mirror of
https://github.com/golang/go.git
synced 2025-12-08 06:10:04 +00:00
This change adds two new methods for invoking system calls under Linux: syscall.AllThreadsSyscall() and syscall.AllThreadsSyscall6(). These system call wrappers ensure that all OSThreads mirror a common system call. The wrappers serialize execution of the runtime to ensure no race conditions where any Go code observes a non-atomic OS state change. As such, the syscalls have higher runtime overhead than regular system calls, and only need to be used where such thread (or 'm' in the parlance of the runtime sources) consistency is required. The new support is used to enable these functions under Linux: syscall.Setegid(), syscall.Seteuid(), syscall.Setgroups(), syscall.Setgid(), syscall.Setregid(), syscall.Setreuid(), syscall.Setresgid(), syscall.Setresuid() and syscall.Setuid(). They work identically to their glibc counterparts. Extensive discussion of the background issue addressed in this patch can be found here: https://github.com/golang/go/issues/1435 In the case where cgo is used, the C runtime can launch pthreads that are not managed by the Go runtime. As such, the added syscall.AllThreadsSyscall*() return ENOTSUP when cgo is enabled. However, for the 9 syscall.Set*() functions listed above, when cgo is active, these functions redirect to invoke their C.set*() equivalents in glibc, which wraps the raw system calls with a nptl:setxid fixup mechanism. This achieves POSIX semantics for these functions in the combined Go and C runtime. As a side note, the glibc/nptl:setxid support (2019-11-30) does not extend to all security related system calls under Linux so using native Go (CGO_ENABLED=0) and these AllThreadsSyscall*()s, where needed, will yield more well defined/consistent behavior over all threads of a Go program. That is, using the syscall.AllThreadsSyscall*() wrappers for things like setting state through SYS_PRCTL and SYS_CAPSET etc. Fixes #1435 Change-Id: Ib1a3e16b9180f64223196a32fc0f9dce14d9105c Reviewed-on: https://go-review.googlesource.com/c/go/+/210639 Trust: Emmanuel Odeke <emm.odeke@gmail.com> Trust: Ian Lance Taylor <iant@golang.org> Trust: Michael Pratt <mpratt@google.com> Run-TryBot: Emmanuel Odeke <emm.odeke@gmail.com> Reviewed-by: Michael Pratt <mpratt@google.com> Reviewed-by: Austin Clements <austin@google.com>
74 lines
2.7 KiB
Go
74 lines
2.7 KiB
Go
// Copyright 2019 The Go Authors. All rights reserved.
|
|
// Use of this source code is governed by a BSD-style
|
|
// license that can be found in the LICENSE file.
|
|
|
|
// Linux system call wrappers that provide POSIX semantics through the
|
|
// corresponding cgo->libc (nptl) wrappers for various system calls.
|
|
|
|
// +build linux
|
|
|
|
package cgo
|
|
|
|
import "unsafe"
|
|
|
|
// Each of the following entries is needed to ensure that the
|
|
// syscall.syscall_linux code can conditionally call these
|
|
// function pointers:
|
|
//
|
|
// 1. find the C-defined function start
|
|
// 2. force the local byte alias to be mapped to that location
|
|
// 3. map the Go pointer to the function to the syscall package
|
|
|
|
//go:cgo_import_static _cgo_libc_setegid
|
|
//go:linkname _cgo_libc_setegid _cgo_libc_setegid
|
|
//go:linkname cgo_libc_setegid syscall.cgo_libc_setegid
|
|
var _cgo_libc_setegid byte
|
|
var cgo_libc_setegid = unsafe.Pointer(&_cgo_libc_setegid)
|
|
|
|
//go:cgo_import_static _cgo_libc_seteuid
|
|
//go:linkname _cgo_libc_seteuid _cgo_libc_seteuid
|
|
//go:linkname cgo_libc_seteuid syscall.cgo_libc_seteuid
|
|
var _cgo_libc_seteuid byte
|
|
var cgo_libc_seteuid = unsafe.Pointer(&_cgo_libc_seteuid)
|
|
|
|
//go:cgo_import_static _cgo_libc_setregid
|
|
//go:linkname _cgo_libc_setregid _cgo_libc_setregid
|
|
//go:linkname cgo_libc_setregid syscall.cgo_libc_setregid
|
|
var _cgo_libc_setregid byte
|
|
var cgo_libc_setregid = unsafe.Pointer(&_cgo_libc_setregid)
|
|
|
|
//go:cgo_import_static _cgo_libc_setresgid
|
|
//go:linkname _cgo_libc_setresgid _cgo_libc_setresgid
|
|
//go:linkname cgo_libc_setresgid syscall.cgo_libc_setresgid
|
|
var _cgo_libc_setresgid byte
|
|
var cgo_libc_setresgid = unsafe.Pointer(&_cgo_libc_setresgid)
|
|
|
|
//go:cgo_import_static _cgo_libc_setresuid
|
|
//go:linkname _cgo_libc_setresuid _cgo_libc_setresuid
|
|
//go:linkname cgo_libc_setresuid syscall.cgo_libc_setresuid
|
|
var _cgo_libc_setresuid byte
|
|
var cgo_libc_setresuid = unsafe.Pointer(&_cgo_libc_setresuid)
|
|
|
|
//go:cgo_import_static _cgo_libc_setreuid
|
|
//go:linkname _cgo_libc_setreuid _cgo_libc_setreuid
|
|
//go:linkname cgo_libc_setreuid syscall.cgo_libc_setreuid
|
|
var _cgo_libc_setreuid byte
|
|
var cgo_libc_setreuid = unsafe.Pointer(&_cgo_libc_setreuid)
|
|
|
|
//go:cgo_import_static _cgo_libc_setgroups
|
|
//go:linkname _cgo_libc_setgroups _cgo_libc_setgroups
|
|
//go:linkname cgo_libc_setgroups syscall.cgo_libc_setgroups
|
|
var _cgo_libc_setgroups byte
|
|
var cgo_libc_setgroups = unsafe.Pointer(&_cgo_libc_setgroups)
|
|
|
|
//go:cgo_import_static _cgo_libc_setgid
|
|
//go:linkname _cgo_libc_setgid _cgo_libc_setgid
|
|
//go:linkname cgo_libc_setgid syscall.cgo_libc_setgid
|
|
var _cgo_libc_setgid byte
|
|
var cgo_libc_setgid = unsafe.Pointer(&_cgo_libc_setgid)
|
|
|
|
//go:cgo_import_static _cgo_libc_setuid
|
|
//go:linkname _cgo_libc_setuid _cgo_libc_setuid
|
|
//go:linkname cgo_libc_setuid syscall.cgo_libc_setuid
|
|
var _cgo_libc_setuid byte
|
|
var cgo_libc_setuid = unsafe.Pointer(&_cgo_libc_setuid)
|