Mirror of the gdb-patches mailing list
 help / color / mirror / Atom feed
* [rfa/gdbserver] Fix crash in thread_db_get_tls_address
@ 2009-01-21 22:57 Ulrich Weigand
  2009-01-22  9:18 ` Doug Evans
  0 siblings, 1 reply; 10+ messages in thread
From: Ulrich Weigand @ 2009-01-21 22:57 UTC (permalink / raw)
  To: gdb-patches; +Cc: drow

Hello,

when debugging remotely using a GDB with private modifcations, I'm running
into a crash in gdbserver, which I believe to be a real bug (even if latent
with mainline GDB).

The problem occurs when the thread_db_get_tls_address routine is invoked
(as a result of processing a qGetTLSAddr: query) on an inferior that
actually has no threads (or where the thread layer is not initialized yet).

This is caused by thread_db_get_tls_address calling find_one_thread,
which in the end calls down into the libthread_db td_ta_map_lwp2thr
routine -- at a time libthread_db is not yet initialized, and in fact
the "thread_agent" handle passed to td_ta_map_lwp2thr was not yet
set up.  This results in a segfault within libthread_db.

Now I guess it is debatable whether or not sending a qGetTLSAddr:
query in this situation is a useful thing, but it seems to me that
gdbserver shouldn't just *crash* ...

The following patch fixes this by returning failure from
thread_db_get_tls_address if called before the thread layer
is properly initialized.


Tested on powerpc64-linux (64-bit / 32-bit) using local gdbserver.

OK for mainline?

Bye,
Ulrich


ChangeLog:

	* thread-db.c (thread_db_get_tls_address): Do not crash if
	called when thread layer is not yet initialized.


Index: src/gdb/gdbserver/thread-db.c
===================================================================
--- src.orig/gdb/gdbserver/thread-db.c
+++ src/gdb/gdbserver/thread-db.c
@@ -388,6 +388,10 @@ thread_db_get_tls_address (struct thread
   td_err_e err;
   struct process_info *process;
 
+  /* If the thread layer is not (yet) initialized, fail.  */
+  if (!all_symbols_looked_up)
+    return -1;
+
   process = get_thread_process (thread);
   if (!process->thread_known)
     find_one_thread (process->lwpid);
-- 
  Dr. Ulrich Weigand
  GNU Toolchain for Linux on System z and Cell BE
  Ulrich.Weigand@de.ibm.com


^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2009-04-03 20:17 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2009-01-21 22:57 [rfa/gdbserver] Fix crash in thread_db_get_tls_address Ulrich Weigand
2009-01-22  9:18 ` Doug Evans
2009-01-22 15:06   ` Ulrich Weigand
2009-01-23  1:08     ` Doug Evans
2009-04-03 18:07       ` [rfa/gdbserver] Updated: " Ulrich Weigand
2009-04-03 18:26         ` Pedro Alves
2009-04-03 19:20           ` Ulrich Weigand
2009-04-03 19:24             ` Pedro Alves
2009-04-03 20:17               ` Ulrich Weigand
2009-04-03 18:29         ` Daniel Jacobowitz

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox