From: Sasha Levin <sashal@kernel.org>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: Michael Forney <mforney@mforney.org>,
Miroslav Benes <mbenes@suse.cz>,
Josh Poimboeuf <jpoimboe@redhat.com>,
Sasha Levin <sashal@kernel.org>,
peterz@infradead.org
Subject: [PATCH AUTOSEL 5.14 09/26] objtool: Update section header before relocations
Date: Wed, 20 Oct 2021 20:20:06 -0400 [thread overview]
Message-ID: <20211021002023.1128949-9-sashal@kernel.org> (raw)
In-Reply-To: <20211021002023.1128949-1-sashal@kernel.org>
From: Michael Forney <mforney@mforney.org>
[ Upstream commit 86e1e054e0d2105cf32b0266cf1a64e6c26424f7 ]
The libelf implementation from elftoolchain has a safety check in
gelf_update_rel[a] to check that the data corresponds to a section
that has type SHT_REL[A] [0]. If the relocation is updated before
the section header is updated with the proper type, this check
fails.
To fix this, update the section header first, before the relocations.
Previously, the section size was calculated in elf_rebuild_reloc_section
by counting the number of entries in the reloc_list. However, we
now need the size during elf_write so instead keep a running total
and add to it for every new relocation.
[0] https://sourceforge.net/p/elftoolchain/mailman/elftoolchain-developers/thread/CAGw6cBtkZro-8wZMD2ULkwJ39J+tHtTtAWXufMjnd3cQ7XG54g@mail.gmail.com/
Signed-off-by: Michael Forney <mforney@mforney.org>
Reviewed-by: Miroslav Benes <mbenes@suse.cz>
Signed-off-by: Josh Poimboeuf <jpoimboe@redhat.com>
Link: https://lore.kernel.org/r/20210509000103.11008-2-mforney@mforney.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/objtool/elf.c | 46 +++++++++++++++++----------------------------
1 file changed, 17 insertions(+), 29 deletions(-)
diff --git a/tools/objtool/elf.c b/tools/objtool/elf.c
index 6cf4c0f11906..a9c2bebd7576 100644
--- a/tools/objtool/elf.c
+++ b/tools/objtool/elf.c
@@ -509,6 +509,7 @@ int elf_add_reloc(struct elf *elf, struct section *sec, unsigned long offset,
list_add_tail(&reloc->list, &sec->reloc->reloc_list);
elf_hash_add(reloc, &reloc->hash, reloc_hash(reloc));
+ sec->reloc->sh.sh_size += sec->reloc->sh.sh_entsize;
sec->reloc->changed = true;
return 0;
@@ -979,26 +980,23 @@ static struct section *elf_create_reloc_section(struct elf *elf,
}
}
-static int elf_rebuild_rel_reloc_section(struct section *sec, int nr)
+static int elf_rebuild_rel_reloc_section(struct section *sec)
{
struct reloc *reloc;
- int idx = 0, size;
+ int idx = 0;
void *buf;
/* Allocate a buffer for relocations */
- size = nr * sizeof(GElf_Rel);
- buf = malloc(size);
+ buf = malloc(sec->sh.sh_size);
if (!buf) {
perror("malloc");
return -1;
}
sec->data->d_buf = buf;
- sec->data->d_size = size;
+ sec->data->d_size = sec->sh.sh_size;
sec->data->d_type = ELF_T_REL;
- sec->sh.sh_size = size;
-
idx = 0;
list_for_each_entry(reloc, &sec->reloc_list, list) {
reloc->rel.r_offset = reloc->offset;
@@ -1013,26 +1011,23 @@ static int elf_rebuild_rel_reloc_section(struct section *sec, int nr)
return 0;
}
-static int elf_rebuild_rela_reloc_section(struct section *sec, int nr)
+static int elf_rebuild_rela_reloc_section(struct section *sec)
{
struct reloc *reloc;
- int idx = 0, size;
+ int idx = 0;
void *buf;
/* Allocate a buffer for relocations with addends */
- size = nr * sizeof(GElf_Rela);
- buf = malloc(size);
+ buf = malloc(sec->sh.sh_size);
if (!buf) {
perror("malloc");
return -1;
}
sec->data->d_buf = buf;
- sec->data->d_size = size;
+ sec->data->d_size = sec->sh.sh_size;
sec->data->d_type = ELF_T_RELA;
- sec->sh.sh_size = size;
-
idx = 0;
list_for_each_entry(reloc, &sec->reloc_list, list) {
reloc->rela.r_offset = reloc->offset;
@@ -1050,16 +1045,9 @@ static int elf_rebuild_rela_reloc_section(struct section *sec, int nr)
static int elf_rebuild_reloc_section(struct elf *elf, struct section *sec)
{
- struct reloc *reloc;
- int nr;
-
- nr = 0;
- list_for_each_entry(reloc, &sec->reloc_list, list)
- nr++;
-
switch (sec->sh.sh_type) {
- case SHT_REL: return elf_rebuild_rel_reloc_section(sec, nr);
- case SHT_RELA: return elf_rebuild_rela_reloc_section(sec, nr);
+ case SHT_REL: return elf_rebuild_rel_reloc_section(sec);
+ case SHT_RELA: return elf_rebuild_rela_reloc_section(sec);
default: return -1;
}
}
@@ -1119,12 +1107,6 @@ int elf_write(struct elf *elf)
/* Update changed relocation sections and section headers: */
list_for_each_entry(sec, &elf->sections, list) {
if (sec->changed) {
- if (sec->base &&
- elf_rebuild_reloc_section(elf, sec)) {
- WARN("elf_rebuild_reloc_section");
- return -1;
- }
-
s = elf_getscn(elf->elf, sec->idx);
if (!s) {
WARN_ELF("elf_getscn");
@@ -1135,6 +1117,12 @@ int elf_write(struct elf *elf)
return -1;
}
+ if (sec->base &&
+ elf_rebuild_reloc_section(elf, sec)) {
+ WARN("elf_rebuild_reloc_section");
+ return -1;
+ }
+
sec->changed = false;
elf->changed = true;
}
--
2.33.0
next prev parent reply other threads:[~2021-10-21 0:21 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-10-21 0:19 [PATCH AUTOSEL 5.14 01/26] kunit: fix reference count leak in kfree_at_end Sasha Levin
2021-10-21 0:19 ` [PATCH AUTOSEL 5.14 02/26] drm/msm/a6xx: Serialize GMU communication Sasha Levin
2021-10-21 0:20 ` [PATCH AUTOSEL 5.14 03/26] gcc-plugins/structleak: add makefile var for disabling structleak Sasha Levin
2021-10-21 0:20 ` [PATCH AUTOSEL 5.14 04/26] iio/test-format: build kunit tests without structleak plugin Sasha Levin
2021-10-21 0:20 ` [PATCH AUTOSEL 5.14 05/26] device property: " Sasha Levin
2021-10-21 0:20 ` [PATCH AUTOSEL 5.14 06/26] thunderbolt: " Sasha Levin
2021-10-21 0:20 ` [PATCH AUTOSEL 5.14 07/26] bitfield: " Sasha Levin
2021-10-21 0:20 ` [PATCH AUTOSEL 5.14 08/26] objtool: Check for gelf_update_rel[a] failures Sasha Levin
2021-10-21 0:20 ` Sasha Levin [this message]
2021-10-21 0:20 ` [PATCH AUTOSEL 5.14 10/26] ALSA: hda: intel: Allow repeatedly probing on codec configuration errors Sasha Levin
2021-10-21 0:20 ` [PATCH AUTOSEL 5.14 11/26] btrfs: deal with errors when checking if a dir entry exists during log replay Sasha Levin
2021-10-21 0:20 ` [PATCH AUTOSEL 5.14 12/26] net: stmmac: add support for dwmac 3.40a Sasha Levin
2021-10-21 0:20 ` [PATCH AUTOSEL 5.14 13/26] ARM: dts: spear3xx: Fix gmac node Sasha Levin
2021-10-21 0:20 ` [PATCH AUTOSEL 5.14 14/26] nfc: nci: fix the UAF of rf_conn_info object Sasha Levin
2021-10-21 0:20 ` [PATCH AUTOSEL 5.14 15/26] isdn: cpai: check ctr->cnr to avoid array index out of bound Sasha Levin
2021-10-21 0:20 ` [PATCH AUTOSEL 5.14 16/26] isdn: mISDN: Fix sleeping function called from invalid context Sasha Levin
2021-10-21 0:20 ` [PATCH AUTOSEL 5.14 17/26] platform/x86: intel_scu_ipc: Increase virtual timeout to 10s Sasha Levin
2021-10-21 0:20 ` [PATCH AUTOSEL 5.14 18/26] platform/x86: intel_scu_ipc: Update timeout value in comment Sasha Levin
2021-10-21 0:20 ` [PATCH AUTOSEL 5.14 19/26] ALSA: hda: avoid write to STATESTS if controller is in reset Sasha Levin
2021-10-21 0:20 ` [PATCH AUTOSEL 5.14 20/26] spi: Fix deadlock when adding SPI controllers on SPI buses Sasha Levin
2021-10-21 0:20 ` [PATCH AUTOSEL 5.14 21/26] spi-mux: Fix false-positive lockdep splats Sasha Levin
2021-10-21 0:20 ` [PATCH AUTOSEL 5.14 22/26] libperf test evsel: Fix build error on !x86 architectures Sasha Levin
2021-10-21 0:20 ` [PATCH AUTOSEL 5.14 23/26] libperf tests: Fix test_stat_cpu Sasha Levin
2021-10-21 0:20 ` [PATCH AUTOSEL 5.14 24/26] perf/x86/msr: Add Sapphire Rapids CPU support Sasha Levin
2021-10-21 0:20 ` [PATCH AUTOSEL 5.14 25/26] Input: snvs_pwrkey - add clk handling Sasha Levin
2021-10-21 0:20 ` [PATCH AUTOSEL 5.14 26/26] Input: xpad - add support for another USB ID of Nacon GC-100 Sasha Levin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20211021002023.1128949-9-sashal@kernel.org \
--to=sashal@kernel.org \
--cc=jpoimboe@redhat.com \
--cc=linux-kernel@vger.kernel.org \
--cc=mbenes@suse.cz \
--cc=mforney@mforney.org \
--cc=peterz@infradead.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).