Mirror of the gdb-patches mailing list
 help / color / mirror / Atom feed
From: Andrew Burgess <aburgess@redhat.com>
To: gdb-patches@sourceware.org
Cc: Andrew Burgess <aburgess@redhat.com>
Subject: [PATCHv7 3/4] gdb: allow 'until' to work in outermost frame
Date: Sat, 18 Jul 2026 14:11:26 +0100	[thread overview]
Message-ID: <041b5b45868f5e24ea1c84db50f4d9854c146e32.1784380038.git.aburgess@redhat.com> (raw)
In-Reply-To: <cover.1784380038.git.aburgess@redhat.com>

The 'until' command with an argument, e.g. 'until *ADDRESS', is
implemented by until_break_command in breakpoint.c.

The most important thing this function does is convert the location
argument, '*ADDRESS' in my example, into a vector of symtab_and_line
objects.  Each of these symtab_and_line objects is then used to create
a temporary bp_until breakpoint.

The other thing that until_break_command does is create a breakpoint
in the caller frame.  This breakpoint is there to ensure the inferior
stops upon exiting the frame in which the 'until' command was issued,
if the until breakpoint was not hit.

When compiling an assembler file into a static test program, if I use
'starti' to stop the inferior within the outermost frame, and then try
to use 'until *ADDRESS' I see the following error:

  (gdb) starti
  Starting program: /tmp/hello

  Program stopped.
  0x0000000000401000 in _start ()
  (gdb) bt
  #0  0x0000000000401000 in _start ()
  (gdb) until *0x0000000000401015
  Warning:
  Cannot insert breakpoint 0.
  Cannot access memory at address 0x1

  Command aborted.
  (gdb)

The problem here is the breakpoint that 'until' tries to create in the
caller frame.  Though the 'bt' in the above example indicates that
there is only a single frame, the outermost frame, this is only
because GDB has specific code in get_prev_frame to stop the backtrace
at the outermost frame.  If we turn this off and try 'bt' again:

  (gdb) set backtrace past-entry on
  (gdb) bt
  #0  0x0000000000401000 in _start ()
  #1  0x0000000000000001 in ?? ()
  #2  0x00007fffffffac73 in ?? ()
  #3  0x0000000000000000 in ?? ()
  (gdb)

What we are seeing here is the garbage values that happen to be in the
registers tricking GDB into thinking there are frames before _start.

GDB's code to handle this is in get_prev_frame, where we call
inside_entry_func.  This checks if a frame is one of the two possible
entry frames, the inferior entry frame or the executable entry frame.
See the previous commit for more details.  The important thing is that
the inferior entry frame is the absolute outer frame, the very first
frame that the inferior executed when starting, while the executable
entry frame is just the first frame within the main executable.

There are a number of user configurable filters in get_prev_frame, the
backtrace past-main filter, the backtrace frame limit filter, and the
backtrace past-entry filter that we are discussing here.

When creating the caller frame breakpoint, the 'until' command doesn't
use get_prev_frame, it uses frame_unwind_caller_frame, which calls
get_prev_frame_always.  This is so that the user configurable filters
don't prevent the caller frame breakpoint from being created.  But
this means that when creating the breakpoint, we skip the entry frame
check.  As a result, the 'until' command will try to place a
breakpoint in the bogus frame #1 shown above.  As the frame is at
address 0x1, which is non-writable, we see an error when trying to
insert the breakpoint.

In this commit I propose that we add an entry frame check into
frame_unwind_caller_frame, similar to the one found in
get_prev_frame.  However, while get_prev_frame checks for both the
inferior and executable entry frames (see previous commit for details
on the differences), in frame_unwind_caller_frame I think we only need
to check for the inferior entry frame.

My reasoning here is that, in most cases, any frames before the
inferior entry frame are likely to be invalid, and any attempt to
write to them will trigger an error.

In contrast, frames before the executable entry frame sit between
standard libraries entry code and the executable's entry function,
these frames, if GDB can find them, are likely to be valid.

An earlier version of this patch tried placing this check into
get_prev_frame_always, however, if get_prev_frame_always is unable to
unwind a frame then it must set the stop reason on the last frame,
this can be seen in `get_frame_unwind_stop_reason` where the assert
`gdb_assert (frame->prev_p);` will trigger if the previous frame is
not setup correctly.

However, setting the stop reason means the decision about whether
there's a previous frame or not is permanent (at least until the next
frame cache flush), but we need commands like 'bt -past-entry' to
work, which means the choice for whether there's a previous frame or
not needs to remain dynamic.

Placing the check in frame_unwind_caller_frame seemed like the best
solution.  This is the function that is called by other parts of GDB
when they need the caller frame.

The test for this fix ran into an issue where the frame-id for the
outermost frame would change between the first instruction and later
instructions in the frame.  I created bug PR gdb/34245 for this issue.

Bug: https://sourceware.org/bugzilla/show_bug.cgi?id=34245
---
 gdb/frame.c                                   |  72 ++++++--
 gdb/testsuite/gdb.base/until-in-entry-frame.c |  22 +++
 .../gdb.base/until-in-entry-frame.exp         | 173 ++++++++++++++++++
 3 files changed, 253 insertions(+), 14 deletions(-)
 create mode 100644 gdb/testsuite/gdb.base/until-in-entry-frame.c
 create mode 100644 gdb/testsuite/gdb.base/until-in-entry-frame.exp

diff --git a/gdb/frame.c b/gdb/frame.c
index e61bfd8d1f7..caa208c6d42 100644
--- a/gdb/frame.c
+++ b/gdb/frame.c
@@ -734,6 +734,52 @@ get_stack_frame_id (const frame_info_ptr &next_frame)
   return get_frame_id (skip_artificial_frames (next_frame));
 }
 
+/* When checking if a frame is an entry frame, there are two different
+   entry frames to consider.  This enum is used to select which entry
+   frame(s) we wish to consider.  See the inside_entry_func function.  */
+
+enum class entry_address_type_flag
+{
+  /* The executable's entry frame.  This is the first frame within the main
+     executable.  */
+  executable = (1 << 0),
+
+  /* The inferior's entry frame.  This is the first frame within the
+     inferior, this can be outside the main executable, e.g. for a
+     dynamically linked executable, this will be the first frame in the
+     dynamic linker.  */
+  inferior = (1 << 1),
+};
+DEF_ENUM_FLAGS_TYPE (enum entry_address_type_flag, entry_address_type_flags);
+
+/* Return true if THIS_FRAME is inside the either of the possible entry
+   frames based on ENTRY_ADDR_TYPES, otherwise return false.  */
+
+static bool
+inside_entry_func (const frame_info_ptr &this_frame,
+		   entry_address_type_flags entry_addr_types)
+{
+  /* It doesn't make sense to call this with no flag bits set.  */
+  gdb_assert (entry_addr_types != (entry_address_type_flags) 0);
+
+  CORE_ADDR frame_func_addr;
+  if (!get_frame_func_if_available (this_frame, &frame_func_addr))
+    return false;
+
+  const entry_point_info &ep_info
+    = current_program_space->get_entry_point_info ();
+
+  /* For each flag set in ENTRY_ADDR_TYPES if FRAME_FUNC_ADDR matches the
+     corresponding entry address from EP_INFO then THIS_FRAME is an entry
+     frame.  */
+  return (((entry_addr_types & entry_address_type_flag::executable)
+	   == entry_address_type_flag::executable
+	   && ep_info.exec_entry_address () == frame_func_addr)
+	  || ((entry_addr_types & entry_address_type_flag::inferior)
+	      == entry_address_type_flag::inferior
+	      && ep_info.inferior_entry_address () == frame_func_addr));
+}
+
 /* Helper for the various frame_unwind_caller_* functions.  Unwind
    INITIAL_NEXT_FRAME at least one frame, but skip any artificial frames,
    that is inline or tailcall frames.
@@ -744,6 +790,15 @@ get_stack_frame_id (const frame_info_ptr &next_frame)
 static frame_info_ptr
 frame_unwind_caller_frame (const frame_info_ptr &initial_next_frame)
 {
+  /* Avoid returning a frame which is possibly before the inferior's entry
+     frame, any such frame is likely invalid.  However, if the user has
+     turned on 'backtrace past-entry' then we assume they know what they
+     are doing and allow these frames.  */
+  if (!user_set_backtrace_options.backtrace_past_entry
+      && inside_entry_func (initial_next_frame,
+			    entry_address_type_flag::inferior))
+    return nullptr;
+
   frame_info_ptr this_frame = get_prev_frame_always (initial_next_frame);
   if (this_frame == nullptr)
     return nullptr;
@@ -2698,19 +2753,6 @@ inside_main_func (const frame_info_ptr &this_frame)
   return sym_addr == get_frame_func (this_frame);
 }
 
