public inbox for libc-alpha@sourceware.org
 help / color / mirror / Atom feed
* [PATCH v5 00/22] Multiple rtld-audit fixes
@ 2021-11-09 18:33 Adhemerval Zanella
  2021-11-09 18:33 ` [PATCH v5 01/22] elf: Avoid unnecessary slowdown from profiling with audit (BZ#15533) Adhemerval Zanella
                   ` (21 more replies)
  0 siblings, 22 replies; 57+ messages in thread
From: Adhemerval Zanella @ 2021-11-09 18:33 UTC (permalink / raw)
  To: libc-alpha, Florian Weimer; +Cc: John Mellor-Crummey, Ben Woodard

This patchset fixes most of the rtld-audit issues brought by John
Mellor-Crummey [1] while trying to use it along with the HPCToolkit.
This should cover all the issues listed as 'Tier 1' [2] (although the
aarch64 SVE is marked as RFC) and also most of the 'Tier2' issue
(BZ#28096 inclusive) which prevents the use of some glibc function
that uses TLS internally on the audit module.

On this set I also added a possible fix for the aarch64 SVE, although
there is some issues regarding STO_AARCH64_VARIANT_PCS.

I also pushed this patch on a personal branch [3].

There is also some point brough by John Melloc-Crummey documents that
I don't have a straighforward answer so I haven't added on this
patchset:

  1 la_activity(LA_ACT_ADD) is never called for auditor namespaces,
     even though la_objopen and la_activity(LA_ACT_CONSISTENT) are.

  There is no easy solution for this: we need at least to load the
  *first* auditor to actually issue the la_activity(LA_ACT_ADD).  It
  means that it would *only* work for subsequent audit modules, and
  adding this specific semantic is confusing and does not really
  improve things (it only helps when multiple audit modules are used).

  2. la_objopen is called for the main binary and for ld.so before the
     first la_activity(LA_ACT_ADD) call.  This contradicts the pattern
     found in a successful dlopen (where la_activity(LA_ACT_ADD)
     precedes la_objopen).

  The constrain here is we need to handle DT_AUDIT and DT_DEPAUDIT
  dynamic tags, which means we need to first load the executable in
  memory to parse the required audit modules.  So we need to first parse
  the dynamic audit tags, load the audit modules, and then load the
  object itself.

  3. For non-PIE executables the base address listed in link_map->l_addr
     for the main application binary is 0, even though dladdr is able to
     recover the correct offset. La_objopen is affected by this.

  This would require to change an internal semantic for link_map->l_addr.
  This is not straighfoward and I am not sure about the direct gains.

I have checked the patches on x86_64, i686, aarch64, armv7, powerpc64,
powerpc64le, and powerpc.

[1] https://sourceware.org/pipermail/libc-alpha/2021-June/127636.html
[2] https://docs.google.com/document/d/1dVaDBdzySecxQqD6hLLzDrEF18M1UtjDna9gL5BWWI0/edit#
[3] https://sourceware.org/git/?p=glibc.git;a=shortlog;h=refs/heads/azanella/ld-audit-fixes

Changes from v4:
  - Added a fix for constructors if executable has a soname of a
    dependency
  - Rebased against master.

Changes from v3
  - Added a aarch64 SVE RFC patch.
  - Fixed an issue with bind-now fix on powerpc64 ELFv1.
  - Rebased against master.

Changes from v2
  - Refactored rtld-audit code to move common come to dl-audit.c.
  - Issue audit la_objopen() for vDSO.
  - Isseu la_activity during application exit.
  - Issue la_symbind() for bind-now (BZ #23734).
  - Fix runtime linker auditing on aarch64 (BZ #26643)

Changes from v1
  - Fixed -fstack-protector-all tst-auditmod17.
  - Simplify the _dl_call_libc_early_init call the 'Fix audit
    regression' patch.
  - Remove symbind check fr BZ#15333.
  - Added the BZ#28096 fix.

Adhemerval Zanella (20):
  elf: Avoid unnecessary slowdown from profiling with audit (BZ#15533)
  elf: Add audit tests for modules with TLSDESC
  elf: Do not fail for failed dlopem on audit modules (BZ #28061)
  elf: Fix initial-exec TLS access on audit modules (BZ #28096)
  elf: Add _dl_audit_objopen
  elf: Add _dl_audit_activity_map and _dl_audit_activity_nsid
  elf: Add _dl_audit_objsearch
  elf: Add _dl_audit_objclose
  elf: Add _dl_audit_symbind_alt and _dl_audit_symbind
  elf: Add _dl_audit_preinit
  elf: Add _dl_audit_pltenter
  elf: Add _dl_audit_pltexit
  elf: Issue audit la_objopen() for vDSO
  elf: Run constructors if executable has a soname of a dependency
  elf: Add main application on main_map l_name
  elf: Add la_activity during application exit
  elf: Issue la_symbind() for bind-now (BZ #23734)
  elf: Add LA_SYMB_BINDNOW
  elf: Move LAV_CURRENT to link_lavcurrent.h
  elf: Add SVE support for aarch64 rtld-audit

Ben Woodard (1):
  elf: Fix runtime linker auditing on aarch64 (BZ #26643)

Vivek Das Mohapatra (1):
  elf: Suppress audit calls when a (new) namespace is empty (BZ #28062)

 NEWS                                      |   4 +
 bits/link_lavcurrent.h                    |  25 ++
 csu/libc-start.c                          |  23 +-
 dlfcn/Makefile                            |   4 +-
 dlfcn/tst-dladdr-self.c                   |  55 +++
 elf/Makefile                              | 126 ++++++-
 elf/Versions                              |   1 +
 elf/dl-addr.c                             |   5 -
 elf/dl-audit.c                            | 394 ++++++++++++++++++++++
 elf/dl-close.c                            |  74 +---
 elf/dl-dst.h                              |   2 +-
 elf/dl-fini.c                             |  25 +-
 elf/dl-init.c                             |   3 +-
 elf/dl-load.c                             | 112 ++----
 elf/dl-misc.c                             |   1 +
 elf/dl-object.c                           |  20 +-
 elf/dl-open.c                             |  22 +-
 elf/dl-reloc.c                            |  26 +-
 elf/dl-runtime.c                          | 244 ++------------
 elf/dl-sym-post.h                         |  47 +--
 elf/dl-tls.c                              |  16 +-
 elf/do-rel.h                              |  71 +++-
 elf/dso-sort-tests-1.def                  |   5 +-
 elf/dynamic-link.h                        |  26 +-
 elf/link.h                                |   7 +-
 elf/rtld.c                                |  81 +----
 elf/setup-vdso.h                          |   2 +-
 elf/tst-audit-tlsdesc-audit.c             |  23 ++
 elf/tst-audit-tlsdesc-dlopen.c            |  67 ++++
 elf/tst-audit-tlsdesc.c                   |  60 ++++
 elf/tst-audit18a.c                        |  39 +++
 elf/tst-audit18b.c                        |  94 ++++++
 elf/tst-audit18bmod.c                     |  23 ++
 elf/tst-audit18mod.c                      |  17 +
 elf/tst-audit19.c                         |  25 ++
 elf/tst-audit20.c                         | 129 +++++++
 elf/tst-audit20mod.c                      |  26 ++
 elf/tst-audit21.c                         |  42 +++
 elf/tst-audit22.c                         | 123 +++++++
 elf/tst-audit23.c                         | 161 +++++++++
 elf/tst-audit23mod.c                      |  23 ++
 elf/tst-audit24a.c                        |  36 ++
 elf/tst-audit24amod1.c                    |  31 ++
 elf/tst-audit24amod2.c                    |  25 ++
 elf/tst-audit24b.c                        |  37 ++
 elf/tst-audit24bmod1.c                    |  31 ++
 elf/tst-audit24bmod2.c                    |  23 ++
 elf/tst-audit24c.c                        |   2 +
 elf/tst-audit24d.c                        |  36 ++
 elf/tst-audit24dmod1.c                    |  33 ++
 elf/tst-audit24dmod2.c                    |  28 ++
 elf/tst-audit24dmod3.c                    |  31 ++
 elf/tst-audit24dmod4.c                    |  25 ++
 elf/tst-audit25a.c                        | 126 +++++++
 elf/tst-audit25b.c                        | 127 +++++++
 elf/tst-audit25mod1.c                     |  30 ++
 elf/tst-audit25mod2.c                     |  30 ++
 elf/tst-audit25mod3.c                     |  22 ++
 elf/tst-audit25mod4.c                     |  22 ++
 elf/tst-auditmod-tlsdesc1.c               |  41 +++
 elf/tst-auditmod-tlsdesc2.c               |  33 ++
 elf/tst-auditmod18a.c                     |  23 ++
 elf/tst-auditmod18b.c                     |  46 +++
 elf/tst-auditmod19.c                      |  57 ++++
 elf/tst-auditmod20.c                      |  73 ++++
 elf/tst-auditmod21.c                      |  69 ++++
 elf/tst-auditmod22.c                      |  65 ++++
 elf/tst-auditmod23.c                      |  78 +++++
 elf/tst-auditmod24a.c                     | 104 ++++++
 elf/tst-auditmod24b.c                     |  99 ++++++
 elf/tst-auditmod24c.c                     |   3 +
 elf/tst-auditmod24d.c                     | 114 +++++++
 elf/tst-auditmod25.c                      |  77 +++++
 gmon/gmon.c                               |  10 +-
 include/dlfcn.h                           |   1 +
 include/link.h                            |   4 +
 sysdeps/aarch64/Makefile                  |  32 ++
 sysdeps/aarch64/bits/link.h               |  28 +-
 sysdeps/aarch64/bits/link_lavcurrent.h    |  25 ++
 sysdeps/aarch64/dl-link.sym               |   7 +-
 sysdeps/aarch64/dl-machine.h              |  14 +-
 sysdeps/aarch64/dl-trampoline.S           | 391 +++++++++++++++++++--
 sysdeps/aarch64/tst-audit26.c             |  37 ++
 sysdeps/aarch64/tst-audit26mod.c          |  33 ++
 sysdeps/aarch64/tst-audit26mod.h          |  50 +++
 sysdeps/aarch64/tst-audit27.c             |  64 ++++
 sysdeps/aarch64/tst-audit27mod.c          |  95 ++++++
 sysdeps/aarch64/tst-audit27mod.h          |  67 ++++
 sysdeps/aarch64/tst-audit28.c             |  44 +++
 sysdeps/aarch64/tst-audit28mod.c          |  48 +++
 sysdeps/aarch64/tst-audit28mod.h          |  74 ++++
 sysdeps/aarch64/tst-auditmod26.c          |  98 ++++++
 sysdeps/aarch64/tst-auditmod27.c          | 252 ++++++++++++++
 sysdeps/aarch64/tst-auditmod28.c          | 193 +++++++++++
 sysdeps/alpha/dl-machine.h                |   2 +-
 sysdeps/alpha/dl-trampoline.S             |   8 +-
 sysdeps/arc/dl-machine.h                  |   2 +-
 sysdeps/arm/dl-machine.h                  |   2 +-
 sysdeps/arm/dl-trampoline.S               |   2 +-
 sysdeps/csky/dl-machine.h                 |   2 +-
 sysdeps/generic/dl-fixup-attribute.h      |  24 ++
 sysdeps/generic/dl-lookupcfg.h            |   1 +
 sysdeps/generic/ldsodefs.h                |  30 ++
 sysdeps/hppa/dl-machine.h                 |   2 +-
 sysdeps/hppa/dl-runtime.c                 |   2 +-
 sysdeps/hppa/dl-trampoline.S              |   6 +-
 sysdeps/i386/dl-fixup-attribute.h         |  30 ++
 sysdeps/i386/dl-machine.h                 |  25 +-
 sysdeps/i386/dl-trampoline.S              |   2 +-
 sysdeps/ia64/dl-machine.h                 |   2 +-
 sysdeps/ia64/dl-trampoline.S              |  16 +-
 sysdeps/m68k/dl-machine.h                 |   2 +-
 sysdeps/m68k/dl-trampoline.S              |   2 +-
 sysdeps/microblaze/dl-machine.h           |   2 +-
 sysdeps/mips/dl-machine.h                 |   2 +-
 sysdeps/nios2/dl-machine.h                |   2 +-
 sysdeps/powerpc/dl-lookupcfg.h            |  30 ++
 sysdeps/powerpc/powerpc32/dl-machine.h    |   2 +-
 sysdeps/powerpc/powerpc64/dl-machine.h    |   2 +-
 sysdeps/powerpc/powerpc64/dl-trampoline.S |   4 +-
 sysdeps/riscv/dl-machine.h                |   2 +-
 sysdeps/s390/s390-32/dl-machine.h         |   2 +-
 sysdeps/s390/s390-32/dl-trampoline.h      |   4 +-
 sysdeps/s390/s390-64/dl-machine.h         |   2 +-
 sysdeps/s390/s390-64/dl-trampoline.h      |   2 +-
 sysdeps/sh/dl-machine.h                   |   2 +-
 sysdeps/sh/dl-trampoline.S                |   4 +-
 sysdeps/sparc/sparc32/dl-machine.h        |   2 +-
 sysdeps/sparc/sparc32/dl-trampoline.S     |   2 +-
 sysdeps/sparc/sparc64/dl-machine.h        |   2 +-
 sysdeps/sparc/sparc64/dl-trampoline.S     |   2 +-
 sysdeps/x86_64/dl-machine.h               |   2 +-
 sysdeps/x86_64/dl-runtime.h               |   2 +-
 sysdeps/x86_64/dl-trampoline.h            |   6 +-
 134 files changed, 4941 insertions(+), 718 deletions(-)
 create mode 100644 bits/link_lavcurrent.h
 create mode 100644 dlfcn/tst-dladdr-self.c
 create mode 100644 elf/dl-audit.c
 create mode 100644 elf/tst-audit-tlsdesc-audit.c
 create mode 100644 elf/tst-audit-tlsdesc-dlopen.c
 create mode 100644 elf/tst-audit-tlsdesc.c
 create mode 100644 elf/tst-audit18a.c
 create mode 100644 elf/tst-audit18b.c
 create mode 100644 elf/tst-audit18bmod.c
 create mode 100644 elf/tst-audit18mod.c
 create mode 100644 elf/tst-audit19.c
 create mode 100644 elf/tst-audit20.c
 create mode 100644 elf/tst-audit20mod.c
 create mode 100644 elf/tst-audit21.c
 create mode 100644 elf/tst-audit22.c
 create mode 100644 elf/tst-audit23.c
 create mode 100644 elf/tst-audit23mod.c
 create mode 100644 elf/tst-audit24a.c
 create mode 100644 elf/tst-audit24amod1.c
 create mode 100644 elf/tst-audit24amod2.c
 create mode 100644 elf/tst-audit24b.c
 create mode 100644 elf/tst-audit24bmod1.c
 create mode 100644 elf/tst-audit24bmod2.c
 create mode 100644 elf/tst-audit24c.c
 create mode 100644 elf/tst-audit24d.c
 create mode 100644 elf/tst-audit24dmod1.c
 create mode 100644 elf/tst-audit24dmod2.c
 create mode 100644 elf/tst-audit24dmod3.c
 create mode 100644 elf/tst-audit24dmod4.c
 create mode 100644 elf/tst-audit25a.c
 create mode 100644 elf/tst-audit25b.c
 create mode 100644 elf/tst-audit25mod1.c
 create mode 100644 elf/tst-audit25mod2.c
 create mode 100644 elf/tst-audit25mod3.c
 create mode 100644 elf/tst-audit25mod4.c
 create mode 100644 elf/tst-auditmod-tlsdesc1.c
 create mode 100644 elf/tst-auditmod-tlsdesc2.c
 create mode 100644 elf/tst-auditmod18a.c
 create mode 100644 elf/tst-auditmod18b.c
 create mode 100644 elf/tst-auditmod19.c
 create mode 100644 elf/tst-auditmod20.c
 create mode 100644 elf/tst-auditmod21.c
 create mode 100644 elf/tst-auditmod22.c
 create mode 100644 elf/tst-auditmod23.c
 create mode 100644 elf/tst-auditmod24a.c
 create mode 100644 elf/tst-auditmod24b.c
 create mode 100644 elf/tst-auditmod24c.c
 create mode 100644 elf/tst-auditmod24d.c
 create mode 100644 elf/tst-auditmod25.c
 create mode 100644 sysdeps/aarch64/bits/link_lavcurrent.h
 create mode 100644 sysdeps/aarch64/tst-audit26.c
 create mode 100644 sysdeps/aarch64/tst-audit26mod.c
 create mode 100644 sysdeps/aarch64/tst-audit26mod.h
 create mode 100644 sysdeps/aarch64/tst-audit27.c
 create mode 100644 sysdeps/aarch64/tst-audit27mod.c
 create mode 100644 sysdeps/aarch64/tst-audit27mod.h
 create mode 100644 sysdeps/aarch64/tst-audit28.c
 create mode 100644 sysdeps/aarch64/tst-audit28mod.c
 create mode 100644 sysdeps/aarch64/tst-audit28mod.h
 create mode 100644 sysdeps/aarch64/tst-auditmod26.c
 create mode 100644 sysdeps/aarch64/tst-auditmod27.c
 create mode 100644 sysdeps/aarch64/tst-auditmod28.c
 create mode 100644 sysdeps/generic/dl-fixup-attribute.h
 create mode 100644 sysdeps/i386/dl-fixup-attribute.h
 create mode 100644 sysdeps/powerpc/dl-lookupcfg.h

