[perl #120635] Perl 64 bit big-endian semctl SETVAL bug

November 26, 2013 19:34
calls to semctl(id,semnum,SETVAL,$wantedval)
On 64 bit big-endian boxes, will ignore the passed
in $wantedval, and always use 0

Here's a script that shows the bug in action....

use strict;

my $nsem = 10;

my $id = semget(IPC_PRIVATE, $nsem, S_IRUSR | S_IWUSR | IPC_CREAT);

my $ret = semctl($id, "ignore", SETALL, pack("s!*",(0)x$nsem));
warn "semctl setall: $!\n" unless(defined($ret));

$ret = semctl($id, 3, SETVAL, 17);
warn "semctl setval: $!\n" unless(defined($ret));

my $semvals;
$ret = semctl($id, "ignore", GETALL, $semvals);
    warn "semctl GETALL: $!\n" unless(defined($ret));
    my @semvals = unpack("s!*", $semvals);
    print "semvals=@semvals\n";

$ret = semctl($id, "ignored", IPC_RMID, "ignored");
die "semctl rmid: $!\n" unless(defined($ret));

On a linux 64 bit box, the output is correct:
semvals=0 0 0 17 0 0 0 0 0 0

On solaris 64 bit box, this is the output:
semvals=0 0 0 0 0 0 0 0 0 0

when I truss the perl process I see this:
semctl(100, 3, SETVAL, 0)   = 0

I looked into it, and I think I found the problem:

The problem begins in union semun, defined as...

           union semun {
               int              val;    /* Value for SETVAL */
               struct semid_ds *buf;    /* Buffer for IPC_STAT, IPC_SET */
               unsigned short  *array;  /* Array for GETALL, SETALL */

In a 64 bit build, val will be a 32 bit signed integer.
It will share the first 32 bits of buf.

In the perl code, doio.c:2128, we have...
        const IV i = SvIV(astr);
        a = INT2PTR(char *,i);          /* ouch */

That takes the passed in 17, and coerces it into a char*,
and assigns it to "a"

Finally, doio.c:2147 does
            unsemds.buf = (struct semid_ds *)a;

Now, on little endian (intel linux) boxes, val gets set to the lower
32bits of a, and things work pretty much like we want.

On a big endian box (Sun Sparc), val gets set to the upper 32 bits,
which are all zeros, and it does not do what we want.

Here's a patch against the git tree...

>From 1752788b779244024f086167a5517d50aa6af5bc Mon Sep 17 00:00:00 2001
From: Brian Childs <>
Date: Tue, 26 Nov 2013 13:12:30 -0500
Subject: [PATCH] Fixes the case where on 64bit big-endian boxes, calls to
 semctl(id,semnum,SETVAL,$wantedval) will ignore the passed
 in $wantedval, and always use 0

 doio.c |    9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

diff --git a/doio.c b/doio.c
index 3ee975d..e7e90d3 100644
--- a/doio.c
+++ b/doio.c
@@ -2141,11 +2141,16 @@ Perl_do_ipcctl(pTHX_ I32 optype, SV **mark, SV **sp)
 #ifdef Semctl
             union semun unsemds;
+            if(cmd == SETVAL) {
+                unsemds.val = PTR2nat(a);
+            }
+            else {
-            unsemds.buff = (struct semid_ds *)a;
+                unsemds.buff = (struct semid_ds *)a;
-            unsemds.buf = (struct semid_ds *)a;
+                unsemds.buf = (struct semid_ds *)a;
+            }
 	    ret = Semctl(id, n, cmd, unsemds);
 	    /* diag_listed_as: sem%s not implemented */