-/* Test whether THIS_FRAME is inside the process entry point function.  */
-
-static bool
-inside_entry_func (const frame_info_ptr &this_frame)
-{
-  const entry_point_info &ep_info
-    = current_program_space->get_entry_point_info ();
-
-  CORE_ADDR frame_func_addr = get_frame_func (this_frame);
-  return (ep_info.exec_entry_address () == frame_func_addr
-	  || ep_info.inferior_entry_address () == frame_func_addr);
-}
-
 /* Return a structure containing various interesting information about
    the frame that called THIS_FRAME.  Returns NULL if there is either
    no such frame or the frame fails any of a set of target-independent
@@ -2793,7 +2835,9 @@ get_prev_frame (const frame_info_ptr &this_frame)
       && get_frame_type (this_frame) == NORMAL_FRAME
       && !user_set_backtrace_options.backtrace_past_entry
       && frame_pc.has_value ()
-      && inside_entry_func (this_frame))
+      && inside_entry_func (this_frame,
+			    (entry_address_type_flag::inferior
+			     | entry_address_type_flag::executable)))
     {
       frame_debug_got_null_frame (this_frame, "inside entry func");
       return NULL;
diff --git a/gdb/testsuite/gdb.base/until-in-entry-frame.c b/gdb/testsuite/gdb.base/until-in-entry-frame.c
new file mode 100644
index 00000000000..6a0e311ef41
--- /dev/null
+++ b/gdb/testsuite/gdb.base/until-in-entry-frame.c
@@ -0,0 +1,22 @@
+/* This testcase is part of GDB, the GNU debugger.
+
+   Copyright 2026 Free Software Foundation, Inc.
+
+   This program is free software; you can redistribute it and/or modify
+   it under the terms of the GNU General Public License as published by
+   the Free Software Foundation; either version 3 of the License, or
+   (at your option) any later version.
+
+   This program is distributed in the hope that it will be useful,
+   but WITHOUT ANY WARRANTY; without even the implied warranty of
+   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+   GNU General Public License for more details.
+
+   You should have received a copy of the GNU General Public License
+   along with this program.  If not, see <http://www.gnu.org/licenses/>.  */
+
+int
+main (void)
+{
+  return 0;
+}
diff --git a/gdb/testsuite/gdb.base/until-in-entry-frame.exp b/gdb/testsuite/gdb.base/until-in-entry-frame.exp
new file mode 100644
index 00000000000..e863c070bd4
--- /dev/null
+++ b/gdb/testsuite/gdb.base/until-in-entry-frame.exp
@@ -0,0 +1,173 @@
+# Copyright 2026 Free Software Foundation, Inc.
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License as published by
+# the Free Software Foundation; either version 3 of the License, or
+# (at your option) any later version.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program.  If not, see <http://www.gnu.org/licenses/>.
+
+# Check that 'until' in the outermost frame works as expected.
+
+standard_testfile
+
+if { [build_executable "failed to build" $testfile $srcfile] } {
+    return
+}
+
+set testfile_static ${testfile}-static
+if { [build_executable "failed to build" $testfile_static $srcfile \
+	  { debug additional_flags=-static } ] } {
+    return
+}
+
+# Use 'frame' to get the name of the current function.  Returns the
+# name of the current function, or the empty string if the current
+# function name cannot be established.
+proc current_function_name { testname } {
+    set func_name ""
+    gdb_test_multiple "frame" $testname {
+	-re -wrap "#0\\s+(?:$::hex in )?(\[^( \]+) \\(.*" {
+	    set func_name $expect_out(1,string)
+	}
+
+	-re -wrap "#0\\s+\[^\r\n\]*\\s+in (\[^( \]+) \\(.*" {
+	    set func_name $expect_out(1,string)
+	}
+    }
+
+    return $func_name
+}
+
+# Start the inferior with 'starti', then use 'until' within the
+# outermost frame.  This is the real outermost frame, not 'main'.
+#
+# PAST_ENTRY should be 'on' or 'off' and is used in a 'set backtrace
+# past-entry ...' command.
+proc run_test { use_stepi past_entry testfile } {
+    clean_restart $testfile
+
+    if {$::use_gdb_stub && [target_info exists gdb,do_reload_on_run]} {
