From: Alan Hayward <alan.hayward@arm.com>
To: gdb-patches@sourceware.org
Cc: nd@arm.com, Alan Hayward <alan.hayward@arm.com>
Subject: [PATCH v3 3/3] Aarch64: Fix segfault when casting dummy calls
Date: Thu, 11 Oct 2018 14:49:00 -0000 [thread overview]
Message-ID: <20181011144905.66908-4-alan.hayward@arm.com> (raw)
In-Reply-To: <20181011144905.66908-1-alan.hayward@arm.com>
Prevent the following causing a segfault on aarch64:
(gdb) b foo if (int)strcmp(name,"abc") == 0
(gdb) run
This is because to aarch64_push_dummy_call determines the return type
of the function and then does not check for null pointer.
A null pointer for the return type means the call has no debug
information. For the code to get here, then either there has been an
error or the call has been cast - but we do not have this information
available.
In addition, aarch64_push_dummy_call does not check if the function is
an IFUNC.
However, aarch64_push_dummy_call only requires the return value in order
to calculate lang_struct_return. This information is available in the
return_method enum. The fix is to simply use this instead.
Add common test case using a shared library to ensure FUNC resolving.
gdb/ChangeLog:
2018-10-11 Alan Hayward <alan.hayward@arm.com>
PR gdb/22736:
* aarch64-tdep.c (aarch64_push_dummy_call): Remove
lang_struct_return code.
gdb/testsuite/ChangeLog:
2018-10-11 Alan Hayward <alan.hayward@arm.com>
PR gdb/22736:
* gdb.base/condbreak-solib-lib.cc: New test.
* gdb.base/condbreak-solib-main.cc: New test.
* gdb.base/condbreak-solib.exp: New file.
---
gdb/aarch64-tdep.c | 30 +---
gdb/testsuite/gdb.base/condbreak-solib-lib.cc | 22 +++
.../gdb.base/condbreak-solib-main.cc | 39 +++++
gdb/testsuite/gdb.base/condbreak-solib.exp | 136 ++++++++++++++++++
4 files changed, 200 insertions(+), 27 deletions(-)
create mode 100644 gdb/testsuite/gdb.base/condbreak-solib-lib.cc
create mode 100644 gdb/testsuite/gdb.base/condbreak-solib-main.cc
create mode 100644 gdb/testsuite/gdb.base/condbreak-solib.exp
diff --git a/gdb/aarch64-tdep.c b/gdb/aarch64-tdep.c
index 63771dc21d..e541e45f61 100644
--- a/gdb/aarch64-tdep.c
+++ b/gdb/aarch64-tdep.c
@@ -1519,9 +1519,6 @@ aarch64_push_dummy_call (struct gdbarch *gdbarch, struct value *function,
{
int argnum;
struct aarch64_call_info info;
- struct type *func_type;
- struct type *return_type;
- int lang_struct_return;
memset (&info, 0, sizeof (info));
@@ -1543,35 +1540,14 @@ aarch64_push_dummy_call (struct gdbarch *gdbarch, struct value *function,
If the language code decides to pass in memory we want to move
the pointer inserted as the initial argument from the argument
list and into X8, the conventional AArch64 struct return pointer
- register.
-
- This is slightly awkward, ideally the flag "lang_struct_return"
- would be passed to the targets implementation of push_dummy_call.
- Rather that change the target interface we call the language code
- directly ourselves. */
-
- func_type = check_typedef (value_type (function));
-
- /* Dereference function pointer types. */
- if (TYPE_CODE (func_type) == TYPE_CODE_PTR)
- func_type = TYPE_TARGET_TYPE (func_type);
-
- gdb_assert (TYPE_CODE (func_type) == TYPE_CODE_FUNC
- || TYPE_CODE (func_type) == TYPE_CODE_METHOD);
-
- /* If language_pass_by_reference () returned true we will have been
- given an additional initial argument, a hidden pointer to the
- return slot in memory. */
- return_type = TYPE_TARGET_TYPE (func_type);
- lang_struct_return = language_pass_by_reference (return_type);
+ register. */
/* Set the return address. For the AArch64, the return breakpoint
is always at BP_ADDR. */
regcache_cooked_write_unsigned (regcache, AARCH64_LR_REGNUM, bp_addr);
- /* If we were given an initial argument for the return slot because
- lang_struct_return was true, lose it. */
- if (lang_struct_return)
+ /* If we were given an initial argument for the return slot, lose it. */
+ if (return_method == return_method_hidden_param)
{
args++;
nargs--;
diff --git a/gdb/testsuite/gdb.base/condbreak-solib-lib.cc b/gdb/testsuite/gdb.base/condbreak-solib-lib.cc
new file mode 100644
index 0000000000..96dfe2182e
--- /dev/null
+++ b/gdb/testsuite/gdb.base/condbreak-solib-lib.cc
@@ -0,0 +1,22 @@
+/* This testcase is part of GDB, the GNU debugger.
+
+ Copyright 2018 Free Software Foundation, Inc.
+
+ This program is free software; you can redistribute it and/or modify
+ it under the terms of the GNU General Public License as published by
+ the Free Software Foundation; either version 3 of the License, or
+ (at your option) any later version.
+
+ This program is distributed in the hope that it will be useful,
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ GNU General Public License for more details.
+
+ You should have received a copy of the GNU General Public License
+ along with this program. If not, see <http://www.gnu.org/licenses/>. */
+
+int
+cmp3 (char *name)
+{
+ return name[0] == '3';
+}
diff --git a/gdb/testsuite/gdb.base/condbreak-solib-main.cc b/gdb/testsuite/gdb.base/condbreak-solib-main.cc
new file mode 100644
index 0000000000..10f2e4d474
--- /dev/null
+++ b/gdb/testsuite/gdb.base/condbreak-solib-main.cc
@@ -0,0 +1,39 @@
+/* This testcase is part of GDB, the GNU debugger.
+
+ Copyright 2018 Free Software Foundation, Inc.
+
+ This program is free software; you can redistribute it and/or modify
+ it under the terms of the GNU General Public License as published by
+ the Free Software Foundation; either version 3 of the License, or
+ (at your option) any later version.
+
+ This program is distributed in the hope that it will be useful,
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ GNU General Public License for more details.
+
+ You should have received a copy of the GNU General Public License
+ along with this program. If not, see <http://www.gnu.org/licenses/>. */
+
+extern int cmp3 (char *name);
+
+const char *word = "stuff";
+
+int
+foo ()
+{
+ return 1;
+}
+
+int
+bar ()
+{
+ return 1;
+}
+
+int
+main (void)
+{
+ foo ();
+ bar ();
+}
diff --git a/gdb/testsuite/gdb.base/condbreak-solib.exp b/gdb/testsuite/gdb.base/condbreak-solib.exp
new file mode 100644
index 0000000000..38169ff81a
--- /dev/null
+++ b/gdb/testsuite/gdb.base/condbreak-solib.exp
@@ -0,0 +1,136 @@
+# This testcase is part of GDB, the GNU debugger.
+# Copyright 2018 Free Software Foundation, Inc.
+
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License as published by
+# the Free Software Foundation; either version 3 of the License, or
+# (at your option) any later version.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program. If not, see <http://www.gnu.org/licenses/>.
+
+# Test conditional breakpoints on functions in shared libraries.
+# See gdb/22736
+
+if { [skip_cplus_tests] || [skip_shlib_tests] } {
+ return 0
+}
+
+global target_size
+set target_size TARGET_UNKNOWN
+if {[is_lp64_target]} {
+ set target_size TARGET_LP64
+} elseif {[is_ilp32_target]} {
+ set target_size TARGET_ILP32
+} else {
+ return 0
+}
+
+set main_basename condbreak-solib-main
+set lib_basename condbreak-solib-lib
+standard_testfile $main_basename.cc $lib_basename.cc
+
+if [get_compiler_info "c++"] {
+ return -1
+}
+
+set libsrc "${srcdir}/${subdir}/${srcfile2}"
+
+
+# Run to main. Set breakpoint at bar. Set conditional breakpoint CBREAK.
+# Continue running. Test that program stops at function STOP, prefixed
+# with the text PREFIX.
+
+proc break_and_run { cbreak stop prefix} {
+
+ if ![runto_main] then {
+ fail "can't run to main"
+ return
+ }
+
+ with_test_prefix $cbreak {
+ gdb_test "b bar" "Breakpoint .*"
+ gdb_test "b $cbreak" "Breakpoint .*"
+ gdb_test "c" ".*${prefix}.*Breakpoint .* $stop .*"
+ }
+}
+
+# Compile binary linked against shared library containing cmp3, using TYPE
+# to build the library as either DEBUG or NODEBUG. Then test conditional
+# breakpoints that make a call into the library.
+
+proc cond_break_test { type } {
+
+ global srcdir subdir srcfile srcfile2 binfile testfile
+ global target_size main_basename lib_basename libsrc
+
+ switch -regexp -- $type {
+ "^debug" {
+ set dir "debug"
+ set debug_flags "debug"
+ }
+ "^nodebug" {
+ set dir "nodebug"
+ set debug_flags ""
+ }
+ }
+
+ remote_exec build "rm -rf [standard_output_file ${dir}]"
+ remote_exec build "mkdir [standard_output_file ${dir}]"
+
+ set lib_so [standard_output_file ${dir}/${lib_basename}.so]
+ set lib_syms [shlib_symbol_file ${dir}/${lib_so}]
+ set binfile [standard_output_file ${dir}/${testfile}]
+
+ # Compile a shared library containing cmp3.
+
+ set lib_flags "c++ ldflags=-Wl,-Bsymbolic $debug_flags"
+
+ if {[gdb_compile_shlib $libsrc $lib_so ${lib_flags}] != ""} {
+ untested "failed to compile shared library"
+ return -1
+ }
+
+ # Compile the main test linked against the shared library.
+
+ set bin_flags "debug shlib=${lib_so}"
+
+ if { [gdb_compile $srcdir/$subdir/${srcfile} ${binfile} executable ${bin_flags}] != "" } {
+ untested "failed to compile"
+ return -1
+ }
+
+ clean_restart $binfile
+
+ with_test_prefix $type {
+
+ # Conditional break with casted function call that fails the condition.
+ break_and_run "foo if (int)cmp3(\"abc\") == 1" "bar" "Continuing.\r\n\r\n"
+
+ # Conditional break with casted function call that passes the condition.
+ break_and_run "foo if (int)cmp3(\"345\") == 1" "foo" "Continuing.\r\n\r\n"
+
+ # Conditional break with function call (no cast).
+ switch -regexp -- $type {
+ "^debug" {
+ #Same results as conditional break with casted function.
+ break_and_run "foo if cmp3(\"abc\") == 1" "bar" "Continuing.\r\n\r\n"
+ break_and_run "foo if cmp3(\"345\") == 1" "foo" "Continuing.\r\n\r\n"
+ }
+ "^nodebug" {
+ #Call will error due to lack of debug information, causing the condition to pass.
+ break_and_run "foo if cmp3(\"abc\") == 1" "foo" "Continuing.\r\nError in testing breakpoint condition"
+ break_and_run "foo if cmp3(\"345\") == 1" "foo" "Continuing.\r\nError in testing breakpoint condition"
+ }
+ }
+ }
+}
+
+cond_break_test debug
+cond_break_test nodebug
+
--
2.17.1 (Apple Git-112)
next prev parent reply other threads:[~2018-10-11 14:49 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-10-11 14:49 [PATCH v3 0/3] " Alan Hayward
2018-10-11 14:49 ` Alan Hayward [this message]
2018-10-19 11:36 ` [PATCH v3 3/3] " Pedro Alves
2018-10-23 16:08 ` Alan Hayward
2018-10-24 15:15 ` Pedro Alves
2018-10-29 11:58 ` Alan Hayward
[not found] ` <862cf8f4-9491-a1eb-251e-6c7c1ffffa6c@redhat.com>
2018-10-29 14:56 ` Alan Hayward
2018-10-29 18:13 ` Pedro Alves
2018-10-30 11:13 ` Alan Hayward
2018-10-30 16:31 ` Pedro Alves
2018-10-30 17:09 ` Alan Hayward
2018-10-30 17:40 ` Pedro Alves
2018-10-11 14:49 ` [PATCH v3 1/3] Use enum for return method for " Alan Hayward
2018-10-19 11:28 ` Pedro Alves
2018-10-11 14:49 ` [PATCH v3 2/3] Pass return_method to _push_dummy_call Alan Hayward
2018-10-19 11:31 ` Pedro Alves
2018-10-18 9:50 ` [PING][PATCH v3 0/3] Aarch64: Fix segfault when casting dummy calls Alan Hayward
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20181011144905.66908-4-alan.hayward@arm.com \
--to=alan.hayward@arm.com \
--cc=gdb-patches@sourceware.org \
--cc=nd@arm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox