[PATCH 2/2] nss: handle stat failure in check_reload_and_get (BZ #28752)
Adhemerval Zanella
adhemerval.zanella@linaro.org
Fri May 27 17:04:04 GMT 2022
On 25/05/2022 21:20, Sam James via Libc-alpha wrote:
> Skip the chroot test if the database isn't loaded
> correctly (because the chroot test uses some
> existing DB state).
>
> The __stat64_time64 -> fstatat call can fail if
> running under an (aggressive) seccomp filter,
> like Firefox seems to use.
>
> This manifested in a crash when using glib built
> with FAM support with such a Firefox build.
>
> Suggested-by: DJ Delorie <dj@redhat.com>
> Signed-off-by: Sam James <sam@gentoo.org>
> ---
> nss/nss_database.c | 33 ++++++++++++++++++---------------
> 1 file changed, 18 insertions(+), 15 deletions(-)
>
> diff --git a/nss/nss_database.c b/nss/nss_database.c
> index d56c5b798d..6c9b440a98 100644
> --- a/nss/nss_database.c
> +++ b/nss/nss_database.c
> @@ -420,21 +420,24 @@ nss_database_check_reload_and_get (struct nss_database_state *local,
> return true;
> }
>
> - /* Before we reload, verify that "/" hasn't changed. We assume that
> - errors here are very unlikely, but the chance that we're entering
> - a container is also very unlikely, so we err on the side of both
> - very unlikely things not happening at the same time. */
> - if (__stat64_time64 ("/", &str) != 0
> - || (local->root_ino != 0
> - && (str.st_ino != local->root_ino
> - || str.st_dev != local->root_dev)))
> - {
> - /* Change detected; disable reloading and return current state. */
> - atomic_store_release (&local->data.reload_disabled, 1);
> - *result = local->data.services[database_index];
> - __libc_lock_unlock (local->lock);
> - return true;
> - }
> + if (local->data.services[database_index] != NULL) {
> + /* Before we reload, verify that "/" hasn't changed. We assume that
> + errors here are very unlikely, but the chance that we're entering
> + a container is also very unlikely, so we err on the side of both
> + very unlikely things not happening at the same time. */
> + if (__stat64_time64 ("/", &str) != 0
> + || (local->root_ino != 0
> + && (str.st_ino != local->root_ino
> + || str.st_dev != local->root_dev)))
> + {
> + /* Change detected; disable reloading and return current state. */
> + atomic_store_release (&local->data.reload_disabled, 1);
> + *result = local->data.services[database_index];
> + __libc_lock_unlock (local->lock);
> + return true;
> + }
> + }
> +
> local->root_ino = str.st_ino;
> local->root_dev = str.st_dev;
> __libc_lock_unlock (local->lock);
Besides the buildbot issue [1] you already noted, please use the expected GNU
indentation. We have now a clang-format script (.clang-format) to help the
format.
[1] https://www.delorie.com/trybots/32bit/9696/nss-tst-reload1.out
More information about the Libc-alpha
mailing list