Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.rc > #393989

Bug#1108549: procps: w acts on value of uninit'd mem w/out systemd; poss segfault

From Andrew Bower <andrew@bower.uk>
Newsgroups linux.debian.bugs.rc
Subject Bug#1108549: procps: w acts on value of uninit'd mem w/out systemd; poss segfault
Date 2025-07-28 00:20 +0200
Message-ID <LdhSN-3fpp-1@gated-at.bofh.it> (permalink)
References <L3vkl-ekRx-1@gated-at.bofh.it> <LbPlT-295q-5@gated-at.bofh.it> <Lc8HT-2nuQ-1@gated-at.bofh.it> <L3vkl-ekRx-1@gated-at.bofh.it> <Lc8HT-2nuQ-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Thu, Jul 24, 2025 at 07:15:12PM +0100, Andrew Bower wrote:
> On Wed, Jul 23, 2025 at 10:31:47PM +0100, Andrew Bower wrote:
> > On Mon, Jun 30, 2025 at 11:36:59PM +0100, Andrew Bower wrote:
> [...] 
> 1. Unitialised 'sessions' variable is a a bug on all systems which leads
>    to a segfault on some. I'm now tagging this bug as having a patch.

In the absence of any other fixes, my patch for this still stands.
But...

> 2. elogind not being queried. Is this an elogind issue? Should it give a
>    different answer to sd_booted() or is this the wrong way to detect the
>    seat management capability? 'who' does not have this problem - it
>    somehow queries elogind anyway.

Removing the call to sd_booted() and just using the result of
sd_get_sessions() is sufficient. I get the correct outcome in this case.

Unfortunately we don't then get any runtime fallback to utmp but my
guess is working elogind support would be preferred (and should be fixed
for trixie).

I am not proposing a patch here because it needs attention from someone
more familiar with the relevant components.

My hunch is that the best plan for trixie is to go straight to calling
sd_get_sessions() and not testing sd_booted(). This would then supersede
the patch for (1).

> procps then resorts to utmp.
> 
> 3. Some (vc) sessions not reported unless running as root, but the non-root
>    user could read utmp. 'who' does not have this problem but then it
>    probably didn't resort to reading utmp (see 2 above).

This was a mistake - ignore this: the additional session was caused by
sudo itself.

Back to linux.debian.bugs.rc | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

Bug#1108549: procps: w acts on value of uninit'd mem w/out systemd; poss segfault Andrew Bower <andrew@bower.uk> - 2025-07-28 00:20 +0200
  Bug#1108549: procps: w acts on value of uninit'd mem w/out systemd; poss segfault Andrew Bower <andrew@bower.uk> - 2025-07-28 09:40 +0200
    Bug#1108549: procps: w acts on value of uninit'd mem w/out systemd; poss segfault Craig Small <csmall@debian.org> - 2025-07-28 12:20 +0200
      Bug#1108549: procps: w acts on value of uninit'd mem w/out systemd; poss segfault Andrew Bower <andrew@bower.uk> - 2025-07-28 19:20 +0200

csiph-web