uutils/coreutils

tac crashes with SIGBUS when input file is truncated during read

Ouverte

#9 748 ouverte le 20 déc. 2025

 (1 commentaire) (0 réaction) (0 personne assignée)Rust (1 981 forks)batch import
U - tacgood first issuereported-canonical

Métriques du dépôt

Stars
 (23 893 étoiles)
Métriques de merge PR
 (Merge moyen 5j 23h) (239 PRs mergées en 30 j)

Description

Component

tac

Description

The tac utility crashes with "Bus error (core dumped)" when an input file is truncated while being read. This happens because tac uses memory-mapped I/O (mmap with MAP_SHARED) without installing a SIGBUS signal handler.

When a mapped file is truncated, subsequent access to the now-invalid memory region triggers SIGBUS. The SAFETY comments in the code acknowledge this behavior but treat process termination as acceptable. GNU tac handles this gracefully by avoiding direct memory mapping of untrusted input sources.

Test / Reproduction Steps

dd if=/dev/zero of=/tmp/tactest bs=1M count=10 2>/dev/null
(sleep 0.001; truncate -s 0 /tmp/tactest) &
tac /tmp/tactest

Impact

Denial of Service: This is particularly problematic for log rotation scenarios where tac might be reading logs that get truncated

Guide contributeur