Usually, glibc inlines calls to non-cancellable versions of some system calls, such as open_not_cancel. The macro definitions are in sysdeps/unix/sysv/linux/not-cancel.h. This patch prevents those definitions from being inlined. It moves them into separate *.c files. This is needed for building Plash's modified version of glibc. Background: Plash is a secure, restricted execution environment that provides functionality similar to chroot(), but more flexible and lightweight. It works partly by dynamically linking Linux executables with a modified glibc. This is not used for taking authority away from a process, only for giving it back. This approach is more complete than using LD_PRELOADed libraries. There's more information on what Plash does at <http://plash.beasts.org>. Plash builds its custom glibc by re-linking the object files produced by the glibc build process. It omits the object files for various system calls and replaces them with its own code. For this to work completely, those system calls cannot be inlined. The attached patch should not break the normal build of glibc. I have tested it for building the Debian glibc packages on i386, but not on other architectures. This patch isn't quite as essential for putting Plash into Debian as the other one I filed in the BTS. One complication in the patch is that Linuxthreads needs to refer to some of the *_not_cancel functions. I have left these as inlined, conditionally, when used by Linuxthreads. Usually Linuxthreads builds its own versions of syscall object files (eg. ptw-close.os), but it can't do this for close-not-cancel.os etc. because these are built from C files, not from the assembler-based syscall generator. The same approach is used for NPTL. However, in this case, the syscall generating code does generate non-cancelling versions of some of the syscalls. (This time they're called "close_nocancel" etc. rather than "close_not_cancel".) For those syscalls, NPTL uses, for example, the ptw-close.os object file, while close-not-cancel.c is replaced with an empty file. Mark
burden for the Debian glibc maintainers, and it would have a performance impact on all Debian applications on all architectures. I fail to see why the core glibc package should be responsible for building this rather mauled library. What's Plash's CPU versions target? For x86, you could probably do this by: - replacing the dynamic linker instead of all of glibc - mapping a fake vsyscall page which checked the syscall number, and diverted to plash's code if appropriate - modifying the auxv vector to point at the modified vsyscall dso instead of the original - chaining to glibc's standard dynamic linker Then you can do it with pristine binaries. Should work on any architecture which can indirect syscalls through a VDSO (at least ia64, amd64, possibly soon ppc/ppc64). I am a little dubious about the other Plash bug, but I'll think about it. It seems marginally within the purview of the libc6-pic package and affects nothing else. But it seems like it would be randomly crippled without this patch.
Daniel Jacobowitz <drow@false.org> wrote: I don't think performance impact should be a real issue with this patch. The NPTL build of glibc doesn't inline these syscalls. Most system calls are not inlined in glibc anyway, and these *_not_cancel calls don't seem to be used from functions that are performance critical. They seem to have been inlined as a convenient way of getting code linked into libpthread.so for Linuxthreads, rather than for performance. I appreciate that it would be a maintenance burden. I'll see if I can get the patch accepted upstream. I created a Plash package that built its own copy of the glibc source. I posted an RFS on debian-mentors, and people complained about duplicating glibc. So I changed it to build from libc6-pic. Interesting idea. Has anyone used the vsyscall mechanism for intercepting syscalls? Having looked into this, one problem is that it won't work with the "libc" and "nptl" builds of glibc that Debian does, because these use "int $0x80" directly. It would only work with the "i686" build. So this won't work with Linux 2.4 or with pre-686 processors. Is your doubt about which package these files would go into, or about these files going into a binary package at all? ie. Would you prefer a new libc6-blah package for putting these files in? glibc functions that call *_not_cancel don't work. It would be a useful starting point. As an alternative, I could build Plash from the NPTL build of glibc: the relevant calls are already not inlined. That would involve changing the patch to put the NPTL object files into libc6-pic instead. But it would require Linux 2.6. Mark
I would be amazed if upstream took it. They are not generally tolerant of this sort of limited-use-large-effect change. Unlikely. Most people need to intercept all syscalls, not just most. It's not useful for that. Correct. It wouldn't anyway; Linux 2.4 did not have a vsyscall. I would have thought it would work with the NPTL build, but I didn't check. Definitely not a new package. Huh? Then why did your patch need to modify NPTL?
Daniel Jacobowitz <drow@false.org> wrote: From my reading of the code, glibc will use a vsyscall entry point if AT_SYSINFO is defined in the auxv, and this doesn't necessarily require Linux 2.6. NPTL inlines some but not all of the not-cancel.h calls. I didn't need them all un-inlined, but for completeness I un-inlined all of them, in case I needed to replace these calls in the future. Mark
Sehr geehrte Damen und Herren, unsere Firma ist ein erfolgreiches, europaweit agierendes Unternehmen und sucht ab sofort neue Arbeitskollegen zur Vervollständigung des Teams europaweit. Die Tätigkeiten werden europaweit gefragt, und Sie haben die Gelegenheit unabhängig von Ihrem Wohnort einzusteigen. Wir bieten Arbeitsstellen für jeden. Die Arbeitsstelle kann sowohl von Rentnern, Hausfrauen als auch nebenberuflich ausgeführt werden. Übersetzungen, Sekretärservice, Begutachter, und eine Menge mehr wird derzeit angeboten. Es werden Ihnen aktuelle Aufträge und die jeweilige Vergütung angeboten und Sie treffen die Auswahl. Jede Aufgabe wird unterschiedlich belohnt, im Schnitt erhalten Sie bei 3-5 Stunden am Tag 1500 bis 2000 Euro Brutto monatlich. Sie haben keine Ausgaben und können sofort bei uns beginnen. Kennziffer NW-7813-156 Es sind 10 offene Arbeitsstellen zu besetzen. Die nötige technische Ausrüstung wird von uns kostenlos zur Verfügung gestellt. Die Position kann gerne von Rentnern, Hausfrauen und auch nebenberuflich ausgeführt werden. Was Sie mitbringen sollten wären technische Grundkenntnisse im Umgang mit dem Fotoapparat, Ehrlichkeit, Zielstrebigkeit, Flexibilität, Freundlichkeit Wenn wir Ihr Interesse geweckt haben, schicken Sie uns Ihre vollständigen Bewerbungsunterlagen noch heute, gerne per E-Mail an: rouxyoguc@realtyagent.com Sie erhalten weitere Unterlagen zugeschickt. Ihre persönlichen Daten behandeln wir vertraulich. Mit freundlichen Grüßen Fuchs SA Rue Danielle-Casanova 31 Malbec 553