uutils/coreutils

tac crashes with SIGBUS when input file is truncated during read

开放

#9,748 创建于 2025年12月20日

 (1 条评论) (0 个反应) (0 位负责人)Rust (2,003 个派生)batch import
U - tacgood first issuereported-canonical

仓库指标

星标
 (23,984 个星标)
PR 合并指标
 (PR 指标待抓取)

描述

Component

tac

Description

The tac utility crashes with "Bus error (core dumped)" when an input file is truncated while being read. This happens because tac uses memory-mapped I/O (mmap with MAP_SHARED) without installing a SIGBUS signal handler.

When a mapped file is truncated, subsequent access to the now-invalid memory region triggers SIGBUS. The SAFETY comments in the code acknowledge this behavior but treat process termination as acceptable. GNU tac handles this gracefully by avoiding direct memory mapping of untrusted input sources.

Test / Reproduction Steps

dd if=/dev/zero of=/tmp/tactest bs=1M count=10 2>/dev/null
(sleep 0.001; truncate -s 0 /tmp/tactest) &
tac /tmp/tactest

Impact

Denial of Service: This is particularly problematic for log rotation scenarios where tac might be reading logs that get truncated

贡献者指南