name field of struct shmdir_name
Prasanna Paithankar
paithankarprasanna@gmail.com
Wed Sep 3 21:33:32 GMT 2025
(Let me know if this should go in the libc-alpha thread, wanted to
know opinions before commiting)
Greetings,
In struct shmdir_name (defined in include/shm-directory.h), the name
field is defined to be of length = 269 (10 + 4 + 255).
----- code for reference (include/shm-directory.h)
/* The directory that contains shared POSIX objects. */
#define SHMDIR _PATH_DEV "shm/"
struct shmdir_name
{
/* The combined prefix/name. The sizeof includes the terminating
NUL byte. 4 bytes are needed for the optional "sem." prefix. */
char name[sizeof (SHMDIR) + 4 + NAME_MAX];
};
-----
This struct is used by shm_open and sem_open, which use openat syscall
to create a file.
The openat will throw an error ENAMETOOLONG if the length of the file
name is greater than NAME_MAX (=255 mostly).
Consider the implementation snippet of __shm_get_name where it tries
to validate and form a valid file path in /dev/shm
----- code for reference (posix/shm-directory.c)
while (name[0] == '/')
++name;
namelen = strlen (name);
if (sem_prefix)
alloc_buffer_copy_bytes (&buffer, "sem.", strlen ("sem."));
alloc_buffer_copy_bytes (&buffer, name, namelen + 1);
if (namelen == 0 || memchr (name, '/', namelen) != NULL)
return EINVAL;
if (alloc_buffer_has_failed (&buffer))
{
if (namelen > NAME_MAX)
return ENAMETOOLONG;
return EINVAL;
}
-----
Proposition:
Can the "+ 4" be removed from the struct definition?
Reasoning:
For semaphore, if the input name length lies between 252-255 both
inclusive, the function __shm_get_name returns successfully (as
namelen < NAME_MAX and buffer has + 4 to contain sem.)
but then eventually fails at openat (as appending sem. overflows NAME_MAX)
Therefore, we can remove the + 4 and perform checks on length in
if (sem_prefix)
{
if (namelen + strlen("sem.") > NAME_MAX) return ENAMETOOLONG;
alloc_buffer_copy_bytes (&buffer, "sem.", strlen ("sem."));
}
Similarly, for shm_open call, the __shm_get_name is successful even
when the name length is lets say 256 (as alloc_buffer_has_failed
(&buffer) is false) but then will eventually fail at openat.
So ,we also put a namelen check in a new else statement as > NAME_MAX.
This removes the + 4 in the name field of the struct.
Regards,
Prasanna Paithankar
More information about the Libc-help
mailing list