Saving errno around signal handlers
Florian Weimer
fweimer@redhat.com
Mon Mar 3 08:59:00 GMT 2014
On 02/28/2014 11:12 PM, Joseph S. Myers wrote:
> So the first question is whether we should take advantage of that POSIX
> permission at all. This seems similar to other cases of programs having
> undefined behavior, where we don't try to make them do anything sensible,
> such as not checking for invalid pointer arguments. Maybe there should be
> a non-default optional sigaction flag SA_SAVEERRNO (allocation of this
> flag value would of course need coordinating with the kernel), and
> _FORTIFY_SOURCE or similar could then map sigaction calls to a non-default
> variant that always uses this flag (it's not clear this is really within
> the scope of _FORTIFY_SOURCE, though)?
Making this opt-in is not very attractive because once you touch
application sources to deal with this, you could just fix the signal
handler.
--
Florian Weimer / Red Hat Product Security Team
More information about the Libc-alpha
mailing list