xcoff reading dynamic relocs

Alan Modra amodra@gmail.com
Fri Dec 13 05:39:06 GMT 2024


On Fri, Dec 13, 2024 at 03:24:49PM +1030, Alan Modra wrote:
> That seems reasonable to me, because prior to this patch l_symndx was
> being set to -1 and -2 for .tdata and .tbss symbols resulting in a
> buffer overflow when accessing the syms array.  (objdump -R on the
> testcase .so segfaults.)

Perhaps this?  Using -1 for .tdata l_symndx was clearly wrong since
that value is already used..  However, I'm unsure what to do here.
ldrel is a public interface.

	* xcofflink.c (_bfd_xcoff_canonicalize_dynamic_reloc): Use
	.tdata and .tbss section symbols.
	(xcoff_create_ldrel): Set l_symndx to -3 for .tdata.

diff --git a/bfd/xcofflink.c b/bfd/xcofflink.c
index b75fb42eed5..057dfbd72e2 100644
--- a/bfd/xcofflink.c
+++ b/bfd/xcofflink.c
@@ -441,10 +441,11 @@ _bfd_xcoff_canonicalize_dynamic_reloc (bfd *abfd,
 
       if (ldrel.l_symndx == -1u)
 	relbuf->sym_ptr_ptr = bfd_abs_section_ptr->symbol_ptr_ptr;
-      else if (ldrel.l_symndx < 3)
+      else if (ldrel.l_symndx + 3 < 6)
 	{
-	  static const char stdsec[3][8] = { ".text", ".data", ".bss" };
-	  const char *name = stdsec[ldrel.l_symndx];
+	  static const char stdsec[6][8]
+	    = { ".tdata", ".tbss", "", ".text", ".data", ".bss" };
+	  const char *name = stdsec[ldrel.l_symndx + 3];
 	  asection *sec = bfd_get_section_by_name (abfd, name);
 	  if (sec == NULL)
 	    {
@@ -5063,7 +5064,7 @@ xcoff_create_ldrel (bfd *output_bfd, struct xcoff_final_link_info *flinfo,
       else if (strcmp (secname, ".bss") == 0)
 	ldrel.l_symndx = 2;
       else if (strcmp (secname, ".tdata") == 0)
-	ldrel.l_symndx = -1;
+	ldrel.l_symndx = -3;
       else if (strcmp (secname, ".tbss") == 0)
 	ldrel.l_symndx = -2;
       else

-- 
Alan Modra


More information about the Binutils mailing list