olga / rpms / glibc

Forked from rpms/glibc 5 years ago
Clone
00db10
commit 68448be208ee06e76665918b37b0a57e3e00c8b4
00db10
Author: Adhemerval Zanella <adhemerval.zanella@linaro.org>
00db10
Date:   Fri Nov 17 16:04:29 2017 -0200
00db10
00db10
    i386: Fix i386 sigaction sa_restorer initialization (BZ#21269)
00db10
    
00db10
    This patch fixes the i386 sa_restorer field initialization for sigaction
00db10
    syscall for kernel with vDSO.  As described in bug report, i386 Linux
00db10
    (and compat on x86_64) interprets SA_RESTORER clear with nonzero
00db10
    sa_restorer as a request for stack switching if the SS segment is 'funny'.
00db10
    This means that anything that tries to mix glibc's signal handling with
00db10
    segmentation (for instance through modify_ldt syscall) is randomly broken
00db10
    depending on what values lands in sa_restorer.
00db10
    
00db10
    The testcase added  is based on Linux test tools/testing/selftests/x86/ldt_gdt.c,
00db10
    more specifically in do_multicpu_tests function.  The main changes are:
00db10
    
00db10
      - C11 atomics instead of plain access.
00db10
    
00db10
      - Remove x86_64 support which simplifies the syscall handling and fallbacks.
00db10
    
00db10
      - Replicate only the test required to trigger the issue.
00db10
    
00db10
    Checked on i686-linux-gnu.
00db10
    
00db10
            [BZ #21269]
00db10
            * sysdeps/unix/sysv/linux/i386/Makefile (tests): Add tst-bz21269.
00db10
            * sysdeps/unix/sysv/linux/i386/sigaction.c (SET_SA_RESTORER): Clear
00db10
            sa_restorer for vDSO case.
00db10
            * sysdeps/unix/sysv/linux/i386/tst-bz21269.c: New file.
00db10
00db10
(Adjusted for conflicted in sysdeps/unix/sysv/linux/i386/Makefile due
00db10
different context around the addition of the new test.)
00db10
00db10
diff --git a/sysdeps/unix/sysv/linux/i386/Makefile b/sysdeps/unix/sysv/linux/i386/Makefile
00db10
index acc30219e8dc965f..78e2101682d8d996 100644
00db10
--- a/sysdeps/unix/sysv/linux/i386/Makefile
00db10
+++ b/sysdeps/unix/sysv/linux/i386/Makefile
00db10
@@ -3,6 +3,9 @@ default-abi := 32
00db10
 
00db10
 ifeq ($(subdir),misc)
00db10
 sysdep_routines += ioperm iopl vm86 call_pselect6 call_fallocate
00db10
+
00db10
+tests += tst-bz21269
00db10
+$(objpfx)tst-bz21269: $(shared-thread-library)
00db10
 endif
00db10
 
00db10
 ifeq ($(subdir),elf)
00db10
diff --git a/sysdeps/unix/sysv/linux/i386/sigaction.c b/sysdeps/unix/sysv/linux/i386/sigaction.c
00db10
index 414ef759a97363c4..f10e1363865c3d18 100644
00db10
--- a/sysdeps/unix/sysv/linux/i386/sigaction.c
00db10
+++ b/sysdeps/unix/sysv/linux/i386/sigaction.c
00db10
@@ -44,7 +44,6 @@ extern void restore_rt (void) asm ("__restore_rt") attribute_hidden;
00db10
 #endif
00db10
 extern void restore (void) asm ("__restore") attribute_hidden;
00db10
 
00db10
-
00db10
 /* If ACT is not NULL, change the action for SIG to *ACT.
00db10
    If OACT is not NULL, put the old action for SIG in *OACT.  */
00db10
 int
00db10
@@ -67,6 +66,8 @@ __libc_sigaction (int sig, const struct sigaction *act, struct sigaction *oact)
00db10
 	  kact.sa_restorer = ((act->sa_flags & SA_SIGINFO)
00db10
 			      ? &restore_rt : &restore);
00db10
 	}
00db10
+      else
00db10
+	kact.sa_restorer = NULL;
00db10
     }
00db10
 
00db10
   /* XXX The size argument hopefully will have to be changed to the
00db10
diff --git a/sysdeps/unix/sysv/linux/i386/tst-bz21269.c b/sysdeps/unix/sysv/linux/i386/tst-bz21269.c
00db10
new file mode 100644
00db10
index 0000000000000000..353e36507dce92ea
00db10
--- /dev/null
00db10
+++ b/sysdeps/unix/sysv/linux/i386/tst-bz21269.c
00db10
@@ -0,0 +1,233 @@
00db10
+/* Test for i386 sigaction sa_restorer handling (BZ#21269)
00db10
+   Copyright (C) 2017 Free Software Foundation, Inc.
00db10
+   This file is part of the GNU C Library.
00db10
+
00db10
+   The GNU C Library is free software; you can redistribute it and/or
00db10
+   modify it under the terms of the GNU Lesser General Public
00db10
+   License as published by the Free Software Foundation; either
00db10
+   version 2.1 of the License, or (at your option) any later version.
00db10
+
00db10
+   The GNU C Library is distributed in the hope that it will be useful,
00db10
+   but WITHOUT ANY WARRANTY; without even the implied warranty of
00db10
+   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
00db10
+   Lesser General Public License for more details.
00db10
+
00db10
+   You should have received a copy of the GNU Lesser General Public
00db10
+   License along with the GNU C Library; if not, see
00db10
+   <http://www.gnu.org/licenses/>.  */
00db10
+
00db10
+/* This is based on Linux test tools/testing/selftests/x86/ldt_gdt.c,
00db10
+   more specifically in do_multicpu_tests function.  The main changes
00db10
+   are:
00db10
+
00db10
+   - C11 atomics instead of plain access.
00db10
+   - Remove x86_64 support which simplifies the syscall handling
00db10
+     and fallbacks.
00db10
+   - Replicate only the test required to trigger the issue for the
00db10
+     BZ#21269.  */
00db10
+
00db10
+#include <stdatomic.h>
00db10
+
00db10
+#include <asm/ldt.h>
00db10
+#include <linux/futex.h>
00db10
+
00db10
+#include <setjmp.h>
00db10
+#include <signal.h>
00db10
+#include <errno.h>
00db10
+#include <sys/syscall.h>
00db10
+#include <sys/mman.h>
00db10
+
00db10
+#include <support/xunistd.h>
00db10
+#include <support/check.h>
00db10
+#include <support/xthread.h>
00db10
+
00db10
+static int
00db10
+xset_thread_area (struct user_desc *u_info)
00db10
+{
00db10
+  long ret = syscall (SYS_set_thread_area, u_info);
00db10
+  TEST_VERIFY_EXIT (ret == 0);
00db10
+  return ret;
00db10
+}
00db10
+
00db10
+static void
00db10
+xmodify_ldt (int func, const void *ptr, unsigned long bytecount)
00db10
+{
00db10
+  TEST_VERIFY_EXIT (syscall (SYS_modify_ldt, 1, ptr, bytecount) == 0);
00db10
+}
00db10
+
00db10
+static int
00db10
+futex (int *uaddr, int futex_op, int val, void *timeout, int *uaddr2,
00db10
+	int val3)
00db10
+{
00db10
+  return syscall (SYS_futex, uaddr, futex_op, val, timeout, uaddr2, val3);
00db10
+}
00db10
+
00db10
+static void
00db10
+xsethandler (int sig, void (*handler)(int, siginfo_t *, void *), int flags)
00db10
+{
00db10
+  struct sigaction sa = { 0 };
00db10
+  sa.sa_sigaction = handler;
00db10
+  sa.sa_flags = SA_SIGINFO | flags;
00db10
+  TEST_VERIFY_EXIT (sigemptyset (&sa.sa_mask) == 0);
00db10
+  TEST_VERIFY_EXIT (sigaction (sig, &sa, 0) == 0);
00db10
+}
00db10
+
00db10
+static jmp_buf jmpbuf;
00db10
+
00db10
+static void
00db10
+sigsegv_handler (int sig, siginfo_t *info, void *ctx_void)
00db10
+{
00db10
+  siglongjmp (jmpbuf, 1);
00db10
+}
00db10
+
00db10
+/* Points to an array of 1024 ints, each holding its own index.  */
00db10
+static const unsigned int *counter_page;
00db10
+static struct user_desc *low_user_desc;
00db10
+static struct user_desc *low_user_desc_clear; /* Used to delete GDT entry.  */
00db10
+static int gdt_entry_num;
00db10
+
00db10
+static void
00db10
+setup_counter_page (void)
00db10
+{
00db10
+  long page_size = sysconf (_SC_PAGE_SIZE);
00db10
+  TEST_VERIFY_EXIT (page_size > 0);
00db10
+  unsigned int *page = xmmap (NULL, page_size, PROT_READ | PROT_WRITE,
00db10
+			      MAP_ANONYMOUS | MAP_PRIVATE | MAP_32BIT, -1);
00db10
+  for (int i = 0; i < (page_size / sizeof (unsigned int)); i++)
00db10
+    page[i] = i;
00db10
+  counter_page = page;
00db10
+}
00db10
+
00db10
+static void
00db10
+setup_low_user_desc (void)
00db10
+{
00db10
+  low_user_desc = xmmap (NULL, 2 * sizeof (struct user_desc),
00db10
+			 PROT_READ | PROT_WRITE,
00db10
+			 MAP_ANONYMOUS | MAP_PRIVATE | MAP_32BIT, -1);
00db10
+
00db10
+  low_user_desc->entry_number    = -1;
