ + foo (); + + xdlclose (h); + return 0; +} + +#include diff --git a/elf/tst-ptrguard-static-dlopen.root/tst-ptrguard-static-dlopen.script b/elf/tst-ptrguard-static-dlopen.root/tst-ptrguard-static-dlopen.script new file mode 100644 index 00000000000..e4f49b34754 --- /dev/null +++ b/elf/tst-ptrguard-static-dlopen.root/tst-ptrguard-static-dlopen.script @@ -0,0 +1 @@ +cp $B/elf/tst-ptrguard-static-dlopen-mod.so $L/tst-ptrguard-static-dlopen-mod.so