diff options
author | Jakub Jelinek <jakub@redhat.com> | 2009-07-27 07:25:57 -0700 |
---|---|---|
committer | Ulrich Drepper <drepper@redhat.com> | 2009-07-27 07:25:57 -0700 |
commit | 09cd1f575476a48b262e4e45997bb56753f9d4f5 (patch) | |
tree | d0e4c2fac24601a041829bf1ff7554687714e52c /elf | |
parent | 009a69f0bcce04d3743c9b59246e6885dbd2b100 (diff) | |
download | glibc-09cd1f575476a48b262e4e45997bb56753f9d4f5.tar glibc-09cd1f575476a48b262e4e45997bb56753f9d4f5.tar.gz glibc-09cd1f575476a48b262e4e45997bb56753f9d4f5.tar.bz2 glibc-09cd1f575476a48b262e4e45997bb56753f9d4f5.zip |
Fix STB_GNU_UNIQUE handling for > 30 unique symbols.
There were several issues when the initial 31 entries hashtab filled up.
size * 3 <= tab->n_elements is always false, table can't have more elements
than its size. I assume from libiberty/hashtab.c this meant to be check for
3/4 full. Even after fixing that, _dl_higher_prime_number (31) apparently
returns 31, only _dl_higher_prime_number (32) returns 61. And, size
variable wasn't updated during reallocation, which means during reallocation
the insertion of the new entry was done into a wrong spot.
All this lead to a hang in ld.so, because a search with n_elements 31 size
31 wouldn't ever terminate.
Diffstat (limited to 'elf')
-rw-r--r-- | elf/dl-lookup.c | 5 |
1 files changed, 3 insertions, 2 deletions
diff --git a/elf/dl-lookup.c b/elf/dl-lookup.c index 18f728812e..1d68d67a35 100644 --- a/elf/dl-lookup.c +++ b/elf/dl-lookup.c @@ -377,10 +377,10 @@ do_lookup_x (const char *undef_name, uint_fast32_t new_hash, idx -= size; } - if (size * 3 <= tab->n_elements) + if (size * 3 <= tab->n_elements * 4) { /* Expand the table. */ - size_t newsize = _dl_higher_prime_number (size); + size_t newsize = _dl_higher_prime_number (size + 1); struct unique_sym *newentries = calloc (sizeof (struct unique_sym), newsize); if (newentries == NULL) @@ -398,6 +398,7 @@ do_lookup_x (const char *undef_name, uint_fast32_t new_hash, tab->free (entries); tab->size = newsize; + size = newsize; entries = tab->entries = newentries; tab->free = free; } |