Unversioned libc imports can split allocator bindings under interposition
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 42/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 活跃
- 技术栈
- c
调研方向
首先定位通用 POSIX 共享模块及其 -nostdlib/-nodefaultlibs/-nostartfiles 链接配置。使用提供的 LD_PRELOAD 命令复现 loader 行为,然后检查 DT_NEEDED 和符号绑定,并运行 SymCrypt 测试套件。完成的标准是:allocator 绑定无法在 interposition 下发生拆分,guestfs-tools 检查通过,并确定所需的 FIPS 认证审查。
由索引模型根据 Issue 内容生成。
描述
Problem
On Azure Linux 3 with SymCrypt 103.8.0, glibc malloc-debug instrumentation causes consumers loading the SymCrypt OpenSSL provider to abort with free(): invalid pointer.
The POSIX shared module is linked with -nostdlib -nodefaultlibs -nostartfiles. Consequently, libsymcrypt.so has no DT_NEEDED entry for libc and its libc imports are unversioned:
aligned_alloc Base
free Base
malloc Base
When glibc's checked allocator is preloaded, the dynamic loader can bind aligned_alloc to libc.so.6 while binding free to libc_malloc_debug.so.0. SymCrypt then allocates and frees through different allocator implementations.
Reproducer
LD_PRELOAD=libc_malloc_debug.so.0 \
GLIBC_TUNABLES=glibc.malloc.check=1 \
python3 -c 'import ctypes; ctypes.CDLL("/path/to/libsymcrypt.so")'
The failure was observed on the released Azure Linux 3 system with SymCrypt 103.8.0 and reproduced in controlled testing with SymCrypt 103.12.1. LD_DEBUG=bindings confirms the split binding.
The same issue breaks the Azure Linux 4 guestfs-tools build when OpenSSL loads the SymCrypt provider. Its current packaging workaround disables malloc checking: microsoft/azurelinux#18715.
Validated fixes
Two independent changes prevent the failure:
- Use
posix_memaligninstead ofaligned_alloc:tobiasb-ms/fix-posix-allocator-interposition - Explicitly link the generic POSIX module against libc, recording
DT_NEEDED: libc.so.6and versioned imports:tobiasb-ms/fix-version-libc-imports
Both pass the SymCrypt test suite and an end-to-end Azure Linux guestfs-tools build and %check (124 tests, 0 failures/errors). Explicit libc linkage is the more structurally reliable fix, but its glibc requirements depend on the build sysroot.
Both changes modify content inside the module's FIPS integrity boundary and therefore require certification review.
- 主要语言
- C
- 星标
- 890
- 派生
- 91
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
我们还没有检查这个项目的环境配置文件。先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
microsoft/SymCrypt 的其他 Issue
-
难度 1/5 1 小时以内 新手友好度 85/100
-
难度 4/5 3-5 天 新手友好度 55/100
-
enhancement
难度 5/5 一周以上 新手友好度 25/100
-
难度 5/5 一周以上 新手友好度 25/100
-
难度 5/5 一周以上 新手友好度 25/100
查看 microsoft/SymCrypt 的全部 Issue
相似的 Issue
-
feature request
难度 2/5 1-3 小时 新手友好度 68/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 88/100
BasedHardware/omi#20271 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 86/100
ImageMagick/ImageMagick#8994 ·
维护者通常 1 天内回复
-
area/ysql kind/bug priority/medium
难度 2/5 1-3 小时 新手友好度 75/100
yugabyte/yugabyte-db#34552 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 84/100
flux-framework/flux-coral2#509 ·