In tst-tls3, all the TLS variables are in the same module. So your failure mode suggests that either the symbols or relocs for those three symbols are wrong (ld bugs) or the run-time reloc processing is wrong (dl-machine.h bugs).