|
|
4c1956 |
commit 3ad5dab476205d6e16156cf0511fa6884b3b0fc4
|
|
|
4c1956 |
Author: Florian Weimer <fweimer@redhat.com>
|
|
|
4c1956 |
Date: Tue Jul 7 09:58:45 2020 +0200
|
|
|
4c1956 |
|
|
|
4c1956 |
elf: Do not signal LA_ACT_CONSISTENT for an empty namespace [BZ #26076]
|
|
|
4c1956 |
|
|
|
4c1956 |
The auditing interface identifies namespaces by their first loaded
|
|
|
4c1956 |
module. Once the namespace is empty, it is no longer possible to signal
|
|
|
4c1956 |
LA_ACT_CONSISTENT for it because the first loaded module is already gone
|
|
|
4c1956 |
at that point.
|
|
|
4c1956 |
|
|
|
4c1956 |
Reviewed-by: Carlos O'Donell <carlos@redhat.com>
|
|
|
4c1956 |
|
|
|
4c1956 |
diff --git a/elf/dl-close.c b/elf/dl-close.c
|
|
|
4c1956 |
index 7fe91bdd9aaf694e..698bda929c0eab6c 100644
|
|
|
4c1956 |
--- a/elf/dl-close.c
|
|
|
4c1956 |
+++ b/elf/dl-close.c
|
|
|
4c1956 |
@@ -795,8 +795,14 @@ _dl_close_worker (struct link_map *map, bool force)
|
|
|
4c1956 |
if (__glibc_unlikely (do_audit))
|
|
|
4c1956 |
{
|
|
|
4c1956 |
struct link_map *head = ns->_ns_loaded;
|
|
|
4c1956 |
- /* Do not call the functions for any auditing object. */
|
|
|
4c1956 |
- if (head->l_auditing == 0)
|
|
|
4c1956 |
+ /* If head is NULL, the namespace has become empty, and the
|
|
|
4c1956 |
+ audit interface does not give us a way to signal
|
|
|
4c1956 |
+ LA_ACT_CONSISTENT for it because the first loaded module is
|
|
|
4c1956 |
+ used to identify the namespace.
|
|
|
4c1956 |
+
|
|
|
4c1956 |
+ Furthermore, do not notify auditors of the cleanup of a
|
|
|
4c1956 |
+ failed audit module loading attempt. */
|
|
|
4c1956 |
+ if (head != NULL && head->l_auditing == 0)
|
|
|
4c1956 |
{
|
|
|
4c1956 |
struct audit_ifaces *afct = GLRO(dl_audit);
|
|
|
4c1956 |
for (unsigned int cnt = 0; cnt < GLRO(dl_naudit); ++cnt)
|