Mirror of the gdb-patches mailing list
 help / color / mirror / Atom feed
From: "Joos, Christina" <christina.joos@intel.com>
To: Thiago Jung Bauermann <thiago.bauermann@linaro.org>
Cc: "gdb-patches@sourceware.org" <gdb-patches@sourceware.org>,
	"tom@tromey.com" <tom@tromey.com>
Subject: RE: [PATCH v4 10/13] gdb: Implement the hook 'is_no_return_shadow_stack_address' for amd64 linux.
Date: Tue, 22 Sep 2026 10:04:45 +0000	[thread overview]
Message-ID: <SN7PR11MB7638E0E490104CF05B08C54F89832@SN7PR11MB7638.namprd11.prod.outlook.com> (raw)
In-Reply-To: <878q4u54oq.fsf@linaro.org>

> -----Original Message-----
> From: Thiago Jung Bauermann <thiago.bauermann@linaro.org>
> Sent: Dienstag, 22. September 2026 05:46
> To: Joos, Christina <christina.joos@intel.com>
> Cc: gdb-patches@sourceware.org; tom@tromey.com
> Subject: Re: [PATCH v4 10/13] gdb: Implement the hook
> 'is_no_return_shadow_stack_address' for amd64 linux.
> 
> Hello Christina,
> 
> "Joos, Christina" <christina.joos@intel.com> writes:
> 
> >> -----Original Message-----
> >> From: Thiago Jung Bauermann <thiago.bauermann@linaro.org>
> >> Sent: Donnerstag, 3. September 2026 09:50
> >> To: Joos, Christina <christina.joos@intel.com>
> >> Cc: gdb-patches@sourceware.org; tom@tromey.com
> >> Subject: Re: [PATCH v4 10/13] gdb: Implement the hook
> >> 'is_no_return_shadow_stack_address' for amd64 linux.
> >>
> >> Christina Schimpe <christina.schimpe@intel.com> writes:
> >>
> >> > diff --git a/gdb/amd64-linux-tdep.c b/gdb/amd64-linux-tdep.c index
> >> > 42a62eaa975..d98415b8989 100644
> >> > --- a/gdb/amd64-linux-tdep.c
> >> > +++ b/gdb/amd64-linux-tdep.c
> >> > @@ -1960,6 +1960,62 @@ amd64_linux_top_addr_empty_shadow_stack
> >> >    return addr == range.second;
> >> >  }
> >> >
> >> > +/* Return a shadow stack frame info, if the shadow stack pointer SSP
> >> > +   belongs to a valid shadow stack frame while the element on the
> shadow
> >> > +   stack VALUE does not refer to a return address.  This can happen, for
> >> > +   instance, in case of signals.  The old shadow stack pointer is pushed
> >> > +   in a special format with bit 63 set.  In case this is true, a valid
> >> > +   shadow stack frame info is returned with its attributes frame_type and
> >> > +   non_return_description configured to
> ssp_frame_type::non_return_frame
> >> > +   and "<sigframe token>", respectively.  */
> >> > +
> >> > +static std::optional<shadow_stack_frame_info>
> >> > +amd64_linux_is_no_return_shadow_stack_address
> >> > +  (gdbarch *gdbarch, const CORE_ADDR ssp, const CORE_ADDR value,
> >> > +   const unsigned long level)
> >> > +{
> >> > +  /* SSP must belong to the shadow stack memory range.  */
> >> > +  std::pair<CORE_ADDR, CORE_ADDR> range;
> >> > +  gdb_assert (gdbarch_address_in_shadow_stack_memory_range
> (gdbarch,
> >> > +							    ssp,
> >> > +							    &range));
> >>
> >> I made this comment at another assert in a previous version of this
> >> series, but it's valid here too:
> >
> > Hm, I don't remember it... :/ Did I fix it already ? Or can you point me to your
> comment?
> 
> It was during review of v2:
> 
> https://inbox.sourceware.org/gdb-patches/87bjh1y3xk.fsf@linaro.org/
> 
> The assert was in amd64_linux_get_shadow_stack_size, but that gdbarch hook
> doesn't exist anymore.
> 
> Also, during review of a different patch series, Andrew Burgess said¹:
> 
> > We shouldn't assert on data from an outside source.  This should be
> > either an error, or a warning if GDB is able to handle this and push
> > on.
> 
> Which I think is a similar concern. Though in that case the outside source was a
> /proc file, not inferior state.

Ah, this makes a lot of sense to me. Thanks a lot for sharing that. The shadow stack
pointer is read using a ptrace call, so it is originally based on an outside source.  It
just may have been updated in between. The range is based on /proc maps interface.

> >> Won't this make GDB crash with a misbehaving inferior? It could
> >> indeed mean an internal error (GDB somehow got the SSP or range
> >> wrong), but it could also be (and probably more likely) an
> >> inconsistent state of the inferior. This can happen in a program
> >> being debugged so GDB should be able to handle it gracefully, and if
> possible provide useful information to the user.
> >>
> >> Maybe turn this into an error ()?
> >
> > Do you have an example program/debug session for this?
> > Then it would be easier for me to write a meaningful error message.
> 
> I don't. While I read the patch I just wondered whether this assert could trigger
> in a situation where the inferior is in a crazy or corrupted state. <hand-
> wave>Maybe it tried to do some stack-switching trick and got it
> wrong?</hand-wave>
> 
> An error message could be direct, maybe something like "SSP doesn't point to
> a shadow stack memory region"...

Yes, sounds good. I will use that wording, but write "The shadow stack pointer" instead of "SSP":

    error (_("The shadow stack pointer does not point to a shadow stack "
	     "memory region"));

> --
> Thiago
> (he/him)
> 
> ¹ https://inbox.sourceware.org/gdb-patches/87a4ppdq5a.fsf@redhat.com/

Regards,
Christina
________________________________________
Intel Deutschland GmbH 

Registered Address: Dornacher Strasse 1, 85622 Feldkirchen, Germany 

Tel: +49 (89) 99143-0 

www.intel.de 

Managing Directors: Candice Moore, Jeffrey Schneiderman, Ramachandran Sitaraman

Chairperson of the Supervisory Board: Sonja Pierer

Registered Seat: Munich Commercial Register B: Amtsgericht Munich HRB 186928

This e-mail and any attachments may contain confidential material for
the sole use of the intended recipient(s). Any review or distribution
by others is strictly prohibited. If you are not the intended
recipient, please contact the sender and delete all copies.

  reply	other threads:[~2026-09-22 10:05 UTC|newest]

Thread overview: 38+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-08 14:36 [PATCH v4 00/13] Add new command to print the shadow stack backtrace Christina Schimpe
2026-07-08 14:36 ` [PATCH v4 01/13] gdb: Generalize handling of the shadow stack pointer Christina Schimpe
2026-07-08 14:36 ` [PATCH v4 02/13] aarch64: Implement gdbarch function top_addr_empty_shadow_stack Christina Schimpe
2026-08-12 22:13   ` Luis
2026-08-25  9:01     ` Joos, Christina
2026-08-29  5:24       ` Thiago Jung Bauermann
2026-08-30 11:14         ` Joos, Christina
2026-09-03  6:49           ` Thiago Jung Bauermann
2026-09-12  6:02   ` Thiago Jung Bauermann
2026-09-21 19:50     ` Joos, Christina
2026-09-22  3:55       ` Thiago Jung Bauermann
2026-07-08 14:36 ` [PATCH v4 03/13] gdb: Add get_main_func_start_pc to refactor frame.c:inside_main_func Christina Schimpe
2026-09-03  6:53   ` Thiago Jung Bauermann
2026-07-08 14:36 ` [PATCH v4 04/13] gdb: Refactor 'stack.c:print_frame' Christina Schimpe
2026-07-08 14:36 ` [PATCH v4 05/13] gdb: Introduce 'stack.c:print_pc' function without frame argument Christina Schimpe
2026-07-08 14:36 ` [PATCH v4 06/13] gdb: Refactor 'find_symbol_funname' and 'info_frame_command_core' in stack.c Christina Schimpe
2026-07-08 14:36 ` [PATCH v4 07/13] gdb: Refactor 'stack.c:print_frame_info' Christina Schimpe
2026-07-08 14:36 ` [PATCH v4 08/13] gdb: Add command option 'bt -shadow' to print the shadow stack backtrace Christina Schimpe
2026-09-03  7:37   ` Thiago Jung Bauermann
2026-09-10 19:36     ` Joos, Christina
2026-09-12  5:52       ` Thiago Jung Bauermann
2026-07-08 14:36 ` [PATCH v4 09/13] gdb: Provide gdbarch hook to distinguish shadow stack backtrace elements Christina Schimpe
2026-09-03  7:44   ` Thiago Jung Bauermann
2026-07-08 14:36 ` [PATCH v4 10/13] gdb: Implement the hook 'is_no_return_shadow_stack_address' for amd64 linux Christina Schimpe
2026-09-03  7:49   ` Thiago Jung Bauermann
2026-09-21 19:49     ` Joos, Christina
2026-09-22  3:46       ` Thiago Jung Bauermann
2026-09-22 10:04         ` Joos, Christina [this message]
2026-07-08 14:36 ` [PATCH v4 11/13] gdb: Enable inferior calls in the shadow stack backtrace Christina Schimpe
2026-09-03  7:51   ` Thiago Jung Bauermann
2026-07-08 14:36 ` [PATCH v4 12/13] gdb: Enable signal trampolines " Christina Schimpe
2026-09-03  7:53   ` Thiago Jung Bauermann
2026-07-08 14:36 ` [PATCH v4 13/13] gdb, mi: Add -shadow-stack-list-frames command Christina Schimpe
2026-09-03  8:10   ` Thiago Jung Bauermann
2026-09-22  7:49     ` Joos, Christina
2026-08-04  7:45 ` RE:[PATCH v4 00/13] Add new command to print the shadow stack backtrace Joos, Christina
2026-09-03  6:44 ` [PATCH " Thiago Jung Bauermann
2026-09-10 19:42   ` Joos, Christina

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=SN7PR11MB7638E0E490104CF05B08C54F89832@SN7PR11MB7638.namprd11.prod.outlook.com \
    --to=christina.joos@intel.com \
    --cc=gdb-patches@sourceware.org \
    --cc=thiago.bauermann@linaro.org \
    --cc=tom@tromey.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox