From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail-pf1-x429.google.com (mail-pf1-x429.google.com [IPv6:2607:f8b0:4864:20::429]) by sourceware.org (Postfix) with ESMTPS id 2DCF03858D20 for ; Tue, 30 Apr 2024 19:27:45 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 2DCF03858D20 Authentication-Results: sourceware.org; dmarc=pass (p=none dis=none) header.from=linaro.org Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=linaro.org ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 2DCF03858D20 Authentication-Results: server2.sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::429 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1714505266; cv=none; b=pE+BNxkwZDdfR8xORsxHnllDURtWCatRLrRpi1neGhSN5Y0EIxRzUAdtwLnxjoZ3DNOzktR8M45KJ4jgBVDpzlWXV81RuZihbGbrTA7/pIfjysVFh67kE5Ac1ILM5USK5v/iLvMiKr6eaWZKIgt8Z6iAPzi2AjraEmbOvVy02VE= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1714505266; c=relaxed/simple; bh=6ev3pHMCworA8WSKYytho1iXjmBf5kPjqv0PQNQltxA=; h=DKIM-Signature:From:To:Subject:Date:Message-ID:MIME-Version; b=xwvaKTYAZ8rZpp2AfENT6KSNY6C65cGM/Vr+8+0ORRLWDt0aUZ6lh48PQFNn7vLW7za65z1BdkxY2m34RyLHbR5ccJKU8/RfUGJnhquH6sP0i5tQuMz3NWhcFtvo+1+Pl0Stu/wVjjeYHQx1KN3POYnICVPwT9B7FzKESPQPpdo= ARC-Authentication-Results: i=1; server2.sourceware.org Received: by mail-pf1-x429.google.com with SMTP id d2e1a72fcca58-6f4081574d6so2233220b3a.2 for ; Tue, 30 Apr 2024 12:27:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1714505263; x=1715110063; darn=sourceware.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=29chawrxaKl5gCKvHbpQeohTLUCNG+48KWoVIEatP4k=; b=Fao0kMToMUzoPOAvRW/G9o1HhMpMObykJJZm5noFv80oIxM6JAAnwYk5OPR7KKgqlf jJVG5dTf9I8UAC8BLeLlLg8GJogWJ55/H3aQ2/txREeIm3xcwRbFpBhWfqjI3k7f+5d2 m2oIR5FpEB10WVh4DFkjBk5jVL5MJwz+3JryvspTNOI4BVnEo2KXON2uIU9UDnwVXnxN PDS0mLZVCmZJEBE6vYXzpSdrlF/fAZAmmRGOpwqZppjup/LFJxvEBhiiYHIieouwHC/8 53u51AmhFuMWhCHgGA9NMAVZcL3+Z37JV1GDKG06rP9qc1BMaIrd7jUij0+DUnVvPf75 uQ/A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1714505263; x=1715110063; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=29chawrxaKl5gCKvHbpQeohTLUCNG+48KWoVIEatP4k=; b=ielP8ObgEb5ZJNnFkznJc/7P3N5Z7KoNR4ZsFtovSTJWXlUM/1iKy23nVpKACZ6Hjz WMii9gVTZKLq9nucAuyBCRWzhCJpcw6LkTuZI/3tw58NLoNLiYFQtORfWFfHWItTw8m3 O2P2cb9geiGGV9mkFBjOItDbarpmvNpN1g7BcJY5OM60jF3tkrvnQQOnDJgaEO9AWH1P A3xdnvEAkdHaAhtqpWS2XtqkObc5r5oE1GG3mpilyxB5kqyEnH5fqQqY3uqNf3vSJ2H6 lLoCmc79cdlaWTDpYhhdSYVCW7G3p7z8q/yOyt+L+2p7UsR4BfWROHHd+ZM35iX1j1XD UKSg== X-Gm-Message-State: AOJu0YwnNI9g9JFIHebVltsLtW4+1oP7PUcbi/9qSZ0is8SSi92dCk7i RxyMJtAUCXBkAp2T3QPqRAtAVqk6P/G1GXZueyRD6u/rYHZnIBzvrqtXLaY6fkkYn+tv8ZatfcW y X-Google-Smtp-Source: AGHT+IH/ta2prUd4pRr+z0YzFLFQnHJlgS96sYlBH7yk0fq9KNraZsJXior0rVMSV5iAIeeHuoCQYQ== X-Received: by 2002:a05:6a00:842:b0:6f3:f062:c09b with SMTP id q2-20020a056a00084200b006f3f062c09bmr668719pfk.6.1714505263502; Tue, 30 Apr 2024 12:27:43 -0700 (PDT) Received: from mandiga.. ([2804:1b3:a7c1:e3c5:c9b5:f382:64ea:c32b]) by smtp.gmail.com with ESMTPSA id gr6-20020a056a004d0600b006ed1ea5219csm21449143pfb.130.2024.04.30.12.27.42 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 30 Apr 2024 12:27:43 -0700 (PDT) From: Adhemerval Zanella To: libc-alpha@sourceware.org Cc: Joe Simmons-Talbott , Siddhesh Poyarekar Subject: [PATCH 0/4] More tunable fixes Date: Tue, 30 Apr 2024 16:25:01 -0300 Message-ID: <20240430192739.1032549-1-adhemerval.zanella@linaro.org> X-Mailer: git-send-email 2.43.0 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Spam-Status: No, score=-5.8 required=5.0 tests=BAYES_00,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_NONE,SPF_HELO_NONE,SPF_PASS,TXREP autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on server2.sourceware.org List-Id: The 680c597e9c3 commit made loader reject ill-formatted strings by first tracking all set tunables and then applying them. However, it does not take into consideration if the same tunable is set multiple times, where parse_tunables_string appends the found tunable without checking if it was already in the list. It leads to a stack-based buffer overflow if the tunable is specified more than the total number of tunables (BZ 31686). While fixing this issue, I noted that the new glibc.rtld.enable_secure check could be optimized a bit to avoid the string comparison on the tunable loop. I also found an issue where it does have the handle case where the environment alias is handled before the GLIBC_TUNABLES, which will change the tunable even if glibc.rtld.enable_secureĀ it set to 0. Fixing it allows us to optimize the environment alias parsing a bit, since only tunable with aliases need to be checked (instead of the whole list). Adhemerval Zanella (4): elf: Only process multiple tunable once (BZ 31686) elf: Remove glibc.rtld.enable_secure check from parse_tunables_string support: Add envp argument to support_capture_subprogram elf: Make glibc.rtld.enable_secure ignore alias environment variables elf/dl-tunables.c | 112 ++++++++++++------ elf/tst-audit18.c | 2 +- elf/tst-audit19b.c | 2 +- elf/tst-audit22.c | 2 +- elf/tst-audit23.c | 2 +- elf/tst-audit25a.c | 4 +- elf/tst-audit25b.c | 4 +- elf/tst-glibc-hwcaps-2-cache.c | 2 +- elf/tst-rtld-run-static.c | 4 +- elf/tst-tunables-enable_secure.c | 131 ++++++++++++++++++--- elf/tst-tunables.c | 61 +++++++++- scripts/gen-tunables.awk | 64 +++++++--- support/capture_subprocess.h | 9 +- support/subprocess.h | 7 +- support/support_capture_subprocess.c | 5 +- support/support_subprocess.c | 5 +- support/tst-support_capture_subprocess.c | 2 +- sysdeps/aarch64/multiarch/memset_generic.S | 4 + sysdeps/sparc/sparc64/rtld-memset.c | 3 + sysdeps/x86/tst-hwcap-tunables.c | 2 +- 20 files changed, 333 insertions(+), 94 deletions(-) -- 2.43.0