Tunables-related security regression
Siddhesh Poyarekar
siddhesh@gotplt.org
Mon Jan 23 10:52:00 GMT 2017
On Monday 23 January 2017 04:08 PM, Florian Weimer wrote:
> I filed
>
> <https://sourceware.org/bugzilla/show_bug.cgi?id=21073>
>
> because tunables change the behavior when filtering insecure environment
> variables such as MALLOC_CHECK_.
>
> We have three different kinds of environment variables:
>
> (1) variables which are removed when AT_SECURE is active
> (2) variables which are ignored when AT_SECURE is active
> (but they are passed to subprocesses, where AT_SECURE
> may not be in effect)
> (3) variables which are not treated in any special way
Thanks for the context.
> I think we need to reintroduce the filtering of MALLOC_CHECK_, and
> re-add the rewriting of the GLIBC_TUNABLES.
Ack, I'll fix this.
> We probably should put GLIBC_TUNABLES into category (1) if tunables are
> *not* active (currently, it's in category (3) because glibc does not
> know anything about tunables if they are disabled).
By not active, do you mean where the source is not configured with
tunables support? That seems pointless since any glibc that did not
have tunables would come under that category, i.e. anything before 2.25.
Siddhesh
More information about the Libc-alpha
mailing list