From patchwork Wed Jul 30 00:01:30 2025 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Samuel Thibault X-Patchwork-Id: 117238 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from server2.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id E55EE3858CD1 for ; Wed, 30 Jul 2025 00:03:28 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org E55EE3858CD1 X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from sonata.ens-lyon.org (domu-toccata.ens-lyon.fr [140.77.166.138]) by sourceware.org (Postfix) with ESMTPS id 33F883858D26; Wed, 30 Jul 2025 00:01:34 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 33F883858D26 Authentication-Results: sourceware.org; dmarc=none (p=none dis=none) header.from=ens-lyon.org Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=bounce.ens-lyon.org ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 33F883858D26 Authentication-Results: server2.sourceware.org; arc=none smtp.remote-ip=140.77.166.138 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1753833694; cv=none; b=v0VIo0GtbrGwGebsdq1F/kZ7ZoLBJzCvcHKmFgLlxWboH+wAmN0nqBNiq9akn4KrYyb398xIxS4NMpv5HF/+0fmTGmDfMeRMsKNUnwAD40ykvLgRm9Xwol/eUaaQx7aJa1WRb4w7GmrKSYqXvPbt8borXyTpOrc8CbUdm2XK4wE= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1753833694; c=relaxed/simple; bh=9NHmKS328irTJvE+ku729lkn03IdP+Wi65UmpTfeCQ4=; h=From:To:Subject:Date:Message-ID:MIME-Version; b=VWatWcex9IgyOVDE7gnfko4XMoHQwuNfcgCGqBK1CY9NCSquKRoMXRk7V4ivOCXOY5RbmHNYvYN7H3JYy8AthygqeIAeLhnYomlv9DKhvcvoFGi3g+Ru9YYAWpPe8oH0l9jAnFgEyNZmgOFOI+trweuFNf8Dyal1Zz9b+dBmr+M= ARC-Authentication-Results: i=1; server2.sourceware.org DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 33F883858D26 Received: from localhost (localhost [127.0.0.1]) by sonata.ens-lyon.org (Postfix) with ESMTP id C8728A1D54; Wed, 30 Jul 2025 02:01:32 +0200 (CEST) Received: from sonata.ens-lyon.org ([127.0.0.1]) by localhost (sonata.ens-lyon.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1LUdFchrjsrY; Wed, 30 Jul 2025 02:01:32 +0200 (CEST) Received: from begin (aamiens-653-1-40-48.w83-192.abo.wanadoo.fr [83.192.199.48]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by sonata.ens-lyon.org (Postfix) with ESMTPSA id 7B33DA0652; Wed, 30 Jul 2025 02:01:32 +0200 (CEST) Received: from samy by begin with local (Exim 4.98.2) (envelope-from ) id 1uguGB-000000046xU-3dfo; Wed, 30 Jul 2025 02:01:31 +0200 From: Samuel Thibault To: libc-alpha@sourceware.org Cc: Samuel Thibault , wilco.dijkstra@arm.com, fweimer@redhat.com, adhemerval.zanella@linaro.org, siddhesh@sourceware.org, eyalit@checkpoint.com Subject: [PATCH] malloc: Make sure tcache_key is not 0 Date: Wed, 30 Jul 2025 02:01:30 +0200 Message-ID: <20250730000130.980053-1-samuel.thibault@ens-lyon.org> X-Mailer: git-send-email 2.47.2 MIME-Version: 1.0 X-Spam-Status: No, score=-12.8 required=5.0 tests=BAYES_00, GIT_PATCH_0, JMQ_SPF_NEUTRAL, KAM_DMARC_STATUS, KAM_NUMSUBJECT, RCVD_IN_VALIDITY_RPBL_BLOCKED, RCVD_IN_VALIDITY_SAFE_BLOCKED, SPF_HELO_PASS, SPF_PASS, TXREP autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on server2.sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org Othersize even if tcache_double_free_verify sets e->key to 0 before calling __libc_free, it gets called again by __libc_free, thus looping indefinitely. Fixes: c968fe50628db74b52124d863cd828225a1d305c ("malloc: Use tailcalls in __libc_free") --- malloc/malloc.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/malloc/malloc.c b/malloc/malloc.c index 5ca390cc22..970717eb28 100644 --- a/malloc/malloc.c +++ b/malloc/malloc.c @@ -3152,6 +3152,9 @@ tcache_key_initialize (void) if (__getrandom_nocancel_nostatus_direct (&tcache_key, sizeof(tcache_key), GRND_NONBLOCK) != sizeof (tcache_key)) + tcache_key = 0; + + while (tcache_key == 0) { tcache_key = random_bits (); #if __WORDSIZE == 64