Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Fri, 31 May 2019 13:43:17 +0200
From: Szabolcs Nagy <nsz@...t70.net>
To: musl@...ts.openwall.com
Subject: Re: Hijacking malloc called within musl libc

* sva sva <azharivs@...il.com> [2019-05-31 00:13:27 -0400]:
> I am interposing all malloc/calloc/realloc/free/memalign but still the
> realloc in scandir gets called from musl's libc. Does that make sense?

no.

it works for me as expected.

you need to write down what you did, what you expected and what you got instead.
(how did you verify that the musl internal realloc gets called?
it can be a bug in your interposer, in your static linker, in ...)

$ cat a.c
#include <dirent.h>
#include <string.h>
#include <stdio.h>
#include <malloc.h>

void *realloc(void *p, size_t size)
{
	printf("realloc %p %zu\n", p, size);
	void *q = malloc(size);
	if (p)
		memcpy(q, p, malloc_usable_size(p));
	return q;
}

static int cmp(const struct dirent **a, const struct dirent **b)
{
	return 0;
}

int main()
{
	struct dirent **de = 0;
	int r = scandir(".", &de, 0, cmp);
	for (int i=0; i<r; i++)
		printf("%d %s\n", i, de[i]->d_name);
}
$ gcc a.c
$ ./a.out
realloc 0 8
realloc 0xffff93274860 24
realloc 0xffff932748c0 56
0 .
1 a.c
2 ..
3 a.out


> On Thu, May 30, 2019 at 6:30 PM Szabolcs Nagy <nsz@...t70.net> wrote:
> 
> > * sva sva <azharivs@...il.com> [2019-05-30 16:39:48 -0400]:
> > > I am LD_PRELOADing an application my own malloc which eventually calls
> > the
> > > libc malloc. Everything is fine until the code hits malloc which is
> > called
> >
> > musl has explicit checks not to allow libc internal malloc
> > calls if user malloc is used (at least for memalign),
> > because mixing user malloc and libc malloc is problematic.
> >
> > this means that currently the common malloc wrapping methods
> > don't work on musl. (you can try to copy the musl malloc
> > implementation into an external library and work with that
> > instead of calling back to libc malloc, but it might need
> > some changes)
> >
> > > from musl's own libc which doesn't get overloaded. I want those to be
> > > overloaded as well.
> > >
> > > More specifically this is the part of libc for scandir code at
> > > src/dirent/scandir.c:
> > > tmp = realloc(names, len * sizeof *names);
> >
> > if you define malloc/calloc/realloc/memalign/free then
> > all musl internal calls to those functions will go to
> > your definitions (including the realloc in scandir).
> >
> > (if you only interpose a subset of the malloc functions
> > that's broken and cannot work)
> >
> > >
> > > I checked how this works for glibc, and apparently they use
> > > __libc_malloc/etc. internally and have malloc as a weak alias for that
> > > which is used every where including the rest of the standard library.
> > > However in musl, there is no such thing as a weak alias defined for
> > > malloc/etc.
> > >
> > > I am kind of stuck here so would appreciate some help.
> > >
> > > Thanks
> > >
> > > Vahid
> >

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.