]> sourceware.org Git - glibc.git/blame - hurd/hurdfault.c
syslog: Fix integer overflow in __vsyslog_internal (CVE-2023-6780)
[glibc.git] / hurd / hurdfault.c
CommitLineData
28f540f4 1/* Handle faults in the signal thread.
dff8da6b 2 Copyright (C) 1994-2024 Free Software Foundation, Inc.
10dc2a90 3 This file is part of the GNU C Library.
28f540f4 4
10dc2a90 5 The GNU C Library is free software; you can redistribute it and/or
41bdb6e2
AJ
6 modify it under the terms of the GNU Lesser General Public
7 License as published by the Free Software Foundation; either
8 version 2.1 of the License, or (at your option) any later version.
28f540f4 9
10dc2a90
UD
10 The GNU C Library is distributed in the hope that it will be useful,
11 but WITHOUT ANY WARRANTY; without even the implied warranty of
12 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
41bdb6e2 13 Lesser General Public License for more details.
28f540f4 14
41bdb6e2 15 You should have received a copy of the GNU Lesser General Public
59ba27a6 16 License along with the GNU C Library; if not, see
5a82c748 17 <https://www.gnu.org/licenses/>. */
28f540f4
RM
18
19#include <hurd.h>
20#include <hurd/signal.h>
21#include "hurdfault.h"
22#include <errno.h>
23#include <string.h>
24#include <setjmp.h>
25#include <stdio.h>
8f480b4b 26#include <thread_state.h>
aa1075ea 27#include "faultexc_server.h" /* mig-generated header for our exc server. */
96aa2d94 28#include <assert.h>
28f540f4
RM
29
30jmp_buf _hurdsig_fault_env;
43b0e40f 31struct hurd_signal_preemptor _hurdsig_fault_preemptor = {0};
28f540f4 32
6bac11d9
MB
33/* XXX temporary to deal with spelling fix */
34weak_alias (_hurdsig_fault_preemptor, _hurdsig_fault_preempter)
35
28f540f4
RM
36static mach_port_t forward_sigexc;
37
28f540f4
RM
38kern_return_t
39_hurdsig_fault_catch_exception_raise (mach_port_t port,
40 thread_t thread,
41 task_t task,
f22a77e1
RM
42#ifdef EXC_MASK_ALL /* New interface flavor. */
43 exception_type_t exception,
44 exception_data_t code,
45 mach_msg_type_number_t codeCnt
46#else /* Vanilla Mach 3.0 interface. */
14906e37 47 integer_t exception,
d8ee5d61 48 integer_t code, long_integer_t subcode
f22a77e1
RM
49#endif
50 )
28f540f4
RM
51{
52 int signo;
0e3426bb 53 struct hurd_signal_detail d;
28f540f4 54
34a5a146
JM
55 if (port != forward_sigexc
56 || thread != _hurd_msgport_thread || task != __mach_task_self ())
28f540f4
RM
57 return EPERM; /* Strange bogosity. */
58
0e3426bb 59 d.exc = exception;
f22a77e1
RM
60#ifdef EXC_MASK_ALL
61 assert (codeCnt >= 2);
62 d.exc_code = code[0];
63 d.exc_subcode = code[1];
64#else
0e3426bb
RM
65 d.exc_code = code;
66 d.exc_subcode = subcode;
f22a77e1 67#endif
0e3426bb 68
28f540f4
RM
69 /* Call the machine-dependent function to translate the Mach exception
70 codes into a signal number and subcode. */
0e3426bb 71 _hurd_exception2signal (&d, &signo);
28f540f4 72
d865ff74 73 return HURD_PREEMPT_SIGNAL_P (&_hurdsig_fault_preemptor, signo, d.exc_subcode)
7974fe21 74 ? 0 : EGREGIOUS;
28f540f4
RM
75}
76
f22a77e1
RM
77#ifdef EXC_MASK_ALL
78/* XXX New interface flavor has additional RPCs that we could be using
79 instead. These RPCs roll a thread_get_state/thread_set_state into
80 the message, so the signal thread ought to use these to save some calls.
81 */
82kern_return_t
83_hurdsig_fault_catch_exception_raise_state
84(mach_port_t port,
85 exception_type_t exception,
86 exception_data_t code,
87 mach_msg_type_number_t codeCnt,
88 int *flavor,
89 thread_state_t old_state,
90 mach_msg_type_number_t old_stateCnt,
91 thread_state_t new_state,
92 mach_msg_type_number_t *new_stateCnt)
93{
94 abort ();
95 return KERN_FAILURE;
96}
97
98kern_return_t
99_hurdsig_fault_catch_exception_raise_state_identity
100(mach_port_t exception_port,
101 thread_t thread,
102 task_t task,
103 exception_type_t exception,
104 exception_data_t code,
105 mach_msg_type_number_t codeCnt,
106 int *flavor,
107 thread_state_t old_state,
108 mach_msg_type_number_t old_stateCnt,
109 thread_state_t new_state,
110 mach_msg_type_number_t *new_stateCnt)
111{
112 abort ();
113 return KERN_FAILURE;
114}
115#endif
116
117
28f540f4
RM
118static void
119faulted (void)
120{
121 struct
122 {
123 mach_msg_header_t head;
124 char buf[64];
125 } request;
f22a77e1 126 mig_reply_header_t reply;
28f540f4
RM
127 extern int _hurdsig_fault_exc_server (mach_msg_header_t *,
128 mach_msg_header_t *);
129
130 /* Wait for the exception_raise message forwarded by the proc server. */
131
132 if (__mach_msg (&request.head, MACH_RCV_MSG, 0,
133 sizeof request, forward_sigexc,
134 MACH_MSG_TIMEOUT_NONE, MACH_PORT_NULL)
135 != MACH_MSG_SUCCESS)
136 __libc_fatal ("msg receive failed on signal thread exc\n");
137
138 /* Run the exc demuxer which should call the server function above.
