[PATCH] Fix readdir_r with long file names

Florian Weimer fweimer@redhat.com
Wed Jun 12 12:57:00 GMT 2013


On 06/11/2013 03:13 AM, Rich Felker wrote:

> I think the text should be informative and objective rather than
> dogmatic. It should include the following information:
>
> - On systems where NAME_MAX is not defined, readdir_r cannot be used
>    safely, as the interface contract for readdir_r is specified in
>    terms of NAME_MAX.
>
> - On systems where NAME_MAX is defined but not enforced for all
>    filesystems, there may be directory entries whose names are readable
>    by readdir but not readdir_r, and attempts to read such names on
>    older versions of glibc may result in exploitable buffer overflows.
>
> - Historically, POSIX does not require readdir to be thread-safe, but
>    on most (all?) known recent systems including glibc-based ones, it
>    is thread-safe as long as the same directory stream (DIR*) is not
>    accessed concurrently from multiple threads.
>
> - Future versions of POSIX will mandate this level of thread-safety
>    for the readdir function and mark readdir_r obsolescent.

I tried to incorporate these points into the most recent version.  I 
will add the bug number to NEWS before the commit.  I also changed 
readdir_r to use _D_EXACT_NAMLEN, as requested by Roland.

-- 
Florian Weimer / Red Hat Product Security Team
-------------- next part --------------
A non-text attachment was scrubbed...
Name: readdir_r.patch
Type: text/x-patch
Size: 11293 bytes
Desc: not available
URL: <http://sourceware.org/pipermail/libc-alpha/attachments/20130612/5435b312/attachment.bin>


More information about the Libc-alpha mailing list