From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from simark.ca by simark.ca with LMTP id yakUD8/tcmpI/QgAWB0awg (envelope-from ) for ; Wed, 05 Aug 2026 04:01:19 -0400 Authentication-Results: simark.ca; dkim=pass (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20251104 header.b=hUzVtVeQ; dkim-atps=neutral Received: by simark.ca (Postfix, from userid 112) id 2A0BF1E166; Wed, 05 Aug 2026 04:01:19 -0400 (EDT) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on simark.ca X-Spam-Level: X-Spam-Status: No, score=-5.4 required=5.0 tests=ARC_SIGNED,ARC_VALID,BAYES_00, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,FREEMAIL_FROM,MAILING_LIST_MULTI, RCVD_IN_DNSWL_MED autolearn=ham autolearn_force=no version=4.0.1 Received: from vm01.sourceware.org (vm01.sourceware.org [IPv6:2620:52:6:3111::32]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by simark.ca (Postfix) with ESMTPS id 1D8991E033 for ; Wed, 05 Aug 2026 04:01:18 -0400 (EDT) Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id F1A384BA23E1 for ; Wed, 5 Aug 2026 08:01:15 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org F1A384BA23E1 Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20251104 header.b=hUzVtVeQ Received: from mail-pl1-x62f.google.com (mail-pl1-x62f.google.com [IPv6:2607:f8b0:4864:20::62f]) by sourceware.org (Postfix) with ESMTPS id A800E4BA7986 for ; Wed, 5 Aug 2026 07:59:49 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org A800E4BA7986 Authentication-Results: sourceware.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=gmail.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org A800E4BA7986 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2607:f8b0:4864:20::62f ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1785916789; cv=none; b=gRcoW7lzsxDMZ3nI0ZiqlcwrZME8r2bkieRoHNentQM1pdRhNqTIWP2igpZEIMN7LlHv6G+HYzpHPjSQbLWY1c82eXqz1FzICYmSQN0DufWZQjKdlkDjSslMb0zbFanVkG2hJUESbhDIdynNyeh93DWkxV++d6Ecbxir8/C+Vpo= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1785916789; c=relaxed/simple; bh=7bkLqrNIgRg118cBX8LRK19QkVQfYd8cL3QXKDpBEBY=; h=DKIM-Signature:From:To:Subject:Date:Message-Id:MIME-Version; b=dKd8+YjxzeTM1vngd+lUWSAunGeqVoVt7ZRHhYb2o7ntcl7bZJ2eCnrTuN51l+YCZcCRjNo2FwXGALoxwS+u1WZYOTow14s4sesiBqO0/rV4HwCqrdPA4G2XwWNSxlYdHbxlkTgYSQMq7R7WJiE5rtarxZsn7V8j/8ubh3lGHGQ= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20251104 header.b=hUzVtVeQ DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org A800E4BA7986 Received: by mail-pl1-x62f.google.com with SMTP id d9443c01a7336-2ccdce28edeso1204265ad.0 for ; Wed, 05 Aug 2026 00:59:49 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785916789; x=1786521589; darn=sourceware.org; h=content-transfer-encoding:mime-version:message-id:date:subject:to :from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=k6ZtB/baujEObpYRnU4EJYX0sKYXXejhSitOgoj0U7E=; b=hUzVtVeQfYtmkYMmOmJmBt92r3ittrDY2LjY70MAEVOQn7/V3O2T5vvNWbD7vZZFrU mG5TAoZ2Z07K9TqehvRkugV9UbMnvpzlR9EYNEA56z7qMlEiLB3bqfXguqsKrpc25crc H08ssiiCmo74QjCpiSv4oAl0KI9GmXfmilYeA9iXInvZM3jQ5QEuRh4UUTASQxAcvGxL 5hRQwvFuWOst/rc/BcT3McHqGeFCQUi9l6q29SCdd77Wjmw+qrY660WJKuYknmaQUdVU EOS8PlgI1ZgZnB25T2cacVk85RTJJI0kEEH6fwM+BnPAhVv/PyrY77m5mv1KWZfh8WWf jB2w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785916789; x=1786521589; h=content-transfer-encoding:mime-version:message-id:date:subject:to :from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=k6ZtB/baujEObpYRnU4EJYX0sKYXXejhSitOgoj0U7E=; b=ph1d9vS21D/INoyjSM0UBbAauJQymJegtG3DSDkMveYnHCNejDOcWrga+smMwU7Dof QGb+DcsoE64d8EWfX8VNOrtXlGxFybCbip+8pr89q1BilXI5OjbRYmvQPpREPr1TjVsO qibCVJgKPd2LIQRjWxXFckskGhHWkj5aSE15aOHWNJWu9b1OGzKxxoINHDmJiLDUTndo 5408sCz6T8IRdexmRY1Y4miVQIv/P+XEjKMMkukVE2Yq1HHLYDoeIoQtzGdK/DnEZ93A sIHk2jtL0JucaJtua6auJugB5xTV9hgBHh3nRWjnyTzwbOGYsYOm7FKN7AgNTo12zHSv Zthw== X-Gm-Message-State: AOJu0YxRT8XDzoidpnFx6Mo28e6AeSIGDfzKcD1B2bzSR1k1Lt6dmBsl 8WIMzXsCG/4sKSxTF/3uwh5BuLHcFuUArzpWDeH6ufamgLAPccLLeHVUr4W9GdhL X-Gm-Gg: AR+sD11nsSfm5keWASAqKTFKgqdSK1fdeHHgRu6UXB27ZwZUib5xhQVFluehV0Om+aG R6wQsZ6yU+cR9wimilWuCpeUBkjwhRh5pFiFWdP5bjL9JRIYdLv+VwXiCrckmgg7Bzd8yOpTH9g 7DxBhRmhmcThsaHBZxdexRIQpbMH//SkcTyTxWwuPywddB5esGhjyAf85VQjTAHPifMErOcXx7z Og6B2xmUmGxHwnaI/Kglr1DaNnJSZtW4zh3bfP0WaOjfsdILHVKC90ICjsi+XpiSGmUD96eJb/a mvVk0/mi6z3RcmgqIFJo6MaXFFH9VhYf4YKGIcEb4Nov5j08v6EGrU1usI64SZRBvEl3arszuoC MF55aRS+m8dLTKnM1SeA4TQ7KLGX6SdXZe55ZaD3rKk9WlJvYMO7M60eMUfyLfh1Ps8e34gby4k oD9gyMMxfEiRRWdvU0oArxUqHBLCg2TJS7aWGVfHm5xSqnw6efkt59XhOWcWHKH09ez/G/mbkK9 9nLqFSCD5iEdzJph0p1GEBvMaB6D6mCOCXZ0DNiy84= X-Received: by 2002:a17:90b:3f48:b0:383:5a16:bd67 with SMTP id 98e67ed59e1d1-3903c783fc7mr3618244a91.4.1785916788487; Wed, 05 Aug 2026 00:59:48 -0700 (PDT) Received: from poweredge.r760.114.212.189.32.r760.114.212.189.32 ([155.254.126.227]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13fca6482e7sm11562489c88.6.2026.08.05.00.59.47 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 05 Aug 2026 00:59:48 -0700 (PDT) From: Jielun Wu To: gdb-patches@sourceware.org Subject: [PATCH] gdb: Reject non-base type operands in typed DWARF expressions Date: Wed, 5 Aug 2026 15:59:33 +0800 Message-Id: <20260805075933.3130855-1-firmiana402@gmail.com> X-Mailer: git-send-email 2.34.1 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-BeenThere: gdb-patches@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Gdb-patches mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: gdb-patches-bounces~public-inbox=simark.ca@sourceware.org DWARF typed expression operators require a type operand that names a DW_TAG_base_type DIE. This applies to DW_OP_const_type, DW_OP_regval_type, DW_OP_deref_type, and the nonzero type operands of DW_OP_convert and DW_OP_reinterpret. dwarf_expr_context::get_base_type documents that contract, but its implementation accepted any DIE that resolved to a GDB type. As a result, typed expression operators could accept non-base DIEs such as DW_TAG_structure_type. Add dwarf2_get_base_type to resolve the referenced DIE, reject invalid or non-base DIEs, and return the corresponding base type. Use it from the DWARF expression evaluator. Add a DWARF assembler test covering DW_OP_const_type with a DW_TAG_structure_type type operand. Bug: https://sourceware.org/bugzilla/show_bug.cgi?id=34375 Signed-off-by: Jielun Wu --- gdb/dwarf2/expr.c | 9 +- gdb/dwarf2/read.c | 38 ++++++++ gdb/dwarf2/read.h | 8 ++ .../gdb.dwarf2/dw2-typed-op-invalid-type.exp | 89 +++++++++++++++++++ 4 files changed, 137 insertions(+), 7 deletions(-) create mode 100644 gdb/testsuite/gdb.dwarf2/dw2-typed-op-invalid-type.exp diff --git a/gdb/dwarf2/expr.c b/gdb/dwarf2/expr.c index 3a6b8f58199..3fd7672bb2f 100644 --- a/gdb/dwarf2/expr.c +++ b/gdb/dwarf2/expr.c @@ -857,13 +857,8 @@ dwarf_expr_context::get_base_type (cu_offset die_cu_off) if (this->m_per_cu == nullptr) return builtin_type (this->m_per_objfile->objfile->arch ())->builtin_int; - struct type *result = dwarf2_get_die_type (die_cu_off, this->m_per_cu, - this->m_per_objfile); - - if (result == nullptr) - error (_("Could not find type for operation")); - - return result; + return dwarf2_get_base_type (die_cu_off, this->m_per_cu, + this->m_per_objfile); } /* See expr.h. */ diff --git a/gdb/dwarf2/read.c b/gdb/dwarf2/read.c index ca475f53745..3571f407a53 100644 --- a/gdb/dwarf2/read.c +++ b/gdb/dwarf2/read.c @@ -17146,6 +17146,44 @@ dwarf2_get_die_type (cu_offset die_offset, dwarf2_per_cu *per_cu, return get_die_type_at_offset (die_offset_sect, per_cu, per_objfile); } +/* See read.h. */ + +struct type * +dwarf2_get_base_type (cu_offset die_offset, dwarf2_per_cu *per_cu, + dwarf2_per_objfile *per_objfile) +{ + dwarf2_cu *cu = per_objfile->get_cu (per_cu); + if (cu == nullptr) + cu = load_cu (per_cu, per_objfile, false); + + /* A dummy CU has no DIE tree to inspect. This helper needs a real CU + to validate the referenced DIE's tag. */ + gdb_assert (cu != nullptr); + + sect_offset sect_off = cu->section_offset () + to_underlying (die_offset); + if (!cu->header.offset_in_unit_p (sect_off)) + error (_(DWARF_ERROR_PREFIX + "DIE at %s referenced by typed DWARF expression operation is " + "outside the current CU in module %s"), + sect_offset_str (sect_off), objfile_name (per_objfile->objfile)); + + die_info *die = follow_die_offset ({ &cu->section (), sect_off }, &cu); + if (die == nullptr) + error (_(DWARF_ERROR_PREFIX + "Cannot find DIE at %s referenced by typed DWARF expression " + "operation in module %s"), + sect_offset_str (sect_off), objfile_name (per_objfile->objfile)); + + if (die->tag != DW_TAG_base_type) + error (_(DWARF_ERROR_PREFIX + "DIE at %s referenced by typed DWARF expression operation has " + "tag '%s', not DW_TAG_base_type in module %s"), + sect_offset_str (sect_off), dwarf_tag_name (die->tag), + objfile_name (per_objfile->objfile)); + + return read_type_die (die, cu); +} + /* Fill in the missing details in SIG_TYPE from DWO_FILE. Error out if there isn't a type unit with the appropriate signature in diff --git a/gdb/dwarf2/read.h b/gdb/dwarf2/read.h index 15dd2abf3a1..ea43ada9d2f 100644 --- a/gdb/dwarf2/read.h +++ b/gdb/dwarf2/read.h @@ -1202,6 +1202,14 @@ dwarf2_per_objfile *get_dwarf2_per_objfile (struct objfile *objfile); struct type *dwarf2_get_die_type (cu_offset die_offset, dwarf2_per_cu *per_cu, dwarf2_per_objfile *per_objfile); +/* Return the type of the DW_TAG_base_type DIE at DIE_OFFSET in the CU + named by PER_CU. Throw an exception if the DIE is invalid or does + not represent a base type. */ + +struct type *dwarf2_get_base_type (cu_offset die_offset, + dwarf2_per_cu *per_cu, + dwarf2_per_objfile *per_objfile); + /* Given an index in .debug_addr, fetch the value. NOTE: This can be called during dwarf expression evaluation, long after the debug information has been read, and thus per_cu->cu diff --git a/gdb/testsuite/gdb.dwarf2/dw2-typed-op-invalid-type.exp b/gdb/testsuite/gdb.dwarf2/dw2-typed-op-invalid-type.exp new file mode 100644 index 00000000000..cc147b98eca --- /dev/null +++ b/gdb/testsuite/gdb.dwarf2/dw2-typed-op-invalid-type.exp @@ -0,0 +1,89 @@ +# Copyright 2026 Free Software Foundation, Inc. + +# This program is free software; you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation; either version 3 of the License, or +# (at your option) any later version. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see . + +# Test that typed DWARF expression operations reject type operands that +# do not reference a DW_TAG_base_type DIE. + +load_lib dwarf.exp + +require dwarf2_support + +standard_testfile main.c -dw.S + +set asm_file [standard_output_file $srcfile2] + +Dwarf::assemble $asm_file { + cu {} { + compile_unit {} { + declare_labels int_label struct_label + + int_label: base_type { + DW_AT_name "int" + DW_AT_encoding @DW_ATE_signed + DW_AT_byte_size 4 DW_FORM_sdata + } + + struct_label: structure_type { + DW_AT_name "not_a_base_type" + DW_AT_byte_size 4 DW_FORM_sdata + } { + member { + DW_AT_name "field" + DW_AT_type :$int_label + DW_AT_data_member_location 0 DW_FORM_sdata + } + } + + DW_TAG_variable { + DW_AT_name "bad_struct_const" + DW_AT_type :$struct_label + DW_AT_external 1 DW_FORM_flag + DW_AT_location { + variable _constants + variable _cu_label + + _op .byte $_constants(DW_OP_const_type) + _op .uleb128 "$struct_label - $_cu_label" + _op .byte 4 + _op .byte 1 + _op .byte 2 + _op .byte 3 + _op .byte 4 + DW_OP_stack_value + } SPECIAL_expr + } + } + } +} + +if {[build_executable ${testfile}.exp ${testfile} \ + [list $srcfile $asm_file] {nodebug}]} { + return +} + +clean_restart ${testfile} + +if {![runto_main]} { + return +} + +set base_type_error \ + "DWARF Error: DIE at $hex referenced by typed DWARF " +append base_type_error \ + "expression operation has tag 'DW_TAG_structure_type', not " +append base_type_error \ + "DW_TAG_base_type .*" + +gdb_test "print bad_struct_const" $base_type_error -- 2.34.1