GNU bug report logs -
#34180
27.0.50; argv[0] used incorrectly to find the .pdmp
Previous Next
Reported by: Stefan Monnier <monnier <at> IRO.UMontreal.CA>
Date: Wed, 23 Jan 2019 16:09:02 UTC
Severity: important
Tags: security
Found in version 27.0.50
Fixed in version 28.1
Done: Lars Ingebrigtsen <larsi <at> gnus.org>
Bug is archived. No further changes may be made.
Full log
Message #37 received at 34180 <at> debbugs.gnu.org (full text, mbox):
On 10/11/21 8:10 AM, Paul Eggert wrote:
> On 10/11/21 7:02 AM, Lars Ingebrigtsen wrote:
>> It looks like find_executable from progreloc in gnulib provides a
>> portable interface for this?
>
> It does, although it drags in a bunch of other Gnulib modules, as this
> stuff is wildly system-dependent.
>
> For ordinary Emacs installation, I've long thought that a better
> approach is to store the default .pdmp file as a readonly char array
> within the Emacs executable itself. This would be easier for installers,
> sysadmins and users, as it would entail no funny rules about installing
> two files, keeping them in sync, symlinks, PATH, argv[0], relative
> names, security, etc.
It's not quite that simple though. The pdmp file includes offsets of
data structures within the Emacs executable. Rebuilding the executable
with a big char array will change these offsets and invalidate the pdmp
blob you're trying to embed. Now, you could try to guess the size of the
blob ahead of time, include a dummy embedded array of that size in
Emacs, dump, and then overwrite the embedded array post-build, but
there's no guarantee that doing that would actually work on all systems.
I'd rather get out of the business of mucking with executable files even
if it means we have a bit of extra complexity arising from having to
deal with out-of-band pdmp files.
This bug report was last modified 3 years and 220 days ago.
Previous Next
GNU bug tracking system
Copyright (C) 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson.