From patchwork Mon Feb 24 17:12:19 2025 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yangyu Chen X-Patchwork-Id: 107044 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from server2.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id C06FF3858C2C for ; Mon, 24 Feb 2025 17:13:37 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org C06FF3858C2C Authentication-Results: sourceware.org; dkim=pass (1024-bit key, unprotected) header.d=qq.com header.i=@qq.com header.a=rsa-sha256 header.s=s201512 header.b=bdYSJWAq X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from out203-205-221-202.mail.qq.com (out203-205-221-202.mail.qq.com [203.205.221.202]) by sourceware.org (Postfix) with UTF8SMTPS id 5D2713858CD9 for ; Mon, 24 Feb 2025 17:12:52 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 5D2713858CD9 Authentication-Results: sourceware.org; dmarc=none (p=none dis=none) header.from=cyyself.name Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=cyyself.name ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 5D2713858CD9 Authentication-Results: server2.sourceware.org; arc=none smtp.remote-ip=203.205.221.202 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1740417173; cv=none; b=aT+VVDazFAJQUPwswJR7WIcqacLZ0yeaRIX9qoV27m3xw21OwrYO7XawTWNLezLPBACC6p5EWchn17IN1XJEAlhOJom+iWDnrrlnQDTCgppLyNWbJ2P+GEF2bIsknMJKIurz2sYxlZbOOgHCO9zsflpRTAaYJhH/wANUtxBDmv0= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1740417173; c=relaxed/simple; bh=9QjhLUM/f0av3/Vc7yaqiDpczUFLKYUDGQuHUqHsBcM=; h=DKIM-Signature:Message-ID:From:To:Subject:Date:MIME-Version; b=an5YcA/RnMVFO7fRQSm/kLinK7TgyLN5QZgFfEOekTRr/y0w/e3Umrt7/vIiP9KgLcqa642y3JiKaIJm0GK3E1neF+KsEkZG5C3h0Ucc5Vn9qJMsl70ONfxn5aewS1vqnI/pco7B8KSxS26yclN0iUOu4YjdDjRacoRzpwISnn4= ARC-Authentication-Results: i=1; server2.sourceware.org DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 5D2713858CD9 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qq.com; s=s201512; t=1740417163; bh=rLqTTqaJlVIa+PODuxbHCIiWOX2a19J20zzv5zlLY+A=; h=From:To:Cc:Subject:Date; b=bdYSJWAqS7aM6wf8BrYG/zrrQZ3t+gBvofUqeMO9Q5Pnk1oa7x2epiBdHTDTpGpdD 06TvSj7WDTUlSBJRcbh0gMTNjkk1wugJJP6qqtXqJHOc1cW3q6d2HH7p9wSBwPlyz8 tiyjTVxqEK9ec5vvNPZXquUmVHG8Pl5ii2rjl8NE= Received: from cyy-pc.lan ([240e:379:2262:7800:6234:c13a:dd03:d987]) by newxmesmtplogicsvrszb20-0.qq.com (NewEsmtp) with SMTP id 31D0445C; Tue, 25 Feb 2025 01:12:29 +0800 X-QQ-mid: xmsmtpt1740417149t2b1puphe Message-ID: X-QQ-XMAILINFO: OJVlX7oey6I06GnkecLjGCVXHvCSAHZxewuAoqcrxG/aqxII04DeMpCoDypd25 kszpWTkoa+pX6SGmZiOGknPHb9/B+ubmnrlD+fGp1XW5ZO20Kvy+ZuM4dnjdT7RjH9y3CENainbI t/RllUWgpxYPms5rzc9+h20SFR4tqcORFChmCzI8LLSPkjp1sohWu7e6jYVtN+Bl8XPHrWMGYn+V hx8kFZJXpW4BdQGsMpCQ1A5uxuvFB+P1swVAEMlXeSBZeSJhiQRhbuRcaoRsopykevYj/RKXXrQf wbNB9oWoW2uSxyTjT5uTIGZAd36cGAfQRYU6wXj6YzG5LKlZP7WqqaZAMw54YUylGL/j2E0I4Woa 4B1537VzRp56WvRiiUhDeOfR8kOkqfYQyvMptG3FxoMbD9JJAEHiJ4TeC6k/3Xs8tNBnKcv42an4 WwbSpc8sLBy5FftLFyQaaUEPdbGDdtxZ7/cYsEde9wDfBDyBzkq9d0SOgE3JNcQFOSgmbUcdxDnw sZHv+i155u1+1EDdAWqvuR6tXESMmSMP7NnqhjP3yYkuDU/LsreaJXzX6cBCQwfNmfw6buSqfmen dl3yYhja7kfCWUTxaGZLww3MUr1gwHsreN8UAkJ8tuqzWFJ6FQCb6RgjePNIHoNy6sS+I0tDUfr9 jD649NaATQWCnK6ZI6vQUgKLlIjcaz7gx9DuGlsEkizL+mGDP+ho5AJwu0lYMr3QP0T7dJTm+CT6 uIb4hpTyq3TROTWH/MbxvIJHrfUCtjlckisz/zDBcTc+VRSDqT788guGTU/5mZZ43FvFQNtKcrCm fYosk445EhX2kp1dOjGLkpuNORklqaqr+g6bA7Cw2d8qTR+I0FCn/EEBmc0UWG1669bzZIhIvWRQ fpFHIQJaxxTbyvPz6+jQS0gn/EGfxl1+qLaSKMSP8gt1QvqsZIYXNf+yLhKaHMqATdlAKgLxUvRZ kr4MYDxLgFT7LMdlWV2L1DGbc1gKQTb/XE4iMQ/20= X-QQ-XMRINFO: Nq+8W0+stu50PRdwbJxPCL0= From: Yangyu Chen To: libc-alpha@sourceware.org Cc: Vivian Wang , Palmer Dabbelt , Vincent Chen , Kito Cheng , Florian Weimer , Andreas Schwab , Jessica Clarke , Andrew Waterman , Piyou Chen , Fangrui Song , Jeff Law , Wei Wu , Jiawei , Liao Shihua , Yixuan Chen , Yulong Shi , Dongyan Chen , Yangyu Chen Subject: [PATCH v4] RISC-V: Fix IFUNC resolver cannot access gp pointer Date: Tue, 25 Feb 2025 01:12:19 +0800 X-OQ-MSGID: <20250224171219.2203646-1-cyy@cyyself.name> X-Mailer: git-send-email 2.47.2 MIME-Version: 1.0 X-Spam-Status: No, score=-8.0 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, GIT_PATCH_0, HELO_DYNAMIC_IPADDR, KAM_STOCKGEN, RCVD_IN_DNSWL_NONE, RDNS_DYNAMIC, SPF_HELO_NONE, SPF_PASS, TXREP autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on server2.sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org In some cases, an IFUNC resolver may need to access the gp pointer to access global variables. Such an object may have l_relocated == 0 at this time. In this case, an IFUNC resolver will fail to access a global variable and cause a SIGSEGV. This patch fixes this issue by relaxing the check of l_relocated in elf_machine_runtime_setup, but added a check for SHARED case to avoid using this code in static-linked executables. Such object have already set up the gp pointer in load_gp function and l->l_scope will be NULL if it is a pie object. So if we use these code to set up the gp pointer again for static-pie, it will causing a SIGSEGV in glibc as original bug on BZ #31317. I have also reproduced and checked BZ #31317 using the mold commit bed5b1731b ("illumos: Treat absolute symbols specially"), this patch can fix the issue. Also, we used the wrong gp pointer previously because ref->st_value is not the relocated address but just the offset from the base address of ELF. An edge case may happen if we reference gp pointer in a IFUNC resolver in a PIE object, but it will not happen in compiler-generated codes since -pie will disable relax to gp. In this case, the GP will be initialized incorrectly since the ref->st_value is not the address after relocation. This patch fixes this issue by adding the l->l_addr to ref->st_value to get the relocated address for the gp pointer. We don't use SYMBOL_ADDRESS macro here because __global_pointer$ is a special symbol that has SHN_ABS type, but it will use PC-relative addressing in the load_gp function using lla. Closes: BZ #32269 Fixes: 96d1b9ac23 ("RISC-V: Fix the static-PIE non-relocated object check") Co-authored-by: Vivian Wang Signed-off-by: Yangyu Chen --- sysdeps/riscv/dl-machine.h | 17 +++++++++++------ 1 file changed, 11 insertions(+), 6 deletions(-) diff --git a/sysdeps/riscv/dl-machine.h b/sysdeps/riscv/dl-machine.h index a30892f080..dcc3e0883b 100644 --- a/sysdeps/riscv/dl-machine.h +++ b/sysdeps/riscv/dl-machine.h @@ -348,7 +348,8 @@ elf_machine_runtime_setup (struct link_map *l, struct r_scope_elem *scope[], gotplt[1] = (ElfW(Addr)) l; } - if (l->l_type == lt_executable && l->l_relocated) +#ifdef SHARED + if (l->l_type == lt_executable) { /* The __global_pointer$ may not be defined by the linker if the $gp register does not be used to access the global variable @@ -362,12 +363,16 @@ elf_machine_runtime_setup (struct link_map *l, struct r_scope_elem *scope[], _dl_lookup_symbol_x ("__global_pointer$", l, &ref, l->l_scope, NULL, 0, 0, NULL); if (ref) - asm ( - "mv gp, %0\n" - : - : "r" (ref->st_value) - ); + asm ( + "mv gp, %0\n" + : + : "r" (ref->st_value + l->l_addr) + /* Don't use SYMBOL_ADDRESS here since __global_pointer$ + can be SHN_ABS type, but we need the address relative to + PC, not the absolute address. */ + ); } +#endif #endif return lazy; }