* [PATCH v3 0/2] gdb: Fix internal inferior calls through GNU IFUNCs
@ 2026-06-29 15:32 Muhammad Kamran
2026-06-29 15:32 ` [PATCH v3 1/2] gdb: Preserve IFUNC marker when finding inferior functions Muhammad Kamran
2026-06-29 15:32 ` [PATCH v3 2/2] gdb: Keep original IFUNC return type when target type is unknown Muhammad Kamran
0 siblings, 2 replies; 3+ messages in thread
From: Muhammad Kamran @ 2026-06-29 15:32 UTC (permalink / raw)
To: gdb-patches
Cc: Simon Marchi, Andrew Burgess, Wilco Dijkstra, Yury Khrustalev,
Thiago Jung Bauermann, Adhemerval Zanella Netto,
Carlos O'Donell, Muhammad Kamran
This series fixes a GDB inferior-call issue exposed by malloc being a GNU
IFUNC in glibc on AArch64. The underlying problem is not AArch64-specific:
it can affect any inferior helper found through find_function_in_inferior's
minimal-symbol fallback when that helper is a GNU IFUNC.
GDB calls find_function_in_inferior ("malloc") when expression evaluation
needs to allocate memory in the inferior, for example for string literal
arguments. In the minimal-symbol fallback, GDB created a synthetic ordinary
function pointer from the minimal symbol address. If the symbol was a GNU
IFUNC, this lost the IFUNC marker, so call_function_by_hand did not resolve
the symbol before calling it.
Patch 1 checks the minimal symbol kind directly and propagates the GNU IFUNC
marker to the synthetic function type for mst_text_gnu_ifunc and
mst_data_gnu_ifunc symbols. The existing fallback address and return type
are unchanged.
Patch 2 fixes the follow-on return-type issue after IFUNC resolution. When
the resolved target type, or the type inferred from the resolver return type,
does not provide a usable return type, find_function_addr now keeps the
original function type's return type. This preserves the synthetic fallback
return type used by find_function_in_inferior ("malloc").
The tests add an internal inferior-call case using an IFUNC malloc and run it
through the existing gdb.base/gnu-ifunc.exp matrix for resolver attr,
resolver debug info, and resolved-target debug info.
Changes since v2:
* Rework the minimal-symbol fallback to check the minimal symbol kind
directly as suggested by Simon.
* Add coverage for both debug and no-debug IFUNC malloc variants by
using the existing framework.
* Preserve the original IFUNC return type when the resolved target type
is unknown.
Muhammad Kamran (2):
gdb: Preserve IFUNC marker when finding inferior functions
gdb: Keep original IFUNC return type when target type is unknown
gdb/infcall.c | 12 +++-
.../gdb.base/gnu-ifunc-inferior-call-final.c | 27 ++++++++
.../gnu-ifunc-inferior-call-resolver.c | 43 +++++++++++++
.../gdb.base/gnu-ifunc-inferior-call.c | 37 +++++++++++
gdb/testsuite/gdb.base/gnu-ifunc.exp | 61 +++++++++++++++++++
gdb/valops.c | 5 ++
6 files changed, 183 insertions(+), 2 deletions(-)
create mode 100644 gdb/testsuite/gdb.base/gnu-ifunc-inferior-call-final.c
create mode 100644 gdb/testsuite/gdb.base/gnu-ifunc-inferior-call-resolver.c
create mode 100644 gdb/testsuite/gdb.base/gnu-ifunc-inferior-call.c
--
2.43.0
^ permalink raw reply [flat|nested] 3+ messages in thread
* [PATCH v3 1/2] gdb: Preserve IFUNC marker when finding inferior functions
2026-06-29 15:32 [PATCH v3 0/2] gdb: Fix internal inferior calls through GNU IFUNCs Muhammad Kamran
@ 2026-06-29 15:32 ` Muhammad Kamran
2026-06-29 15:32 ` [PATCH v3 2/2] gdb: Keep original IFUNC return type when target type is unknown Muhammad Kamran
1 sibling, 0 replies; 3+ messages in thread
From: Muhammad Kamran @ 2026-06-29 15:32 UTC (permalink / raw)
To: gdb-patches
Cc: Simon Marchi, Andrew Burgess, Wilco Dijkstra, Yury Khrustalev,
Thiago Jung Bauermann, Adhemerval Zanella Netto,
Carlos O'Donell, Muhammad Kamran
GDB calls find_function_in_inferior ("malloc") when expression
evaluation needs to allocate memory in the inferior, e.g. for string
literal arguments.
The minimal-symbol fallback created a synthetic ordinary function
pointer from msymbol.value_address (). If the symbol was a GNU IFUNC,
this discarded the IFUNC marker, so call_function_by_hand did not
resolve the symbol before calling it.
Check the minimal symbol kind directly and propagate the GNU IFUNC
marker to the synthetic function type for mst_text_gnu_ifunc and
mst_data_gnu_ifunc symbols. This keeps the existing fallback address
and return type while allowing inferior calls through IFUNC symbols to
be resolved correctly.
Extend gdb.base/gnu-ifunc.exp with an internal inferior-call test that
uses an IFUNC malloc. The test runs through the existing IFUNC matrix
for resolver attr, resolver debug info, and resolved-target debug
info.
---
.../gdb.base/gnu-ifunc-inferior-call-final.c | 27 ++++++++
.../gnu-ifunc-inferior-call-resolver.c | 43 ++++++++++++
.../gdb.base/gnu-ifunc-inferior-call.c | 37 ++++++++++
gdb/testsuite/gdb.base/gnu-ifunc.exp | 68 +++++++++++++++++++
gdb/valops.c | 5 ++
5 files changed, 180 insertions(+)
create mode 100644 gdb/testsuite/gdb.base/gnu-ifunc-inferior-call-final.c
create mode 100644 gdb/testsuite/gdb.base/gnu-ifunc-inferior-call-resolver.c
create mode 100644 gdb/testsuite/gdb.base/gnu-ifunc-inferior-call.c
diff --git a/gdb/testsuite/gdb.base/gnu-ifunc-inferior-call-final.c b/gdb/testsuite/gdb.base/gnu-ifunc-inferior-call-final.c
new file mode 100644
index 00000000000..1a9ae6fdcba
--- /dev/null
+++ b/gdb/testsuite/gdb.base/gnu-ifunc-inferior-call-final.c
@@ -0,0 +1,27 @@
+/* This testcase is part of GDB, the GNU debugger.
+
+ Copyright 2026 Free Software Foundation, Inc.
+
+ This program is free software; you can redistribute it and/or modify
+ it under the terms of the GNU General Public License as published by
+ the Free Software Foundation; either version 3 of the License, or
+ (at your option) any later version.
+
+ This program is distributed in the hope that it will be useful,
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ GNU General Public License for more details.
+
+ You should have received a copy of the GNU General Public License
+ along with this program. If not, see <http://www.gnu.org/licenses/>. */
+
+#include <stddef.h>
+
+extern char arena[32];
+
+void *
+dummy_malloc (size_t size)
+{
+ (void) size;
+ return arena;
+}
diff --git a/gdb/testsuite/gdb.base/gnu-ifunc-inferior-call-resolver.c b/gdb/testsuite/gdb.base/gnu-ifunc-inferior-call-resolver.c
new file mode 100644
index 00000000000..217002968de
--- /dev/null
+++ b/gdb/testsuite/gdb.base/gnu-ifunc-inferior-call-resolver.c
@@ -0,0 +1,43 @@
+/* This testcase is part of GDB, the GNU debugger.
+
+ Copyright 2026 Free Software Foundation, Inc.
+
+ This program is free software; you can redistribute it and/or modify
+ it under the terms of the GNU General Public License as published by
+ the Free Software Foundation; either version 3 of the License, or
+ (at your option) any later version.
+
+ This program is distributed in the hope that it will be useful,
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ GNU General Public License for more details.
+
+ You should have received a copy of the GNU General Public License
+ along with this program. If not, see <http://www.gnu.org/licenses/>. */
+
+#include <stddef.h>
+
+extern void *dummy_malloc (size_t size);
+
+typedef void *(*malloc_t) (size_t size);
+
+#ifndef IFUNC_RESOLVER_ATTR
+asm (".type malloc, %gnu_indirect_function");
+malloc_t
+malloc (unsigned long hwcap)
+#else
+static malloc_t
+resolve_malloc (void)
+#endif
+{
+#ifndef IFUNC_RESOLVER_ATTR
+ (void) hwcap;
+#endif
+ return dummy_malloc;
+}
+
+#ifdef IFUNC_RESOLVER_ATTR
+extern void *malloc (size_t size);
+
+__typeof (malloc) malloc __attribute__ ((ifunc ("resolve_malloc")));
+#endif
diff --git a/gdb/testsuite/gdb.base/gnu-ifunc-inferior-call.c b/gdb/testsuite/gdb.base/gnu-ifunc-inferior-call.c
new file mode 100644
index 00000000000..67d195d25f0
--- /dev/null
+++ b/gdb/testsuite/gdb.base/gnu-ifunc-inferior-call.c
@@ -0,0 +1,37 @@
+/* This testcase is part of GDB, the GNU debugger.
+
+ Copyright 2026 Free Software Foundation, Inc.
+
+ This program is free software; you can redistribute it and/or modify
+ it under the terms of the GNU General Public License as published by
+ the Free Software Foundation; either version 3 of the License, or
+ (at your option) any later version.
+
+ This program is distributed in the hope that it will be useful,
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ GNU General Public License for more details.
+
+ You should have received a copy of the GNU General Public License
+ along with this program. If not, see <http://www.gnu.org/licenses/>. */
+
+char arena[32];
+const char *str;
+
+int
+str_in_arena (void)
+{
+ return str == arena;
+}
+
+void
+get_string (const char *s)
+{
+ str = s;
+}
+
+int
+main (void)
+{
+ return 0;
+}
diff --git a/gdb/testsuite/gdb.base/gnu-ifunc.exp b/gdb/testsuite/gdb.base/gnu-ifunc.exp
index e6389102ae3..e2626b9cc0c 100644
--- a/gdb/testsuite/gdb.base/gnu-ifunc.exp
+++ b/gdb/testsuite/gdb.base/gnu-ifunc.exp
@@ -25,6 +25,13 @@ set libsrc ${libfile}.c
set final_file "${testfile}-final"
set final_src ${final_file}.c
+set infcall_file "${testfile}-inferior-call"
+set infcall_src ${infcall_file}.c
+set infcall_resolver_file "${testfile}-inferior-call-resolver"
+set infcall_resolver_src ${infcall_resolver_file}.c
+set infcall_final_file "${testfile}-inferior-call-final"
+set infcall_final_src ${infcall_final_file}.c
+
# Return the binary suffix appended to program and library names to
# make each testcase variant unique.
proc make_binsuffix {resolver_attr resolver_debug final_debug} {
@@ -356,6 +363,66 @@ proc misc_tests {resolver_attr resolver_debug final_debug} {
}
}
+# Test that GDB resolves a GNU IFUNC minimal symbol when it uses
+# find_function_in_inferior to make an internal inferior call. String
+# literals are copied into the inferior with a call to malloc, so an
+# IFUNC malloc exercises this path.
+
+proc_with_prefix test_inferior_call {resolver_attr resolver_debug final_debug} {
+ global srcdir subdir
+ global infcall_file infcall_src
+ global infcall_resolver_file infcall_resolver_src
+ global infcall_final_file infcall_final_src
+
+ set suffix [make_binsuffix $resolver_attr $resolver_debug $final_debug]
+ set executable ${infcall_file}-$suffix
+ set binfile [standard_output_file $executable]
+ set resolver_obj [standard_output_file ${infcall_resolver_file}-$suffix.o]
+ set final_obj [standard_output_file ${infcall_final_file}-$suffix.o]
+
+ set resolver_opts {additional_flags=-fno-builtin-malloc}
+ set final_opts {}
+
+ if {$resolver_attr} {
+ lappend resolver_opts "additional_flags=-DIFUNC_RESOLVER_ATTR"
+ }
+
+ if {$resolver_debug} {
+ lappend resolver_opts "debug"
+ }
+
+ if {$final_debug} {
+ lappend final_opts "debug"
+ }
+
+ if { [gdb_compile ${srcdir}/${subdir}/${infcall_resolver_src} \
+ $resolver_obj object $resolver_opts] != ""
+ || [gdb_compile ${srcdir}/${subdir}/${infcall_final_src} \
+ $final_obj object $final_opts] != ""
+ || [gdb_compile [list ${srcdir}/${subdir}/${infcall_src} \
+ $resolver_obj $final_obj] \
+ $binfile executable {debug}] != "" } {
+ untested "failed to compile inferior call testcase"
+ return
+ }
+
+ clean_restart $executable
+ if {![runto_main]} {
+ return
+ }
+
+ # Without debug info for both the resolver and the resolved target,
+ # find_function_addr currently loses the synthetic return type after
+ # resolving the IFUNC.
+ if {!$resolver_debug && !$final_debug} {
+ unsupported "internal call resolves IFUNC malloc"
+ return
+ }
+ gdb_test "print (get_string (\"hello-ifunc\"), str_in_arena ())" \
+ " = 1" \
+ "internal call resolves IFUNC malloc"
+}
+
# Test all the combinations of:
#
# - An ifunc resolver with the same name as the ifunc symbol vs an
@@ -374,6 +441,7 @@ foreach_with_prefix resolver_attr {0 1} {
if { [build $resolver_attr $resolver_debug $final_debug] != 0 } {
misc_tests $resolver_attr $resolver_debug $final_debug
set-break $resolver_attr $resolver_debug $final_debug
+ test_inferior_call $resolver_attr $resolver_debug $final_debug
}
}
}
diff --git a/gdb/valops.c b/gdb/valops.c
index ab6fd5079e1..454f093ab68 100644
--- a/gdb/valops.c
+++ b/gdb/valops.c
@@ -138,6 +138,11 @@ find_function_in_inferior (const char *name, struct objfile **objf_p)
type = lookup_function_type (type);
type = lookup_pointer_type (type);
maddr = msymbol.value_address ();
+ minimal_symbol_type minsym_type = msymbol.minsym->type ();
+
+ if (minsym_type == mst_text_gnu_ifunc
+ || minsym_type == mst_data_gnu_ifunc)
+ type->target_type ()->set_is_gnu_ifunc (true);
if (objf_p)
*objf_p = objfile;
--
2.43.0
^ permalink raw reply [flat|nested] 3+ messages in thread
* [PATCH v3 2/2] gdb: Keep original IFUNC return type when target type is unknown
2026-06-29 15:32 [PATCH v3 0/2] gdb: Fix internal inferior calls through GNU IFUNCs Muhammad Kamran
2026-06-29 15:32 ` [PATCH v3 1/2] gdb: Preserve IFUNC marker when finding inferior functions Muhammad Kamran
@ 2026-06-29 15:32 ` Muhammad Kamran
1 sibling, 0 replies; 3+ messages in thread
From: Muhammad Kamran @ 2026-06-29 15:32 UTC (permalink / raw)
To: gdb-patches
Cc: Simon Marchi, Andrew Burgess, Wilco Dijkstra, Yury Khrustalev,
Thiago Jung Bauermann, Adhemerval Zanella Netto,
Carlos O'Donell, Muhammad Kamran
When find_function_addr resolves a GNU IFUNC, it tries to replace the
original function type with the resolved target type, or with the type
returned by the resolver. If neither source provides a useful return
type, keep the return type from the original function value.
This matters for internal inferior calls such as
find_function_in_inferior ("malloc"), where GDB creates a synthetic
function type with a known fallback return type.
Remove the guard from the IFUNC inferior-call test so the no-debug
resolver/no-debug target variants are tested too.
---
gdb/infcall.c | 12 ++++++++++--
gdb/testsuite/gdb.base/gnu-ifunc.exp | 7 -------
2 files changed, 10 insertions(+), 9 deletions(-)
diff --git a/gdb/infcall.c b/gdb/infcall.c
index e6b24ff5310..077407073ac 100644
--- a/gdb/infcall.c
+++ b/gdb/infcall.c
@@ -395,6 +395,9 @@ find_function_addr (struct value *function,
FUNCTION_TYPE have been asked for. */
if (retval_type != NULL || function_type != NULL)
{
+ /* Default to original function type's return type. Target type
+ replaces this only if it provides a usable return type. */
+ value_type = ftype->target_type ();
type *target_ftype = find_function_type (funaddr);
/* If we don't have debug info for the target function,
see if we can instead extract the target function's
@@ -403,8 +406,13 @@ find_function_addr (struct value *function,
target_ftype = find_gnu_ifunc_target_type (resolver_addr);
if (target_ftype != NULL)
{
- value_type = check_typedef (target_ftype)->target_type ();
- ftype = target_ftype;
+ struct type *target_value_type
+ = check_typedef (target_ftype)->target_type ();
+ if (target_value_type != NULL)
+ {
+ value_type = target_value_type;
+ ftype = target_ftype;
+ }
}
}
}
diff --git a/gdb/testsuite/gdb.base/gnu-ifunc.exp b/gdb/testsuite/gdb.base/gnu-ifunc.exp
index e2626b9cc0c..cf199daca83 100644
--- a/gdb/testsuite/gdb.base/gnu-ifunc.exp
+++ b/gdb/testsuite/gdb.base/gnu-ifunc.exp
@@ -411,13 +411,6 @@ proc_with_prefix test_inferior_call {resolver_attr resolver_debug final_debug} {
return
}
- # Without debug info for both the resolver and the resolved target,
- # find_function_addr currently loses the synthetic return type after
- # resolving the IFUNC.
- if {!$resolver_debug && !$final_debug} {
- unsupported "internal call resolves IFUNC malloc"
- return
- }
gdb_test "print (get_string (\"hello-ifunc\"), str_in_arena ())" \
" = 1" \
"internal call resolves IFUNC malloc"
--
2.43.0
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-06-29 15:34 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-06-29 15:32 [PATCH v3 0/2] gdb: Fix internal inferior calls through GNU IFUNCs Muhammad Kamran
2026-06-29 15:32 ` [PATCH v3 1/2] gdb: Preserve IFUNC marker when finding inferior functions Muhammad Kamran
2026-06-29 15:32 ` [PATCH v3 2/2] gdb: Keep original IFUNC return type when target type is unknown Muhammad Kamran
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox