glibc/malloc/set-freeres.c
Florian Weimer fada901819 dlfcn: dlerror needs to call free from the base namespace [BZ #24773]
Calling free directly may end up freeing a pointer allocated by the
dynamic loader using malloc from libc.so in the base namespace using
the allocator from libc.so in a secondary namespace, which results in
crashes.

This commit redirects the free call through GLRO and the dynamic
linker, to reach the correct namespace.  It also cleans up the dlerror
handling along the way, so that pthread_setspecific is no longer
needed (which avoids triggering bug 24774).
2021-04-21 19:49:51 +02:00

71 lines
2.2 KiB
C

/* Copyright (C) 1997-2021 Free Software Foundation, Inc.
This file is part of the GNU C Library.
The GNU C Library is free software; you can redistribute it and/or
modify it under the terms of the GNU Lesser General Public
License as published by the Free Software Foundation; either
version 2.1 of the License, or (at your option) any later version.
The GNU C Library is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
Lesser General Public License for more details.
You should have received a copy of the GNU Lesser General Public
License along with the GNU C Library; if not, see
<https://www.gnu.org/licenses/>. */
#include <atomic.h>
#include <stdlib.h>
#include <set-hooks.h>
#include <libc-internal.h>
#include <unwind-link.h>
#include <dlfcn/dlerror.h>
#include "../nss/nsswitch.h"
#include "../libio/libioP.h"
DEFINE_HOOK (__libc_subfreeres, (void));
symbol_set_define (__libc_freeres_ptrs);
extern __attribute__ ((weak)) void __libpthread_freeres (void);
void __libc_freeres_fn_section
__libc_freeres (void)
{
/* This function might be called from different places. So better
protect for multiple executions since these are fatal. */
static long int already_called;
if (!atomic_compare_and_exchange_bool_acq (&already_called, 1, 0))
{
void *const *p;
call_function_static_weak (__nss_module_freeres);
call_function_static_weak (__nss_action_freeres);
call_function_static_weak (__nss_database_freeres);
_IO_cleanup ();
/* We run the resource freeing after IO cleanup. */
RUN_HOOK (__libc_subfreeres, ());
/* Call the libpthread list of cleanup functions
(weak-ref-and-check). */
if (&__libpthread_freeres != NULL)
__libpthread_freeres ();
#ifdef SHARED
__libc_unwind_link_freeres ();
#endif
call_function_static_weak (__libc_dlerror_result_free);
for (p = symbol_set_first_element (__libc_freeres_ptrs);
!symbol_set_end_p (__libc_freeres_ptrs, p); ++p)
free (*p);
}
}
libc_hidden_def (__libc_freeres)