From nobody Tue Aug 25 01:34:08 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1779486781; cv=none; d=zohomail.com; s=zohoarc; b=UFjCGn/Ohyk47ZMY/g2+pz+F8apQA4XC5RmPf7gkdvun8xDOC8JIqepwLBbbPexoUdYpUy3mBOHZSYwt57hz5pfudOCFNxn5/thmUkvmY1YnncQ/NUSVdh06RlPb3ulf4iaKOYY1awrbFM9Jy6nSGKWle3buHDzNogvgcQe20tw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1779486781; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=tHQeDeHt0oUp033jzT0FOiSVJPMSn3mSXwb3YdNT7mM=; b=ZrQg59BbaJza92mu/4RQmAbUEoZfa4BYbR3wkh4/IDrTS12vfpk/o+KZE5dOBNi3OwqDMUGbl4LjY+L64CCUNGQpgl7jVvXJJGWOWmgokEUlz/66wdecJeYzAjD8kgX9ig/8lZOwWfLvkStv47VvF6XhyA/awWE5FTh3CznFBPU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1779486781850364.99218275556575; Fri, 22 May 2026 14:53:01 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wQXn9-0005ZI-7z; Fri, 22 May 2026 17:52:27 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wQXn7-0005Ot-N0; Fri, 22 May 2026 17:52:25 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wQXn5-0004ZE-Hn; Fri, 22 May 2026 17:52:25 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 467781AFB7B; Sat, 23 May 2026 00:49:21 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 6FF6D3B71CA; Sat, 23 May 2026 00:49:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1779486561; bh=IxlVzasWUz1jAgKSjDI2NIizegDam5b3CcOyjw+M1BU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=bLN6ExPB4hgQySkkQjp8XglktG7Y+u/b/wG6uBNnum5r8mi3rf/fPlH5Fh7/4kPjF qLnykjU2sweubI1kWyFxkkT+Mr0cngB0cFHsx1yDp0aHXYOpI+7hCit+UFfWAMEXA4 PaFeWAVjEwa2ln5W5f2zRbgdMzNd635Sn8FKhfDXivFxCtkUpqbsxAljS+2CPEU99k oO9cCUBXnks6lF6SZNC42xrMZnH8NQoJjku5vetdnAl6kNfQ5+yTrQFQdjO1+53vyh nPlGbkHTLavFQYJV9ECMrfg8K9jNDzfMHcVdpt5Xjlh+ZQZ4GhQU5gmmjiXQ2Ne0bx QHrKvht6hvm4A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Helge Deller , Michael Tokarev Subject: [Stable-10.2.3 133/149] linux-user: Fix AT_EXECFN in AUXV for symlinked programs Date: Sat, 23 May 2026 00:49:05 +0300 Message-ID: <20260522214923.807017-34-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1779486784435154100 Content-Type: text/plain; charset="utf-8" From: Helge Deller The AT_EXECFN entry in AUXV needs to keep the value which was used when the program was started. Especially for symlinked programs qemu should not try to resolve the realpath. Here is a reproducer: (arm64-chroot)root@p100:/# cd /usr/bin (arm64-chroot)root@p100:/usr/bin# ln -s echo testprog (arm64-chroot)root@p100:/usr/bin# LD_SHOW_AUXV=3D1 ./testprog | grep AT_EXE= CFN AT_EXECFN: ./testprog In this example, "./testprog" is the correct output, and not "/usr/bin/echo= ". This patch fixes parts of commit 258bec39 ("linux-user: Fix access to /proc/self/exe"). Fixes: 258bec39 ("linux-user: Fix access to /proc/self/exe") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3379 Signed-off-by: Helge Deller (cherry picked from commit 6b5aef7cac9dab7c16451588cff6615eb2048293) Signed-off-by: Michael Tokarev diff --git a/linux-user/main.c b/linux-user/main.c index 86d04cca3c..c08c73fd80 100644 --- a/linux-user/main.c +++ b/linux-user/main.c @@ -772,8 +772,10 @@ int main(int argc, char **argv, char **envp) } =20 /* Resolve executable file name to full path name */ - if (realpath(exec_path, real_exec_path)) { - exec_path =3D real_exec_path; + /* Keep how we started the program in exec_path, e.g. "./my_program" */ + /* Store real path in real_exec_path, e.g. "/usr/local/bin/my_program"= */ + if (!realpath(exec_path, real_exec_path)) { + printf("Could not resolve %s\n", exec_path); } =20 /* diff --git a/linux-user/syscall.c b/linux-user/syscall.c index bb818f35d9..5c101c19e4 100644 --- a/linux-user/syscall.c +++ b/linux-user/syscall.c @@ -8799,9 +8799,9 @@ static int maybe_do_fake_open(CPUArchState *cpu_env, = int dirfd, return -1; } if (safe) { - return safe_openat(dirfd, exec_path, flags, mode); + return safe_openat(dirfd, real_exec_path, flags, mode); } else { - return openat(dirfd, exec_path, flags, mode); + return openat(dirfd, real_exec_path, flags, mode); } } =20 @@ -8934,9 +8934,9 @@ ssize_t do_guest_readlink(const char *pathname, char = *buf, size_t bufsiz) * Don't worry about sign mismatch as earlier mapping * logic would have thrown a bad address error. */ - ret =3D MIN(strlen(exec_path), bufsiz); + ret =3D MIN(strlen(real_exec_path), bufsiz); /* We cannot NUL terminate the string. */ - memcpy(buf, exec_path, ret); + memcpy(buf, real_exec_path, ret); } else { ret =3D readlink(path(pathname), buf, bufsiz); } @@ -9027,7 +9027,7 @@ static int do_execv(CPUArchState *cpu_env, int dirfd, =20 const char *exe =3D p; if (is_proc_myself(p, "exe")) { - exe =3D exec_path; + exe =3D real_exec_path; } ret =3D is_execveat ? safe_execveat(dirfd, exe, argp, envp, flags) @@ -11038,9 +11038,9 @@ static abi_long do_syscall1(CPUArchState *cpu_env, = int num, abi_long arg1, * Don't worry about sign mismatch as earlier mapping * logic would have thrown a bad address error. */ - ret =3D MIN(strlen(exec_path), arg4); + ret =3D MIN(strlen(real_exec_path), arg4); /* We cannot NUL terminate the string. */ - memcpy(p2, exec_path, ret); + memcpy(p2, real_exec_path, ret); } else { ret =3D get_errno(readlinkat(arg1, path(p), p2, arg4)); } diff --git a/linux-user/user-internals.h b/linux-user/user-internals.h index 24d35998f0..7730444aa5 100644 --- a/linux-user/user-internals.h +++ b/linux-user/user-internals.h @@ -24,6 +24,7 @@ #include "exec/translation-block.h" =20 extern char *exec_path; +extern char real_exec_path[PATH_MAX]; void init_task_state(TaskState *ts); void task_settid(TaskState *); void stop_all_tasks(void); --=20 2.47.3