From: Adhemerval Zanella <adhemerval.zanella@linaro.org>
To: Florian Weimer <fweimer@redhat.com>
Cc: libc-alpha@sourceware.org, John Mellor-Crummey <johnmc@rice.edu>,
Ben Woodard <woodard@redhat.com>,
Vivek Das Mohapatra <vivek@collabora.com>
Subject: Re: [PATCH v5 04/22] elf: Suppress audit calls when a (new) namespace is empty (BZ #28062)
Date: Thu, 11 Nov 2021 09:25:29 -0300 [thread overview]
Message-ID: <eb435cb7-7c9c-fdb8-07d5-e7378fc12221@linaro.org> (raw)
In-Reply-To: <87o86qzyrk.fsf@oldenburg.str.redhat.com>
On 11/11/2021 09:02, Florian Weimer wrote:
> * Adhemerval Zanella:
>
>> On 10/11/2021 11:15, Florian Weimer wrote:
>>> * Adhemerval Zanella:
>>>
>>>> diff --git a/elf/dl-load.c b/elf/dl-load.c
>>>> index 9f4fa9617d..72298776f6 100644
>>>> --- a/elf/dl-load.c
>>>> +++ b/elf/dl-load.c
>>>> @@ -1067,8 +1067,11 @@ _dl_map_object_from_fd (const char *name, const char *origname, int fd,
>>>> && __glibc_unlikely (GLRO(dl_naudit) > 0))
>>>> {
>>>> struct link_map *head = GL(dl_ns)[nsid]._ns_loaded;
>>>> - /* Do not call the functions for any auditing object. */
>>>> - if (head->l_auditing == 0)
>>>> + /* Do not call the functions for any auditing object and also do not
>>>> + try to call auditing functions if the namespace is currently
>>>> + empty. This happens when opening the first DSO in a new
>>>> + namespace. */
>>>> + if (head != NULL && head->l_auditing == 0)
>>>> {
>>>> struct audit_ifaces *afct = GLRO(dl_audit);
>>>> for (unsigned int cnt = 0; cnt < GLRO(dl_naudit); ++cnt)
>>>
>>> As far as I can tell, using GL(dl_ns)[nsid]._ns_loaded for la_activity
>>> is a completely arbitrary choice. I think we should use
>>> &GL(dl_ns)[nsid] for secondary namespace instead, and keep
>>> GL(dl_ns)[LM_ID_BASE]._ns_loaded for backwards compatibility.
>>>
>>> This will allow us to generate an LA_ACT_ADD event for an empty
>>> namespace.
>>
>> I am not really following you here, '&GL(dl_ns)[nsid]' is just the container
>> here, we need to iterate over the 'link_maps' within it.
>
> Hmm. I had a peeked at the Solaris documentation, and it says that
> LA_ACT_ADD uses the head link map of the namespace as a cookie.
>
> I really dislike that we produce a LA_ACT_DELETE without the
> corresponding LA_ACT_ADD due to this issue.
>
> Can we use the link map allocated used _dl_new_object as the cookie if
> the namespace is empty? This seems like the right thing to do here.
> The allocation happens just a few lines further down.
But afaiu the LA_ACT_ADD activity is to inform already loaded objects
that a new object is being processed. Both man-pages and Solaris
documentation states 'objects are *being added*...', so I think passing
the cookie of the new allocated is not what the interface is suppose
to do.
next prev parent reply other threads:[~2021-11-11 12:25 UTC|newest]
Thread overview: 57+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-11-09 18:33 [PATCH v5 00/22] Multiple rtld-audit fixes Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 01/22] elf: Avoid unnecessary slowdown from profiling with audit (BZ#15533) Adhemerval Zanella
2021-11-10 12:11 ` Florian Weimer
2021-11-10 19:53 ` Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 02/22] elf: Add audit tests for modules with TLSDESC Adhemerval Zanella
2021-11-10 13:55 ` Florian Weimer
2021-11-11 19:18 ` Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 03/22] elf: Do not fail for failed dlopem on audit modules (BZ #28061) Adhemerval Zanella
2021-11-09 18:51 ` H.J. Lu
2021-11-11 17:24 ` Adhemerval Zanella
2021-11-10 14:00 ` Florian Weimer
2021-11-11 17:29 ` Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 04/22] elf: Suppress audit calls when a (new) namespace is empty (BZ #28062) Adhemerval Zanella
2021-11-10 14:15 ` Florian Weimer
2021-11-11 11:51 ` Adhemerval Zanella
2021-11-11 12:02 ` Florian Weimer
2021-11-11 12:25 ` Adhemerval Zanella [this message]
2021-11-11 12:33 ` Florian Weimer
2021-11-11 13:02 ` Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 05/22] elf: Fix initial-exec TLS access on audit modules (BZ #28096) Adhemerval Zanella
2021-11-10 13:23 ` Florian Weimer
2021-11-11 18:54 ` Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 06/22] elf: Add _dl_audit_objopen Adhemerval Zanella
2021-11-10 16:51 ` Florian Weimer
2021-11-09 18:33 ` [PATCH v5 07/22] elf: Add _dl_audit_activity_map and _dl_audit_activity_nsid Adhemerval Zanella
2021-11-10 16:59 ` Florian Weimer
2021-11-09 18:33 ` [PATCH v5 08/22] elf: Add _dl_audit_objsearch Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 09/22] elf: Add _dl_audit_objclose Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 10/22] elf: Add _dl_audit_symbind_alt and _dl_audit_symbind Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 11/22] elf: Add _dl_audit_preinit Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 12/22] elf: Add _dl_audit_pltenter Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 13/22] elf: Add _dl_audit_pltexit Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 14/22] elf: Issue audit la_objopen() for vDSO Adhemerval Zanella
2021-11-11 17:50 ` Florian Weimer
2021-11-11 20:16 ` Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 15/22] elf: Run constructors if executable has a soname of a dependency Adhemerval Zanella
2021-11-11 12:30 ` Florian Weimer
2021-11-12 19:02 ` Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 16/22] elf: Add main application on main_map l_name Adhemerval Zanella
2021-11-11 12:39 ` Florian Weimer
2021-11-12 19:30 ` Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 17/22] elf: Add la_activity during application exit Adhemerval Zanella
2021-11-11 12:50 ` Florian Weimer
2021-11-12 19:32 ` Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 18/22] elf: Issue la_symbind() for bind-now (BZ #23734) Adhemerval Zanella
2021-11-11 17:39 ` Florian Weimer
2021-11-15 14:20 ` Adhemerval Zanella
2021-11-15 14:23 ` Florian Weimer
2021-11-15 15:54 ` Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 19/22] elf: Add LA_SYMB_BINDNOW Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 20/22] elf: Move LAV_CURRENT to link_lavcurrent.h Adhemerval Zanella
2021-11-11 17:42 ` Florian Weimer
2021-11-15 14:21 ` Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 21/22] elf: Fix runtime linker auditing on aarch64 (BZ #26643) Adhemerval Zanella
2021-11-09 18:33 ` [RFC v5 22/22] elf: Add SVE support for aarch64 rtld-audit Adhemerval Zanella
2021-11-10 13:52 ` Florian Weimer
2021-11-15 17:04 ` Adhemerval Zanella
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=eb435cb7-7c9c-fdb8-07d5-e7378fc12221@linaro.org \
--to=adhemerval.zanella@linaro.org \
--cc=fweimer@redhat.com \
--cc=johnmc@rice.edu \
--cc=libc-alpha@sourceware.org \
--cc=vivek@collabora.com \
--cc=woodard@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).