00db10
+  low_user_desc->base_addr       = (unsigned long) &counter_page[1];
00db10
+  low_user_desc->limit           = 0xffff;
00db10
+  low_user_desc->seg_32bit       = 1;
00db10
+  low_user_desc->contents        = 0;
00db10
+  low_user_desc->read_exec_only  = 0;
00db10
+  low_user_desc->limit_in_pages  = 1;
00db10
+  low_user_desc->seg_not_present = 0;
00db10
+  low_user_desc->useable         = 0;
00db10
+
00db10
+  xset_thread_area (low_user_desc);
00db10
+
00db10
+  low_user_desc_clear = low_user_desc + 1;
00db10
+  low_user_desc_clear->entry_number = gdt_entry_num;
00db10
+  low_user_desc_clear->read_exec_only = 1;
00db10
+  low_user_desc_clear->seg_not_present = 1;
00db10
+}
00db10
+
00db10
+/* Possible values of futex:
00db10
+   0: thread is idle.
00db10
+   1: thread armed.
00db10
+   2: thread should clear LDT entry 0.
00db10
+   3: thread should exit.  */
00db10
+static atomic_uint ftx;
00db10
+
00db10
+static void *
00db10
+threadproc (void *ctx)
00db10
+{
00db10
+  while (1)
00db10
+    {
00db10
+      futex ((int *) &ftx, FUTEX_WAIT, 1, NULL, NULL, 0);
00db10
+      while (atomic_load (&ftx) != 2)
00db10
+	{
00db10
+	  if (atomic_load (&ftx) >= 3)
00db10
+	    return NULL;
00db10
+	}
00db10
+
00db10
+      /* clear LDT entry 0.  */
00db10
+      const struct user_desc desc = { 0 };
00db10
+      xmodify_ldt (1, &desc, sizeof (desc));
00db10
+
00db10
+      /* If ftx == 2, set it to zero,  If ftx == 100, quit.  */
00db10
+      if (atomic_fetch_add (&ftx, -2) != 2)
00db10
+	return NULL;
00db10
+    }
00db10
+}
00db10
+
00db10
+
00db10
+/* As described in testcase, for historical reasons x86_32 Linux (and compat
00db10
+   on x86_64) interprets SA_RESTORER clear with nonzero sa_restorer as a
00db10
+   request for stack switching if the SS segment is 'funny' (this is default
00db10
+   scenario for vDSO system).  This means that anything that tries to mix
00db10
+   signal handling with segmentation should explicit clear the sa_restorer.
00db10
+
00db10
+   This testcase check if sigaction in fact does it by changing the local
00db10
+   descriptor table (LDT) through the modify_ldt syscall and triggering
00db10
+   a synchronous segfault on iret fault by trying to install an invalid
00db10
+   segment.  With a correct zeroed sa_restorer it should not trigger an
00db10
+   'real' SEGSEGV and allows the siglongjmp in signal handler.  */
00db10
+
00db10
+static int
00db10
+do_test (void)
00db10
+{
00db10
+  setup_counter_page ();
00db10
+  setup_low_user_desc ();
00db10
+
00db10
+  pthread_t thread;
00db10
+  unsigned short orig_ss;
00db10
+
00db10
+  xsethandler (SIGSEGV, sigsegv_handler, 0);
00db10
+  /* 32-bit kernels send SIGILL instead of SIGSEGV on IRET faults.  */
00db10
+  xsethandler (SIGILL, sigsegv_handler, 0);
00db10
+
00db10
+  thread = xpthread_create (0, threadproc, 0);
00db10
+
00db10
+  asm volatile ("mov %%ss, %0" : "=rm" (orig_ss));
00db10
+
00db10
+  for (int i = 0; i < 5; i++)
00db10
+    {
00db10
+      if (sigsetjmp (jmpbuf, 1) != 0)
00db10
+	continue;
00db10
+
00db10
+      /* Make sure the thread is ready after the last test. */
00db10
+      while (atomic_load (&ftx) != 0)
00db10
+	;
00db10
+
00db10
+      struct user_desc desc = {
00db10
+	.entry_number       = 0,
00db10
+	.base_addr          = 0,
00db10
+	.limit              = 0xffff,
00db10
+	.seg_32bit          = 1,
00db10
+	.contents           = 0,
00db10
+	.read_exec_only     = 0,
00db10
+	.limit_in_pages     = 1,
00db10
+	.seg_not_present    = 0,
00db10
+	.useable            = 0
00db10
+      };
00db10
+
00db10
+      xmodify_ldt (0x11, &desc, sizeof (desc));
00db10
+
00db10
+      /* Arm the thread.  */
00db10
+      ftx = 1;
00db10
+      futex ((int*) &ftx, FUTEX_WAKE, 0, NULL, NULL, 0);
00db10
+
00db10
+      asm volatile ("mov %0, %%ss" : : "r" (0x7));
00db10
+
00db10
+      /* Fire up thread modify_ldt call.  */
00db10
+      atomic_store (&ftx, 2);
00db10
+
00db10
+      while (atomic_load (&ftx) != 0)
00db10
+	;
00db10
+
00db10
+      /* On success, modify_ldt will segfault us synchronously and we will
00db10
+	 escape via siglongjmp.  */
00db10
+      support_record_failure ();
00db10
+    }
00db10
+
00db10
+  atomic_store (&ftx, 100);
00db10
+  futex ((int*) &ftx, FUTEX_WAKE, 0, NULL, NULL, 0);
00db10
+
00db10
+  xpthread_join (thread);
00db10
+
00db10
+  return 0;
00db10
+}
00db10
+
00db10
+#include <support/test-driver.c>