From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from simark.ca by simark.ca with LMTP id qUcgLEjhtGqL3zsAWB0awg (envelope-from ) for ; Thu, 24 Sep 2026 04:37:28 -0400 Authentication-Results: simark.ca; dkim=pass (2048-bit key; unprotected) header.d=intel.com header.i=@intel.com header.a=rsa-sha256 header.s=Intel header.b=cMde+NPN; dkim-atps=neutral Received: by simark.ca (Postfix, from userid 112) id B19BD1E033; Thu, 24 Sep 2026 04:37:28 -0400 (EDT) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on simark.ca X-Spam-Level: X-Spam-Status: No, score=-3.4 required=5.0 tests=ARC_SIGNED,ARC_VALID,BAYES_00, DKIMWL_WL_HIGH,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,MAILING_LIST_MULTI, RCVD_IN_DNSWL_MED,RCVD_IN_VALIDITY_CERTIFIED_BLOCKED, RCVD_IN_VALIDITY_RPBL_BLOCKED,RCVD_IN_VALIDITY_SAFE_BLOCKED autolearn=ham autolearn_force=no version=4.0.1 Received: from vm01.sourceware.org (vm01.sourceware.org [38.145.34.32]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by simark.ca (Postfix) with ESMTPS id B1E241E033 for ; Thu, 24 Sep 2026 04:37:27 -0400 (EDT) Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id D92174BB5885 for ; Thu, 24 Sep 2026 08:37:26 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org D92174BB5885 Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=intel.com header.i=@intel.com header.a=rsa-sha256 header.s=Intel header.b=cMde+NPN Received: from mgamail.intel.com (mgamail.intel.com [192.198.163.14]) by sourceware.org (Postfix) with ESMTPS id 2D7B14BB3BE8 for ; Thu, 24 Sep 2026 08:34:59 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 2D7B14BB3BE8 Authentication-Results: sourceware.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=intel.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 2D7B14BB3BE8 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=192.198.163.14 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1790238899; cv=none; b=v12Au1ainkXyjHOjWko7V04ZeH0FmAqau9JtzE1CX0iAUKn3+MNf3IhEiEaj4l9KYvwThNdb6F5Dws0zWNVIGw9pU9Y0rCiIp0eb4uJqEkFlIFZgWBGTYFr99QWb9gARM08f08MzXNZiGJLbaG8iI0L7PwGoDUfVFo+0ph9/UQ0= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1790238899; c=relaxed/simple; bh=23s55CkWFNOGatkaM+ajlDWF64R/rBXQumZ9xdbjVnw=; h=DKIM-Signature:From:To:Subject:Date:Message-ID:MIME-Version; b=t+Hy3Zoa62fSPJowVCpClMQpy6jD/o92vTA1oKeI68DBV8dzCxO63BDWK+oeigrn3I6ROhjhfOfaEbDEa1ghnuqlDdMYykGVyFmnYneH1NFDSlb/32Ra/2Bm1kKktPYLJKDle3aPEzqf60X7kWGLMXgpPuJt6O5x3sux2fYiKXY= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=intel.com header.i=@intel.com header.a=rsa-sha256 header.s=Intel header.b=cMde+NPN DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 2D7B14BB3BE8 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1790238900; x=1821774900; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=23s55CkWFNOGatkaM+ajlDWF64R/rBXQumZ9xdbjVnw=; b=cMde+NPN4pWjpaC24p545dkFQbvW2FVmTKQsJopBnofvnkR9W0ZMMLGf eMDDoe5ZvroVk0CRTHKyBHuI4CH9eXKlxcsv28z4a1Vpy5ekWPmFVVVqq 1RfaiUc40cCJVx7ugDqfehMmoMn4wTKZp697uAQtuCG9K/ena2rtPgTDi h0jbiZiXhVFCfmInZQlM6rnAx7ZNtsC5YVqQ73IQtbBHRaiQ2ZwmA1uAE SPryiTJzvSUfAc4t1Zeb9oQA7d7vjJA07zqhsLUIAAEkapdi623EDl2l+ 6ZE/TAPJoNjUjLU5Wv1o7r7GCSNk86XhVyIJTmO+9gONC2Glud5/C6nZa g==; X-CSE-ConnectionGUID: JhFObV1ATVmNvvCaqhoLlQ== X-CSE-MsgGUID: Y5n6UrQoQByO3I0s3ulX3Q== X-IronPort-AV: E=McAfee;i="6800,10657,11914"; a="91021391" X-IronPort-AV: E=Sophos;i="6.27,120,1787036400"; d="scan'208";a="91021391" Received: from fmviesa003.fm.intel.com ([10.60.135.143]) by fmvoesa108.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 24 Sep 2026 01:34:58 -0700 X-CSE-ConnectionGUID: VDyjVLv/R1Ok1EuDkrgHBQ== X-CSE-MsgGUID: FoeGzU2QS+CYu3U3nv+2NQ== X-ExtLoop1: 1 Received: from gkldtt-dev-004.igk.intel.com (HELO localhost) ([10.123.221.202]) by fmviesa003-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 24 Sep 2026 01:34:57 -0700 From: Christina Joos To: gdb-patches@sourceware.org Cc: thiago.bauermann@linaro.org, tom@tromey.com, luis.machado.foss@gmail.com Subject: [PATCH v5 11/13] gdb: Enable inferior calls in the shadow stack backtrace. Date: Thu, 24 Sep 2026 10:33:08 +0200 Message-ID: <20260924083311.1961530-12-christina.joos@intel.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260924083311.1961530-1-christina.joos@intel.com> References: <20260924083311.1961530-1-christina.joos@intel.com> MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit X-BeenThere: gdb-patches@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Gdb-patches mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: gdb-patches-bounces~public-inbox=simark.ca@sourceware.org Similar to the normal backtrace display in the shadow stack backtrace for inferior function calls. Example for a nested inferior call: ~~~ (gdb) bt -shadow \#0 \#1 \#2 0x000000000040045a in call1 at /tmp/amd64-shadow-stack.c:27 \#3 0x0000000000400466 in main at /tmp/amd64-shadow-stack.c:38 (gdb) bt \#0 call2 () at /tmp/amd64-shadow-stack.c:21 \#1 \#2 call2 () at /tmp/amd64-shadow-stack.c:21 \#3 \#4 call2 () at /tmp/amd64-shadow-stack.c:21 \#5 0x000000000040045a in call1 () at /tmp/amd64-shadow-stack.c:27 \#6 0x0000000000400466 in main () at /tmp/amd64-shadow-stack.c:38 ~~~ Reviewed-by: Thiago Jung Bauermann --- gdb/shadow-stack.c | 36 +++++++++++++++++++ gdb/shadow-stack.h | 4 +++ .../gdb.arch/amd64-shadow-stack-cmds.exp | 24 +++++++++++++ 3 files changed, 64 insertions(+) diff --git a/gdb/shadow-stack.c b/gdb/shadow-stack.c index 75d9e0597ac..a31bb02bceb 100644 --- a/gdb/shadow-stack.c +++ b/gdb/shadow-stack.c @@ -215,6 +215,29 @@ find_pc_funname (CORE_ADDR pc) return funname; } +/* Check if the shadow stack frame's value VAL is an inferior call + return address. */ + +static bool +is_infcall_return_address (const CORE_ADDR val) +{ + const int inf_thread_num = inferior_thread ()->global_num; + + for (breakpoint &b : all_breakpoints ()) + { + if (b.type != bp_call_dummy + || b.thread != inf_thread_num + || b.frame_id.code_addr != val) + continue; + + for (bp_location &bl : b.locations ()) + if (bl.pspace == current_program_space) + return true; + } + + return false; +} + /* Print information of shadow stack frame info FRAME. The output is formatted according to PRINT_WHAT. For the meaning of PRINT_WHAT, see enum print_what comments in frame.h. Note that PRINT_WHAT is overridden, @@ -242,6 +265,8 @@ do_print_shadow_stack_frame_info gdb_assert (frame.non_return_description.has_value ()); str = frame.non_return_description.value (); } + else if (frame.type == ssp_frame_type::dummy_frame) + str = ""; else gdb_assert_not_reached ("Invalid shadow stack frame type."); @@ -430,6 +455,17 @@ get_shadow_stack_frame_info return *no_return_frame; } + if (is_infcall_return_address (value)) + { + /* If VALUE belongs to a dummy call breakpoint get_sal_arch won't + return a valid gdbarch and we can assign the current gdbarch + here. We also don't show any SAL information, so we can set it + to an empty optional. */ + return std::optional + ({ssp, value, level, fallback_arch, {}, ssp_frame_type::dummy_frame, + {}, ssp_unwind_stop_reason::no_error}); + } + /* At this point, we know that SSP points to VALUE which is a return address. In contrast to find_frame_sal which is used for the normal backtrace command, VALUE always points at the return instruction diff --git a/gdb/shadow-stack.h b/gdb/shadow-stack.h index 4278620c70c..225fd3996cd 100644 --- a/gdb/shadow-stack.h +++ b/gdb/shadow-stack.h @@ -76,6 +76,10 @@ enum class ssp_frame_type This frame type is configured in the target specific implementation of is_no_return_shadow_stack_address. */ non_return_frame, + + /* A fake frame, created by GDB when performing an inferior function + call. */ + dummy_frame, }; /* Information of a shadow stack frame belonging to a shadow stack element diff --git a/gdb/testsuite/gdb.arch/amd64-shadow-stack-cmds.exp b/gdb/testsuite/gdb.arch/amd64-shadow-stack-cmds.exp index 0347313b647..3259fd2f918 100644 --- a/gdb/testsuite/gdb.arch/amd64-shadow-stack-cmds.exp +++ b/gdb/testsuite/gdb.arch/amd64-shadow-stack-cmds.exp @@ -167,6 +167,30 @@ save_vars { ::env(GLIBC_TUNABLES) } { gdb_continue_to_end } + with_test_prefix "test inferior call shadow stack backtrace" { + restart_and_run_infcall_call2 + gdb_test "bt -shadow" \ + [multi_line \ + "#0\[ \t\]*" \ + "#1\[ \t\]*$hex in \[^\r\n\]+" \ + "#2\[ \t\]*$hex in \[^\r\n\]+" ] \ + "Test shadow stack backtrace for inferior calls." + + set inside_infcall_str \ + "The program being debugged stopped while in a function called from GDB" + gdb_test "call (int) call2()" \ + "Breakpoint \[0-9\]*, call2.*$inside_infcall_str.*" \ + "Execute an inferior call inside an inferior call." + + gdb_test "bt -shadow" \ + [multi_line \ + "#0\[ \t\]*" \ + "#1\[ \t\]*" \ + "#2\[ \t\]*$hex in \[^\r\n\]+" \ + "#3\[ \t\]*$hex in \[^\r\n\]+" ] \ + "Test shadow stack backtrace for nested inferior calls." + } + clean_restart ${::testfile} if { ![runto_main] } { return -- 2.53.0 ________________________________________ Intel Deutschland GmbH Registered Address: Dornacher Strasse 1, 85622 Feldkirchen, Germany Tel: +49 (89) 99143-0 www.intel.de Managing Directors: Candice Moore, Jeffrey Schneiderman, Ramachandran Sitaraman Chairperson of the Supervisory Board: Sonja Pierer Registered Seat: Munich Commercial Register B: Amtsgericht Munich HRB 186928 This e-mail and any attachments may contain confidential material for the sole use of the intended recipient(s). Any review or distribution by others is strictly prohibited. If you are not the intended recipient, please contact the sender and delete all copies.