[Bug dynamic-link/20915] New: global-dynamic TLS broken on aarch64

fweimer at redhat dot com sourceware-bugzilla@sourceware.org
Fri Dec 2 16:25:00 GMT 2016


https://sourceware.org/bugzilla/show_bug.cgi?id=20915

            Bug ID: 20915
           Summary: global-dynamic TLS broken on aarch64
           Product: glibc
           Version: unspecified
            Status: NEW
          Severity: normal
          Priority: P2
         Component: dynamic-link
          Assignee: unassigned at sourceware dot org
          Reporter: fweimer at redhat dot com
  Target Milestone: ---
            Target: aarch64
             Flags: security-

elf/tst-tls-manydynamic fails on aarch64.

This started happening with commit 17af5da98cd2c9ec958421ae2108f877e0945451
(fix non-LE TLS in static programs), due to the hunk in nptl/allocatestack.c:

diff --git a/nptl/allocatestack.c b/nptl/allocatestack.c
index 60b34dc..3016a2e 100644
--- a/nptl/allocatestack.c
+++ b/nptl/allocatestack.c
@@ -1207,9 +1207,12 @@ init_one_static_tls (struct pthread *curp, struct
link_map *map)
 #  error "Either TLS_TCB_AT_TP or TLS_DTV_AT_TP must be defined"
 # endif

-  /* We cannot delay the initialization of the Static TLS area, since
-     it can be accessed with LE or IE, but since the DTV is only used
-     by GD and LD, we can delay its update to avoid a race.  */
+  /* Fill in the DTV slot so that a later LD/GD access will find it.  */
+  dtv_t *dtv = GET_DTV (TLS_TPADJ (curp));
+  dtv[map->l_tls_modid].pointer.to_free = NULL;
+  dtv[map->l_tls_modid].pointer.val = dest;
+
+  /* Initialize the memory.  */
   memset (__mempcpy (dest, map->l_tls_initimage, map->l_tls_initimage_size),
          '\0', map->l_tls_blocksize - map->l_tls_initimage_size);
 }

This is unsafe because the caller in _dl_try_allocate_static_tls only makes
sure that the DTV of the current thread is up-to-date with respect to the
global generation counter.  The TLS modid is not necessary current for other
threads at this point.

I don't know if DTV initialization at this point is actually needed.

-- 
You are receiving this mail because:
You are on the CC list for the bug.


More information about the Glibc-bugs mailing list