From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from silver.cherry.relay.mailchannels.net (silver.cherry.relay.mailchannels.net [23.83.223.166]) by sourceware.org (Postfix) with ESMTPS id E836D3858D33 for ; Mon, 20 Nov 2023 23:02:17 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org E836D3858D33 Authentication-Results: sourceware.org; dmarc=fail (p=none dis=none) header.from=sourceware.org Authentication-Results: sourceware.org; spf=fail smtp.mailfrom=sourceware.org ARC-Filter: OpenARC Filter v1.0.0 sourceware.org E836D3858D33 Authentication-Results: server2.sourceware.org; arc=pass smtp.remote-ip=23.83.223.166 ARC-Seal: i=2; a=rsa-sha256; d=sourceware.org; s=key; t=1700521339; cv=pass; b=GrjsXxUr3I0v1N6XDwixoJOiO21o5tGZ3V3YjdrudCtNhzMBIP4j32WsKuGj6buJFfYaPGoMO1Qpcpe/dTnhBXB7Hg37fwdqa1spwDTfjVChk/iw1mIRXfW7imSxa5X/DcMI4GjZVuquYBMwqAiAjE0B5NneOaLoMAhCMD3aBtY= ARC-Message-Signature: i=2; a=rsa-sha256; d=sourceware.org; s=key; t=1700521339; c=relaxed/simple; bh=gXK2rNWS6HJc91LXNoAUz3QZLu48dwErrOlXX4sMsGM=; h=Message-ID:Date:MIME-Version:Subject:To:From; b=KN6zIFmd1gc0wLYzY3oG7qG/EwcsCnuWBNx7WrRWT9eugdCQCWghbIFvLS1ZVtLKOZnFBFm7bBnYSAoew/SD1BbpZ7I1CkrD8JkPd2z3FMwlS3pbgfVdWslQPw8dcuMt7gzZepuFee0VHRJ8C3bq7um8uTmFR9Jlre0FzQGn7SA= ARC-Authentication-Results: i=2; server2.sourceware.org X-Sender-Id: dreamhost|x-authsender|siddhesh@gotplt.org Received: from relay.mailchannels.net (localhost [127.0.0.1]) by relay.mailchannels.net (Postfix) with ESMTP id DBD617A27B8; Mon, 20 Nov 2023 23:02:16 +0000 (UTC) Received: from pdx1-sub0-mail-a272.dreamhost.com (unknown [127.0.0.6]) (Authenticated sender: dreamhost) by relay.mailchannels.net (Postfix) with ESMTPA id 9B4EC7A2785; Mon, 20 Nov 2023 23:02:16 +0000 (UTC) ARC-Seal: i=1; s=arc-2022; d=mailchannels.net; t=1700521336; a=rsa-sha256; cv=none; b=pFAlAWlHiu/pBC2dQifDttshQ8PhNJWdC6TXrRWu2AW+5GfFzsCi+6VmIF1SQxBSJTKNRW mgYMezBR77BR2lMPaPUVz6Swq8Zd1/mkAFJ5336D2j+adLq/x668H9DvFaRN/V/+ufoX0G jYmEnJQKQqA1JJffOo5Z6D9rVoJb9bKUGPsykWVKKrKTgCCLDy9Jkie5JUvBky+vM3MXYf 7rAVkeItnMT+cAthV9NSwlJTtL4zGE4p2C9dKwV4hL9jjG696EWy52+oGWbndjWTmvNaaz migXaQ3Bj+qUdcy7pNpEsSicZ52WyJHkJqO62gM5+41lOp4LZ+HnuEDZdd1cCw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=mailchannels.net; s=arc-2022; t=1700521336; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=8VuJwiZjf0l5WemOQ5H+RQI/W3UzjkW9UOYHHNnoClc=; b=qFs0djZhvrjraPJ6bm1+mMRuQz3C8qH0LGw+yoaMqSo+TIV+OPUNcbVvLoQRtsOT1ZbzX9 0N+11J4ozGjk3bgPAdE2yh6ObIvYa4G/Czf3QpKpdwz6rAvlLAA4xysB1A01jqWrvt17TP 3EdPl8mmFrLS+ufTejP/sXtCxT7Htha+9BTVgx8h9WfzgfcVYmq/Jz0gmBMo/IK1oymyxa 5QbmmQvL6DcHMoVwPBqJrpUNguH8sskcJIh9SE6xFca0hz8ARfPic82ha/I45peVBBNyQ0 j8vq/K/lqyQ2nH+nDq0G9W2DLeTBpIyftowAjQh3HIgs7GfrIumZbyJl0OT2+w== ARC-Authentication-Results: i=1; rspamd-7f8878586f-7pl2d; auth=pass smtp.auth=dreamhost smtp.mailfrom=siddhesh@sourceware.org X-Sender-Id: dreamhost|x-authsender|siddhesh@gotplt.org X-MC-Relay: Neutral X-MailChannels-SenderId: dreamhost|x-authsender|siddhesh@gotplt.org X-MailChannels-Auth-Id: dreamhost X-Stretch-Obese: 4cb8f47c43c03344_1700521336755_2206827498 X-MC-Loop-Signature: 1700521336755:2224125414 X-MC-Ingress-Time: 1700521336755 Received: from pdx1-sub0-mail-a272.dreamhost.com (pop.dreamhost.com [64.90.62.162]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384) by 100.119.176.6 (trex/6.9.2); Mon, 20 Nov 2023 23:02:16 +0000 Received: from [192.168.2.12] (bras-vprn-toroon4834w-lp130-02-142-113-138-136.dsl.bell.ca [142.113.138.136]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: siddhesh@gotplt.org) by pdx1-sub0-mail-a272.dreamhost.com (Postfix) with ESMTPSA id 4SZ31N2D1XzLh; Mon, 20 Nov 2023 15:02:16 -0800 (PST) Message-ID: <02772071-2fc5-4e85-ab31-201662aba93d@sourceware.org> Date: Mon, 20 Nov 2023 18:02:15 -0500 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v3 18/19] elf: Ignore LD_BIND_NOW and LD_BIND_NOT for setuid binaries Content-Language: en-US To: Adhemerval Zanella , libc-alpha@sourceware.org References: <20231106202552.3404059-1-adhemerval.zanella@linaro.org> <20231106202552.3404059-19-adhemerval.zanella@linaro.org> From: Siddhesh Poyarekar In-Reply-To: <20231106202552.3404059-19-adhemerval.zanella@linaro.org> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Spam-Status: No, score=-1172.2 required=5.0 tests=BAYES_00,GIT_PATCH_0,KAM_DMARC_NONE,KAM_DMARC_STATUS,RCVD_IN_DNSWL_NONE,RCVD_IN_MSPIKE_H4,RCVD_IN_MSPIKE_WL,SPF_HELO_NONE,SPF_SOFTFAIL,TXREP,T_SCC_BODY_TEXT_LINE autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on server2.sourceware.org List-Id: On 2023-11-06 15:25, Adhemerval Zanella wrote: > To avoid any environment variable to change setuid binaries > semantics. > > Checked on x86_64-linux-gnu. > --- Reviewed-by: Siddhesh Poyarekar > elf/rtld.c | 8 ++++++-- > elf/tst-env-setuid.c | 4 ++-- > sysdeps/generic/unsecvars.h | 2 ++ > 3 files changed, 10 insertions(+), 4 deletions(-) > > diff --git a/elf/rtld.c b/elf/rtld.c > index d1017ba9e9..cfba30eba0 100644 > --- a/elf/rtld.c > +++ b/elf/rtld.c > @@ -2598,12 +2598,14 @@ process_envvars (struct dl_main_state *state) > > case 8: > /* Do we bind early? */ > - if (memcmp (envline, "BIND_NOW", 8) == 0) > + if (!__libc_enable_secure > + && memcmp (envline, "BIND_NOW", 8) == 0) > { > GLRO(dl_lazy) = envline[9] == '\0'; > break; > } > - if (memcmp (envline, "BIND_NOT", 8) == 0) > + if (! __libc_enable_secure > + && memcmp (envline, "BIND_NOT", 8) == 0) > GLRO(dl_bind_not) = envline[9] != '\0'; > break; > > @@ -2680,6 +2682,8 @@ process_envvars (struct dl_main_state *state) > > if (GLRO(dl_debug_mask) != 0 > || GLRO(dl_verbose) != 0 > + || GLRO(dl_lazy) != 1 > + || GLRO(dl_bind_not) != 0 > || state->mode != rtld_mode_normal > || state->version_info) > _exit (5); > diff --git a/elf/tst-env-setuid.c b/elf/tst-env-setuid.c > index dcf213a4cd..eb9613d717 100644 > --- a/elf/tst-env-setuid.c > +++ b/elf/tst-env-setuid.c > @@ -61,12 +61,12 @@ static const struct envvar_t filtered_envvars[] = > { "RES_OPTIONS", FILTERED_VALUE }, > { "LD_DEBUG", "all" }, > { "LD_DEBUG_OUTPUT", "/tmp/some-file" }, > + { "LD_BIND_NOW", "0" }, > + { "LD_BIND_NOT", "1" }, > }; > > static const struct envvar_t unfiltered_envvars[] = > { > - { "LD_BIND_NOW", "0" }, > - { "LD_BIND_NOT", "1" }, > /* Non longer supported option. */ > { "LD_ASSUME_KERNEL", UNFILTERED_VALUE }, > }; > diff --git a/sysdeps/generic/unsecvars.h b/sysdeps/generic/unsecvars.h > index f7ebed60e5..c71b70ed95 100644 > --- a/sysdeps/generic/unsecvars.h > +++ b/sysdeps/generic/unsecvars.h > @@ -7,6 +7,8 @@ > "GLIBC_TUNABLES\0" \ > "HOSTALIASES\0" \ > "LD_AUDIT\0" \ > + "LD_BIND_NOT\0" \ > + "LD_BIND_NOW\0" \ > "LD_DEBUG\0" \ > "LD_DEBUG_OUTPUT\0" \ > "LD_DYNAMIC_WEAK\0" \