Skip to content

Commit ccb526e

Browse files
committed
Auto merge of #126606 - zachs18:patch-2, r=joboet
Guard against calling `libc::exit` multiple times on Linux. Mitigates (but does not fix) #126600 by ensuring only one thread which calls Rust `exit` actually calls `libc::exit`, and all other callers of Rust `exit` block.
2 parents 59a4f02 + 9801076 commit ccb526e

File tree

4 files changed

+68
-0
lines changed

4 files changed

+68
-0
lines changed

library/std/src/rt.rs

+3
Original file line numberDiff line numberDiff line change
@@ -144,6 +144,9 @@ fn lang_start_internal(
144144
rtabort!("drop of the panic payload panicked");
145145
});
146146
panic::catch_unwind(cleanup).map_err(rt_abort)?;
147+
// Guard against multple threads calling `libc::exit` concurrently.
148+
// See the documentation for `unique_thread_exit` for more information.
149+
panic::catch_unwind(|| crate::sys::exit_guard::unique_thread_exit()).map_err(rt_abort)?;
147150
ret_code
148151
}
149152

library/std/src/sys/exit_guard.rs

+63
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,63 @@
1+
cfg_if::cfg_if! {
2+
if #[cfg(target_os = "linux")] {
3+
/// Mitigation for <https://github.com/rust-lang/rust/issues/126600>
4+
///
5+
/// On glibc, `libc::exit` has been observed to not always be thread-safe.
6+
/// It is currently unclear whether that is a glibc bug or allowed by the standard.
7+
/// To mitigate this problem, we ensure that only one
8+
/// Rust thread calls `libc::exit` (or returns from `main`) by calling this function before
9+
/// calling `libc::exit` (or returning from `main`).
10+
///
11+
/// Technically, this is not enough to ensure soundness, since other code directly calling
12+
/// `libc::exit` will still race with this.
13+
///
14+
/// *This function does not itself call `libc::exit`.* This is so it can also be used
15+
/// to guard returning from `main`.
16+
///
17+
/// This function will return only the first time it is called in a process.
18+
///
19+
/// * If it is called again on the same thread as the first call, it will abort.
20+
/// * If it is called again on a different thread, it will wait in a loop
21+
/// (waiting for the process to exit).
22+
#[cfg_attr(any(test, doctest), allow(dead_code))]
23+
pub(crate) fn unique_thread_exit() {
24+
let this_thread_id = unsafe { libc::pthread_self() };
25+
use crate::sync::{Mutex, PoisonError};
26+
static EXITING_THREAD_ID: Mutex<Option<libc::pthread_t>> = Mutex::new(None);
27+
let mut exiting_thread_id =
28+
EXITING_THREAD_ID.lock().unwrap_or_else(PoisonError::into_inner);
29+
match *exiting_thread_id {
30+
None => {
31+
// This is the first thread to call `unique_thread_exit`,
32+
// and this is the first time it is called.
33+
// Set EXITING_THREAD_ID to this thread's ID and return.
34+
*exiting_thread_id = Some(this_thread_id);
35+
},
36+
Some(exiting_thread_id) if exiting_thread_id == this_thread_id => {
37+
// This is the first thread to call `unique_thread_exit`,
38+
// but this is the second time it is called.
39+
// Abort the process.
40+
core::panicking::panic_nounwind("std::process::exit called re-entrantly")
41+
}
42+
Some(_) => {
43+
// This is not the first thread to call `unique_thread_exit`.
44+
// Pause until the process exits.
45+
drop(exiting_thread_id);
46+
loop {
47+
// Safety: libc::pause is safe to call.
48+
unsafe { libc::pause(); }
49+
}
50+
}
51+
}
52+
}
53+
} else {
54+
/// Mitigation for <https://github.com/rust-lang/rust/issues/126600>
55+
///
56+
/// Mitigation is ***NOT*** implemented on this platform, either because this platform
57+
/// is not affected, or because mitigation is not yet implemented for this platform.
58+
#[cfg_attr(any(test, doctest), allow(dead_code))]
59+
pub(crate) fn unique_thread_exit() {
60+
// Mitigation not required on platforms where `exit` is thread-safe.
61+
}
62+
}
63+
}

library/std/src/sys/mod.rs

+1
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@ mod personality;
77

88
pub mod backtrace;
99
pub mod cmath;
10+
pub mod exit_guard;
1011
pub mod os_str;
1112
pub mod path;
1213
pub mod sync;

library/std/src/sys/pal/unix/os.rs

+1
Original file line numberDiff line numberDiff line change
@@ -758,6 +758,7 @@ pub fn home_dir() -> Option<PathBuf> {
758758
}
759759

760760
pub fn exit(code: i32) -> ! {
761+
crate::sys::exit_guard::unique_thread_exit();
761762
unsafe { libc::exit(code as c_int) }
762763
}
763764

0 commit comments

Comments
 (0)