<feed xmlns='http://www.w3.org/2005/Atom'>
<title>delta/glibc.git/malloc, branch azanella/generic-strings</title>
<subtitle>sourceware.org: git/glibc.git
</subtitle>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/glibc.git/'/>
<entry>
<title>malloc: Add ChangeLog for accidentally committed change</title>
<updated>2018-08-20T12:57:13+00:00</updated>
<author>
<name>Florian Weimer</name>
<email>fweimer@redhat.com</email>
</author>
<published>2018-08-20T12:57:13+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/glibc.git/commit/?id=35cfefd96062145eeb8aee6bd72d07e0909a6b2e'/>
<id>35cfefd96062145eeb8aee6bd72d07e0909a6b2e</id>
<content type='text'>
Commit b90ddd08f6dd688e651df9ee89ca3a69ff88cd0c ("malloc: Additional
checks for unsorted bin integrity I.") was committed without a
whitespace fix, so it is adjusted here as well.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Commit b90ddd08f6dd688e651df9ee89ca3a69ff88cd0c ("malloc: Additional
checks for unsorted bin integrity I.") was committed without a
whitespace fix, so it is adjusted here as well.
</pre>
</div>
</content>
</entry>
<entry>
<title>malloc: Additional checks for unsorted bin integrity I.</title>
<updated>2018-08-17T14:04:02+00:00</updated>
<author>
<name>Istvan Kurucsai</name>
<email>pistukem@gmail.com</email>
</author>
<published>2018-01-16T13:54:32+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/glibc.git/commit/?id=b90ddd08f6dd688e651df9ee89ca3a69ff88cd0c'/>
<id>b90ddd08f6dd688e651df9ee89ca3a69ff88cd0c</id>
<content type='text'>
On Thu, Jan 11, 2018 at 3:50 PM, Florian Weimer &lt;fweimer@redhat.com&gt; wrote:
&gt; On 11/07/2017 04:27 PM, Istvan Kurucsai wrote:
&gt;&gt;
&gt;&gt; +          next = chunk_at_offset (victim, size);
&gt;
&gt;
&gt; For new code, we prefer declarations with initializers.

Noted.

&gt;&gt; +          if (__glibc_unlikely (chunksize_nomask (victim) &lt;= 2 * SIZE_SZ)
&gt;&gt; +              || __glibc_unlikely (chunksize_nomask (victim) &gt;
&gt;&gt; av-&gt;system_mem))
&gt;&gt; +            malloc_printerr("malloc(): invalid size (unsorted)");
&gt;&gt; +          if (__glibc_unlikely (chunksize_nomask (next) &lt; 2 * SIZE_SZ)
&gt;&gt; +              || __glibc_unlikely (chunksize_nomask (next) &gt;
&gt;&gt; av-&gt;system_mem))
&gt;&gt; +            malloc_printerr("malloc(): invalid next size (unsorted)");
&gt;&gt; +          if (__glibc_unlikely ((prev_size (next) &amp; ~(SIZE_BITS)) !=
&gt;&gt; size))
&gt;&gt; +            malloc_printerr("malloc(): mismatching next-&gt;prev_size
&gt;&gt; (unsorted)");
&gt;
&gt;
&gt; I think this check is redundant because prev_size (next) and chunksize
&gt; (victim) are loaded from the same memory location.

I'm fairly certain that it compares mchunk_size of victim against
mchunk_prev_size of the next chunk, i.e. the size of victim in its
header and footer.

&gt;&gt; +          if (__glibc_unlikely (bck-&gt;fd != victim)
&gt;&gt; +              || __glibc_unlikely (victim-&gt;fd != unsorted_chunks (av)))
&gt;&gt; +            malloc_printerr("malloc(): unsorted double linked list
&gt;&gt; corrupted");
&gt;&gt; +          if (__glibc_unlikely (prev_inuse(next)))
&gt;&gt; +            malloc_printerr("malloc(): invalid next-&gt;prev_inuse
&gt;&gt; (unsorted)");
&gt;
&gt;
&gt; There's a missing space after malloc_printerr.

Noted.

&gt; Why do you keep using chunksize_nomask?  We never investigated why the
&gt; original code uses it.  It may have been an accident.

