1
0
mirror of https://sourceware.org/git/glibc.git synced 2025-07-30 22:43:12 +03:00

elf: Fix data race in _dl_name_match_p [BZ #21349]

dlopen updates libname_list by writing to lastp->next, but concurrent
reads in _dl_name_match_p were not synchronized when it was called
without holding GL(dl_load_lock), which can happen during lazy symbol
resolution.

This patch fixes the race between _dl_name_match_p reading lastp->next
and add_name_to_object writing to it. This could cause segfault on
targets with weak memory order when lastp->next->name is read, which
was observed on an arm system. Fixes bug 21349.

(Code is from Maninder Singh, comments and description is from Szabolcs
Nagy.)

Co-authored-by: Vaneet Narang <v.narang@samsung.com>
Co-authored-by: Szabolcs Nagy <szabolcs.nagy@arm.com>
Reviewed-by: Adhemerval Zanella  <adhemerval.zanella@linaro.org>
This commit is contained in:
Maninder Singh
2018-01-10 15:17:30 +00:00
committed by Szabolcs Nagy
parent 69499bb6ee
commit 395be7c218
2 changed files with 20 additions and 2 deletions

View File

@ -347,7 +347,9 @@ _dl_name_match_p (const char *name, const struct link_map *map)
if (strcmp (name, runp->name) == 0)
return 1;
else
runp = runp->next;
/* Synchronize with the release MO store in add_name_to_object.
See CONCURRENCY NOTES in add_name_to_object in dl-load.c. */
runp = atomic_load_acquire (&runp->next);
return 0;
}