Bug#1028200: glibc: FTBFS on alpha due to buggy GL(dl_phdr) and GL(dl_phnum) [BZ #29864]

John Paul Adrian Glaubitz <[email protected]> Sun, 08 Jan 2023 13:39:59 +0100
Newsgroups gmane.linux.debian.ports.alpha
Message-ID <167318159982.1878821.14614663297550225142.reportbug__42970.9962032334$1673181936$gmane$org@nofan.physik.fu-berlin.de>
Source: glibc
Version: 2.36-8
Severity: normal
Tags: patch upstream
User: [email protected]
Usertags: alpha
X-Debbugs-Cc: [email protected]

Hello!

glibc fails to build from source on alpha with many testsuite failures [1]
due to a regression introduced in glibc 2.34 [2].

According to the discussion on the libc-alpha mailing list, this issue
affects multiple architectures for static builds. It just happens that
it causes segmentation faults on alpha [3].

A proposed patch by Adhemveral Zanella has been posted on the list [4]
but not been merged yet. I tested the first version of the patch [3] and
can confirm that it works. I will test the posted version [4] now.

Adhemerval said that he plans to backport the patch down to 2.34, so it
will eventually show up in 2.36 as well. Either way, it might be a good
idea to already carry the patch in Debian but I'm not sure.

Thanks,
Adrian

> [1] https://buildd.debian.org/status/logs.php?pkg=glibc&arch=alpha
> [2] https://sourceware.org/pipermail/libc-alpha/2023-January/144445.html
> [3] https://sourceware.org/pipermail/libc-alpha/2023-January/144452.html
> [4] https://sourceware.org/pipermail/libc-alpha/2023-January/144457.html

--
 .''`.  John Paul Adrian Glaubitz
: :' :  Debian Developer
`. `'   Physicist
  `-    GPG: 62FF 8A75 84E0 2956 9546  0006 7426 3B37 F5B5 F913
0001-Fix-GL-dl_phdr-and-GL-dl_phnum-for-static-builds-BZ29864.patch (message/rfc822, 15.1 KB)
Return-path: <bounce-debian-alpha=glaubitz=physik.fu-berlin.de@lists.debian.org>
Delivery-date: Tue, 03 Jan 2023 15:48:42 +0100
Received: from deliver1.zedat.fu-berlin.de ([130.133.4.79])
          by mbox5.zedat.fu-berlin.de (Exim 4.95)
          for [email protected] with esmtps (TLS1.2)
          tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
          (envelope-from <bounce-debian-alpha=glaubitz=physik.fu-berlin.de@lists.debian.org>)
          id 1pCiao-001rrY-MQ; Tue, 03 Jan 2023 15:48:42 +0100
Received: from dispatch2.zedat.fu-berlin.de ([130.133.4.71])
          by deliver1.zedat.fu-berlin.de (Exim 4.95)
          for [email protected] with esmtps (TLS1.2)
          tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
          (envelope-from <bounce-debian-alpha=glaubitz=physik.fu-berlin.de@lists.debian.org>)
          id 1pCiao-000GO4-L7; Tue, 03 Jan 2023 15:48:42 +0100
Received: from dispatch1.zedat.fu-berlin.de ([130.133.4.70])
          by dispatch2.zedat.fu-berlin.de (Exim 4.95)
          for [email protected] with esmtps (TLS1.2)
          tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
          (envelope-from <bounce-debian-alpha=glaubitz=physik.fu-berlin.de@lists.debian.org>)
          id 1pCiag-001ZZq-NG; Tue, 03 Jan 2023 15:48:34 +0100
Received: from inpost1.zedat.fu-berlin.de ([130.133.4.68])
          by dispatch1.zedat.fu-berlin.de (Exim 4.95)
          for [email protected] with esmtps (TLS1.2)
          tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
          (envelope-from <bounce-debian-alpha=glaubitz=physik.fu-berlin.de@lists.debian.org>)
          id 1pCiad-0024Nt-17; Tue, 03 Jan 2023 15:48:31 +0100
Received: from outpost19.zedat.fu-berlin.de ([130.133.4.112])
          by inpost1.zedat.fu-berlin.de (Exim 4.95)
          for [email protected] with esmtps (TLS1.3)
          tls TLS_AES_256_GCM_SHA384
          (envelope-from <bounce-debian-alpha=glaubitz=physik.fu-berlin.de@lists.debian.org>)
          id 1pCiac-001vIo-VE; Tue, 03 Jan 2023 15:48:30 +0100
Received: from relay1.zedat.fu-berlin.de ([130.133.4.67])
          by outpost.zedat.fu-berlin.de (Exim 4.95)
          for [email protected] with esmtps (TLS1.3)
          tls TLS_AES_256_GCM_SHA384
          (envelope-from <bounce-debian-alpha=glaubitz=physik.fu-berlin.de@lists.debian.org>)
          id 1pCiac-002les-TZ; Tue, 03 Jan 2023 15:48:30 +0100
Received: from bendel.debian.org ([82.195.75.100])
          by relay1.zedat.fu-berlin.de (Exim 4.95)
          for [email protected] with esmtps (TLS1.3)
          tls TLS_AES_256_GCM_SHA384
          (envelope-from <bounce-debian-alpha=glaubitz=physik.fu-berlin.de@lists.debian.org>)
          id 1pCiac-0031OA-Qx; Tue, 03 Jan 2023 15:48:30 +0100
Received: from localhost (localhost [127.0.0.1])
	by bendel.debian.org (Postfix) with QMQP
	id BB47F20838; Tue,  3 Jan 2023 14:48:12 +0000 (UTC)
X-Mailbox-Line: From [email protected]  Tue Jan  3 14:48:12 2023
Old-Return-Path: <[email protected]>
X-Original-To: [email protected]
Delivered-To: [email protected]
Received: from localhost (localhost [127.0.0.1])
	by bendel.debian.org (Postfix) with ESMTP id 287A920778
	for <[email protected]>; Tue,  3 Jan 2023 14:30:29 +0000 (UTC)
X-Virus-Scanned: at lists.debian.org with policy bank en-lt
X-Amavis-Spam-Status: No, score=-4.38 tagged_above=-10000 required=5.3
	tests=[BAYES_00=-2, DIGITS_LETTERS=1, DKIM_SIGNED=0.1,
	DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FOURLA=0.1,
	LDO_WHITELIST=-5, MURPHY_DRUGS_REL8=0.02, RCVD_IN_DNSWL_NONE=-0.0001,
	URIBL_BLACK=1.7] autolearn=no autolearn_force=no
Received: from bendel.debian.org ([127.0.0.1])
	by localhost (lists.debian.org [127.0.0.1]) (amavisd-new, port 2525)
	with ESMTP id tMsG2uCT38TR for <[email protected]>;
	Tue,  3 Jan 2023 14:30:20 +0000 (UTC)
X-policyd-weight: NOT_IN_SBL_XBL_SPAMHAUS=-1.5 CL_IP_EQ_HELO_IP=-2 (check from: .linaro. - helo: .mail-oa1-x2b.google. - helo-domain: .google.)  FROM/MX_MATCHES_HELO(DOMAIN)=-2; rate: -5.5
Received: from mail-oa1-x2b.google.com (mail-oa1-x2b.google.com [IPv6:2001:4860:4864:20::2b])
	(using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)
	 key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256
	 client-signature RSA-PSS (2048 bits) client-digest SHA256)
	(Client CN "smtp.gmail.com", Issuer "GTS CA 1D4" (not verified))
	by bendel.debian.org (Postfix) with ESMTPS id D3AB6207D2
	for <[email protected]>; Tue,  3 Jan 2023 14:30:20 +0000 (UTC)
Received: by mail-oa1-x2b.google.com with SMTP id 586e51a60fabf-14fb7fdb977so30272580fac.12
        for <[email protected]>; Tue, 03 Jan 2023 06:30:20 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=linaro.org; s=google;
        h=content-transfer-encoding:mime-version:message-id:date:subject:cc
         :to:from:from:to:cc:subject:date:message-id:reply-to;
        bh=eomuqx6adxr6lAzpv6smuOpebEyjdJTZipoNUmb4/Hs=;
        b=CGcIlYKUoS4s9HOnlU4AwaZ8pAhbM210laKO6dAcaULu/eu8O5iqjVeI2GFmMsO4IR
         Ejd3hLzdCyUTKx/+FFXUJAibW5dst2/qvE1if9Z3kknSu+ZiOlz75DE8PcKFUgkNQxX6
         BXDiZvXjFA/gQy/p3Zyg2lJRn5Hva0dkvJjrUk3yCh6Z8OWGoFtpPEF5pRIHSkJfvfIO
         q/Kz3t1z+uFtCrxge3jUzuKr2boJSy9908U38EDoxVht+40T4gEwAF8QhFaUdoM2mZqD
         5ALFVip7w7Q8Wky7xcqwIQsJ00D8zpKo9i315cPVspcVOzePmHS9qOWZpfu/DJx5ZWAc
         0c9Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20210112;
        h=content-transfer-encoding:mime-version:message-id:date:subject:cc
         :to:from:x-gm-message-state:from:to:cc:subject:date:message-id
         :reply-to;
        bh=eomuqx6adxr6lAzpv6smuOpebEyjdJTZipoNUmb4/Hs=;
        b=PBNkHR2ZUymnceg8qxcXqgTa9DM8ZKmK2SwC/yHKSuZ6ok12Ms6KdhToEYU+vDsFjd
         kLsl5VT8bYFTG7dX2Q9vRw0h3me+8Qq0XJfbOj8tC24zVeoj4rNBy3N8gOpwI6ogHJPF
         QhKrBMGlY6YMDCI3C58u6YxukZxsIu6IAd0zqj596STwoU5GbjcVYW/0hhdNeJXE9pxP
         GL2A51fKSDBYx1yJpBuKnnDM14gn0O4RGBFzp2aC86gFSJTqrXKOmyRkmR0BFPz/Z0BQ
         c8I5eB5rxPgufL+h5BmCunuY3DWeNaLATaFAfCsR9cLM4/kDj1vnzLxplGAzbZGEWdf4
         iFqQ==
X-Gm-Message-State: AFqh2kqs4UC1N5YQg95wB2GK2RteKZbVvGCLmkvUmDX1DfFfD8uCkUmT
	2GonLGMMjM7CRFzfzvhJK3dKTw==
X-Google-Smtp-Source: AMrXdXvgrDyEJ6OACbHGG7M0zczcutq/yWSodnBIUHg/XrCAGwqi3Spv38tKBRlEXKMTT7di4+2xNA==
X-Received: by 2002:a05:6870:bc12:b0:14c:7959:8c2e with SMTP id oa18-20020a056870bc1200b0014c79598c2emr21634936oab.2.1672756216662;
        Tue, 03 Jan 2023 06:30:16 -0800 (PST)
Received: from mandiga.. ([2804:1b3:a7c0:1729:332c:1ce3:286f:eb6])
        by smtp.gmail.com with ESMTPSA id n38-20020a05687055a600b0013b9ee734dcsm14219866oao.35.2023.01.03.06.30.14
        (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
        Tue, 03 Jan 2023 06:30:15 -0800 (PST)
From: Adhemerval Zanella <[email protected]>
To: [email protected],
	Florian Weimer <[email protected]>,
	=?UTF-8?q?Yago=20Guti=C3=A9rrez?= <[email protected]>
Cc: John Paul Adrian Glaubitz <[email protected]>,
	"debian-alpha @ lists . debian . org" <[email protected]>,
	[email protected]
Subject: [PATCH] elf: Fix GL(dl_phdr) and GL(dl_phnum) for static builds [BZ #29864]
Date: Tue,  3 Jan 2023 11:30:11 -0300
Message-Id: <[email protected]>
X-Mailer: git-send-email 2.34.1
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
X-Rc-Spam: 2008-11-04_01
X-Rc-Virus: 2007-09-13_01
X-Rc-Spam: 2008-11-04_01
Resent-Message-ID: <cBZMQlUKR3G.A.dOH.sAEtjB@bendel>
Resent-From: [email protected]
X-Mailing-List: <[email protected]> archive/latest/19936
X-Loop: [email protected]
List-Id: <debian-alpha.lists.debian.org>
List-URL: <https://lists.debian.org/debian-alpha/>
List-Post: <mailto:[email protected]>
List-Help: <mailto:[email protected]?subject=help>
List-Subscribe: <mailto:[email protected]?subject=subscribe>
List-Unsubscribe: <mailto:[email protected]?subject=unsubscribe>
Precedence: list
Resent-Sender: [email protected]
List-Archive: https://lists.debian.org/msgid-search/[email protected]
Resent-Date: Tue,  3 Jan 2023 14:48:12 +0000 (UTC)
X-Originating-IP: 82.195.75.100
X-purgate: bulk
X-purgate-type: bulk
X-purgate-ID: 151147::1672757311-BB923379-056BBAD9/9/2797
X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4
X-Spam-Flag: NO
X-Spam-Status: No, score=0.2 required=5.0 tests=DKIM_SIGNED,DKIM_VALID,
	DKIM_VALID_AU,FU_XPURGATE_BULK,HEADER_FROM_DIFFERENT_DOMAINS,
	MAILING_LIST_MULTI,RCVD_IN_MSPIKE_H3,RCVD_IN_MSPIKE_WL,SPF_HELO_NONE,
	SPF_NONE
X-Spam-Checker-Version: SpamAssassin 3.4.6 on Tokelau.ZEDAT.FU-Berlin.DE
X-ZEDAT-Hint: V

The 73fc4e28b9464f0e refactor did not add the GL(dl_phdr) and
GL(dl_phnum) for static build, relying on the __ehdr_start symbol,
which is always added by the static linker, to get the correct values.

This is problematic in some ways:

  - The segment may see its in-memory size differ from its in-file
    size (or the binary may have holes).  The Linux has fixed is to
    provide concise values for both AT_PHDR and AT_PHNUM (commit
    0da1d5002745c - "fs/binfmt_elf: Fix AT_PHDR for unusual ELF files")

  - Some archs (alpha for instance) the hidden weak reference is not
    correctly pulled by the static linker and  __ehdr_start address
    end up being 0, which makes GL(dl_phdr) and GL(dl_phnum) have both
    invalid values (and triggering a segfault later on libc.so while
    accessing TLS variables).

The safer fix is to just restore the previous behavior to setup
GL(dl_phdr) and GL(dl_phnum) for static based on kernel auxv.  The
__ehdr_start fallback can also be simplified by not assuming weak
linkage (as for PIE).

The libc-static.c auxv init logic is moved to dl-support.c, since
the later is build without SHARED and then GLRO macro is defined
to access the variables directly.

The _dl_phdr is also assumed to be always non NULL, since an invalid
NULL values does not trigger TLS initialization (which is used in
various libc systems).

Checked on aarch64-linux-gnu, x86_64-linux-gnu, and i686-linux-gnu.
---
 csu/libc-start.c                        | 21 ----------
 csu/libc-tls.c                          | 25 ++++++------
 elf/dl-support.c                        | 52 ++++++++++++++++---------
 sysdeps/unix/sysv/linux/dl-parse_auxv.h |  1 +
 4 files changed, 46 insertions(+), 53 deletions(-)

diff --git a/csu/libc-start.c b/csu/libc-start.c
index 543560f36c..bfeee6d851 100644
--- a/csu/libc-start.c
+++ b/csu/libc-start.c
@@ -262,28 +262,7 @@ LIBC_START_MAIN (int (*main) (int, char **, char ** MAIN_AUXVEC_DECL),
   }
 #  endif
   _dl_aux_init (auxvec);
-  if (GL(dl_phdr) == NULL)
 # endif
-    {
-      /* Starting from binutils-2.23, the linker will define the
-         magic symbol __ehdr_start to point to our own ELF header
-         if it is visible in a segment that also includes the phdrs.
-         So we can set up _dl_phdr and _dl_phnum even without any
-         information from auxv.  */
-
-      extern const ElfW(Ehdr) __ehdr_start
-# if BUILD_PIE_DEFAULT
-	__attribute__ ((visibility ("hidden")));
-# else
-	__attribute__ ((weak, visibility ("hidden")));
-      if (&__ehdr_start != NULL)
-# endif
-        {
-          assert (__ehdr_start.e_phentsize == sizeof *GL(dl_phdr));
-          GL(dl_phdr) = (const void *) &__ehdr_start + __ehdr_start.e_phoff;
-          GL(dl_phnum) = __ehdr_start.e_phnum;
-        }
-    }
 
   __tunables_init (__environ);
 
diff --git a/csu/libc-tls.c b/csu/libc-tls.c
index ca4def2613..51d3cf99bf 100644
--- a/csu/libc-tls.c
+++ b/csu/libc-tls.c
@@ -119,19 +119,18 @@ __libc_setup_tls (void)
   __tls_pre_init_tp ();
 
   /* Look through the TLS segment if there is any.  */
-  if (_dl_phdr != NULL)
-    for (phdr = _dl_phdr; phdr < &_dl_phdr[_dl_phnum]; ++phdr)
-      if (phdr->p_type == PT_TLS)
-	{
-	  /* Remember the values we need.  */
-	  memsz = phdr->p_memsz;
-	  filesz = phdr->p_filesz;
-	  initimage = (void *) phdr->p_vaddr + main_map->l_addr;
-	  align = phdr->p_align;
-	  if (phdr->p_align > max_align)
-	    max_align = phdr->p_align;
-	  break;
-	}
+  for (phdr = _dl_phdr; phdr < &_dl_phdr[_dl_phnum]; ++phdr)
+    if (phdr->p_type == PT_TLS)
+      {
+	/* Remember the values we need.  */
+	memsz = phdr->p_memsz;
+	filesz = phdr->p_filesz;
+	initimage = (void *) phdr->p_vaddr + main_map->l_addr;
+	align = phdr->p_align;
+	if (phdr->p_align > max_align)
+	  max_align = phdr->p_align;
+	break;
+      }
 
   /* Calculate the size of the static TLS surplus, with 0 auditors.  */
   _dl_tls_static_surplus_init (0);
diff --git a/elf/dl-support.c b/elf/dl-support.c
index 614b5b3e0c..b5ec5bd6d1 100644
--- a/elf/dl-support.c
+++ b/elf/dl-support.c
@@ -250,12 +250,27 @@ _dl_aux_init (ElfW(auxv_t) *av)
 #endif
 
   _dl_auxv = av;
-  dl_parse_auxv_t auxv_values;
-  /* Use an explicit initialization loop here because memset may not
-     be available yet.  */
-  for (int i = 0; i < array_length (auxv_values); ++i)
-    auxv_values[i] = 0;
+  dl_parse_auxv_t auxv_values = { 0, };
   _dl_parse_auxv (av, auxv_values);
+
+  _dl_phdr = (void*) auxv_values[AT_PHDR];
+  _dl_phnum = auxv_values[AT_PHNUM];
+
+  if (_dl_phdr == NULL)
+    {
+      /* Starting from binutils-2.23, the linker will define the
+         magic symbol __ehdr_start to point to our own ELF header
+         if it is visible in a segment that also includes the phdrs.
+         So we can set up _dl_phdr and _dl_phnum even without any
+         information from auxv.  */
+
+      extern const ElfW(Ehdr) __ehdr_start attribute_hidden;
+      assert (__ehdr_start.e_phentsize == sizeof *GL(dl_phdr));
+      _dl_phdr = (const void *) &__ehdr_start + __ehdr_start.e_phoff;
+      _dl_phnum = __ehdr_start.e_phnum;
+    }
+
+  assert (_dl_phdr != NULL);
 }
 #endif
 
@@ -324,20 +339,19 @@ _dl_non_dynamic_init (void)
   if (_dl_platform != NULL)
     _dl_platformlen = strlen (_dl_platform);
 
-  if (_dl_phdr != NULL)
-    for (const ElfW(Phdr) *ph = _dl_phdr; ph < &_dl_phdr[_dl_phnum]; ++ph)
-      switch (ph->p_type)
-	{
-	/* Check if the stack is nonexecutable.  */
-	case PT_GNU_STACK:
-	  _dl_stack_flags = ph->p_flags;
-	  break;
-
-	case PT_GNU_RELRO:
-	  _dl_main_map.l_relro_addr = ph->p_vaddr;
-	  _dl_main_map.l_relro_size = ph->p_memsz;
-	  break;
-	}
+  for (const ElfW(Phdr) *ph = _dl_phdr; ph < &_dl_phdr[_dl_phnum]; ++ph)
+    switch (ph->p_type)
+      {
+      /* Check if the stack is nonexecutable.  */
+      case PT_GNU_STACK:
+	_dl_stack_flags = ph->p_flags;
+	break;
+
+      case PT_GNU_RELRO:
+	_dl_main_map.l_relro_addr = ph->p_vaddr;
+	_dl_main_map.l_relro_size = ph->p_memsz;
+	break;
+      }
 
   call_function_static_weak (_dl_find_object_init);
 
diff --git a/sysdeps/unix/sysv/linux/dl-parse_auxv.h b/sysdeps/unix/sysv/linux/dl-parse_auxv.h
index bf9374371e..2bf3a0ca6b 100644
--- a/sysdeps/unix/sysv/linux/dl-parse_auxv.h
+++ b/sysdeps/unix/sysv/linux/dl-parse_auxv.h
@@ -21,6 +21,7 @@
 #include <fpu_control.h>
 #include <ldsodefs.h>
 #include <link.h>
+#include <dl-auxv.h>  /* For DL_PLATFORM_AUXV  */
 
 typedef ElfW(Addr) dl_parse_auxv_t[AT_MINSIGSTKSZ + 1];