From: Aditya Vidyadhar Kamath <akamath996@gmail.com>
To: ulrich.weigand@de.ibm.com, simon.marchi@polymtl.ca, tom@tromey.com
Cc: gdb-patches@sourceware.org, Aditya.Kamath1@ibm.com,
sangamesh.swamy@in.ibm.com, PRAJWAL.B.MEHENDARKAR@ibm.com
Subject: [PATCH v3] Fix crash in AIX when current working directory is NULL
Date: Wed, 22 Jul 2026 17:16:20 +0530 [thread overview]
Message-ID: <20260722114619.78355-2-akamath996@gmail.com> (raw)
From: Aditya Kamath <Aditya.Kamath1@ibm.com>
This issue is seen in other targets as well.
In AIX if we do not have read permission in a current directory we get,
gdb ~/gdb_tests/simple_test
gdb: warning: error finding working directory: A parameter must be a directory.
GNU gdb (GDB) 18.0.50.20260619-git
Copyright (C) 2026 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.
Type "show copying" and "show warranty" for details.
This GDB was configured as "powerpc64-ibm-aix7.2.0.0".
Type "show configuration" for configuration details.
For bug reporting instructions, please see:
<https://www.gnu.org/software/gdb/bugs/>.
+------------------------------------------------------------------------------+
| Find the GDB manual online at: |
| http://www.gnu.org/software/gdb/documentation/. |
| For help, type "help". |
| Type "apropos word" to search for commands related to "word". |
+------------------------------------------------------------------------------+
Reading symbols from //gdb_tests/simple_test...
terminate called after throwing an instance of 'std::logic_error'
what(): basic_string: construction from null is not valid
Fatal signal: IOT/Abort trap
----- Backtrace -----
0x100943f1b gdb_internal_backtrace_1
//home/binutils-gdb/gdb/bt-utils.c:122
0x100944027 _Z22gdb_internal_backtracev
//home/binutils-gdb/gdb/bt-utils.c:173
0x10060faa7 handle_fatal_signal
//home/binutils-gdb/gdb/event-top.c:1008
0x4fdf ???
---------------------
A fatal error internal to GDB has been detected, further
debugging is not possible. GDB will now terminate.
This is a bug, please report it. For instructions, see:
<https://www.gnu.org/software/gdb/bugs/>.
=============================
The reason for the same above is that in AIX, the variable current_directory in dwarf2/read.c
can be NULL if getcwd () fails during GDB initialisation. When this happens the dwarf2_per_bfd
construction initialisation list captured_cwd to NULL resulting in this segmentation fault shown above.
There are two reasons this happened:
1: The current working directory got deleted in another terminal.
2: Insufficient permission to read the current directory or its parent/predicissor directory.
This patch is a fix to the same.
Afer this fix we get GDB loaded correctly.
gdb ~/gdb_tests/simple_test
gdb: warning: error finding working directory: A parameter must be a directory.
GNU gdb (GDB) 18.0.50.20260619-git
Copyright (C) 2026 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.
Type "show copying" and "show warranty" for details.
This GDB was configured as "powerpc64-ibm-aix7.2.0.0".
Type "show configuration" for configuration details.
For bug reporting instructions, please see:
<https://www.gnu.org/software/gdb/bugs/>.
+------------------------------------------------------------------------------+
| Find the GDB manual online at: |
| http://www.gnu.org/software/gdb/documentation/. |
| For help, type "help". |
| Type "apropos word" to search for commands related to "word". |
+------------------------------------------------------------------------------+
Reading symbols from //gdb_tests/simple_test...
(gdb) q
Also adding a test case for the same.
The reason I could not do it in a simple exp file is AIX is protecting the currrent working
directory when I try to delete. It says The requested resource is busy.
So I had to write a C code the fork () and child will delete the current working directory.
Then from here exec gdb with a binary having dwarf symbols to reproduce the crash.
---
gdb/dwarf2/read.c | 9 ++-
gdb/dwarf2/read.h | 7 +-
gdb/testsuite/gdb.base/getcwd-fail-helper.c | 84 +++++++++++++++++++++
gdb/testsuite/gdb.base/getcwd-fail.c | 5 ++
gdb/testsuite/gdb.base/getcwd-fail.exp | 70 +++++++++++++++++
5 files changed, 171 insertions(+), 4 deletions(-)
create mode 100644 gdb/testsuite/gdb.base/getcwd-fail-helper.c
create mode 100644 gdb/testsuite/gdb.base/getcwd-fail.c
create mode 100644 gdb/testsuite/gdb.base/getcwd-fail.exp
diff --git a/gdb/dwarf2/read.c b/gdb/dwarf2/read.c
index 114c608fde3..5b163041e02 100644
--- a/gdb/dwarf2/read.c
+++ b/gdb/dwarf2/read.c
@@ -859,7 +859,9 @@ dwarf2_per_bfd::dwarf2_per_bfd (bfd *obfd, const dwarf2_debug_sections *names,
bool can_copy_)
: obfd (obfd),
can_copy (can_copy_),
- captured_cwd (current_directory),
+ captured_cwd (current_directory != nullptr
+ ? std::optional<std::string> (current_directory)
+ : std::nullopt),
captured_debug_dir (debug_file_directory)
{
if (names == NULL)
@@ -6735,7 +6737,10 @@ try_open_dwop_file (dwarf2_per_bfd *per_bfd, const char *file_name, int is_dwp,
gdb::unique_xmalloc_ptr<char> absolute_name;
desc = openp (search_path, flags, file_name, O_RDONLY | O_BINARY,
- &absolute_name, per_bfd->captured_cwd.c_str ());
+ &absolute_name,
+ (per_bfd->captured_cwd.has_value ()
+ ? per_bfd->captured_cwd->c_str ()
+ : nullptr));
if (desc < 0)
return NULL;
diff --git a/gdb/dwarf2/read.h b/gdb/dwarf2/read.h
index 15dd2abf3a1..a7c1861a64d 100644
--- a/gdb/dwarf2/read.h
+++ b/gdb/dwarf2/read.h
@@ -757,8 +757,11 @@ struct dwarf2_per_bfd
abstract_to_concrete;
/* Current directory, captured at the moment that object this was
- created. */
- std::string captured_cwd;
+ created. If nullopt, the working directory was unavailable
+ which means getcwd failed either due to directory deletion or
+ permission issues. So paths should be treated as absolute. */
+ std::optional<std::string> captured_cwd;
+
/* Captured copy of debug_file_directory. */
std::string captured_debug_dir;
};
diff --git a/gdb/testsuite/gdb.base/getcwd-fail-helper.c b/gdb/testsuite/gdb.base/getcwd-fail-helper.c
new file mode 100644
index 00000000000..1cedc7090e8
--- /dev/null
+++ b/gdb/testsuite/gdb.base/getcwd-fail-helper.c
@@ -0,0 +1,84 @@
+/* This testcase is part of GDB, the GNU debugger.
+
+ Copyright 2026 Free Software Foundation, Inc.
+
+ This program is free software; you can redistribute it and/or modify
+ it under the terms of the GNU General Public License as published by
+ the Free Software Foundation; either version 3 of the License, or
+ (at your option) any later version.
+
+ This program is distributed in the hope that it will be useful,
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ GNU General Public License for more details.
+
+ You should have received a copy of the GNU General Public License
+ along with this program. If not, see <http://www.gnu.org/licenses/>. */
+
+/* Helper to reproduce getcwd failure by deleting cwd via child process. */
+#include <stdio.h>
+#include <stdlib.h>
+#include <unistd.h>
+#include <sys/wait.h>
+#include <sys/stat.h>
+
+int
+main (int argc, char *argv[])
+{
+ const char *temp_dir = argv[1];
+ const char *gdb_path = argv[2];
+
+ /* Create and change to temp directory. */
+ if (mkdir (temp_dir, 0755) != 0)
+ {
+ perror ("mkdir failed");
+ return 1;
+ }
+
+ if (chdir (temp_dir) != 0)
+ {
+ perror ("chdir failed");
+ return 1;
+ }
+
+ /* child deletes directory, parent execs GDB. */
+ pid_t pid = fork ();
+ if (pid < 0)
+ {
+ perror ("fork failed");
+ return 1;
+ }
+
+ if (pid == 0)
+ {
+ /* cd to / and delete the temp directory. */
+ if (chdir ("/") != 0)
+ exit (1);
+
+ if (rmdir (temp_dir) != 0)
+ exit (1);
+
+ exit (0);
+ }
+
+ /* wait for child to delete directory. */
+ int status;
+ waitpid (pid, &status, 0);
+
+ if (!WIFEXITED (status) || WEXITSTATUS (status) != 0)
+ {
+ fprintf (stderr, "Failed to delete directory\n");
+ return 1;
+ }
+
+ /* Exec GDB. */
+ char **gdb_args = malloc ((argc - 1) * sizeof (char *));
+ gdb_args[0] = (char *) gdb_path;
+ for (int i = 3; i < argc; i++)
+ gdb_args[i - 2] = argv[i];
+ gdb_args[argc - 2] = NULL;
+
+ execv (gdb_path, gdb_args);
+ perror ("execv failed");
+ return 1;
+}
diff --git a/gdb/testsuite/gdb.base/getcwd-fail.c b/gdb/testsuite/gdb.base/getcwd-fail.c
new file mode 100644
index 00000000000..398ec675a07
--- /dev/null
+++ b/gdb/testsuite/gdb.base/getcwd-fail.c
@@ -0,0 +1,5 @@
+int
+main (void)
+{
+ return 0;
+}
diff --git a/gdb/testsuite/gdb.base/getcwd-fail.exp b/gdb/testsuite/gdb.base/getcwd-fail.exp
new file mode 100644
index 00000000000..e0283753932
--- /dev/null
+++ b/gdb/testsuite/gdb.base/getcwd-fail.exp
@@ -0,0 +1,70 @@
+# Copyright 2026 Free Software Foundation, Inc.
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License as published by
+# the Free Software Foundation; either version 3 of the License, or
+# (at your option) any later version.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program. If not, see <http://www.gnu.org/licenses/>.
+
+# Test GDB when current working directory has been deleted.
+# Reproduces crash: getcwd() returns NULL.
+
+standard_testfile .c
+
+if {[prepare_for_testing "failed to prepare" $testfile $srcfile {debug}]} {
+ return -1
+}
+
+# Compile helper program
+set helper_src "${srcdir}/${subdir}/getcwd-fail-helper.c"
+set helper_bin [standard_output_file "getcwd-fail-helper"]
+
+# Debug needs to be there so we can trigger getcwd the dwarf2/read.c code.
+if {[gdb_compile $helper_src $helper_bin executable {debug}] != ""} {
+ untested "failed to compile helper"
+ return -1
+}
+
+set temp_dir [standard_output_file "temp_getcwd_test"]
+set gdb_path [transform $GDB]
+
+# The test code creates temp dir, child deletes it, parent execs GDB
+set test "gdb in deleted cwd"
+set spawn_id [remote_spawn host "$helper_bin $temp_dir $gdb_path -nw -nx -q $binfile"]
+
+set crashed 0
+
+remote_expect host 30 {
+ -re "terminate called.*logic_error.*basic_string.*construction from null" {
+ set crashed 1
+ exp_continue
+ }
+ -re "Fatal signal.*IOT/Abort" {
+ set crashed 1
+ exp_continue
+ }
+ -re "$gdb_prompt $" {
+ if {$crashed} {
+ fail "$test - crashed"
+ } else {
+ pass "$test"
+ }
+ }
+ eof {
+ if {$crashed} {
+ fail "$test - crashed with std::logic_error"
+ } else {
+ pass "$test"
+ }
+ }
+ timeout {
+ fail "$test - timeout"
+ }
+}
--
2.51.2
next reply other threads:[~2026-07-22 11:47 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-22 11:46 Aditya Vidyadhar Kamath [this message]
2026-07-22 15:48 ` Tom Tromey
2026-07-23 7:24 ` Aditya Kamath
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260722114619.78355-2-akamath996@gmail.com \
--to=akamath996@gmail.com \
--cc=Aditya.Kamath1@ibm.com \
--cc=PRAJWAL.B.MEHENDARKAR@ibm.com \
--cc=gdb-patches@sourceware.org \
--cc=sangamesh.swamy@in.ibm.com \
--cc=simon.marchi@polymtl.ca \
--cc=tom@tromey.com \
--cc=ulrich.weigand@de.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox