Mirror of the gdb-patches mailing list
 help / color / mirror / Atom feed
* [PATCH v3 0/2] gdb: Fix internal inferior calls through GNU IFUNCs
@ 2026-06-29 15:32 Muhammad Kamran
  2026-06-29 15:32 ` [PATCH v3 1/2] gdb: Preserve IFUNC marker when finding inferior functions Muhammad Kamran
  2026-06-29 15:32 ` [PATCH v3 2/2] gdb: Keep original IFUNC return type when target type is unknown Muhammad Kamran
  0 siblings, 2 replies; 3+ messages in thread
From: Muhammad Kamran @ 2026-06-29 15:32 UTC (permalink / raw)
  To: gdb-patches
  Cc: Simon Marchi, Andrew Burgess, Wilco Dijkstra, Yury Khrustalev,
	Thiago Jung Bauermann, Adhemerval Zanella Netto,
	Carlos O'Donell, Muhammad Kamran

This series fixes a GDB inferior-call issue exposed by malloc being a GNU
IFUNC in glibc on AArch64.  The underlying problem is not AArch64-specific:
it can affect any inferior helper found through find_function_in_inferior's
minimal-symbol fallback when that helper is a GNU IFUNC.

GDB calls find_function_in_inferior ("malloc") when expression evaluation
needs to allocate memory in the inferior, for example for string literal
arguments.  In the minimal-symbol fallback, GDB created a synthetic ordinary
function pointer from the minimal symbol address.  If the symbol was a GNU
IFUNC, this lost the IFUNC marker, so call_function_by_hand did not resolve
the symbol before calling it.

Patch 1 checks the minimal symbol kind directly and propagates the GNU IFUNC
marker to the synthetic function type for mst_text_gnu_ifunc and
mst_data_gnu_ifunc symbols.  The existing fallback address and return type
are unchanged.

Patch 2 fixes the follow-on return-type issue after IFUNC resolution.  When
the resolved target type, or the type inferred from the resolver return type,
does not provide a usable return type, find_function_addr now keeps the
original function type's return type.  This preserves the synthetic fallback
return type used by find_function_in_inferior ("malloc").

The tests add an internal inferior-call case using an IFUNC malloc and run it
through the existing gdb.base/gnu-ifunc.exp matrix for resolver attr,
resolver debug info, and resolved-target debug info.

Changes since v2:
	* Rework the minimal-symbol fallback to check the minimal symbol kind
	  directly as suggested by Simon.
	* Add coverage for both debug and no-debug IFUNC malloc variants by
	  using the existing framework.
	* Preserve the original IFUNC return type when the resolved target type
	  is unknown.

Muhammad Kamran (2):
  gdb: Preserve IFUNC marker when finding inferior functions
  gdb: Keep original IFUNC return type when target type is unknown

 gdb/infcall.c                                 | 12 +++-
 .../gdb.base/gnu-ifunc-inferior-call-final.c  | 27 ++++++++
 .../gnu-ifunc-inferior-call-resolver.c        | 43 +++++++++++++
 .../gdb.base/gnu-ifunc-inferior-call.c        | 37 +++++++++++
 gdb/testsuite/gdb.base/gnu-ifunc.exp          | 61 +++++++++++++++++++
 gdb/valops.c                                  |  5 ++
 6 files changed, 183 insertions(+), 2 deletions(-)
 create mode 100644 gdb/testsuite/gdb.base/gnu-ifunc-inferior-call-final.c
 create mode 100644 gdb/testsuite/gdb.base/gnu-ifunc-inferior-call-resolver.c
 create mode 100644 gdb/testsuite/gdb.base/gnu-ifunc-inferior-call.c

-- 
2.43.0


^ permalink raw reply	[flat|nested] 3+ messages in thread

* [PATCH v3 1/2] gdb: Preserve IFUNC marker when finding inferior functions
  2026-06-29 15:32 [PATCH v3 0/2] gdb: Fix internal inferior calls through GNU IFUNCs Muhammad Kamran
@ 2026-06-29 15:32 ` Muhammad Kamran
  2026-06-29 15:32 ` [PATCH v3 2/2] gdb: Keep original IFUNC return type when target type is unknown Muhammad Kamran
  1 sibling, 0 replies; 3+ messages in thread
From: Muhammad Kamran @ 2026-06-29 15:32 UTC (permalink / raw)
  To: gdb-patches
  Cc: Simon Marchi, Andrew Burgess, Wilco Dijkstra, Yury Khrustalev,
	Thiago Jung Bauermann, Adhemerval Zanella Netto,
	Carlos O'Donell, Muhammad Kamran

GDB calls find_function_in_inferior ("malloc") when expression
evaluation needs to allocate memory in the inferior, e.g. for string
literal arguments.

The minimal-symbol fallback created a synthetic ordinary function
pointer from msymbol.value_address ().  If the symbol was a GNU IFUNC,
this discarded the IFUNC marker, so call_function_by_hand did not
resolve the symbol before calling it.

Check the minimal symbol kind directly and propagate the GNU IFUNC
marker to the synthetic function type for mst_text_gnu_ifunc and
mst_data_gnu_ifunc symbols.  This keeps the existing fallback address
and return type while allowing inferior calls through IFUNC symbols to
be resolved correctly.

Extend gdb.base/gnu-ifunc.exp with an internal inferior-call test that
uses an IFUNC malloc.  The test runs through the existing IFUNC matrix
for resolver attr, resolver debug info, and resolved-target debug
info.
---
 .../gdb.base/gnu-ifunc-inferior-call-final.c  | 27 ++++++++
 .../gnu-ifunc-inferior-call-resolver.c        | 43 ++++++++++++
 .../gdb.base/gnu-ifunc-inferior-call.c        | 37 ++++++++++
 gdb/testsuite/gdb.base/gnu-ifunc.exp          | 68 +++++++++++++++++++
 gdb/valops.c                                  |  5 ++
 5 files changed, 180 insertions(+)
 create mode 100644 gdb/testsuite/gdb.base/gnu-ifunc-inferior-call-final.c
 create mode 100644 gdb/testsuite/gdb.base/gnu-ifunc-inferior-call-resolver.c
 create mode 100644 gdb/testsuite/gdb.base/gnu-ifunc-inferior-call.c

diff --git a/gdb/testsuite/gdb.base/gnu-ifunc-inferior-call-final.c b/gdb/testsuite/gdb.base/gnu-ifunc-inferior-call-final.c
new file mode 100644
index 00000000000..1a9ae6fdcba
--- /dev/null
+++ b/gdb/testsuite/gdb.base/gnu-ifunc-inferior-call-final.c
@@ -0,0 +1,27 @@
+/* This testcase is part of GDB, the GNU debugger.
+
+   Copyright 2026 Free Software Foundation, Inc.
+
+   This program is free software; you can redistribute it and/or modify
+   it under the terms of the GNU General Public License as published by
+   the Free Software Foundation; either version 3 of the License, or
+   (at your option) any later version.
+
+   This program is distributed in the hope that it will be useful,
+   but WITHOUT ANY WARRANTY; without even the implied warranty of
+   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+   GNU General Public License for more details.
+
+   You should have received a copy of the GNU General Public License
+   along with this program.  If not, see <http://www.gnu.org/licenses/>.  */
+
+#include <stddef.h>
+
+extern char arena[32];
+
+void *
+dummy_malloc (size_t size)
+{
+  (void) size;
+  return arena;
+}
diff --git a/gdb/testsuite/gdb.base/gnu-ifunc-inferior-call-resolver.c b/gdb/testsuite/gdb.base/gnu-ifunc-inferior-call-resolver.c
new file mode 100644
index 00000000000..217002968de
--- /dev/null
+++ b/gdb/testsuite/gdb.base/gnu-ifunc-inferior-call-resolver.c
@@ -0,0 +1,43 @@
+/* This testcase is part of GDB, the GNU debugger.
+
+   Copyright 2026 Free Software Foundation, Inc.
+
+   This program is free software; you can redistribute it and/or modify
+   it under the terms of the GNU General Public License as published by
+   the Free Software Foundation; either version 3 of the License, or
+   (at your option) any later version.
+
+   This program is distributed in the hope that it will be useful,
+   but WITHOUT ANY WARRANTY; without even the implied warranty of
+   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+   GNU General Public License for more details.
+
+   You should have received a copy of the GNU General Public License
+   along with this program.  If not, see <http://www.gnu.org/licenses/>.  */
+
+#include <stddef.h>
+
+extern void *dummy_malloc (size_t size);
+
+typedef void *(*malloc_t) (size_t size);
+
+#ifndef IFUNC_RESOLVER_ATTR
+asm (".type malloc, %gnu_indirect_function");
+malloc_t
+malloc (unsigned long hwcap)
+#else
+static malloc_t
+resolve_malloc (void)
+#endif
+{
+#ifndef IFUNC_RESOLVER_ATTR
+  (void) hwcap;
+#endif
+  return dummy_malloc;
+}
+
+#ifdef IFUNC_RESOLVER_ATTR
+extern void *malloc (size_t size);
+
+__typeof (malloc) malloc __attribute__ ((ifunc ("resolve_malloc")));
+#endif
diff --git a/gdb/testsuite/gdb.base/gnu-ifunc-inferior-call.c b/gdb/testsuite/gdb.base/gnu-ifunc-inferior-call.c
new file mode 100644
index 00000000000..67d195d25f0
--- /dev/null
+++ b/gdb/testsuite/gdb.base/gnu-ifunc-inferior-call.c
@@ -0,0 +1,37 @@
+/* This testcase is part of GDB, the GNU debugger.
+
+   Copyright 2026 Free Software Foundation, Inc.
+
+   This program is free software; you can redistribute it and/or modify
+   it under the terms of the GNU General Public License as published by
+   the Free Software Foundation; either version 3 of the License, or
+   (at your option) any later version.
+
+   This program is distributed in the hope that it will be useful,
+   but WITHOUT ANY WARRANTY; without even the implied warranty of
+   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+   GNU General Public License for more details.
+
+   You should have received a copy of the GNU General Public License
+   along with this program.  If not, see <http://www.gnu.org/licenses/>.  */
+
+char arena[32];
+const char *str;
+
+int
+str_in_arena (void)
+{
+  return str == arena;
+}
+
+void
+get_string (const char *s)
+{
+  str = s;
+}
+
+int
+main (void)
+{
+  return 0;
+}
diff --git a/gdb/testsuite/gdb.base/gnu-ifunc.exp b/gdb/testsuite/gdb.base/gnu-ifunc.exp
index e6389102ae3..e2626b9cc0c 100644
--- a/gdb/testsuite/gdb.base/gnu-ifunc.exp
+++ b/gdb/testsuite/gdb.base/gnu-ifunc.exp
@@ -25,6 +25,13 @@ set libsrc ${libfile}.c
 set final_file "${testfile}-final"
 set final_src ${final_file}.c
 
+set infcall_file "${testfile}-inferior-call"
+set infcall_src ${infcall_file}.c
+set infcall_resolver_file "${testfile}-inferior-call-resolver"
+set infcall_resolver_src ${infcall_resolver_file}.c
+set infcall_final_file "${testfile}-inferior-call-final"
+set infcall_final_src ${infcall_final_file}.c
+
 # Return the binary suffix appended to program and library names to
 # make each testcase variant unique.
 proc make_binsuffix {resolver_attr resolver_debug final_debug} {
@@ -356,6 +363,66 @@ proc misc_tests {resolver_attr resolver_debug final_debug} {
     }
 }
 
+# Test that GDB resolves a GNU IFUNC minimal symbol when it uses
+# find_function_in_inferior to make an internal inferior call.  String
+# literals are copied into the inferior with a call to malloc, so an
+# IFUNC malloc exercises this path.
+
+proc_with_prefix test_inferior_call {resolver_attr resolver_debug final_debug} {
+    global srcdir subdir
+    global infcall_file infcall_src
+    global infcall_resolver_file infcall_resolver_src
+    global infcall_final_file infcall_final_src
+
+    set suffix [make_binsuffix $resolver_attr $resolver_debug $final_debug]
+    set executable ${infcall_file}-$suffix
+    set binfile [standard_output_file $executable]
+    set resolver_obj [standard_output_file ${infcall_resolver_file}-$suffix.o]
+    set final_obj [standard_output_file ${infcall_final_file}-$suffix.o]
+
+    set resolver_opts {additional_flags=-fno-builtin-malloc}
+    set final_opts {}
+
+    if {$resolver_attr} {
+	lappend resolver_opts "additional_flags=-DIFUNC_RESOLVER_ATTR"
+    }
+
+    if {$resolver_debug} {
+	lappend resolver_opts "debug"
+    }
+
+    if {$final_debug} {
+	lappend final_opts "debug"
+    }
+
+    if { [gdb_compile ${srcdir}/${subdir}/${infcall_resolver_src} \
+	      $resolver_obj object $resolver_opts] != ""
+	 || [gdb_compile ${srcdir}/${subdir}/${infcall_final_src} \
+		 $final_obj object $final_opts] != ""
+	 || [gdb_compile [list ${srcdir}/${subdir}/${infcall_src} \
+			      $resolver_obj $final_obj] \
+		 $binfile executable {debug}] != "" } {
+	untested "failed to compile inferior call testcase"
+	return
+    }
+
+    clean_restart $executable
+    if {![runto_main]} {
+	return
+    }
+
+    # Without debug info for both the resolver and the resolved target,
+    # find_function_addr currently loses the synthetic return type after
+    # resolving the IFUNC.
+    if {!$resolver_debug && !$final_debug} {
+	unsupported "internal call resolves IFUNC malloc"
+	return
+    }
+    gdb_test "print (get_string (\"hello-ifunc\"), str_in_arena ())" \
+	" = 1" \
+	"internal call resolves IFUNC malloc"
+}
+
 # Test all the combinations of:
 #
 # - An ifunc resolver with the same name as the ifunc symbol vs an
@@ -374,6 +441,7 @@ foreach_with_prefix resolver_attr {0 1} {
 	    if { [build $resolver_attr $resolver_debug $final_debug] != 0 } {
 		misc_tests $resolver_attr $resolver_debug $final_debug
 		set-break $resolver_attr $resolver_debug $final_debug
+		test_inferior_call $resolver_attr $resolver_debug $final_debug
 	    }
 	}
     }
diff --git a/gdb/valops.c b/gdb/valops.c
index ab6fd5079e1..454f093ab68 100644
--- a/gdb/valops.c
+++ b/gdb/valops.c
@@ -138,6 +138,11 @@ find_function_in_inferior (const char *name, struct objfile **objf_p)
 	  type = lookup_function_type (type);
 	  type = lookup_pointer_type (type);
 	  maddr = msymbol.value_address ();
+	  minimal_symbol_type minsym_type = msymbol.minsym->type ();
+
+	  if (minsym_type == mst_text_gnu_ifunc
+	      || minsym_type == mst_data_gnu_ifunc)
+	    type->target_type ()->set_is_gnu_ifunc (true);
 
 	  if (objf_p)
 	    *objf_p = objfile;
-- 
2.43.0


^ permalink raw reply	[flat|nested] 3+ messages in thread

* [PATCH v3 2/2] gdb: Keep original IFUNC return type when target type is unknown
  2026-06-29 15:32 [PATCH v3 0/2] gdb: Fix internal inferior calls through GNU IFUNCs Muhammad Kamran
  2026-06-29 15:32 ` [PATCH v3 1/2] gdb: Preserve IFUNC marker when finding inferior functions Muhammad Kamran
@ 2026-06-29 15:32 ` Muhammad Kamran
  1 sibling, 0 replies; 3+ messages in thread
From: Muhammad Kamran @ 2026-06-29 15:32 UTC (permalink / raw)
  To: gdb-patches
  Cc: Simon Marchi, Andrew Burgess, Wilco Dijkstra, Yury Khrustalev,
	Thiago Jung Bauermann, Adhemerval Zanella Netto,
	Carlos O'Donell, Muhammad Kamran

When find_function_addr resolves a GNU IFUNC, it tries to replace the
original function type with the resolved target type, or with the type
returned by the resolver.  If neither source provides a useful return
type, keep the return type from the original function value.

This matters for internal inferior calls such as
find_function_in_inferior ("malloc"), where GDB creates a synthetic
function type with a known fallback return type.

Remove the guard from the IFUNC inferior-call test so the no-debug
resolver/no-debug target variants are tested too.
---
 gdb/infcall.c                        | 12 ++++++++++--
 gdb/testsuite/gdb.base/gnu-ifunc.exp |  7 -------
 2 files changed, 10 insertions(+), 9 deletions(-)

diff --git a/gdb/infcall.c b/gdb/infcall.c
index e6b24ff5310..077407073ac 100644
--- a/gdb/infcall.c
+++ b/gdb/infcall.c
@@ -395,6 +395,9 @@ find_function_addr (struct value *function,
 	     FUNCTION_TYPE have been asked for.  */
 	  if (retval_type != NULL || function_type != NULL)
 	    {
+	      /* Default to original function type's return type.  Target type
+		 replaces this only if it provides a usable return type.  */
+	      value_type = ftype->target_type ();
 	      type *target_ftype = find_function_type (funaddr);
 	      /* If we don't have debug info for the target function,
 		 see if we can instead extract the target function's
@@ -403,8 +406,13 @@ find_function_addr (struct value *function,
 		target_ftype = find_gnu_ifunc_target_type (resolver_addr);
 	      if (target_ftype != NULL)
 		{
-		  value_type = check_typedef (target_ftype)->target_type ();
-		  ftype = target_ftype;
+		  struct type *target_value_type
+		    = check_typedef (target_ftype)->target_type ();
+		  if (target_value_type != NULL)
+		    {
+		      value_type = target_value_type;
+		      ftype = target_ftype;
+		    }
 		}
 	    }
 	}
diff --git a/gdb/testsuite/gdb.base/gnu-ifunc.exp b/gdb/testsuite/gdb.base/gnu-ifunc.exp
index e2626b9cc0c..cf199daca83 100644
--- a/gdb/testsuite/gdb.base/gnu-ifunc.exp
+++ b/gdb/testsuite/gdb.base/gnu-ifunc.exp
@@ -411,13 +411,6 @@ proc_with_prefix test_inferior_call {resolver_attr resolver_debug final_debug} {
 	return
     }
 
-    # Without debug info for both the resolver and the resolved target,
-    # find_function_addr currently loses the synthetic return type after
-    # resolving the IFUNC.
-    if {!$resolver_debug && !$final_debug} {
-	unsupported "internal call resolves IFUNC malloc"
-	return
-    }
     gdb_test "print (get_string (\"hello-ifunc\"), str_in_arena ())" \
 	" = 1" \
 	"internal call resolves IFUNC malloc"
-- 
2.43.0


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-06-29 15:34 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-06-29 15:32 [PATCH v3 0/2] gdb: Fix internal inferior calls through GNU IFUNCs Muhammad Kamran
2026-06-29 15:32 ` [PATCH v3 1/2] gdb: Preserve IFUNC marker when finding inferior functions Muhammad Kamran
2026-06-29 15:32 ` [PATCH v3 2/2] gdb: Keep original IFUNC return type when target type is unknown Muhammad Kamran

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox