Bug 13618 - elf_machine_rela may call unrelocated address while resolving IFUNC
Summary: elf_machine_rela may call unrelocated address while resolving IFUNC
Alias: None
Product: glibc
Classification: Unclassified
Component: libc (show other bugs)
Version: 2.15
: P2 critical
Target Milestone: ---
Assignee: Ulrich Drepper
: 13580 13633 14133 (view as bug list)
Depends on:
Reported: 2012-01-23 20:23 UTC by Paul Pluzhnikov
Modified: 2014-06-13 14:05 UTC (History)
6 users (show)

See Also:
Last reconfirmed:
fweimer: security-


Note You need to log in before you can comment on or make changes to this bug.
Description Paul Pluzhnikov 2012-01-23 20:23:48 UTC
The test is reduced from

Reproduces with current git trunk.

// foo.c
#include <math.h>
int foo (double d) { return floor (d) != 0; }

// bar.c
int bar () { return foo (); }

// main.c
#include <dlfcn.h>
#include <stdio.h>

main (int argc, char *argv[])
  const char *lib = "./bar.so";
  if (argc > 1) lib = argv[1];
  void *h = dlopen (lib, RTLD_NOW);  // RTLD_LAZY -> no bug
  if (h == 0)
      puts (dlerror ());
      return 1;
  return 0;

gcc -fPIC -shared -fno-builtin -o foo.so foo.c -lm &&
gcc -fPIC -shared -o bar.so -Wl,--no-as-needed -lm ./foo.so bar.c &&
gcc -g main.c -ldl

gdb -q ./a.out

Program received signal SIGSEGV, Segmentation fault.
0x0000000000005446 in ?? ()
(gdb) bt
#0  0x0000000000005446 in ?? ()
#1  0x00007ffff7351005 in floor () at ../sysdeps/x86_64/fpu/multiarch/s_floor.S:26
#2  0x00007ffff7de738f in elf_machine_rela (sym=0x7ffff7338c88, skip_ifunc=<optimized out>, reloc_addr_arg=0x7ffff7336008, version=<optimized out>, map=0x602af0, 
    reloc=<optimized out>) at ../sysdeps/x86_64/dl-machine.h:302
#3  elf_dynamic_do_Rela (skip_ifunc=<optimized out>, lazy=<optimized out>, nrelative=<optimized out>, relsize=<optimized out>, reladdr=<optimized out>, map=0x602af0)
    at do-rel.h:146
#4  _dl_relocate_object (scope=0x602e48, reloc_mode=<optimized out>, consider_profiling=0) at dl-reloc.c:265
#5  0x00007ffff7deda23 in dl_open_worker (a=0x7fffffffd400) at dl-open.c:338
#6  0x00007ffff7de9686 in _dl_catch_error (objname=0x7fffffffd3f0, errstring=0x7fffffffd3f8, mallocedp=0x7fffffffd3ef, operate=0x7ffff7ded7c0 <dl_open_worker>, 
    args=0x7fffffffd400) at dl-error.c:178
#7  0x00007ffff7ded36c in _dl_open (file=0x40080c "./bar.so", mode=-2147483646, caller_dlopen=<optimized out>, nsid=-2, argc=1, argv=0x7fffffffd748, env=0x7fffffffd758)
    at dl-open.c:575
#8  0x00007ffff7bd7f26 in dlopen_doit (a=0x7fffffffd610) at dlopen.c:67
#9  0x00007ffff7de9686 in _dl_catch_error (objname=0x7ffff7dda0d0, errstring=0x7ffff7dda0d8, mallocedp=0x7ffff7dda0c8, operate=0x7ffff7bd7ec0 <dlopen_doit>, args=0x7fffffffd610)
    at dl-error.c:178
#10 0x00007ffff7bd84dc in _dlerror_run (operate=0x7ffff7bd7ec0 <dlopen_doit>, args=0x7fffffffd610) at dlerror.c:164
#11 0x00007ffff7bd7fc1 in __dlopen (file=<optimized out>, mode=<optimized out>) at dlopen.c:88
#12 0x00000000004006f1 in main (argc=1, argv=0x7fffffffd748) at main.c:8

What appears to be happening is that __floor (IFUNC) jumps to *unrelocated*
GOT entry for __get_cpu_features.
Comment 1 Andreas Jaeger 2012-01-24 12:18:44 UTC
*** Bug 13580 has been marked as a duplicate of this bug. ***
Comment 2 Andreas Jaeger 2012-01-24 12:19:42 UTC
Thanks for the testcase.
Comment 3 Ulrich Drepper 2012-01-27 20:05:52 UTC
I added a patch.
Comment 4 Mike Frysinger 2012-01-27 21:04:28 UTC
i suspect this is said commit:

seems to fix my known failing test case (svn)
Comment 5 Paul Pluzhnikov 2012-01-31 03:49:05 UTC
*** Bug 13633 has been marked as a duplicate of this bug. ***
Comment 6 Paul Pluzhnikov 2012-05-23 03:21:09 UTC
*** Bug 14133 has been marked as a duplicate of this bug. ***
Comment 7 Paul Pluzhnikov 2012-05-23 03:23:19 UTC
(In reply to comment #6)
> *** Bug 14133 has been marked as a duplicate of this bug. ***

In PR13618, Marc-Antoine Perennou asks for the fix to be back-ported to 15.1 branch.
Comment 8 Jackie Rosen 2014-02-16 16:56:36 UTC Comment hidden (spam)