You are right, I don't think it makes a difference in these checks. So
the size local can be reused for the checks against victim. For next,
leaving it as such avoids the masking operation.

&gt; Again, for non-main arenas, the checks against av-&gt;system_mem could be made
&gt; tighter (against the heap size).  Maybe you could put the condition into a
&gt; separate inline function?

We could also do a chunk boundary check similar to what I proposed in
the thread for the first patch in the series to be even more strict.
I'll gladly try to implement either but believe that refining these
checks would bring less benefits than in the case of the top chunk.
Intra-arena or intra-heap overlaps would still be doable here with
unsorted chunks and I don't see any way to counter that besides more
generic measures like randomizing allocations and your metadata
encoding patches.

I've attached a revised version with the above comments incorporated
but without the refined checks.

Thanks,
Istvan

From a12d5d40fd7aed5fa10fc444dcb819947b72b315 Mon Sep 17 00:00:00 2001
From: Istvan Kurucsai &lt;pistukem@gmail.com&gt;
Date: Tue, 16 Jan 2018 14:48:16 +0100
Subject: [PATCH v2 1/1] malloc: Additional checks for unsorted bin integrity
 I.

Ensure the following properties of chunks encountered during binning:
- victim chunk has reasonable size
- next chunk has reasonable size
- next-&gt;prev_size == victim-&gt;size
- valid double linked list
- PREV_INUSE of next chunk is unset

    * malloc/malloc.c (_int_malloc): Additional binning code checks.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
On Thu, Jan 11, 2018 at 3:50 PM, Florian Weimer &lt;fweimer@redhat.com&gt; wrote:
&gt; On 11/07/2017 04:27 PM, Istvan Kurucsai wrote:
&gt;&gt;
&gt;&gt; +          next = chunk_at_offset (victim, size);
&gt;
&gt;
&gt; For new code, we prefer declarations with initializers.

Noted.

&gt;&gt; +          if (__glibc_unlikely (chunksize_nomask (victim) &lt;= 2 * SIZE_SZ)
&gt;&gt; +              || __glibc_unlikely (chunksize_nomask (victim) &gt;
&gt;&gt; av-&gt;system_mem))
&gt;&gt; +            malloc_printerr("malloc(): invalid size (unsorted)");
&gt;&gt; +          if (__glibc_unlikely (chunksize_nomask (next) &lt; 2 * SIZE_SZ)
&gt;&gt; +              || __glibc_unlikely (chunksize_nomask (next) &gt;
&gt;&gt; av-&gt;system_mem))
&gt;&gt; +            malloc_printerr("malloc(): invalid next size (unsorted)");
&gt;&gt; +          if (__glibc_unlikely ((prev_size (next) &amp; ~(SIZE_BITS)) !=
&gt;&gt; size))
&gt;&gt; +            malloc_printerr("malloc(): mismatching next-&gt;prev_size
&gt;&gt; (unsorted)");
&gt;
&gt;
&gt; I think this check is redundant because prev_size (next) and chunksize
&gt; (victim) are loaded from the same memory location.

I'm fairly certain that it compares mchunk_size of victim against
mchunk_prev_size of the next chunk, i.e. the size of victim in its
header and footer.

&gt;&gt; +          if (__glibc_unlikely (bck-&gt;fd != victim)
&gt;&gt; +              || __glibc_unlikely (victim-&gt;fd != unsorted_chunks (av)))
&gt;&gt; +            malloc_printerr("malloc(): unsorted double linked list
&gt;&gt; corrupted");
&gt;&gt; +          if (__glibc_unlikely (prev_inuse(next)))
&gt;&gt; +            malloc_printerr("malloc(): invalid next-&gt;prev_inuse
&gt;&gt; (unsorted)");
&gt;
&gt;
&gt; There's a missing space after malloc_printerr.

Noted.

&gt; Why do you keep using chunksize_nomask?  We never investigated why the
&gt; original code uses it.  It may have been an accident.

You are right, I don't think it makes a difference in these checks. So
the size local can be reused for the checks against victim. For next,
leaving it as such avoids the masking operation.

&gt; Again, for non-main arenas, the checks against av-&gt;system_mem could be made
&gt; tighter (against the heap size).  Maybe you could put the condition into a
&gt; separate inline function?

We could also do a chunk boundary check similar to what I proposed in
the thread for the first patch in the series to be even more strict.
I'll gladly try to implement either but believe that refining these
checks would bring less benefits than in the case of the top chunk.
Intra-arena or intra-heap overlaps would still be doable here with
unsorted chunks and I don't see any way to counter that besides more
generic measures like randomizing allocations and your metadata
encoding patches.

I've attached a revised version with the above comments incorporated
but without the refined checks.

Thanks,
Istvan

From a12d5d40fd7aed5fa10fc444dcb819947b72b315 Mon Sep 17 00:00:00 2001
From: Istvan Kurucsai &lt;pistukem@gmail.com&gt;
Date: Tue, 16 Jan 2018 14:48:16 +0100
Subject: [PATCH v2 1/1] malloc: Additional checks for unsorted bin integrity
 I.

Ensure the following properties of chunks encountered during binning:
- victim chunk has reasonable size
- next chunk has reasonable size
- next-&gt;prev_size == victim-&gt;size
- valid double linked list
- PREV_INUSE of next chunk is unset

    * malloc/malloc.c (_int_malloc): Additional binning code checks.
</pre>
</div>
</content>
</entry>
<entry>
<title>malloc: Mitigate null-byte overflow attacks</title>
<updated>2018-08-17T01:26:16+00:00</updated>
<author>
<name>Moritz Eckert</name>
<email>m.eckert@cs.ucsb.edu</email>
</author>
<published>2018-08-17T01:08:36+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/glibc.git/commit/?id=d6db68e66dff25d12c3bc5641b60cbd7fb6ab44f'/>
<id>d6db68e66dff25d12c3bc5641b60cbd7fb6ab44f</id>
<content type='text'>
* malloc/malloc.c (_int_free): Check for corrupt prev_size vs size.
(malloc_consolidate): Likewise.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* malloc/malloc.c (_int_free): Check for corrupt prev_size vs size.
(malloc_consolidate): Likewise.
</pre>
</div>
</content>
</entry>
<entry>
<title>malloc: Verify size of top chunk.</title>
<updated>2018-08-16T19:24:24+00:00</updated>
<author>
<name>Pochang Chen</name>
<email>johnchen902@gmail.com</email>
</author>
<published>2018-08-16T19:24:24+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/glibc.git/commit/?id=30a17d8c95fbfb15c52d1115803b63aaa73a285c'/>
<id>30a17d8c95fbfb15c52d1115803b63aaa73a285c</id>
<content type='text'>
The House of Force is a well-known technique to exploit heap
overflow. In essence, this exploit takes three steps:
1. Overwrite the size of top chunk with very large value (e.g. -1).
2. Request x bytes from top chunk. As the size of top chunk
   is corrupted, x can be arbitrarily large and top chunk will
   still be offset by x.
3. The next allocation from top chunk will thus be controllable.

If we verify the size of top chunk at step 2, we can stop such attack.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The House of Force is a well-known technique to exploit heap
overflow. In essence, this exploit takes three steps:
1. Overwrite the size of top chunk with very large value (e.g. -1).
2. Request x bytes from top chunk. As the size of top chunk
   is corrupted, x can be arbitrarily large and top chunk will
   still be offset by x.
3. The next allocation from top chunk will thus be controllable.

If we verify the size of top chunk at step 2, we can stop such attack.
</pre>
</div>
</content>
</entry>
<entry>
<title>libc: Extend __libc_freeres framework (Bug 23329).</title>
<updated>2018-06-30T02:39:06+00:00</updated>
<author>
<name>Carlos O'Donell</name>
<email>carlos@redhat.com</email>
</author>
<published>2018-06-22T13:28:47+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/glibc.git/commit/?id=2827ab990aefbb0e53374199b875d98f116d6390'/>
<id>2827ab990aefbb0e53374199b875d98f116d6390</id>
<content type='text'>
The __libc_freeres framework does not extend to non-libc.so objects.
This causes problems in general for valgrind and mtrace detecting
unfreed objects in both libdl.so and libpthread.so.  This change is
a pre-requisite to properly moving the malloc hooks out of malloc
since such a move now requires precise accounting of all allocated
data before destructors are run.

This commit adds a proper hook in libc.so.6 for both libdl.so and
for libpthread.so, this ensures that shm-directory.c which uses
freeit () to free memory is called properly.  We also remove the
nptl_freeres hook and fall back to using weak-ref-and-check idiom
for a loaded libpthread.so, thus making this process similar for
all DSOs.

Lastly we follow best practice and use explicit free calls for
both libdl.so and libpthread.so instead of the generic hook process
which has undefined order.

Tested on x86_64 with no regressions.

Signed-off-by: DJ Delorie &lt;dj@redhat.com&gt;
Signed-off-by: Carlos O'Donell &lt;carlos@redhat.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The __libc_freeres framework does not extend to non-libc.so objects.
This causes problems in general for valgrind and mtrace detecting
unfreed objects in both libdl.so and libpthread.so.  This change is
a pre-requisite to properly moving the malloc hooks out of malloc
since such a move now requires precise accounting of all allocated
data before destructors are run.

This commit adds a proper hook in libc.so.6 for both libdl.so and
for libpthread.so, this ensures that shm-directory.c which uses
freeit () to free memory is called properly.  We also remove the
nptl_freeres hook and fall back to using weak-ref-and-check idiom
for a loaded libpthread.so, thus making this process similar for
all DSOs.

Lastly we follow best practice and use explicit free calls for
both libdl.so and libpthread.so instead of the generic hook process
which has undefined order.

Tested on x86_64 with no regressions.

Signed-off-by: DJ Delorie &lt;dj@redhat.com&gt;
Signed-off-by: Carlos O'Donell &lt;carlos@redhat.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>malloc: Update heap dumping/undumping comments [BZ #23351]</title>
<updated>2018-06-29T12:55:15+00:00</updated>
<author>
<name>Florian Weimer</name>
<email>fweimer@redhat.com</email>
</author>
<published>2018-06-29T12:54:59+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/glibc.git/commit/?id=524d796d5f52913d5d33edede74a5075dbda25ca'/>
<id>524d796d5f52913d5d33edede74a5075dbda25ca</id>
<content type='text'>
Also remove a few now-unused declarations and definitions.

Reviewed-by: Carlos O'Donell &lt;carlos@redhat.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Also remove a few now-unused declarations and definitions.

Reviewed-by: Carlos O'Donell &lt;carlos@redhat.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>Run thread shutdown functions in an explicit order</title>
<updated>2018-06-26T13:27:12+00:00</updated>
<author>
<name>Florian Weimer</name>
<email>fweimer@redhat.com</email>
</author>
<published>2018-06-26T13:13:54+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/glibc.git/commit/?id=124e025864bb39732c71fc60c1443d5680881a0a'/>
<id>124e025864bb39732c71fc60c1443d5680881a0a</id>
<content type='text'>
This removes the __libc_thread_subfreeres hook in favor of explict
calls.

Reviewed-by: Carlos O'Donell &lt;carlos@redhat.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This removes the __libc_thread_subfreeres hook in favor of explict
calls.

Reviewed-by: Carlos O'Donell &lt;carlos@redhat.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>malloc: harden removal from unsorted list</title>
<updated>2018-03-14T20:25:57+00:00</updated>
<author>
<name>Francois Goichon</name>
<email>fgoichon@google.com</email>
</author>
<published>2018-03-14T20:25:57+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/glibc.git/commit/?id=bdc3009b8ff0effdbbfb05eb6b10966753cbf9b8'/>
<id>bdc3009b8ff0effdbbfb05eb6b10966753cbf9b8</id>
<content type='text'>
* malloc/malloc.c (_int_malloc): Added check before removing from
unsorted list.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* malloc/malloc.c (_int_malloc): Added check before removing from
unsorted list.
</pre>
</div>
</content>
</entry>
<entry>
<title>malloc: Revert sense of prev_inuse in comments</title>
<updated>2018-03-09T15:21:22+00:00</updated>
<author>
<name>Florian Weimer</name>
<email>fweimer@redhat.com</email>
</author>
<published>2018-03-09T15:21:22+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/glibc.git/commit/?id=229855e5983881812b21b215346cb990722c6023'/>
<id>229855e5983881812b21b215346cb990722c6023</id>
<content type='text'>
Reviewed-by: Carlos O'Donell &lt;carlos@redhat.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Reviewed-by: Carlos O'Donell &lt;carlos@redhat.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>Mechanically remove _IO_ name aliases for types and constants.</title>
<updated>2018-02-21T19:11:05+00:00</updated>
<author>
<name>Zack Weinberg</name>
<email>zackw@panix.com</email>
</author>
<published>2018-02-07T23:42:04+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/glibc.git/commit/?id=9964a14579e5eef925aaa82facc4980f627802fe'/>
<id>9964a14579e5eef925aaa82facc4980f627802fe</id>
<content type='text'>
This patch mechanically removes all remaining uses, and the
definitions, of the following libio name aliases:

 name                         replaced with
 ----                         -------------
 _IO_FILE                     FILE
 _IO_fpos_t                   __fpos_t
 _IO_fpos64_t                 __fpos64_t
 _IO_size_t                   size_t
 _IO_ssize_t                  ssize_t or __ssize_t
 _IO_off_t                    off_t
 _IO_off64_t                  off64_t
 _IO_pid_t                    pid_t
 _IO_uid_t                    uid_t
 _IO_wint_t                   wint_t
 _IO_va_list                  va_list or __gnuc_va_list
 _IO_BUFSIZ                   BUFSIZ
 _IO_cookie_io_functions_t    cookie_io_functions_t
 __io_read_fn                 cookie_read_function_t
 __io_write_fn                cookie_write_function_t
 __io_seek_fn                 cookie_seek_function_t
 __io_close_fn                cookie_close_function_t

I used __fpos_t and __fpos64_t instead of fpos_t and fpos64_t because
the definitions of fpos_t and fpos64_t depend on the largefile mode.
I used __ssize_t and __gnuc_va_list in a handful of headers where
namespace cleanliness might be relevant even though they're
internal-use-only.  In all other cases, I used the public-namespace
name.

There are a tiny handful of places where I left a use of 'struct _IO_FILE'
alone, because it was being used together with 'struct _IO_FILE_plus'
or 'struct _IO_FILE_complete' in the same arithmetic expression.

Because this patch was almost entirely done with search and replace, I
may have introduced indentation botches.  I did proofread the diff,
but I may have missed something.

The ChangeLog below calls out all of the places where this was not a
pure search-and-replace change.

Installed stripped libraries and executables are unchanged by this patch,
except that some assertions in vfscanf.c change line numbers.

	* libio/libio.h (_IO_FILE): Delete; all uses changed to FILE.
	(_IO_fpos_t): Delete; all uses changed to __fpos_t.
	(_IO_fpos64_t): Delete; all uses changed to __fpos64_t.
	(_IO_size_t): Delete; all uses changed to size_t.
	(_IO_ssize_t): Delete; all uses changed to ssize_t or __ssize_t.
	(_IO_off_t): Delete; all uses changed to off_t.
	(_IO_off64_t): Delete; all uses changed to off64_t.
	(_IO_pid_t): Delete; all uses changed to pid_t.
	(_IO_uid_t): Delete; all uses changed to uid_t.
	(_IO_wint_t): Delete; all uses changed to wint_t.
	(_IO_va_list): Delete; all uses changed to va_list or __gnuc_va_list.
	(_IO_BUFSIZ): Delete; all uses changed to BUFSIZ.
	(_IO_cookie_io_functions_t): Delete; all uses changed to
	cookie_io_functions_t.
	(__io_read_fn): Delete; all uses changed to cookie_read_function_t.
	(__io_write_fn): Delete; all uses changed to cookie_write_function_t.
	(__io_seek_fn): Delete; all uses changed to cookie_seek_function_t.
	(__io_close_fn): Delete: all uses changed to cookie_close_function_t.