+	# This is the path taken by the 'native-gdbserver' board.
+	# Start gdbserver and connect, this should leave the inferior
+	# at the first instruction.
+	if { [gdb_reload] != 0 } {
+	    return -1
+	}
+	pass "connected to gdbserver"
+    } else {
+	# Start inferior with 'starti' and then wait for a prompt.
+	if { [gdb_starti_cmd] < 0 } {
+	    untested starti
+	    return
+	}
+	gdb_test "" "Program stopped.*" "prompt after starti"
+    }
+
+    set func_name [current_function_name \
+		       "function name for first function"]
+
+    gdb_test_no_output "set backtrace past-entry $past_entry"
+
+    # On x86-64 GDB does get a valid frame-id for the very first
+    # instruction, but from the second instruction onwards it gets
+    # outer_frame_id.  As a result an 'until' setup at the first
+    # instruction doesn't match later on within the same function as
+    # the frame-ids no longer match.
+    #
+    # Try to work around this by issuing a 'stepi' to move to the
+    # second instruction.
+    #
+    # This is only a heuristic though.  On different architectures GDB
+    # might have a valid frame-id for multiple instructions within the
+    # outer frame, or might not have outer_frame_id for all
+    # instructions.
+    #
+    # Also, we need to consider that the very first instruction might
+    # be a control flow instruction, so using stepi could send the
+    # inferior to another function.  We try to spot this case and
+    # perform an early return if that happens.
+    if { $use_stepi } {
+	gdb_test "stepi"
+	set func_name_after [current_function_name \
+				 "function name after stepi"]
+	if { $func_name ne $func_name_after } {
+	    unsupported "stepi moved to another function"
+	    return
+	}
+    }
+
+    # If the 'until' doesn't trigger then stop in 'main' as a backup.
+    gdb_breakpoint main
+
+    # Find an address to use in the 'until' command.
+    set until_address ""
+    set capture_address false
+    gdb_test_multiple "disassemble" "find address for until" -lbl {
+	-re "\r\n=> $::hex \[^\r\n\]+(?=\r\n)" {
+	    set capture_address true
+	    exp_continue
+	}
+
+	-re "\r\n\\s+($::hex) \[^\r\n\]+(?=\r\n)" {
+	    if { $capture_address } {
+		set until_address $expect_out(1,string)
+		set capture_address false
+	    }
+
+	    exp_continue
+	}
+
+	-re "\r\n$::gdb_prompt $" {
+	    set found_address [expr { $until_address ne "" }]
+	    if { !$found_address } {
+		unsupported "$gdb_test_name (no instruction found)"
+		return
+	    }
+	    pass $gdb_test_name
+	}
+    }
+
+    # Send the 'until' command and then wait for GDB to stop.  See the
+    # notes above about the 'stepi' for why we sometimes expect to see
+    # GDB reach 'main' here.
+    send_gdb "until *${until_address}\n"
+    gdb_test_multiple "" "after until" {
+	-re -wrap "Breakpoint $::decimal, (?:\[^\r\n\]+ in )?main \\(\\).*" {
+	    kfail "gdb/34245" "$gdb_test_name (skipped until breakpoint)"
+	}
+
+	-re -wrap "\r\n(?:$::hex in )?$func_name \\(\\).*" {
+	    pass $gdb_test_name
+	}
+
+	-re -wrap "Warning:\r\nCannot insert breakpoint 0\\.\r\nCannot access memory at address $::hex.*Command aborted\\." {
+	    # With PAST_ENTRY 'on', GDB discovers some invalid frames
+	    # past the entry frame based on whatever happens to be in
+	    # the registers when the entry function is called.  These
+	    # invalid frames are often non-writable, so GDB will fail
+	    # to insert the breakpoint when the inferior resumes.
+	    #
+	    # We still count this as a pass though; the user should
+	    # only turn on 'backtrace past-entry' when they know that
+	    # is needed, so failure here is totally expected.
+	    gdb_assert { $past_entry eq "on" } "$gdb_test_name (caller breakpoint failed)"
+	}
+    }
+}
+
+foreach_with_prefix past_entry { off on } {
+    foreach_with_prefix use_stepi { true false } {
+	run_test $use_stepi $past_entry $testfile
+
+	with_test_prefix "static" {
+	    run_test $use_stepi $past_entry $testfile_static
+	}
+    }
+}
-- 
2.25.4


