1
0
mirror of https://github.com/golang/go synced 2024-09-28 22:14:28 -06:00
go/src
Cherry Mui 77f2750f43 misc/wasm, cmd/link: do not let command line args overwrite global data
On Wasm, wasm_exec.js puts command line arguments at the beginning
of the linear memory (following the "zero page"). Currently there
is no limit for this, and a very long command line can overwrite
the program's data section. Prevent this by limiting the command
line to 4096 bytes, and in the linker ensuring the data section
starts at a high enough address (8192).

(Arguably our address assignment on Wasm is a bit confusing. This
is the minimum fix I can come up with.)

Thanks to Ben Lubar for reporting this issue.

Fixes #48797
Fixes CVE-2021-38297

Change-Id: I0f50fbb2a5b6d0d047e3c134a88988d9133e4ab3
Reviewed-on: https://team-review.git.corp.google.com/c/golang/go-private/+/1205933
Reviewed-by: Roland Shoemaker <bracewell@google.com>
Reviewed-by: Than McIntosh <thanm@google.com>
Reviewed-on: https://go-review.googlesource.com/c/go/+/354571
Reviewed-by: Cherry Mui <cherryyz@google.com>
Reviewed-by: Heschi Kreinick <heschi@google.com>
Trust: Michael Knyszek <mknyszek@google.com>
Run-TryBot: Michael Knyszek <mknyszek@google.com>
TryBot-Result: Go Bot <gobot@golang.org>
2021-10-07 18:45:53 +00:00
..
archive all: use bytes.Cut, strings.Cut 2021-10-06 15:53:04 +00:00
bufio bufio: reject UnreadByte or UnreadRune after a Discard or WriteTo 2021-10-01 17:40:49 +00:00
builtin
bytes strings,bytes: avoid allocations in Trim/TrimLeft/TrimRight 2021-10-06 22:42:28 +00:00
cmd misc/wasm, cmd/link: do not let command line args overwrite global data 2021-10-07 18:45:53 +00:00
compress compress/gzip: add missing license 2021-09-28 19:51:56 +00:00
constraints constraints: new package 2021-09-24 00:39:31 +00:00
container
context context: implement Context.Value using iteration rather than recursion 2021-10-02 00:44:24 +00:00
crypto all: use bytes.Cut, strings.Cut 2021-10-06 15:53:04 +00:00
database/sql all: remove some unused code 2021-09-14 00:49:39 +00:00
debug cmd/link,runtime: remove functab relocations 2021-10-05 23:25:06 +00:00
embed embed: guarantee the returned file of FS.Open implements io.Seeker 2021-09-10 13:30:50 +00:00
encoding all: use bytes.Cut, strings.Cut 2021-10-06 15:53:04 +00:00
errors
expvar
flag
fmt
go go/types: better error message for invalid untyped nil conversion 2021-10-07 14:37:45 +00:00
hash hash/crc32: improve performance of ppc64SlicingUpdateBy8 on ppc64le 2021-09-22 16:53:49 +00:00
html all: use bytes.Cut, strings.Cut 2021-10-06 15:53:04 +00:00
image image/draw: add RGBA64Image fast path for RGBA dst 2021-09-27 10:10:16 +00:00
index/suffixarray
internal internal/cpu: remove option to mark cpu features required 2021-10-06 18:44:56 +00:00
io io: add examples for (*SectionReader) Read/Size 2021-09-28 19:51:08 +00:00
log log: don't format if writing to io.Discard 2021-09-17 19:00:29 +00:00
math math: add Remainder example 2021-10-07 18:09:53 +00:00
mime all: use bytes.Cut, strings.Cut 2021-10-06 15:53:04 +00:00
net net/http: add Cookie.Valid method 2021-10-06 23:26:57 +00:00
os all: use bytes.Cut, strings.Cut 2021-10-06 15:53:04 +00:00
path
plugin
reflect reflect,runtime: add reflect support for regabi on PPC64 2021-09-28 18:58:50 +00:00
regexp all: use bytes.Cut, strings.Cut 2021-10-06 15:53:04 +00:00
runtime cmd/compile,runtime: implement uint64->float32 correctly on 32-bit archs 2021-10-07 18:34:24 +00:00
sort
strconv all: use bytes.Cut, strings.Cut 2021-10-06 15:53:04 +00:00
strings strings,bytes: avoid allocations in Trim/TrimLeft/TrimRight 2021-10-06 22:42:28 +00:00
sync runtime,sync: using fastrandn instead of modulo reduction 2021-10-07 14:01:52 +00:00
syscall all: use bytes.Cut, strings.Cut 2021-10-06 15:53:04 +00:00
testdata
testing testing: document f.Fuzz requirement to not change underlying data 2021-10-05 20:15:01 +00:00
text all: use bytes.Cut, strings.Cut 2021-10-06 15:53:04 +00:00
time time: fallback to slower TestTicker test after one failure 2021-10-06 23:01:01 +00:00
unicode unicode: add examples for the Is functions 2021-10-06 23:19:13 +00:00
unsafe
vendor all: update go.mod for golang.org/x/net 2021-10-06 20:21:49 +00:00
all.bash
all.bat
all.rc
bootstrap.bash
buildall.bash
clean.bash
clean.bat
clean.rc
cmp.bash
go.mod all: update go.mod for golang.org/x/net 2021-10-06 20:21:49 +00:00
go.sum all: update go.mod for golang.org/x/net 2021-10-06 20:21:49 +00:00
make.bash
make.bat
Make.dist
make.rc
race.bash
race.bat
README.vendor
run.bash
run.bat
run.rc

Vendoring in std and cmd
========================

The Go command maintains copies of external packages needed by the
standard library in the src/vendor and src/cmd/vendor directories.

In GOPATH mode, imports of vendored packages are resolved to these
directories following normal vendor directory logic
(see golang.org/s/go15vendor).

In module mode, std and cmd are modules (defined in src/go.mod and
src/cmd/go.mod). When a package outside std or cmd is imported
by a package inside std or cmd, the import path is interpreted
as if it had a "vendor/" prefix. For example, within "crypto/tls",
an import of "golang.org/x/crypto/cryptobyte" resolves to
"vendor/golang.org/x/crypto/cryptobyte". When a package with the
same path is imported from a package outside std or cmd, it will
be resolved normally. Consequently, a binary may be built with two
copies of a package at different versions if the package is
imported normally and vendored by the standard library.

Vendored packages are internally renamed with a "vendor/" prefix
to preserve the invariant that all packages have distinct paths.
This is necessary to avoid compiler and linker conflicts. Adding
a "vendor/" prefix also maintains the invariant that standard
library packages begin with a dotless path element.

The module requirements of std and cmd do not influence version
selection in other modules. They are only considered when running
module commands like 'go get' and 'go mod vendor' from a directory
in GOROOT/src.

Maintaining vendor directories
==============================

Before updating vendor directories, ensure that module mode is enabled.
Make sure GO111MODULE=off is not set ('on' or 'auto' should work).

Requirements may be added, updated, and removed with 'go get'.
The vendor directory may be updated with 'go mod vendor'.
A typical sequence might be:

    cd src
    go get -d golang.org/x/net@latest
    go mod tidy
    go mod vendor

Use caution when passing '-u' to 'go get'. The '-u' flag updates
modules providing all transitively imported packages, not only
the module providing the target package.

Note that 'go mod vendor' only copies packages that are transitively
imported by packages in the current module. If a new package is needed,
it should be imported before running 'go mod vendor'.