diff options
author | H.J. Lu <hjl.tools@gmail.com> | 2018-01-19 09:53:50 -0800 |
---|---|---|
committer | H.J. Lu <hjl.tools@gmail.com> | 2018-01-19 09:54:03 -0800 |
commit | 8337b12d0b80b0f26ec88156b8dd4972a9cb34c3 (patch) | |
tree | 4008d492c137fe6278300de815eda6152e57d025 | |
parent | fbd72f14904b8a81816528e0cc5bb3315fc70a47 (diff) | |
download | glibc-8337b12d0b80b0f26ec88156b8dd4972a9cb34c3.tar glibc-8337b12d0b80b0f26ec88156b8dd4972a9cb34c3.tar.gz glibc-8337b12d0b80b0f26ec88156b8dd4972a9cb34c3.tar.bz2 glibc-8337b12d0b80b0f26ec88156b8dd4972a9cb34c3.zip |
x86-64: Properly align La_x86_64_retval to VEC_SIZE [BZ #22715]
_dl_runtime_profile calls _dl_call_pltexit, passing a pointer to
La_x86_64_retval which is allocated on stack. The lrv_vector0
field in La_x86_64_retval must be aligned to size of vector register.
When allocating stack space for La_x86_64_retval, we need to make sure
that the address of La_x86_64_retval + RV_VECTOR0_OFFSET is aligned to
VEC_SIZE. This patch checks the alignment of the lrv_vector0 field
and pads the stack space if needed.
Tested with x32 and x86-64 on SSE4, AVX and AVX512 machines. It fixed
FAIL: elf/tst-audit10
FAIL: elf/tst-audit4
FAIL: elf/tst-audit5
FAIL: elf/tst-audit6
FAIL: elf/tst-audit7
on x32 AVX512 machine.
(cherry picked from commit 207a72e2988c6d6343f50fe0128eb4fc4edfdd15)
[BZ #22715]
* sysdeps/x86_64/dl-trampoline.h (_dl_runtime_profile): Properly
align La_x86_64_retval to VEC_SIZE.
-rw-r--r-- | ChangeLog | 6 | ||||
-rw-r--r-- | NEWS | 1 | ||||
-rw-r--r-- | sysdeps/x86_64/dl-trampoline.h | 12 |
3 files changed, 17 insertions, 2 deletions
@@ -1,3 +1,9 @@ +2018-01-19 H.J. Lu <hongjiu.lu@intel.com> + + [BZ #22715] + * sysdeps/x86_64/dl-trampoline.h (_dl_runtime_profile): Properly + align La_x86_64_retval to VEC_SIZE. + 2018-01-11 Florian Weimer <fweimer@redhat.com> * sysdeps/x86/cpu-features.c (init_cpu_features): Move check for @@ -48,6 +48,7 @@ The following bugs are resolved with this release: [21624] Unsafe alloca allows local attackers to alias stack and heap (CVE-2017-1000366) [21666] Avoid .symver on common symbols [22641] x86: Fix mis-merge of XSAVE ld.so trampoline selection + [22715] x86-64: Properly align La_x86_64_retval to VEC_SIZE Version 2.23 diff --git a/sysdeps/x86_64/dl-trampoline.h b/sysdeps/x86_64/dl-trampoline.h index aadc91d38a..c5f9237151 100644 --- a/sysdeps/x86_64/dl-trampoline.h +++ b/sysdeps/x86_64/dl-trampoline.h @@ -446,8 +446,16 @@ _dl_runtime_profile: # ifdef RESTORE_AVX /* sizeof(La_x86_64_retval). Need extra space for 2 SSE registers to detect if xmm0/xmm1 registers are changed - by audit module. */ - sub $(LRV_SIZE + XMM_SIZE*2), %RSP_LP + by audit module. Since rsp is aligned to VEC_SIZE, we + need to make sure that the address of La_x86_64_retval + + LRV_VECTOR0_OFFSET is aligned to VEC_SIZE. */ +# define LRV_SPACE (LRV_SIZE + XMM_SIZE*2) +# define LRV_MISALIGNED ((LRV_SIZE + LRV_VECTOR0_OFFSET) & (VEC_SIZE - 1)) +# if LRV_MISALIGNED == 0 + sub $LRV_SPACE, %RSP_LP +# else + sub $(LRV_SPACE + VEC_SIZE - LRV_MISALIGNED), %RSP_LP +# endif # else sub $LRV_SIZE, %RSP_LP # sizeof(La_x86_64_retval) # endif |