From patchwork Mon Jun 15 19:49:26 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: DJ Delorie X-Patchwork-Id: 137070 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 47C9A48FDB1C for ; Mon, 15 Jun 2026 20:42:04 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 47C9A48FDB1C Authentication-Results: sourceware.org; dkim=pass (1024-bit key, unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=gH/6f7G0 X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by sourceware.org (Postfix) with ESMTP id 2A2FE49002D1 for ; Mon, 15 Jun 2026 20:40:57 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 2A2FE49002D1 Authentication-Results: sourceware.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=redhat.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 2A2FE49002D1 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1781556057; cv=none; b=gelPR3GlN9FHDmFZ1/zoH0vEN2dQt5dtjrmZdvZWDXMEFuIvd3tYD1fm/ZellC2EN4vM7cbnXZXuBjnKVgliPtst3KbzAyFPfJLvXngZ6Zv9MVLVlteZWFDF4ez0Ta4FdoefnVsjDX8CWdthZzyUllMmlklWFi3yeBnbUTLSjX0= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1781556057; c=relaxed/simple; bh=x47zuBeWzNfMRQ7unE7W/hzmJS7af3BuVg32iyfYSl8=; h=DKIM-Signature:Message-ID:From:Date:Subject:To; b=A7eGIToEuY8dCxDYdQL6I4xrM/3IsGW/QohJcACWtiSzElvb1rrYm76FK1b7zZU4j+aNyIJLGAYmfPeTTOkfwGJvR0qbvf6iVsO9ACmZiy83xU4EI1UnGt1jCEQgiK7iS74uunTouH6wjeAbP5pt96y+JA+67cK8c2qk6get+W0= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (1024-bit key, unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=gH/6f7G0 DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 2A2FE49002D1 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1781556056; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:content-type:content-type:in-reply-to:in-reply-to: references:references; bh=T9kWA3lkM+eUf1W+a5BwxVqPHc2T/9Up4M1iJ78D9N0=; b=gH/6f7G07oS/1waOadInExbN/xZEs0GuUm7Rp6b1K7N5NTP8+6csJirrxs2UR4+HC9qrVI UxeaTlibK2A7zazs22nAAt/IrkYDbWLYyVE1aBT1MK5r9y4Hy6fo0rs9GAx3UnWepNdYi7 6Oa94066VDA4nKkaQVvNyE32rnGkjFk= Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-467-y-TRVjp9MlSX5-xpr0BRxQ-1; Mon, 15 Jun 2026 16:40:55 -0400 X-MC-Unique: y-TRVjp9MlSX5-xpr0BRxQ-1 X-Mimecast-MFC-AGG-ID: y-TRVjp9MlSX5-xpr0BRxQ_1781556054 Received: from mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.111]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 4ACC4195605E for ; Mon, 15 Jun 2026 20:40:54 +0000 (UTC) Received: from greed.delorie.com (unknown [10.22.88.175]) by mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 0A5481800361 for ; Mon, 15 Jun 2026 20:40:53 +0000 (UTC) Received: from greed.delorie.com (localhost [127.0.0.1]) by greed.delorie.com (8.16.1/8.16.1) with ESMTPS id 65FKelFN1342562 (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384 bits=256 verify=NOT) for ; Mon, 15 Jun 2026 16:40:47 -0400 Received: (from dj@localhost) by greed.delorie.com (8.16.1/8.16.1/Submit) id 65FJuoR41339557; Mon, 15 Jun 2026 15:56:50 -0400 Message-ID: <92f591f18b344ec625cff4184e191e6c6de7c550.1781552966.git.dj@redhat.com> In-Reply-To: References: From: DJ Delorie Date: Mon, 15 Jun 2026 15:49:26 -0400 Subject: [PATCH v8 3/5] Add system-wide tunables: Apply tunables part To: libc-alpha@sourceware.org X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.111 X-Mimecast-Spam-Score: 2 X-Mimecast-MFC-PROC-ID: cMExkT0KZZoictjxYiXdbC297zKSpkquX_TcqsKGGjA_1781556054 X-Mimecast-Originator: redhat.com Content-type: text/plain; charset=UTF-8 X-Spam-Status: No, score=-9.2 required=5.0 tests=BAYES_00, DKIMWL_WL_HIGH, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, RCVD_IN_MSPIKE_H3, RCVD_IN_MSPIKE_WL, RCVD_IN_SBL_CSS, SPF_HELO_PASS, SPF_NONE, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org Load ld.so.cache and fetch the tunables extension. Apply those tunables to the current program. We do not yet apply security policies. --- elf/dl-cache.c | 50 ++++++++++++++++++++++++++++++++++++ elf/dl-tunables.c | 65 +++++++++++++++++++++++++++++++++++++++++++++++ elf/tunconf.h | 3 +++ 3 files changed, 118 insertions(+) diff --git a/elf/dl-cache.c b/elf/dl-cache.c index 07c7e639f5..b18cf58905 100644 --- a/elf/dl-cache.c +++ b/elf/dl-cache.c @@ -28,6 +28,7 @@ #include #include #include +#include "tunconf.h" /* This is the starting address and the size of the mmap()ed file. */ static struct cache_file *cache; @@ -613,3 +614,52 @@ _dl_unload_cache (void) now. */ } #endif + +const struct tunable_header_cached * +_dl_load_cache_tunables (const char **data) +{ + struct cache_extension_all_loaded ext; + struct tunable_header_cached *thc; + struct tunable_entry_cached *tec; + int i, count; + + if (_dl_check_ldsocache_needs_loading ()) + _dl_maybe_load_ldsocache (); + + if (cache_new) + *data = (const char *) cache_new; + else + return NULL; + + if (!cache_extension_load (cache_new, cache, cachesize, &ext)) + return NULL; + + /* Validate length/contents here. */ + if (ext.sections[cache_extension_tag_tunables].size + < sizeof(struct tunable_header_cached)) + return NULL; + + thc = (struct tunable_header_cached *) + ext.sections[cache_extension_tag_tunables].base; + tec = thc->tunables; + count = thc->num_tunables; + + if (ext.sections[cache_extension_tag_tunables].base + + ext.sections[cache_extension_tag_tunables].size + < (void *) & tec[count]) + return NULL; + + /* Validate each entry. */ + int s_start = (const char *) (&cache_new->libs[cache_new->nlibs]) - *data; + int s_end = s_start + cache_new->len_strings; + for (i = 0; i < count; i ++) + { + if (thc->tunables[i].name_offset < s_start + || thc->tunables[i].name_offset >= s_end + || thc->tunables[i].value_offset < s_start + || thc->tunables[i].value_offset >= s_end) + return NULL; + } + + return thc; +} diff --git a/elf/dl-tunables.c b/elf/dl-tunables.c index 5c65e8b458..f183e99855 100644 --- a/elf/dl-tunables.c +++ b/elf/dl-tunables.c @@ -37,6 +37,7 @@ #define TUNABLES_INTERNAL 1 #include "dl-tunables.h" +#include "tunconf.h" static char ** get_next_env (char **envp, char **name, char **val, char ***prev_envp) @@ -302,6 +303,70 @@ __tunables_init (char **envp) if (MALLOC_DEFAULT_THP_PAGESIZE > 0) TUNABLE_SET (glibc, malloc, hugetlb, 1); +#if defined(SHARED) && defined (USE_LDCONFIG) + const struct tunable_header_cached *thc; + const char *td; + + thc = _dl_load_cache_tunables (&td); + if (thc != NULL) + { + for (int t = 0; t < thc->num_tunables; ++ t) + { + const struct tunable_entry_cached *tec = &( thc->tunables[t] ); + int tid = tec->tunable_id; + const char *name = td + tec->name_offset; + const char *value = td + tec->value_offset; + + /* Check that we have the correct tunable, and search by + name if needed. We rely on order of operations here to + avoid mis-indexing tunables[]. */ + if (tid < 0 || tid >= tunables_list_size + || strcmp (name, tunable_list[tid].name) != 0) + { + /* It does not, search by name instead. */ + tid = -1; + for (int i = 0; i < tunables_list_size; i++) + { + if (strcmp (name, tunable_list[i].name) == 0) + { + tid = i; + break; + } + } + if (tid == -1) + continue; + } + /* At this point, TID is valid for the tunable we want. See + if the parsed type matches the desired type. */ + + if (tunable_list[tid].type.type_code == TUNABLE_TYPE_STRING) + { + /* This is a memory leak but there's no easy way around + it, as the mapping will go away if the disk file is + updated and the cache is reloaded. */ + tunable_list[tid].val.strval.str = __strdup (value); + tunable_list[tid].val.strval.len = strlen (value); + tunable_list[tid].initialized = true; + } + else + { + tunable_val_t tval; + if (tec->flags & TUNCONF_FLAG_PARSED) + { + tval.numval = tec->parsed_value; + do_tunable_update_val (& tunable_list[tid], + &tval, NULL, NULL); + } + else + { + tunable_initialize (& tunable_list[tid], + value, strlen (value)); + } + } + } + } +#endif /* defined(SHARED) && defined (USE_LDCONFIG) */ + /* Ignore tunables for AT_SECURE programs. */ if (__libc_enable_secure) return; diff --git a/elf/tunconf.h b/elf/tunconf.h index 85e1c142fa..b063c1bc96 100644 --- a/elf/tunconf.h +++ b/elf/tunconf.h @@ -36,3 +36,6 @@ void parse_tunconf (const char *filename, char *opt_chroot); struct tunable_header_cached * get_tunconf_ext (uint32_t str_offset); #define TUNCONF_SIZE(thc_p) (sizeof(struct tunable_header_cached) \ + thc_p->num_tunables * sizeof (struct tunable_entry_cached)) + +extern const struct tunable_header_cached * +_dl_load_cache_tunables (const char **data);