Saving errno around signal handlers

Florian Weimer fweimer@redhat.com
Mon Mar 3 08:59:00 GMT 2014


On 02/28/2014 11:12 PM, Joseph S. Myers wrote:

> So the first question is whether we should take advantage of that POSIX
> permission at all.  This seems similar to other cases of programs having
> undefined behavior, where we don't try to make them do anything sensible,
> such as not checking for invalid pointer arguments.  Maybe there should be
> a non-default optional sigaction flag SA_SAVEERRNO (allocation of this
> flag value would of course need coordinating with the kernel), and
> _FORTIFY_SOURCE or similar could then map sigaction calls to a non-default
> variant that always uses this flag (it's not clear this is really within
> the scope of _FORTIFY_SOURCE, though)?

Making this opt-in is not very attractive because once you touch 
application sources to deal with this, you could just fix the signal 
handler.

-- 
Florian Weimer / Red Hat Product Security Team



More information about the Libc-alpha mailing list