From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by sourceware.org (Postfix) with ESMTPS id 1AFFB3857818 for ; Fri, 10 Dec 2021 14:59:02 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.1 sourceware.org 1AFFB3857818 Received: from mimecast-mx01.redhat.com (mimecast-mx01.redhat.com [209.132.183.4]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id us-mta-197-5cBX-b69PdeNjvUnOYnhlQ-1; Fri, 10 Dec 2021 09:58:58 -0500 X-MC-Unique: 5cBX-b69PdeNjvUnOYnhlQ-1 Received: from smtp.corp.redhat.com (int-mx07.intmail.prod.int.phx2.redhat.com [10.5.11.22]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mimecast-mx01.redhat.com (Postfix) with ESMTPS id 93DE081EE62; Fri, 10 Dec 2021 14:58:57 +0000 (UTC) Received: from oldenburg.str.redhat.com (unknown [10.39.193.123]) by smtp.corp.redhat.com (Postfix) with ESMTPS id E92F11009AF8; Fri, 10 Dec 2021 14:58:56 +0000 (UTC) From: Florian Weimer To: "H.J. Lu" Cc: libc-alpha@sourceware.org Subject: Re: [PATCH v4] elf: Only allow execute libc.so.6 directly [BZ #28453] References: <20211210145220.3750010-1-hjl.tools@gmail.com> Date: Fri, 10 Dec 2021 15:58:55 +0100 In-Reply-To: <20211210145220.3750010-1-hjl.tools@gmail.com> (H. J. Lu's message of "Fri, 10 Dec 2021 06:52:20 -0800") Message-ID: <87r1ak7bgw.fsf@oldenburg.str.redhat.com> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.2 (gnu/linux) MIME-Version: 1.0 X-Scanned-By: MIMEDefang 2.84 on 10.5.11.22 X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com Content-Type: text/plain X-Spam-Status: No, score=-5.8 required=5.0 tests=BAYES_00, DKIMWL_WL_HIGH, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, RCVD_IN_DNSWL_LOW, RCVD_IN_MSPIKE_H3, RCVD_IN_MSPIKE_WL, SPF_HELO_NONE, SPF_NONE, TXREP, URIBL_BLACK autolearn=ham autolearn_force=no version=3.4.4 X-Spam-Checker-Version: SpamAssassin 3.4.4 (2020-01-24) on server2.sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 10 Dec 2021 14:59:03 -0000 * H. J. Lu: > + /* With DT_NEEDED dependencies, it is a shared library. Only allow > + execute libc.so directly. */ > + if (__glibc_unlikely (main_map->l_info[DT_NEEDED] != NULL)) > + return (main_map->l_info[DT_SONAME] != NULL > + && strncmp ("libc.so.6", > + ((const char *) D_PTR (main_map, l_info[DT_STRTAB]) > + + main_map->l_info[DT_SONAME]->d_un.d_val), > + sizeof ("libc.so.6") - 1) == 0); I don't think this works. See /usr/bin/npc in Fedora, it has a soname. Thanks, Florian