id = 1729 title = "mremap fails with EFAULT if address range overlaps with stack guard" state = "closed" created_at = "2023-06-25T06:50:48.249Z" closed_at = "2024-10-20T22:02:11.370Z" labels = ["linux-user"] url = "https://gitlab.com/qemu-project/qemu/-/issues/1729" host-os = "any linux" host-arch = "x86_64" qemu-version = "any version" guest-os = "alpine-linux" guest-arch = "ARM 32-bit" description = """When running 32-bit user-static on 64-bit host, `mremap` behave differently from the kernel. This difference let programs that call `pthread_getattr_np` on musl-libc to run into a loop on repeated calling `mremap`. https://git.musl-libc.org/cgit/musl/plain/src/thread/pthread_getattr_np.c ``` c \t\twhile (mremap(p-l-PAGE_SIZE, PAGE_SIZE, 2*PAGE_SIZE, 0)==MAP_FAILED && errno==ENOMEM) \t\t\tl += PAGE_SIZE; ```""" reproduce = """Compile the following program against musl-libc arm 32-bit, and run it in qemu-user-static on x86_64 host. ``` c #define _GNU_SOURCE #include int main(int argc, char *argv[]) { \tpthread_attr_t attr; \treturn pthread_getattr_np(pthread_self(), &attr); } ``` For example, on x86_64 fedora 38 with podman and qemu-user-static installed, we can reproduce this with alpine container: ``` $ podman run --rm -it --arch arm/v7 docker.io/library/alpine:latest / # apk add alpine-sdk ...... / # cat test.c #define _GNU_SOURCE #include int main(int argc, char *argv[]) { \tpthread_attr_t attr; \treturn pthread_getattr_np(pthread_self(), &attr); } / # gcc test.c / # ./a.out ```""" additional = """Original thread on musl mail list where this was initially reported: https://www.openwall.com/lists/musl/2017/06/15/9"""