Skip to content

Fix AT_PHDR on Linux < 5.18 when growing PIE binaries - #669

Open
isanych wants to merge 1 commit into
NixOS:masterfrom
isanych:rocky9fix
Open

isanych wants to merge 1 commit into
NixOS:masterfrom
isanych:rocky9fix

Conversation

@isanych

@isanych isanych commented Oct 1, 2026

Copy link
Copy Markdown

Kernels before 5.18 (e.g. RHEL 9's 5.14) compute AT_PHDR as load_bias + e_phoff and ignore PT_PHDR. When the file has to grow, patchelf moves the program headers into a new PT_LOAD segment. If the new segment's file offset differs from its virtual address, ld.so is handed a bogus phdr pointer and the binary segfaults at startup.

This happens in two cases:

  • Non-alloc sections (.symtab, .strtab, ...) sit after the last segment, so the new segment's file offset is larger than its virtual address. Make the virtual address equal the file offset.

  • Executables with a large .bss (e.g. Qt's lupdate) get the new PT_LOAD placed at a virtual address above its file offset. Pad the file so vaddr == file offset for executables.

grow-file.sh now passes.

Kernels before 5.18 (e.g. RHEL 9's 5.14) compute AT_PHDR as
load_bias + e_phoff and ignore PT_PHDR. When the file has to grow,
patchelf moves the program headers into a new PT_LOAD segment. If the
new segment's file offset differs from its virtual address, ld.so is
handed a bogus phdr pointer and the binary segfaults at startup.

This happens in two cases:

- Non-alloc sections (.symtab, .strtab, ...) sit after the last
  segment, so the new segment's file offset is larger than its
  virtual address. Make the virtual address equal the file offset.

- Executables with a large .bss (e.g. Qt's lupdate) get the new
  PT_LOAD placed at a virtual address above its file offset. Pad the
  file so vaddr == file offset for executables.

grow-file.sh now passes.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant