[PATCH] assert.c: Undefine _FORTIFY_SOURCE [BZ 32456]

Florian Weimer fweimer@redhat.com
Thu Jan 2 09:28:12 GMT 2025


* H. J. Lu:

> When _FORTIFY_SOURCE is defined to >= 1, __printf_buffer, which is
> called with (mode_flags & PRINTF_FORTIFY) != 0 via assert (), calls
> __readonly_area to check if the format string is readonly.  The
> readonly check will fail in 2 cases:
> 1. When the message is translated and re-encoded, the format string
> is writable.
> 2. When fopen on /proc/self/maps returns NULL due to the malloc
> failure, as in test-assert-2.c, __readonly_area return -1.
> This triggers the fortification error:
>
>   if (readonly_format < 0)
>     __libc_fatal ("*** %n in writable segment detected ***\n");
>
> Undefine _FORTIFY_SOURCE to fix BZ 32456.
>
> Signed-off-by: H.J. Lu <hjl.tools@gmail.com>
> ---
>  assert/assert.c | 15 +++++++++++++++
>  1 file changed, 15 insertions(+)
>
> diff --git a/assert/assert.c b/assert/assert.c
> index 47b06ec7fd..5446bbde52 100644
> --- a/assert/assert.c
> +++ b/assert/assert.c
> @@ -15,6 +15,21 @@
>     License along with the GNU C Library; if not, see
>     <https://www.gnu.org/licenses/>.  */
>  
> +/* When _FORTIFY_SOURCE is defined to >= 1, __printf_buffer, which is
> +   called with (mode_flags & PRINTF_FORTIFY) != 0 via assert (), calls
> +   __readonly_area to check if the format string is readonly.  The
> +   readonly check will fail in 2 cases:
> +   1. When the message is translated and re-encoded, the format string
> +   is writable.
> +   2. When fopen on /proc/self/maps returns NULL due to the malloc
> +   failure, as in test-assert-2.c, __readonly_area return -1.
> +   This triggers the fortification error:
> +
> +     if (readonly_format < 0)
> +       __libc_fatal ("*** %n in writable segment detected ***\n");
> +
> +   Undefine _FORTIFY_SOURCE to avoid this error.  */
> +#undef _FORTIFY_SOURCE
>  #include <assert.h>
>  #include <atomic.h>
>  #include <ldsodefs.h>

Please see this parallel thread;

  [PATCH] assert: Remove the use of %n from __assert_fail_base (BZ #32456)
  <https://inbox.sourceware.org/libc-alpha/20241230163153.2399453-1-adhemerval.zanella@linaro.org/>

Thanks,
Florian



More information about the Libc-alpha mailing list