mirror of
				https://sourceware.org/git/glibc.git
				synced 2025-10-30 10:45:40 +03:00 
			
		
		
		
	As discussed in libc-alpha [1] current clone with CLONE_VM (without
CLONE_THREAD set) will reset the pthread pid/tid fields to -1.  The
issue is since memory is shared between the parent and child it will
clobber parent's cached pid/tid leading to internal inconsistencies
if the value is not restored.
And even it is restored it may lead to racy conditions when between
set/restore a thread might invoke pthread function that validate the
pthread with INVALID_TD_P/INVALID_NOT_TERMINATED_TD_P and thus get
wrong results.
As stated in BZ19957, previously reports of this behaviour was close
with EWONTFIX due the fact usage of clone outside glibc is tricky
since glibc requires consistent internal pthread, while using clone
directly may not provide it. However since now posix_spawn uses
clone (CLONE_VM) to fixes various issues related to previous vfork
usage this issue requires fixing.
The vfork implementation also does something similar, but instead
it negates and restores only the *pid* field and functions that
might access its value know to handle such case (getpid, raise
and pthread ones that uses INVALID_TD_P/INVALID_NOT_TERMINATED_TD_P
macros that check only *tid* field).  Also vfork does not call
__clone directly, instead calling either __NR_vfork or __NR_clone
directly.
So this patch removes this clone behavior by avoiding setting
the pthread pid/tid field for CLONE_VM. There is no need to
check for CLONE_THREAD, since the minimum supported kernel in all
architecture implies that CLONE_VM must be used with CLONE_THREAD,
otherwise clone returns EINVAL.
Instead of current approach of:
   int clone(int (*fn)(void *), void *child_stack, int flags, ...)
      [...]
      if (flags & CLONE_THREAD)
        goto do_syscall;
      pid_t new_value;
      if (flags & CLONE_VM)
        new_value = -1;
      else
        new_value = getpid ();
      THREAD_SETMEM (THREAD_SELF, pid, new_value);
      THREAD_SETMEM (THREAD_SELF, tid, new_value);
    do_syscall:
      [...]
The new approach uses:
   int clone(int (*fn)(void *), void *child_stack, int flags, ...)
      [...]
      if (flags & CLONE_VM)
        goto do_syscall;
      pid_t new_value = getpid ();
      THREAD_SETMEM (THREAD_SELF, pid, new_value);
      THREAD_SETMEM (THREAD_SELF, tid, new_value);
    do_syscall:
      [...]
It also removes the linux tst-getpid2.c test which expects the previous
behavior and instead add another clone test.
Tested on x86_64, i686, x32, powerpc64le, aarch64, armhf, s390, and
s390x. I also did limited check on mips32 and sparc64 (using the new
added test).
I also got reviews from both m68k, hppa, and tile.  So I presume for
these architecture the patch works.
The fixes for alpha, microblaze, sh, ia64, and nio2 have not been
tested.
[1] https://sourceware.org/ml/libc-alpha/2016-04/msg00307.html
	* sysdeps/unix/sysv/linux/Makefile [$(subdir) == nptl] (test): Remove
	tst-getpid2.
	(test): Add tst-clone2.
	* sysdeps/unix/sysv/linux/tst-clone2.c: New file.
	* sysdeps/unix/sysv/linux/aarch64/clone.S (__clone): Do not change
	pid/tid fields for CLONE_VM.
	* sysdeps/unix/sysv/linux/arm/clone.S: Likewise.
	* sysdeps/unix/sysv/linux/i386/clone.S: Likewise.
	* sysdeps/unix/sysv/linux/mips/clone.S: Likewise.
	* sysdeps/unix/sysv/linux/powerpc/powerpc32/clone.S: Likewise.
	* sysdeps/unix/sysv/linux/powerpc/powerpc64/clone.S: Likewise.
	* sysdeps/unix/sysv/linux/s390/s390-32/clone.S: Likewise.
	* sysdeps/unix/sysv/linux/s390/s390-64/clone.S: Likewise.
	* sysdeps/unix/sysv/linux/sparc/sparc32/clone.S: Likewise.
	* sysdeps/unix/sysv/linux/sparc/sparc64/clone.S: Likewise.
	* sysdeps/unix/sysv/linux/x86_64/clone.S: Likewise.
	* sysdeps/unix/sysv/linux/tst-getpid2.c: Remove file.
		
	
		
			
				
	
	
		
			166 lines
		
	
	
		
			4.0 KiB
		
	
	
	
		
			ArmAsm
		
	
	
	
	
	
			
		
		
	
	
			166 lines
		
	
	
		
			4.0 KiB
		
	
	
	
		
			ArmAsm
		
	
	
	
	
	
| /* Copyright (C) 1996-2016 Free Software Foundation, Inc.
 | |
|    This file is part of the GNU C Library.
 | |
|    Contributed by Ralf Baechle <ralf@linux-mips.org>, 1996.
 | |
| 
 | |
|    The GNU C Library is free software; you can redistribute it and/or
 | |
|    modify it under the terms of the GNU Lesser General Public
 | |
|    License as published by the Free Software Foundation; either
 | |
|    version 2.1 of the License, or (at your option) any later version.
 | |
| 
 | |
|    The GNU C Library is distributed in the hope that it will be useful,
 | |
|    but WITHOUT ANY WARRANTY; without even the implied warranty of
 | |
|    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 | |
|    Lesser General Public License for more details.
 | |
| 
 | |
|    You should have received a copy of the GNU Lesser General Public
 | |
|    License along with the GNU C Library.  If not, see
 | |
|    <http://www.gnu.org/licenses/>.  */
 | |
| 
 | |
| /* clone() is even more special than fork() as it mucks with stacks
 | |
|    and invokes a function in the right context after its all over.  */
 | |
| 
 | |
| #include <sys/asm.h>
 | |
| #include <sysdep.h>
 | |
| #define _ERRNO_H	1
 | |
| #include <bits/errno.h>
 | |
| #include <tls.h>
 | |
| 
 | |
| #define CLONE_VM      0x00000100
 | |
| #define CLONE_THREAD  0x00010000
 | |
| 
 | |
| /* int clone(int (*fn)(void *arg), void *child_stack, int flags, void *arg,
 | |
| 	     void *parent_tidptr, void *tls, void *child_tidptr) */
 | |
| 
 | |
| 	.text
 | |
| 	.set		nomips16
 | |
| #if _MIPS_SIM == _ABIO32
 | |
| # define EXTRA_LOCALS 1
 | |
| #else
 | |
| # define EXTRA_LOCALS 0
 | |
| #endif
 | |
| LOCALSZ= 4
 | |
| FRAMESZ= (((NARGSAVE+LOCALSZ)*SZREG)+ALSZ)&ALMASK
 | |
| GPOFF= FRAMESZ-(1*SZREG)
 | |
| NESTED(__clone,4*SZREG,sp)
 | |
| #ifdef __PIC__
 | |
| 	SETUP_GP
 | |
| #endif
 | |
| 	PTR_SUBU sp, FRAMESZ
 | |
| 	cfi_adjust_cfa_offset (FRAMESZ)
 | |
| 	SETUP_GP64_STACK (GPOFF, __clone)
 | |
| #ifdef __PIC__
 | |
| 	SAVE_GP (GPOFF)
 | |
| #endif
 | |
| #ifdef PROF
 | |
| 	.set		noat
 | |
| 	move		$1,ra
 | |
| 	jal		_mcount
 | |
| 	.set		at
 | |
| #endif
 | |
| 
 | |
| 
 | |
| 	/* Sanity check arguments.  */
 | |
| 	li		v0,EINVAL
 | |
| 	beqz		a0,L(error)	/* No NULL function pointers.  */
 | |
| 	beqz		a1,L(error)	/* No NULL stack pointers.  */
 | |
| 
 | |
| 	PTR_SUBU	a1,32		/* Reserve argument save space.  */
 | |
| 	PTR_S		a0,0(a1)	/* Save function pointer.  */
 | |
| 	PTR_S		a3,PTRSIZE(a1)	/* Save argument pointer.  */
 | |
| 	LONG_S		a2,(PTRSIZE*2)(a1)	/* Save clone flags.  */
 | |
| 
 | |
| 	move		a0,a2
 | |
| 
 | |
| 	/* Shuffle in the last three arguments - arguments 5, 6, and 7 to
 | |
| 	   this function, but arguments 3, 4, and 5 to the syscall.  */
 | |
| #if _MIPS_SIM == _ABIO32
 | |
| 	PTR_L		a2,(FRAMESZ+PTRSIZE+PTRSIZE+16)(sp)
 | |
| 	PTR_S		a2,16(sp)
 | |
| 	PTR_L		a2,(FRAMESZ+16)(sp)
 | |
| 	PTR_L		a3,(FRAMESZ+PTRSIZE+16)(sp)
 | |
| #else
 | |
| 	move		a2,a4
 | |
| 	move		a3,a5
 | |
| 	move		a4,a6
 | |
| #endif
 | |
| 
 | |
| 	/* Do the system call */
 | |
| 	li		v0,__NR_clone
 | |
| 	cfi_endproc
 | |
| 	syscall
 | |
| 
 | |
| 	bnez		a3,L(error)
 | |
| 	beqz		v0,L(thread_start)
 | |
| 
 | |
| 	/* Successful return from the parent */
 | |
| 	cfi_startproc
 | |
| 	cfi_adjust_cfa_offset (FRAMESZ)
 | |
| 	SETUP_GP64_STACK_CFI (GPOFF)
 | |
| 	cfi_remember_state
 | |
| 	RESTORE_GP64_STACK
 | |
| 	PTR_ADDU	sp, FRAMESZ
 | |
| 	cfi_adjust_cfa_offset (-FRAMESZ)
 | |
| 	ret
 | |
| 
 | |
| 	/* Something bad happened -- no child created */
 | |
| L(error):
 | |
| 	cfi_restore_state
 | |
| #ifdef __PIC__
 | |
| 	PTR_LA		t9,__syscall_error
 | |
| 	RESTORE_GP64_STACK
 | |
| 	PTR_ADDU	sp, FRAMESZ
 | |
| 	cfi_adjust_cfa_offset (-FRAMESZ)
 | |
| 	jr		t9
 | |
| #else
 | |
| 	RESTORE_GP64_STACK
 | |
| 	PTR_ADDU	sp, FRAMESZ
 | |
| 	cfi_adjust_cfa_offset (-FRAMESZ)
 | |
| 	j		__syscall_error
 | |
| #endif
 | |
| 	END(__clone)
 | |
| 
 | |
| /* Load up the arguments to the function.  Put this block of code in
 | |
|    its own function so that we can terminate the stack trace with our
 | |
|    debug info.  */
 | |
| 
 | |
| ENTRY(__thread_start)
 | |
| L(thread_start):
 | |
| 	cfi_undefined ($31)
 | |
| 	/* cp is already loaded.  */
 | |
| 	SAVE_GP (GPOFF)
 | |
| 	/* The stackframe has been created on entry of clone().  */
 | |
| 
 | |
| 	/* Check and see if we need to reset the PID.  */
 | |
| 	and	a1,a0,CLONE_VM
 | |
| 	beqz	a1,L(restore_pid)
 | |
| L(donepid):
 | |
| 
 | |
| 	/* Restore the arg for user's function.  */
 | |
| 	PTR_L		t9,0(sp)	/* Function pointer.  */
 | |
| 	PTR_L		a0,PTRSIZE(sp)	/* Argument pointer.  */
 | |
| 
 | |
| 	/* Call the user's function.  */
 | |
| 	jal		t9
 | |
| 
 | |
| 	/* Call _exit rather than doing it inline for breakpoint purposes.  */
 | |
| 	move		a0,v0
 | |
| #ifdef __PIC__
 | |
| 	PTR_LA		t9,_exit
 | |
| 	jalr		t9
 | |
| #else
 | |
| 	jal		_exit
 | |
| #endif
 | |
| 
 | |
| L(restore_pid):
 | |
| 	li		v0,__NR_getpid
 | |
| 	syscall
 | |
| 	READ_THREAD_POINTER(v1)
 | |
| 	INT_S		v0,PID_OFFSET(v1)
 | |
| 	INT_S		v0,TID_OFFSET(v1)
 | |
| 	b		L(donepid)
 | |
| 
 | |
| 	END(__thread_start)
 | |
| 
 | |
| libc_hidden_def (__clone)
 | |
| weak_alias (__clone, clone)
 |