Go to file
Adhemerval Zanella fe05e1cb6d posix: Fix improper assert in Linux posix_spawn (BZ#22273)
As noted by Florian Weimer, current Linux posix_spawn implementation
can trigger an assert if the auxiliary process is terminated before
actually setting the err member:

    340   /* Child must set args.err to something non-negative - we rely on
    341      the parent and child sharing VM.  */
    342   args.err = -1;
    [...]
    362   new_pid = CLONE (__spawni_child, STACK (stack, stack_size), stack_size,
    363                    CLONE_VM | CLONE_VFORK | SIGCHLD, &args);
    364
    365   if (new_pid > 0)
    366     {
    367       ec = args.err;
    368       assert (ec >= 0);

Another possible issue is killing the child between setting the err and
actually calling execve.  In this case the process will not ran, but
posix_spawn also will not report any error:

    269
    270   args->err = 0;
    271   args->exec (args->file, args->argv, args->envp);

As suggested by Andreas Schwab, this patch removes the faulty assert
and also handles any signal that happens before fork and execve as the
spawn was successful (and thus relaying the handling to the caller to
figure this out).  Different than Florian, I can not see why using
atomics to set err would help here, essentially the code runs
sequentially (due CLONE_VFORK) and I think it would not be legal the
compiler evaluate ec without checking for new_pid result (thus there
is no need to compiler barrier).

Summarizing the possible scenarios on posix_spawn execution, we
have:

  1. For default case with a success execution, args.err will be 0, pid
     will not be collected and it will be reported to caller.

  2. For default failure case, args.err will be positive and the it will
     be collected by the waitpid.  An error will be reported to the
     caller.

  3. For the unlikely case where the process was terminated and not
     collected by a caller signal handler, it will be reported as succeful
     execution and not be collected by posix_spawn (since args.err will
     be 0). The caller will need to actually handle this case.

  4. For the unlikely case where the process was terminated and collected
     by caller we have 3 other possible scenarios:

     4.1. The auxiliary process was terminated with args.err equal to 0:
	  it will handled as 1. (so it does not matter if we hit the pid
          reuse race since we won't possible collect an unexpected
          process).

     4.2. The auxiliary process was terminated after execve (due a failure
          in calling it) and before setting args.err to -1: it will also
          be handle as 1. but with the issue of not be able to report the
          caller a possible execve failures.

     4.3. The auxiliary process was terminated after args.err is set to -1:
          this is the case where it will be possible to hit the pid reuse
          case where we will need to collected the auxiliary pid but we
          can not be sure if it will be expected one.  I think for this
          case we need to actually change waitpid to use WNOHANG to avoid
          hanging indefinitely on the call and report an error to caller
          since we can't differentiate between a default failure as 2.
          and a possible pid reuse race issue.

Checked on x86_64-linux-gnu.

	* sysdeps/unix/sysv/linux/spawni.c (__spawnix): Handle the case where
	the auxiliary process is terminated by a signal before calling _exit
	or execve.
2017-10-20 16:25:59 -02:00
ChangeLog.old Add missing reference to bug 21654 2017-10-07 13:14:36 +02:00
argp Mark internal argp functions with attribute_hidden [BZ #18822] 2017-10-01 15:10:27 -07:00
assert Fix position of tests-unsupported definition in assert/Makefile. 2017-08-22 00:30:51 +00:00
benchtests Benchtests for sinf, cosf and sincosf 2017-10-13 14:19:45 +05:30
bits posix: Add p{readv,writev}2 flags to generic uio-ext.h 2017-10-17 17:52:04 -02:00
catgets Don't compile non-lib modules as lib modules [BZ #21864] 2017-08-21 05:34:54 -07:00
conform Fix mcontext_t sigcontext namespace (bug 21457). 2017-08-30 22:02:04 +00:00
crypt crypt: Use NSPR header files in addition to NSS header files [BZ #17956] 2017-10-04 15:02:35 +02:00
csu Hide internal __libc_print_version function [BZ #18822] 2017-10-01 17:55:30 -07:00
ctype Use locale_t, not __locale_t, throughout glibc 2017-06-20 20:30:06 -04:00
debug Enable unwind info in libc-start.c and backtrace.c 2017-09-19 15:07:58 +01:00
dev Rename xlocale.h to bits/types/__locale_t.h. 2017-06-20 20:28:11 -04:00
dirent hurd: Fix dirfd symbol exposition from ftw 2017-09-28 00:49:05 +02:00
dlfcn Mark __dso_handle as hidden [BZ #18822] 2017-09-26 16:53:44 -07:00
elf Use $(DEFAULT-LDFLAGS-$(@F)) in +link-static-before-libc 2017-10-04 17:16:04 -07:00
gmon Add a test for profiling static executable 2017-10-14 12:58:55 -07:00
gnulib Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
grp Remove compat from DEFAULT_CONFIG lookup strings 2017-09-12 10:21:48 -07:00
gshadow Remove __need macros from stdio.h and wchar.h. 2017-06-08 13:58:17 -04:00
hesiod Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
hurd hurd: fix gethostname(NULL, 0) 2017-09-07 00:51:17 +02:00
iconv Mark internal functions with attribute_hidden [BZ #18822] 2017-10-01 15:07:23 -07:00
iconvdata Add new codepage charmaps/IBM858 [BZ #21084] 2017-09-14 15:50:57 +02:00
include Use __f128 to define FLT128_* constants in include/float.h for old GCC. 2017-10-17 20:16:01 +00:00
inet Hide internal idna functions [BZ #18822] 2017-10-01 17:33:22 -07:00
intl Hide internal __hash_string function [BZ #18822] 2017-10-01 17:41:34 -07:00
io hurd: Fix dirfd symbol exposition from ftw 2017-09-28 00:49:05 +02:00
libidn Remove add-ons mechanism. 2017-10-05 15:58:13 +00:00
libio Always do locking when iterating over list of streams (bug 15142) 2017-10-05 17:26:05 +02:00
locale Add new locale mjw_IN [BZ #13994] 2017-10-19 16:11:28 +02:00
localedata Add new locale kab_DZ [BZ #18812] 2017-10-20 18:13:22 +02:00
login openpty: use TIOCGPTPEER to open slave side fd 2017-10-08 17:47:58 +02:00
mach hurd: Remove duplicate symbol version 2017-08-28 14:19:55 +02:00
malloc Fix build issue with SINGLE_THREAD_P 2017-10-20 17:39:47 +01:00
manual Add _Float128 function aliases. 2017-10-18 17:37:18 +00:00
math Let signbit use the builtin in C++ mode with gcc < 6.x (bug 22296) 2017-10-17 12:06:44 -02:00
mathvec Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
misc Hide internal __hasmntopt function [BZ #18822] 2017-10-01 17:37:42 -07:00
nis nscd: remove reference to libnsl 2017-10-11 15:51:52 +02:00
nptl nptl: Preserve error in setxid thread broadcast in coredumps [BZ #22153] 2017-10-13 22:51:56 +02:00
nptl_db Move all old ChangeLogs to a top-level ChangeLog.old directory. 2017-09-01 09:31:43 -04:00
nscd nscd: remove reference to libnsl 2017-10-11 15:51:52 +02:00
nss nss_files: Avoid large buffers with many host addresses [BZ #22078] 2017-10-11 07:07:51 +02:00
po Update translations 2017-09-11 05:50:49 +05:30
posix CVE-2017-15670: glob: Fix one-byte overflow [BZ #22320] 2017-10-20 18:46:48 +02:00
pwd Remove __need macros from stdio.h and wchar.h. 2017-06-08 13:58:17 -04:00
resolv resolv: Remove bogus targets that build ga_test 2017-10-20 09:29:09 -07:00
resource Hide internal __setrlimit function [BZ #18822] 2017-10-01 17:46:54 -07:00
rt aio: Remove internal_function function attribute 2017-08-31 15:59:06 +02:00
scripts Fix armv7-a compiler option name 2017-10-17 13:32:03 -02:00
setjmp Remove __need macros from signal.h. 2017-05-20 19:04:43 -04:00
shadow Remove __need macros from stdio.h and wchar.h. 2017-06-08 13:58:17 -04:00
signal Hide internal signal functions [BZ #18822] 2017-10-01 16:04:41 -07:00
socket __opensock: Remove internal_function attribute 2017-08-17 10:18:15 +02:00
soft-fp Use libm_alias_* in soft-fp. 2017-10-11 00:03:46 +00:00
stdio-common [BZ #22142] powerpc: Fix the carry bit on mpn_[add|sub]_n on POWER7 2017-10-13 15:44:39 -03:00
stdlib Place monetary symbol in el_GR and el_CY after the amount 2017-10-17 15:29:50 +02:00
streams Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
string Hide internal __strsep function [BZ #18822] 2017-10-01 16:03:41 -07:00
sunrpc sunrpc/tst-udp-nonblocking: Fix timeout value 2017-09-10 21:09:28 +02:00
support support_format_hostent: Add more error information for NETDB_INTERNAL 2017-10-05 12:20:19 +02:00
sysdeps posix: Fix improper assert in Linux posix_spawn (BZ#22273) 2017-10-20 16:25:59 -02:00
sysvipc Fix test-sysvsem on some platforms 2017-01-02 18:53:50 -02:00
termios Hide internal __tcgetattr function [BZ #18822] 2017-10-01 17:48:24 -07:00
time time: Remove the internal_function attribute 2017-08-31 15:59:07 +02:00
timezone zic: Use PRIdMAX to print line numbers 2017-07-25 12:34:14 +05:30
wcsmbs Mark ____wcsto*_l_internal functions with attribute_hidden [BZ #18822] 2017-10-01 15:09:28 -07:00
wctype Use locale_t, not __locale_t, throughout glibc 2017-06-20 20:30:06 -04:00
.gitattributes Assume __NR_openat is always defined 2016-03-23 23:35:08 +01:00
.gitignore Add *.pyc to .gitignore 2015-05-18 15:26:26 +05:30
COPYING Update to latest versions of GPL-2.0 and LGPL-2.1 2013-09-09 12:52:48 +10:00
COPYING.LIB Update to latest versions of GPL-2.0 and LGPL-2.1 2013-09-09 12:52:48 +10:00
ChangeLog posix: Fix improper assert in Linux posix_spawn (BZ#22273) 2017-10-20 16:25:59 -02:00
INSTALL Remove add-ons mechanism. 2017-10-05 15:58:13 +00:00
LICENSES Expand LICENSES file. 2012-12-05 21:56:15 +00:00
MAINTAINERS Add MAINTAINERS 2017-05-11 13:38:30 -04:00
Makeconfig Add a test for profiling static executable 2017-10-14 12:58:55 -07:00
Makefile Remove add-ons mechanism. 2017-10-05 15:58:13 +00:00
Makefile.in New make target to only build benchmark binaries 2016-04-20 10:23:28 +05:30
Makerules Place $(elf-objpfx)sofini.os last [BZ #22051] 2017-08-31 06:28:46 -07:00
NEWS Mention Tim Rühsen as the reporter for CVE-2017-15670 2017-10-20 19:28:44 +02:00
README Require Linux kernel 3.2 or later on x86 / x86_64. 2017-05-08 10:45:20 +00:00
Rules Suppress internal declarations for most of the testsuite. 2017-05-11 19:27:59 -04:00
abi-tags Remove the bulk of the NaCl port. 2017-05-20 08:09:10 -04:00
aclocal.m4 gmon: Add test for basic mcount/gprof functionality 2017-08-15 15:49:45 +02:00
config.h.in Don't use hidden visibility in libc.a with PIE on i386 2017-10-04 17:18:42 -07:00
config.make.in Remove add-ons mechanism. 2017-10-05 15:58:13 +00:00
configure Remove add-ons mechanism. 2017-10-05 15:58:13 +00:00
configure.ac Remove add-ons mechanism. 2017-10-05 15:58:13 +00:00
extra-lib.mk Rename cppflags-iterator.mk to libof-iterator.mk, remove extra-modules.mk. 2017-05-09 07:06:29 -04:00
gen-locales.mk Split locale generation snippet into a separate file 2015-05-13 13:05:28 +05:30
libc-abis A few more archs have IFUNC support. 2010-03-17 02:43:12 -07:00
libof-iterator.mk Rename cppflags-iterator.mk to libof-iterator.mk, remove extra-modules.mk. 2017-05-09 07:06:29 -04:00
o-iterator.mk Fri Mar 17 12:58:37 1995 Roland McGrath <roland@churchy.gnu.ai.mit.edu> 1995-03-17 18:42:51 +00:00
shlib-versions Extend NSS test suite 2017-07-17 15:52:44 -04:00
test-skeleton.c Update copyright dates with scripts/update-copyrights. 2017-01-01 00:14:16 +00:00
version.h version.h: Switch to ".9000" as the suffix for the development version 2017-10-16 21:39:18 +02:00