139 That function returns 0 if the exception was expected. */
f22a77e1
RM
140 _hurdsig_fault_exc_server (&request.head, &reply.Head);
141 if (reply.Head.msgh_remote_port != MACH_PORT_NULL)
142 __mach_msg (&reply.Head, MACH_SEND_MSG, reply.Head.msgh_size,
7974fe21 143 0, MACH_PORT_NULL, MACH_MSG_TIMEOUT_NONE, MACH_PORT_NULL);
f22a77e1 144 if (reply.RetCode == MIG_BAD_ID)
7974fe21
RM
145 __mach_msg_destroy (&request.head);
146
f22a77e1 147 if (reply.RetCode)
7974fe21
RM
148 __libc_fatal ("BUG: unexpected fault in signal thread\n");
149
10dc2a90 150 _hurdsig_fault_preemptor.signals = 0;
5e17a480 151 longjmp (_hurdsig_fault_env, 1);
28f540f4
RM
152}
153
154static char faultstack[1024];
155
156/* Send exceptions for the signal thread to the proc server.
157 It will forward the message on to our message port,
158 and then restore the thread's state to code which
159 does `longjmp (_hurd_sigthread_fault_env, 1)'. */
160
161void
162_hurdsig_fault_init (void)
163{
164 error_t err;
165 struct machine_thread_state state;
166 mach_port_t sigexc;
167
63f89404
RM
168 /* Allocate a port to receive signal thread exceptions.
169 We will move this receive right to the proc server. */
a5a81fec
RM
170 err = __mach_port_allocate (__mach_task_self (),
171 MACH_PORT_RIGHT_RECEIVE, &sigexc);
172 assert_perror (err);
226f1f8a
SB
173 err = __mach_port_insert_right (__mach_task_self (), sigexc,
174 sigexc, MACH_MSG_TYPE_MAKE_SEND);
a5a81fec
RM
175 assert_perror (err);
176
63f89404
RM
177 /* Allocate a port to receive the exception msgs forwarded
178 from the proc server. */
226f1f8a
SB
179 err = __mach_port_allocate (__mach_task_self (),
180 MACH_PORT_RIGHT_RECEIVE, &forward_sigexc);
a5a81fec 181 assert_perror (err);
63f89404
RM
182
183 /* Set the queue limit for this port to just one. The proc server will
184 notice if we ever get a second exception while one remains queued and
185 unreceived, and decide we are hopelessly buggy. */
f22a77e1
RM
186#ifdef MACH_PORT_RECEIVE_STATUS_COUNT
187 {
188 const mach_port_limits_t lim = { mpl_qlimit: 1 };
189 assert (MACH_PORT_RECEIVE_STATUS_COUNT == sizeof lim / sizeof (natural_t));
190 err = __mach_port_set_attributes (__mach_task_self (), forward_sigexc,
191 MACH_PORT_RECEIVE_STATUS,
21297437
RM
192 (mach_port_info_t) &lim,
193 MACH_PORT_RECEIVE_STATUS_COUNT);
f22a77e1
RM
194 }
195#else
63f89404 196 err = __mach_port_set_qlimit (__mach_task_self (), forward_sigexc, 1);
f22a77e1 197#endif
a5a81fec 198 assert_perror (err);
28f540f4 199
63f89404
RM
200 /* This state will be restored when we fault.
201 It runs the function above. */
28f540f4 202 memset (&state, 0, sizeof state);
f8baf2a2 203 MACHINE_THREAD_STATE_FIX_NEW (&state);
be9c1b9c
SB
204 MACHINE_THREAD_STATE_SETUP_CALL (&state, faultstack,
205 sizeof faultstack, faulted);
28f540f4 206
a5a81fec
RM
207 err = __USEPORT
208 (PROC,
209 __proc_handle_exceptions (port,
210 sigexc,
211 forward_sigexc, MACH_MSG_TYPE_MAKE_SEND,
212 MACHINE_THREAD_STATE_FLAVOR,
213 (natural_t *) &state,
214 MACHINE_THREAD_STATE_COUNT));
215 assert_perror (err);
63f89404
RM
216
217 /* Direct signal thread exceptions to the proc server. */
7595ddb8 218#ifdef THREAD_EXCEPTION_PORT
63f89404
RM
219 err = __thread_set_special_port (_hurd_msgport_thread,
220 THREAD_EXCEPTION_PORT, sigexc);
7595ddb8
RM
221#elif defined (EXC_MASK_ALL)
222 __thread_set_exception_ports (_hurd_msgport_thread,
223 EXC_MASK_ALL & ~(EXC_MASK_SYSCALL
224 | EXC_MASK_MACH_SYSCALL
225 | EXC_MASK_RPC_ALERT),
226 sigexc,
f22a77e1
RM
227 EXCEPTION_STATE_IDENTITY,
228 MACHINE_THREAD_STATE);
7595ddb8
RM
229#else
230# error thread_set_exception_ports?
231#endif
63f89404
RM
232 __mach_port_deallocate (__mach_task_self (), sigexc);
233 assert_perror (err);
28f540f4 234}
This page took 0.578654 seconds and 5 git commands to generate.