  parent reply	other threads:[~2026-07-18 13:13 UTC|newest]

Thread overview: 54+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-06-08 18:14 [PATCH] " Andrew Burgess
2026-06-11 19:24 ` Guinevere Larsen
2026-06-11 20:40   ` Andrew Burgess
2026-06-12 12:49     ` Guinevere Larsen
2026-06-11 21:59 ` [PATCHv2 0/3] " Andrew Burgess
2026-06-11 21:59   ` [PATCHv2 1/3] gdb: rename program_space::entry_point_address* functions Andrew Burgess
2026-06-12 15:41     ` Pedro Alves
2026-06-11 21:59   ` [PATCHv2 2/3] gdb: introduce program_space::get_entry_point_info function Andrew Burgess
2026-06-12  6:07     ` Eli Zaretskii
2026-06-15 10:14       ` Andrew Burgess
2026-06-15 12:01         ` Eli Zaretskii
2026-06-12 15:41     ` Pedro Alves
2026-06-15 10:29       ` Andrew Burgess
2026-06-16 18:36         ` Pedro Alves
2026-06-23  9:46           ` Andrew Burgess
2026-06-23 10:20             ` Pedro Alves
2026-06-11 21:59   ` [PATCHv2 3/3] gdb: allow 'until' to work in outermost frame Andrew Burgess
2026-06-12 15:57     ` Pedro Alves
2026-06-16 19:47   ` [PATCHv3 0/4] " Andrew Burgess
2026-06-16 19:47     ` [PATCHv3 1/4] gdb: rename program_space::entry_point_address* functions Andrew Burgess
2026-06-16 19:47     ` [PATCHv3 2/4] gdb: introduce program_space::get_entry_point_info function Andrew Burgess
2026-06-17 11:52       ` Eli Zaretskii
2026-06-16 19:47     ` [PATCHv3 3/4] gdb: allow 'until' to work in outermost frame Andrew Burgess
2026-06-16 19:47     ` [PATCHv3 4/4] gdb: cache program space entry point information Andrew Burgess
2026-06-23 10:47     ` [PATCHv4 0/4] gdb: allow 'until' to work in outermost frame Andrew Burgess
2026-06-23 10:47       ` [PATCHv4 1/4] gdb: rename program_space::entry_point_address* functions Andrew Burgess
2026-06-23 10:47       ` [PATCHv4 2/4] gdb: introduce program_space::get_entry_point_info function Andrew Burgess
2026-06-23 10:47       ` [PATCHv4 3/4] gdb: allow 'until' to work in outermost frame Andrew Burgess
2026-06-23 10:47       ` [PATCHv4 4/4] gdb: cache program space entry point information Andrew Burgess
2026-06-25 15:26       ` [PATCHv5 0/4] gdb: allow 'until' to work in outermost frame Andrew Burgess
2026-06-25 15:26         ` [PATCHv5 1/4] gdb: rename program_space::entry_point_address* functions Andrew Burgess
2026-06-25 15:26         ` [PATCHv5 2/4] gdb: introduce program_space::get_entry_point_info function Andrew Burgess
2026-06-25 15:26         ` [PATCHv5 3/4] gdb: allow 'until' to work in outermost frame Andrew Burgess
2026-06-25 15:26         ` [PATCHv5 4/4] gdb: cache program space entry point information Andrew Burgess
2026-07-10 14:24         ` [PATCHv6 0/4] gdb: allow 'until' to work in outermost frame Andrew Burgess
2026-07-10 14:24           ` [PATCHv6 1/4] gdb: rename program_space::entry_point_address* functions Andrew Burgess
2026-07-10 14:24           ` [PATCHv6 2/4] gdb: introduce program_space::get_entry_point_info function Andrew Burgess
2026-07-10 15:39             ` Simon Marchi
2026-07-10 14:24           ` [PATCHv6 3/4] gdb: allow 'until' to work in outermost frame Andrew Burgess
2026-07-10 17:00             ` Simon Marchi
2026-07-10 17:01               ` Simon Marchi
2026-07-16 15:06               ` Andrew Burgess
2026-07-10 14:24           ` [PATCHv6 4/4] gdb: cache program space entry point information Andrew Burgess
2026-07-10 17:07             ` Simon Marchi
2026-07-18 13:11           ` [PATCHv7 0/4] gdb: allow 'until' to work in outermost frame Andrew Burgess
2026-07-18 13:11             ` [PATCHv7 1/4] gdb: rename program_space::entry_point_address* functions Andrew Burgess
2026-07-18 13:11             ` [PATCHv7 2/4] gdb: introduce program_space::get_entry_point_info function Andrew Burgess
2026-07-18 13:11             ` Andrew Burgess [this message]
2026-07-18 13:11             ` [PATCHv7 4/4] gdb: cache program space entry point information Andrew Burgess
2026-07-20  9:52             ` [PATCHv8 0/4] gdb: allow 'until' to work in outermost frame Andrew Burgess
2026-07-20  9:52               ` [PATCHv8 1/4] gdb: rename program_space::entry_point_address* functions Andrew Burgess
2026-07-20  9:52               ` [PATCHv8 2/4] gdb: introduce program_space::get_entry_point_info function Andrew Burgess
2026-07-20  9:52               ` [PATCHv8 3/4] gdb: allow 'until' to work in outermost frame Andrew Burgess
2026-07-20  9:52               ` [PATCHv8 4/4] gdb: cache program space entry point information Andrew Burgess

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=041b5b45868f5e24ea1c84db50f4d9854c146e32.1784380038.git.aburgess@redhat.com \
    --to=aburgess@redhat.com \
    --cc=gdb-patches@sourceware.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox