Bug 1804204 - Missing ENDBR in libGL.so.1.7.0
Summary: Missing ENDBR in libGL.so.1.7.0
Keywords:
Status: CLOSED UPSTREAM
Alias: None
Product: Fedora
Classification: Fedora
Component: libglvnd
Version: rawhide
Hardware: x86_64
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Nicolas Chauvet (kwizart)
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks: 1802674
TreeView+ depends on / blocked
 
Reported: 2020-02-18 12:52 UTC by xupengfe
Modified: 2020-03-12 17:02 UTC (History)
10 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2020-02-18 14:45:19 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)
It contained dmesg, coredumpctl, journalctl and startx failed log. (886.65 KB, application/zip)
2020-02-18 12:52 UTC, xupengfe
no flags Details


Links
System ID Private Priority Status Summary Last Updated
freedesktop.org Gitlab glvnd/libglvnd/issues/202 0 None None None 2020-03-12 17:02:38 UTC

Description xupengfe 2020-02-18 12:52:17 UTC
Created attachment 1663742 [details]
It contained dmesg, coredumpctl, journalctl and startx failed log.

Description of problem:
CET enabled kernel with Fedora31 could only boot up in text mode,
it could not boot up in graphic mode, which is due to gnome-session-check-accelerated is blocked.

Version-Release number of selected component (if applicable):

Fedora31

How reproducible:


Steps to Reproduce:
1. Boot up CET enabled kernel in Fedora31 with fully CET compiler enabled(GCC, GLIBC, Binutils) in text mode.
2. Execute "startx", which will be failed as below dmesg, coredumpctl, journalctl info:

Dmesg: 
[ 4535.125179] traps: gnome-session-c[12216] control protection ip:7fc655e1f440 sp:7ffd96b641f8 ssp:7fc655e7ffe0 error:3(endbranch) in libGL.so.1.7.0[7fc655e12000+1f000]
[ 4537.551401] traps: gnome-session-c[12234] control protection ip:7fc7243c7440 sp:7ffe09a496f8 ssp:7fc72448dfe0 error:3(endbranch) in libGL.so.1.7.0[7fc7243ba000+1f000]


coredumpctl:
Fri 2020-02-07 12:06:48 EST   12216     0     0  11 truncated /usr/libexec/gnome-session-check-accelerated
Fri 2020-02-07 12:06:53 EST   12234     0     0  11 truncated /usr/libexec/gnome-session-check-accelerated


journalctl:
Feb 07 12:06:46 localhost.localdomain audit[12216]: ANOM_ABEND auid=1000 uid=0 gid=0 ses=2 pid=12216 comm="gnome-session-c" exe="/usr/libexec/gnome-session-check-accelerated" sig=11 res=1
Feb 07 12:06:46 localhost.localdomain kernel: traps: gnome-session-c[12216] control protection ip:7fc655e1f440 sp:7ffd96b641f8 ssp:7fc655e7ffe0 error:3(endbranch) in libGL.so.1.7.0[7fc655e12000+1f000]
Feb 07 12:06:46 localhost.localdomain audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=systemd-coredump@10-12226-0 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Feb 07 12:06:46 localhost.localdomain systemd[1]: Started Process Core Dump (PID 12226/UID 0).
Feb 07 12:06:47 localhost.localdomain systemd-coredump[12227]: Core file was truncated to 2147483648 bytes.


Actual results:
startx could not work, and CET enabled kernel could not access graphic mode.

Expected results:
startx could work, and CET enabled kernel could access graphic mode.

Additional info:

Comment 1 H.J. Lu 2020-02-18 13:08:19 UTC
libGL.so.1.7.0 has

Displaying notes found in: .note.gnu.property
  Owner                Data size 	Description
  GNU                  0x00000010	NT_GNU_PROPERTY_TYPE_0
      Properties: x86 feature: IBT, SHSTK

But ENDBR is missing at indirect branch targets.

Comment 2 leigh scott 2020-02-18 13:26:31 UTC
You need to have everything built with CET support 

https://gitlab.freedesktop.org/mesa/mesa/merge_requests/1621#note_209102

Comment 3 Nicolas Chauvet (kwizart) 2020-02-18 13:29:27 UTC
This improvement might be more relevant to libglvnd upstream
located at https://gitlab.freedesktop.org/glvnd/libglvnd

Comment 4 H.J. Lu 2020-02-18 14:27:34 UTC
ENDBR is missing at glGetString:

(gdb) bt
#0  0x00007f80f4697440 in glGetString () at /lib64/libGL.so.1
#1  0x00007f80f3cd6fd2 in epoxy_internal_gl_version () at /lib64/libepoxy.so.0
#2  0x00007f80f343e1ca in gdk_gl_context_make_current ()
    at /lib64/libgdk-3.so.0
#3  0x000056040fa6a5c8 in main ()
(gdb) disass glGetString
Dump of assembler code for function glGetString:
   0x00007f80f4697440 <+0>:	mov    0x41b89(%rip),%rax        # 0x7f80f46d8fd0
   0x00007f80f4697447 <+7>:	mov    %fs:(%rax),%r11
   0x00007f80f469744b <+11>:	jmpq   *0x2510(%r11)
   0x00007f80f4697452 <+18>:	data16 nopw %cs:0x0(%rax,%rax,1)
   0x00007f80f469745d <+29>:	nopl   (%rax)
End of assembler dump.
(gdb)

Comment 5 Nicolas Chauvet (kwizart) 2020-02-18 14:45:19 UTC
Again, upstream bug tracker is located at :
https://gitlab.freedesktop.org/glvnd/libglvnd

Comment 6 Nicolas Chauvet (kwizart) 2020-02-18 14:47:08 UTC
Once upstream will fix and fedora will enable a toolchain with CET enabled we will update the package in rawhide like any normal update.
So please don't duplicate upstream work in downstream bug tracker. Thx for your understanding.


Note You need to log in before you can comment on or make changes to this bug.