	* libio/iofopncook.c: Remove unnecessary forward declarations.
	* libio/iolibio.h: Correct outdated commentary.
	* malloc/malloc.c (__malloc_stats): Remove unnecessary casts.
	* stdio-common/fxprintf.c (__fxprintf_nocancel):
	Remove unnecessary casts.
	* stdio-common/getline.c: Use _IO_getdelim directly.
	Don't redefine ssize_t.
	* stdio-common/printf_fp.c, stdio_common/printf_fphex.c
	* stdio-common/printf_size.c: Don't redefine size_t or FILE.
	Remove outdated comments.
	* stdio-common/vfscanf.c: Don't redefine va_list.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This patch mechanically removes all remaining uses, and the
definitions, of the following libio name aliases:

 name                         replaced with
 ----                         -------------
 _IO_FILE                     FILE
 _IO_fpos_t                   __fpos_t
 _IO_fpos64_t                 __fpos64_t
 _IO_size_t                   size_t
 _IO_ssize_t                  ssize_t or __ssize_t
 _IO_off_t                    off_t
 _IO_off64_t                  off64_t
 _IO_pid_t                    pid_t
 _IO_uid_t                    uid_t
 _IO_wint_t                   wint_t
 _IO_va_list                  va_list or __gnuc_va_list
 _IO_BUFSIZ                   BUFSIZ
 _IO_cookie_io_functions_t    cookie_io_functions_t
 __io_read_fn                 cookie_read_function_t
 __io_write_fn                cookie_write_function_t
 __io_seek_fn                 cookie_seek_function_t
 __io_close_fn                cookie_close_function_t

I used __fpos_t and __fpos64_t instead of fpos_t and fpos64_t because
the definitions of fpos_t and fpos64_t depend on the largefile mode.
I used __ssize_t and __gnuc_va_list in a handful of headers where
namespace cleanliness might be relevant even though they're
internal-use-only.  In all other cases, I used the public-namespace
name.

There are a tiny handful of places where I left a use of 'struct _IO_FILE'
alone, because it was being used together with 'struct _IO_FILE_plus'
or 'struct _IO_FILE_complete' in the same arithmetic expression.

Because this patch was almost entirely done with search and replace, I
may have introduced indentation botches.  I did proofread the diff,
but I may have missed something.

The ChangeLog below calls out all of the places where this was not a
pure search-and-replace change.

Installed stripped libraries and executables are unchanged by this patch,
except that some assertions in vfscanf.c change line numbers.

	* libio/libio.h (_IO_FILE): Delete; all uses changed to FILE.
	(_IO_fpos_t): Delete; all uses changed to __fpos_t.
	(_IO_fpos64_t): Delete; all uses changed to __fpos64_t.
	(_IO_size_t): Delete; all uses changed to size_t.
	(_IO_ssize_t): Delete; all uses changed to ssize_t or __ssize_t.
	(_IO_off_t): Delete; all uses changed to off_t.
	(_IO_off64_t): Delete; all uses changed to off64_t.
	(_IO_pid_t): Delete; all uses changed to pid_t.
	(_IO_uid_t): Delete; all uses changed to uid_t.
	(_IO_wint_t): Delete; all uses changed to wint_t.
	(_IO_va_list): Delete; all uses changed to va_list or __gnuc_va_list.
	(_IO_BUFSIZ): Delete; all uses changed to BUFSIZ.
	(_IO_cookie_io_functions_t): Delete; all uses changed to
	cookie_io_functions_t.
	(__io_read_fn): Delete; all uses changed to cookie_read_function_t.
	(__io_write_fn): Delete; all uses changed to cookie_write_function_t.
	(__io_seek_fn): Delete; all uses changed to cookie_seek_function_t.
	(__io_close_fn): Delete: all uses changed to cookie_close_function_t.

	* libio/iofopncook.c: Remove unnecessary forward declarations.
	* libio/iolibio.h: Correct outdated commentary.
	* malloc/malloc.c (__malloc_stats): Remove unnecessary casts.
	* stdio-common/fxprintf.c (__fxprintf_nocancel):
	Remove unnecessary casts.
	* stdio-common/getline.c: Use _IO_getdelim directly.
	Don't redefine ssize_t.
	* stdio-common/printf_fp.c, stdio_common/printf_fphex.c
	* stdio-common/printf_size.c: Don't redefine size_t or FILE.
	Remove outdated comments.
	* stdio-common/vfscanf.c: Don't redefine va_list.
</pre>
</div>
</content>
</entry>
</feed>
