[PATCH] assert.c: Undefine _FORTIFY_SOURCE [BZ 32456]

Sam James sam@gentoo.org
Thu Jan 2 17:22:57 GMT 2025


Florian Weimer <fweimer@redhat.com> writes:

> * H. J. Lu:
>
>> When _FORTIFY_SOURCE is defined to >= 1, __printf_buffer, which is
>> called with (mode_flags & PRINTF_FORTIFY) != 0 via assert (), calls
>> __readonly_area to check if the format string is readonly.  The
>> readonly check will fail in 2 cases:
>> 1. When the message is translated and re-encoded, the format string
>> is writable.
>> 2. When fopen on /proc/self/maps returns NULL due to the malloc
>> failure, as in test-assert-2.c, __readonly_area return -1.
>> This triggers the fortification error:
>>
>>   if (readonly_format < 0)
>>     __libc_fatal ("*** %n in writable segment detected ***\n");
>>
>> Undefine _FORTIFY_SOURCE to fix BZ 32456.
>>
>> Signed-off-by: H.J. Lu <hjl.tools@gmail.com>
>> ---
>>  assert/assert.c | 15 +++++++++++++++
>>  1 file changed, 15 insertions(+)
>>
>> diff --git a/assert/assert.c b/assert/assert.c
>> index 47b06ec7fd..5446bbde52 100644
>> --- a/assert/assert.c
>> +++ b/assert/assert.c
>> @@ -15,6 +15,21 @@
>>     License along with the GNU C Library; if not, see
>>     <https://www.gnu.org/licenses/>.  */
>>  
>> +/* When _FORTIFY_SOURCE is defined to >= 1, __printf_buffer, which is
>> +   called with (mode_flags & PRINTF_FORTIFY) != 0 via assert (), calls
>> +   __readonly_area to check if the format string is readonly.  The
>> +   readonly check will fail in 2 cases:
>> +   1. When the message is translated and re-encoded, the format string
>> +   is writable.
>> +   2. When fopen on /proc/self/maps returns NULL due to the malloc
>> +   failure, as in test-assert-2.c, __readonly_area return -1.
>> +   This triggers the fortification error:
>> +
>> +     if (readonly_format < 0)
>> +       __libc_fatal ("*** %n in writable segment detected ***\n");
>> +
>> +   Undefine _FORTIFY_SOURCE to avoid this error.  */
>> +#undef _FORTIFY_SOURCE
>>  #include <assert.h>
>>  #include <atomic.h>
>>  #include <ldsodefs.h>
>
> Please see this parallel thread;
>
>   [PATCH] assert: Remove the use of %n from __assert_fail_base (BZ #32456)
>   <https://inbox.sourceware.org/libc-alpha/20241230163153.2399453-1-adhemerval.zanella@linaro.org/>

I'd personally like it if this went in for now so we can carry on our
testing pre-release without the noise of a (known) test failure.


More information about the Libc-alpha mailing list