-- 
2.32.0


^ permalink raw reply	[flat|nested] 57+ messages in thread

end of thread, other threads:[~2021-11-15 17:04 UTC | newest]

Thread overview: 57+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-11-09 18:33 [PATCH v5 00/22] Multiple rtld-audit fixes Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 01/22] elf: Avoid unnecessary slowdown from profiling with audit (BZ#15533) Adhemerval Zanella
2021-11-10 12:11   ` Florian Weimer
2021-11-10 19:53     ` Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 02/22] elf: Add audit tests for modules with TLSDESC Adhemerval Zanella
2021-11-10 13:55   ` Florian Weimer
2021-11-11 19:18     ` Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 03/22] elf: Do not fail for failed dlopem on audit modules (BZ #28061) Adhemerval Zanella
2021-11-09 18:51   ` H.J. Lu
2021-11-11 17:24     ` Adhemerval Zanella
2021-11-10 14:00   ` Florian Weimer
2021-11-11 17:29     ` Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 04/22] elf: Suppress audit calls when a (new) namespace is empty (BZ #28062) Adhemerval Zanella
2021-11-10 14:15   ` Florian Weimer
2021-11-11 11:51     ` Adhemerval Zanella
2021-11-11 12:02       ` Florian Weimer
2021-11-11 12:25         ` Adhemerval Zanella
2021-11-11 12:33           ` Florian Weimer
2021-11-11 13:02             ` Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 05/22] elf: Fix initial-exec TLS access on audit modules (BZ #28096) Adhemerval Zanella
2021-11-10 13:23   ` Florian Weimer
2021-11-11 18:54     ` Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 06/22] elf: Add _dl_audit_objopen Adhemerval Zanella
2021-11-10 16:51   ` Florian Weimer
2021-11-09 18:33 ` [PATCH v5 07/22] elf: Add _dl_audit_activity_map and _dl_audit_activity_nsid Adhemerval Zanella
2021-11-10 16:59   ` Florian Weimer
2021-11-09 18:33 ` [PATCH v5 08/22] elf: Add _dl_audit_objsearch Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 09/22] elf: Add _dl_audit_objclose Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 10/22] elf: Add _dl_audit_symbind_alt and _dl_audit_symbind Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 11/22] elf: Add _dl_audit_preinit Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 12/22] elf: Add _dl_audit_pltenter Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 13/22] elf: Add _dl_audit_pltexit Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 14/22] elf: Issue audit la_objopen() for vDSO Adhemerval Zanella
2021-11-11 17:50   ` Florian Weimer
2021-11-11 20:16     ` Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 15/22] elf: Run constructors if executable has a soname of a dependency Adhemerval Zanella
2021-11-11 12:30   ` Florian Weimer
2021-11-12 19:02     ` Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 16/22] elf: Add main application on main_map l_name Adhemerval Zanella
2021-11-11 12:39   ` Florian Weimer
2021-11-12 19:30     ` Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 17/22] elf: Add la_activity during application exit Adhemerval Zanella
2021-11-11 12:50   ` Florian Weimer
2021-11-12 19:32     ` Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 18/22] elf: Issue la_symbind() for bind-now (BZ #23734) Adhemerval Zanella
2021-11-11 17:39   ` Florian Weimer
2021-11-15 14:20     ` Adhemerval Zanella
2021-11-15 14:23       ` Florian Weimer
2021-11-15 15:54         ` Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 19/22] elf: Add LA_SYMB_BINDNOW Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 20/22] elf: Move LAV_CURRENT to link_lavcurrent.h Adhemerval Zanella
2021-11-11 17:42   ` Florian Weimer
2021-11-15 14:21     ` Adhemerval Zanella
2021-11-09 18:33 ` [PATCH v5 21/22] elf: Fix runtime linker auditing on aarch64 (BZ #26643) Adhemerval Zanella
2021-11-09 18:33 ` [RFC v5 22/22] elf: Add SVE support for aarch64 rtld-audit Adhemerval Zanella
2021-11-10 13:52   ` Florian Weimer
2021-11-15 17:04     ` Adhemerval Zanella

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).