Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1251506 > unrolled thread
| Started by | Andrew Bower <andrew@bower.uk> |
|---|---|
| First post | 2025-07-01 00:40 +0200 |
| Last post | 2025-07-29 01:00 +0200 |
| Articles | 4 — 1 participant |
Back to article view | Back to linux.debian.bugs.dist
Bug#1108549: procps: w segfaults when run as non-root user Andrew Bower <andrew@bower.uk> - 2025-07-01 00:40 +0200
Bug#1108549: procps: w segfaults when run as non-root user Andrew Bower <andrew@bower.uk> - 2025-07-23 23:40 +0200
Bug#1108549: procps: w segfaults when run as non-root user Andrew Bower <andrew@bower.uk> - 2025-07-24 20:20 +0200
Bug#1108549: procps: w acts on value of uninit'd mem w/out systemd; poss segfault Andrew Bower <andrew@bower.uk> - 2025-07-29 01:00 +0200
| From | Andrew Bower <andrew@bower.uk> |
|---|---|
| Date | 2025-07-01 00:40 +0200 |
| Subject | Bug#1108549: procps: w segfaults when run as non-root user |
| Message-ID | <L3vkl-ekRx-1@gated-at.bofh.it> |
Package: procps Version: 2:4.0.4-8 Severity: important Dear Maintainer, Running 'w' as a non-root user on i386 segfaults: $ gdb w GNU gdb (Debian 16.3-1) 16.3 [...] This GDB was configured as "i686-linux-gnu". [...] (gdb) run Starting program: /usr/bin/w [Thread debugging using libthread_db enabled] Using host libthread_db library "/lib/i386-linux-gnu/libthread_db.so.1". 23:21:56 up 4 min, 0 users, load average: 0.74, 1.06, 0.52 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT Program received signal SIGSEGV, Segmentation fault. Download failed: Invalid argument. Continuing without source file ./src/w.c. 0x00401979 in main (argc=<optimized out>, argv=<optimized out>) at src/w.c:1130 warning: 1130 src/w.c: No such file or directory This reliably reproduces in the failing environment but not when run as root or on an amd64 host with kernel 6.12.27-1. Thanks! -- System Information: Debian Release: 13.0 APT prefers testing APT policy: (700, 'testing'), (600, 'unstable') Architecture: i386 (i686) Kernel: Linux 6.10.12-686 (SMP w/2 CPU threads; PREEMPT) Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), LANGUAGE not set Shell: /bin/sh linked to /usr/bin/dash Init: sysvinit (via /sbin/init) Versions of packages procps depends on: ii init-system-helpers 1.68 ii libc6 2.41-9 ii libncursesw6 6.5+20250216-2 ii libproc2-0 2:4.0.4-8 ii libsystemd0 257.6-1 ii libtinfo6 6.5+20250216-2 Versions of packages procps recommends: ii linux-sysctl-defaults 4.12 ii psmisc 23.7-2 procps suggests no packages. -- no debconf information
[toc] | [next] | [standalone]
| From | Andrew Bower <andrew@bower.uk> |
|---|---|
| Date | 2025-07-23 23:40 +0200 |
| Message-ID | <LbPlT-295q-5@gated-at.bofh.it> |
| In reply to | #1251506 |
[Multipart message — attachments visible in raw view] — view raw
Hi, On Mon, Jun 30, 2025 at 11:36:59PM +0100, Andrew Bower wrote: > Running 'w' as a non-root user on i386 segfaults: > > $ gdb w > GNU gdb (Debian 16.3-1) 16.3 > [...] > This GDB was configured as "i686-linux-gnu". > [...] > (gdb) run > Starting program: /usr/bin/w > [Thread debugging using libthread_db enabled] > Using host libthread_db library "/lib/i386-linux-gnu/libthread_db.so.1". > 23:21:56 up 4 min, 0 users, load average: 0.74, 1.06, 0.52 > USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT > > Program received signal SIGSEGV, Segmentation fault. > Download failed: Invalid argument. Continuing without source file ./src/w.c. > 0x00401979 in main (argc=<optimized out>, argv=<optimized out>) at src/w.c:1130 > warning: 1130 src/w.c: No such file or directory > > This reliably reproduces in the