| Summary: | security_flags.inc: Segmentation fault observed using shared object from python (using ctypes module) when PIE is enabled | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| Product: | [Build System, Metadata & Runtime] OE-Core | Reporter: | Bhargav Das <BHARGAV_DAS> | ||||||||
| Component: | configuration | Assignee: | Sundeep KOKKONDA <sundeep.kokkonda> | ||||||||
| Status: | RESOLVED NOTABUG | QA Contact: | |||||||||
| Severity: | major | ||||||||||
| Priority: | Medium+ | CC: | randy.macleod, richard.purdie, yashinde145 | ||||||||
| Version: | unspecified | ||||||||||
| Target Milestone: | 4.2 M1 | ||||||||||
| Hardware: | All | ||||||||||
| OS: | Multiple | ||||||||||
| Whiteboard: | |||||||||||
| OS type for building Yocto: | --- | Type of Regression: | --- | ||||||||
| Verified: | Documentation change: | Don't know | |||||||||
| Attachments: |
|
||||||||||
If you compile the test case using a recipe, is the segfault still observed? If so that would simplify the reproduction of the bug and help track down the issue. We need to work out if the SDK toolchain is causing part of the problem somehow... See Richard's question above. @Richard, yes the segmentation fault is observed even when compiled using recipe. Please check the attached zip "test-app-python-recipe.zip" for the recipe. Created attachment 4910 [details]
Test application recipe
Seems to be reproducible with the core toolchain rather than just the SDK so that's good news. Hi Randy, is there any update on this issue or a timeline by which we expect this bug to be resolved ? I am analysing the segmentation fault. It would be due to the shared object file generated from C++ sources and then using it to compile python file . C/C++ have pointers whereas python does not support them, so there might be some memory allocation/deallocation problem while compiling the python file with shared object generated from C++ sources. Checking on that. Created attachment 4912 [details]
The updated hellopy.py
(In reply to comment #8) > Created attachment 4912 [details] > The updated hellopy.py PFA hellopy.py file. According to the analysis done, it was found that the function argument types and function return types of the functions accessed from the shared object(generated from C++ files) were not mentioned in the given python file. Whenever working with ctypes in Python, the function argument types and return types should be informed explicitly(lines 5-10 in given hellopy.py) in python file otherwise it gives segmentation fault. Adding these lines fixes the segmentation fault. Since this is a code missing problem, adding SECURITY_CFLAGS_pn-python3 = "${SECURITY_NOPIE_CFLAGS}" in build still reproduces the segmentation fault. > Since this is a code missing problem, adding SECURITY_CFLAGS_pn-python3 = "${SECURITY_NOPIE_CFLAGS}" in build still reproduces the segmentation fault.
@Yash in the master, when we add
' SECURITY_CFLAGS:pn-python3 = "${SECURITY_NOPIE_CFLAGS}" ' (check the new override syntax '_' vs ':') the segmentation fault is not observed.
>> Since this is a code missing problem, adding SECURITY_CFLAGS_pn-python3 = "${SECURITY_NOPIE_CFLAGS}" in build still reproduces the segmentation fault. > @Yash in the master, when we add ' SECURITY_CFLAGS:pn-python3 = "${SECURITY_NOPIE_CFLAGS}" ' (check the new override syntax '_' vs ':') the segmentation fault is not observed. This is for the original hellopy.py. Checked the updated hellopy.py it works but what I don't understand is why the original code doesn't work when pie is used to compile python. (In reply to comment #11) > >> Since this is a code missing problem, adding SECURITY_CFLAGS_pn-python3 = "${SECURITY_NOPIE_CFLAGS}" in build still reproduces the segmentation fault. > > > @Yash in the master, when we add > ' SECURITY_CFLAGS:pn-python3 = "${SECURITY_NOPIE_CFLAGS}" ' (check the new > override syntax '_' vs ':') the segmentation fault is not observed. > > This is for the original hellopy.py. > > Checked the updated hellopy.py it works but what I don't understand is why > the original code doesn't work when pie is used to compile python. Please refer the explanation given in comment 9. Occurring of segmentation fault is independent of using PIE . Python should be explicitly informed about the function argument types and returns types when using ctypes which was not present in the original hellopy.py. If there are no other queries, can we close this issue? Yes, we can close this issue. Closing the issue. Issue closed. |
Created attachment 4908 [details] Files to reproduce issue security_flags.inc: Segmentation fault while using shared object (.so) from python, ctypes module when PIE is enabled. This was first observed in dunfell branch but it is also reproducible is poky master. Steps to reproduce, 1. Clone poky 2. source poky/oe-init-build-env -b build-qemu qemux86-64 3. Add the following in local.conf - require conf/distro/include/security_flags.inc - IMAGE_INSTALL_append = “ openssh python3 python3-ctypes” #(this is required to bring in the test binaries and for the python modules) 4. Build core-image-minimal 5 .Build toolchain/sdk using, - bitbake -c populate_sdk core-image-minimal 6. After the sdk build, install the sdk in a location, sdk is present in tmp/deploy/sdk, <sdk>.sh 7. Export the variables, using - source environment-setup-aarch64-mel-linux (this file will be present inside the SDK installation location) 8. For the next step, use the attached files from the attachments. 9. Compile the .so (shared object) using, (make sure hellopython.cc and hellopython.h is present in the same directory) - $CXX $CXXFLAGS $LDFLAGS -shared -Wl,-soname,libhellopython -o libhellopython.so -fPIC hellopython.cc 10.Boot qemux86-64 image 11.Transfer "libhellopython.so" and "hellopy.py" to the target. (use scp, since openssh is already added) 11.Copy "libhellopython.so" to /usr/lib in target (qemu). 12.Run the python script using - python3 ./hellopy.py 13.A 'segmentation fault' should be observed. Note: 1. 'segmentation fault' is not observed when security_flags.inc is not included in local.conf. 2. When python is excluded from compiling with PIE using the following line, 'segmentation fault' is not observed - SECURITY_CFLAGS_pn-python3 = "${SECURITY_NOPIE_CFLAGS}" 3. This issue not observed in ubuntu 18.04, ubuntu 20.04 and debian 11 4. When the compiled libhellopython.so is access by a native c++ script i.e. hellocxx.cpp (attached), 'segmentation fault' is not observed.