README

This directory contains the sources of the GNU C Library.
See the file "version.h" for what release version you have.

The GNU C Library is the standard system C library for all GNU systems,
and is an important part of what makes up a GNU system.  It provides the
system API for all programs written in C and C-compatible languages such
as C++ and Objective C; the runtime facilities of other programming
languages use the C library to access the underlying operating system.

In GNU/Linux systems, the C library works with the Linux kernel to
implement the operating system behavior seen by user applications.
In GNU/Hurd systems, it works with a microkernel and Hurd servers.

The GNU C Library implements much of the POSIX.1 functionality in the
GNU/Hurd system, using configurations i[4567]86-*-gnu.  The current
GNU/Hurd support requires out-of-tree patches that will eventually be
incorporated into an official GNU C Library release.

When working with Linux kernels, this version of the GNU C Library
requires Linux kernel version 3.2 or later.

Also note that the shared version of the libgcc_s library must be
installed for the pthread library to work correctly.

The GNU C Library supports these configurations for using Linux kernels:

	aarch64*-*-linux-gnu
	alpha*-*-linux-gnu
	arm-*-linux-gnueabi
	hppa-*-linux-gnu	Not currently functional without patches.
	i[4567]86-*-linux-gnu
	x86_64-*-linux-gnu	Can build either x86_64 or x32
	ia64-*-linux-gnu
	m68k-*-linux-gnu
	microblaze*-*-linux-gnu
	mips-*-linux-gnu
	mips64-*-linux-gnu
	powerpc-*-linux-gnu	Hardware or software floating point, BE only.
	powerpc64*-*-linux-gnu	Big-endian and little-endian.
	s390-*-linux-gnu
	s390x-*-linux-gnu
	sh[34]-*-linux-gnu
	sparc*-*-linux-gnu
	sparc64*-*-linux-gnu
	tilegx-*-linux-gnu
	tilepro-*-linux-gnu

If you are interested in doing a port, please contact the glibc
maintainers; see http://www.gnu.org/software/libc/ for more
information.

See the file INSTALL to find out how to configure, build, and install
the GNU C Library.  You might also consider reading the WWW pages for
the C library at http://www.gnu.org/software/libc/.

The GNU C Library is (almost) completely documented by the Texinfo manual
found in the `manual/' subdirectory.  The manual is still being updated
and contains some known errors and omissions; we regret that we do not
have the resources to work on the manual as much as we would like.  For
corrections to the manual, please file a bug in the `manual' component,
following the bug-reporting instructions below.  Please be sure to check
the manual in the current development sources to see if your problem has
already been corrected.

Please see http://www.gnu.org/software/libc/bugs.html for bug reporting
information.  We are now using the Bugzilla system to track all bug reports.
This web page gives detailed information on how to report bugs properly.

The GNU C Library is free software.  See the file COPYING.LIB for copying
conditions, and LICENSES for notices about a few contributions that require
these additional notices to be distributed.  License copyright years may be
listed using range notation, e.g., 1996-2015, indicating that every year in
the range, inclusive, is a copyrightable year that would otherwise be listed
individually.