failing environment but not when run as root or > on an amd64 host with kernel 6.12.27-1. The proximate cause seems to be that sessions is undefined and that sessions_list is then also used, undefined. This part of the bug is therefore not architecture-specific even if the crash is not generally reproduced yet. I attach a patch that fixes the segfault to advance the discussion. Personally I think this ought to be fixed for trixie. However, we are unfortunately not out of the woods: elogind is running on this host and root is able to see the sessions. So is 'who' as non-root with the newly libsystemd-ised coreutils: $ w 21:26:33 up 10 min, 0 users, load average: 0.00, 0.10, 0.12 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT Segmentation fault $ debian/procps/usr/bin/w # with patch 21:26:42 up 11 min, 0 users, load average: 0.00, 0.10, 0.12 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT $ sudo w Please touch the FIDO authenticator. 21:26:50 up 11 min, 1 user, load average: 0.64, 0.23, 0.16 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT ajb85 pts/0 - 21:26 0.00s 0.03s 0.12s sudo w $ sudo debian/procps/usr/bin/w # with patch 21:26:54 up 11 min, 1 user, load average: 0.59, 0.23, 0.16 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT ajb85 pts/0 - 21:26 0.00s 0.02s 0.06s sudo debian/procps/usr/bin/w $ who ajb85 seat0 2025-07-23 21:17 ajb85 tty1 2025-07-23 21:17 This secondary issue could of course be an elogingd problem so I am copying this message to the elogind package tracker for awareness. Thanks!
[toc] | [prev] | [next] | [standalone]
| From | Andrew Bower <andrew@bower.uk> |
|---|---|
| Date | 2025-07-24 20:20 +0200 |
| Message-ID | <Lc8HT-2nuQ-1@gated-at.bofh.it> |
| In reply to | #1253722 |
Control: tag -1 + patch On Wed, Jul 23, 2025 at 10:31:47PM +0100, Andrew Bower wrote: > On Mon, Jun 30, 2025 at 11:36:59PM +0100, Andrew Bower wrote: [...] > However, we are unfortunately not out of the woods: elogind is running > on this host and root is able to see the sessions. So is 'who' as > non-root with the newly libsystemd-ised coreutils: Done a bit more digging. A number of issues - sorry, I don't have time to split them out into appropriate bugs right now. The first is definitely for procps: 1. Unitialised 'sessions' variable is a a bug on all systems which leads to a segfault on some. I'm now tagging this bug as having a patch. 2. elogind not being queried. Is this an elogind issue? Should it give a different answer to sd_booted() or is this the wrong way to detect the seat management capability? 'who' does not have this problem - it somehow queries elogind anyway. procps then resorts to utmp. 3. Some (vc) sessions not reported unless running as root, but the non-root user could read utmp. 'who' does not have this problem but then it probably didn't resort to reading utmp (see 2 above). 4. Virtual console sessions reported as pts/# instead of tty# in utmp - I guess we can blame login for that but we're off on a tangent now: 1-3 are more important to sort out.
[toc] | [prev] | [next] | [standalone]
| From | Andrew Bower <andrew@bower.uk> |
|---|---|
| Date | 2025-07-29 01:00 +0200 |
| Subject | Bug#1108549: procps: w acts on value of uninit'd mem w/out systemd; poss segfault |
| Message-ID | <LdEZ3-3vmo-11@gated-at.bofh.it> |
| In reply to | #1251506 |
On Mon, Jul 28, 2025 at 06:16:24PM +0100, Andrew Bower wrote: > What do you think of this variation? See https://salsa.debian.org/debian/procps/-/merge_requests/9 for my implementation of this approach.
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.bugs.dist
csiph-web