* Replace gdb-13.2.tar.bz2 with gdb-14.2.tar.bz2. - Maintenance script import-fedora.sh: * Drop patch skips: * gdb-6.5-BEA-testsuite.patch - Maintenance script qa-local.sh: * Drop SLE-11. GDB 14.2 requires MPFR, and the SLE-11 version (2.3.2) is older than required (3.1.0+). * Add ALP. * Update version to 14.2. - Maintenance script qa.sh: * Add PR30480, PR31440, PR31806 kfail. * Add PR31810, PR31809, PR31811 kfail. * Expand gdb.base/rtld-step.exp kfail. * Add gdb.threads/thread-specific-bp.exp kfail. - Fedora patches updated: * gdb-6.3-gstack-20050411.patch * gdb-6.5-bz185337-resolve-tls-without-debuginfo-v2.patch * gdb-6.6-buildid-locate-rpm.patch * gdb-6.6-buildid-locate-solib-missing-ids.patch * gdb-6.6-buildid-locate.patch * gdb-6.6-testsuite-timeouts.patch * gdb-core-open-vdso-warning.patch * gdb-fedora-libncursesw.patch * gdb-linux_perf-bundle.patch * gdb-rhbz-2232086-cpp-ify-mapped-symtab.patch * gdb-rhbz-2232086-generate-dwarf-5-index-consistently.patch * gdb-rhbz-2232086-generate-gdb-index-consistently.patch - Fedora patches removed: * gdb-binutils29988-read_indexed_address.patch * gdb-bz2196395-debuginfod-legacy-openssl-crash.patch * gdb-bz2237392-dwarf-obstack-allocation.patch * gdb-bz2237515-debuginfod-double-free.patch * gdb-rhbz1773651-gdb-index-internal-error.patch * gdb-rhbz2160211-excessive-core-file-warnings.patch * gdb-rhbz2192105-ftbs-dangling-pointer * gdb-rhbz2233961-CVE-2022-4806.patch * gdb-rhbz2233965-memory-leak.patch - Fedora patches added: * gdb-ftbs-swapped-calloc-args.patch * gdb-rhbz2250652-avoid-PyOS_ReadlineTState.patch * gdb-rhbz2250652-gdbpy_gil.patch * gdb-rhbz2261580-intrusive_list-assertion-fix.patch - Fedora fixup patches added: * fixup-skip-tests.patch - Fedora fixup patches updated: * fixup-gdb-linux_perf-bundle.patch - Patches updated: * gdb-symtab-work-around-pr-gas-29517.patch * gdb-symtab-work-around-gas-pr28629.patch * gdb-testsuite-ada-pie.patch * gdb-python-finishbreakpoint-update.patch * gdb-testsuite-prevent-compilation-fails-with-unix-fpie-pie.patch * gdb-fix-segfault-in-for_each_block-part-1.patch * gdb-fix-segfault-in-for_each_block-part-2.patch * gdb-symtab-don-t-defer-backward-refs-inter-cu-intra-.patch * gdb-symtab-factor-out-m_deferred_entries-usage.patch * gdb-symtab-factor-out-m_die_range_map-usage.patch * gdb-symtab-fix-dw_tag_inlined_subroutine-entries-in-.patch * gdb-symtab-handle-nullptr-parent-in-parent_map-set_p.patch * gdb-symtab-keep-track-of-all-parents-for-cooked-inde.patch * gdb-symtab-keep-track-of-processed-dies-in-shard.patch * gdb-symtab-recurse-into-c-dw_tag_subprogram-dies-for.patch * gdb-symtab-refactor-condition-in-scan_attributes.patch * gdb-symtab-resolve-deferred-entries-inter-shard-case.patch * gdb-symtab-resolve-deferred-entries-intra-shard-case.patch - Patches added: * gdb-symtab-work-around-pr-gas-29517-dwarf2-case.patch * fix-the-gdb.ada-inline-section-gc.exp-test.patch * gdb-testsuite-handle-pac-marker.patch * change-gdb.base-examine-backwards.exp-for-aix.patch * gdb-testsuite-fix-spurious-fails-with-examine-backwa.patch * gdb-testsuite-make-gdb.base-solib-search.exp-more-ro.patch * gdb-testsuite-fix-regexp-in-vgdb_start.patch * powerpc-and-aarch64-fix-reverse-stepping-failure.patch * gdb-tdep-fix-gdb.base-watch-bitfields.exp-on-aarch64.patch * gdb-tdep-fix-gdb.base-watchpoint-unaligned.exp-on-aa.patch * gdb-testsuite-add-pr-gdb-26967-kfail-in-two-more-tes.patch * gdb-testsuite-fix-gdb.base-eh_return.exp.patch * fixup-powerpc-and-aarch64-fix-reverse-stepping-failu.patch * gdb-exp-fix-printing-of-out-of-bounds-struct-members.patch * gdb-fix-heap-use-after-free-in-select_event_lwp.patch * fix-regression-on-aarch64-linux-gdbserver.patch * gdb-testsuite-factor-out-proc-get_portnum.patch * gdb-testsuite-make-portnum-a-persistent-global.patch * gdb-testsuite-factor-out-proc-with_lock.patch * gdb-testsuite-factor-out-proc-lock_dir.patch * gdb-testsuite-move-gpu-parallel.lock-to-cache-dir.patch * gdb-testsuite-use-unique-portnum-in-parallel-testing.patch * gdb-testsuite-use-unique-portnum-in-parallel-testing-check-slash-slash-case.patch * gdb-tdep-fix-reverse-execution-of-ldr-immediate-t4.patch * gdb-exp-fix-cast-handling-for-indirection.patch * gdb-remote-fix-abort-on-remote_close_error.patch * gdb-testsuite-use-find_gnatmake-instead-of-gdb_find_.patch * gdb-testsuite-simplify-gdb.server-server-kill-python.patch * gdb-testsuite-fix-gdbserver-pid-in-gdb.server-server.patch * gdb-testsuite-add-missing-include-in-gdb.base-ctf-pt.patch * gdb-testsuite-fix-gdb.ada-verylong.exp-on-32-bit-tar.patch * gdb-testsuite-add-missing-includes-in-gdb.trace-coll.patch * gdb-testsuite-fix-missing-return-type-in-gdb.linespe.patch * gdb-testsuite-fix-gdb.base-ending-run.exp-on-manjaro.patch * gdb-testsuite-fix-test-case-gdb.threads-attach-stopp.patch * gdb-testsuite-add-missing-include-in-gdb.base-rtld-s.patch * gdb-testsuite-fix-valgrind-tests-on-debian.patch * gdb-testsuite-fix-gdb.server-server-connect.exp-for-.patch * gdb-testsuite-handle-core-without-build-id-in-gdb.ba.patch * gdb-testsuite-fix-gdb.base-list-no-debug.exp-on-debi.patch * gdb-testsuite-reset-errcnt-and-warncnt-in-default_gd.patch * gdb-testsuite-fix-test-in-gdb.python-py-finish-break.patch * gdb-testsuite-further-handle-long-filenames-in-gdb.b.patch * gdb-testsuite-fix-license-text-in-gdb.reverse-map-to.patch * gdb-testsuite-call-ldd-version-in-gdb.testsuite-dump.patch * gdb-testsuite-fix-gdb.mi-mi-dprintf.exp-with-read1.patch * gdb-testsuite-fix-gdb.cp-namespace.exp-with-read1.patch * gdb-testsuite-fix-typo-in-gdb.base-catch-syscall.exp.patch * gdb-testsuite-use-more-progbits-for-arm.patch * gdb-testsuite-fix-gdb.dwarf2-dw2-gas-workaround.exp.patch * gdb-testsuite-add-gdb.dwarf2-backward-spec-inter-cu..patch * gdb-testsuite-add-gdb.dwarf2-forward-spec-inter-cu.e.patch * gdb-symtab-workaround-pr-gas-31115.patch * gdb-arm-remove-tpidruro-register-from-non-freebsd-ta.patch * gdb-tdep-fix-catching-syscall-execve-exit-for-arm.patch * gdb-arm-fix-epilogue-frame-id.patch * gdb-linux-delete-all-other-lwps-immediately-on-ptrac.patch * add-maint-info-linux-lwps-command.patch * fix-gdb.threads-threads-after-exec.exp-race.patch * rs6000-unwind-on-each-instruction-fix.patch * gdb-python-make-gdb.unwindinfo.add_saved_register-mo.patch * gdb-arm-remove-thumb-bit-in-arm_adjust_breakpoint_ad.patch * gdb-testsuite-fix-error-in-gdb.server-server-kill-py.patch - Patches dropped: * remove-some-unnecessary-includes-from-exp.y.patch * gdb-testsuite-fix-gdb.gdb-python-helper.exp-with-o2-.patch * gdb-testsuite-simplify-gdb.base-unwind-on-each-insn..patch * gdb-testsuite-handle-output-after-prompt-in-gdb.thre.patch * gdb-testsuite-add-xfail-in-gdb.arch-i386-pkru.exp.patch * gdb-testsuite-factor-out-proc-linux_kernel_version.patch * gdb-testsuite-add-xfail-in-gdb.python-py-record-btra.patch * gdb-testsuite-fix-gdb.threads-schedlock.exp-on-fast-.patch * gdb-testsuite-simplify-gdb.arch-amd64-disp-step-avx..patch * gdb-testsuite-fix-gdb.threads-schedlock.exp-for-gcc-.patch * gdb-testsuite-add-xfail-case-in-gdb.python-py-record.patch * aarch64-avoid-initializers-for-vlas.patch * gdb-tdep-aarch64-fix-frame-address-of-last-insn.patch * fix-pr30369-regression-on-aarch64-arm-pr30506.patch * gdb-testsuite-fix-breakpoint-regexp-in-gdb.ada-out_o.patch * gdb-testsuite-relax-breakpoint-count-check-in-gdb.py.patch * gdb-testsuite-fix-buffer-overflow-in-gdb.base-signed.patch * gdb-testsuite-require-syscall-time-in-gdb.reverse-ti.patch * gdb-testsuite-handle-missing-gdc-in-gdb.dlang-dlang-.patch * gdb-testsuite-add-basic-lmap-for-tcl-8.6.patch * gdb-testsuite-fix-gdb.rust-watch.exp-on-ppc64le.patch * gdb-testsuite-fix-gdb.python-py-breakpoint.exp-timeo.patch * powerpc-fix-for-gdb.reverse-finish-precsave.exp-and-.patch * powerpc-regression-fix-for-reverse-finish-command.patch * gdb-testsuite-don-t-use-string-cat-in-gdb.dwarf2-dw2.patch * move-step_until-procedure.patch * gdb-testsuite-fix-gdb.arch-i386-signal.exp-on-x86_64.patch * gdb-testsuite-fix-regexps-in-gdb.base-step-over-sysc.patch * gdb-testsuite-add-kfail-for-pr-ada-30908.patch * gdb-testsuite-fix-gdb.ada-mi_task_arg.exp-with-newer.patch * gdb-testsuite-fix-gdb.cp-m-static.exp-regression-on-.patch * gdb-symtab-fix-line-number-of-static-const-class-mem.patch * gdb-symtab-handle-pu-in-iterate_over_some_symtabs.patch * gdb-testsuite-fix-gdb.dwarf2-nullptr_t.exp-with-cc-w.patch * gdb-symtab-fix-too-many-symbols-in-gdbpy_lookup_stat.patch * gdb-support-rseq-auxvs.patch * gdb-testsuite-add-xfail-for-gdb-29965-in-gdb.threads.patch * gdb-cli-handle-pending-c-after-rl_callback_read_char.patch * gdb-testsuite-add-have_host_locale.patch * gdb-symtab-find-main-language-without-symtab-expansi.patch * gdb-symtab-don-t-deduplicate-variables-in-gdb-index.patch * xcoffread.c-fix-werror-dangling-pointer-issue-with-m.patch * avoid-manual-memory-management-in-go-lang.c.patch * gdb-go-handle-v3-go_0-mangled-prefix.patch * gdb-symtab-handle-self-reference-die.patch * gdb-symtab-handle-self-reference-in-inherit_abstract.patch * gdb-symtab-add-optimized-out-static-var-to-cooked-in.patch * gdb-testsuite-fix-gdb.python-py-breakpoint.exp-with-.patch * gdb-tui-fix-segfault-in-tui_find_disassembly_address.patch * gdb-testsuite-add-wait_for_msg-arg-to-term-resize-fi.patch * gdb-testsuite-fix-gdb-server-ext-run-exp-for-obs.patch * gdb-testsuite-work-around-skip_prologue-problems-in-gdb.threads-process-dies-while-detaching.exp.patch OBS-URL: https://build.opensuse.org/package/show/devel:gcc/gdb?expand=0&rev=386
145 lines
4.9 KiB
Diff
145 lines
4.9 KiB
Diff
From 350172ea215c7074601e8424ff636563612f91e8 Mon Sep 17 00:00:00 2001
|
|
From: Pedro Alves <pedro@palves.net>
|
|
Date: Wed, 21 Feb 2024 16:23:55 +0000
|
|
Subject: [PATCH 14/48] [gdb] Fix heap-use-after-free in select_event_lwp
|
|
|
|
PR gdb/31259 reveals one scenario where we run into a
|
|
heap-use-after-free reported by thread sanitizer, while running
|
|
gdb.base/vfork-follow-parent.exp.
|
|
|
|
The heap-use-after-free happens during the following scenario:
|
|
|
|
- linux_nat_wait_1 is about to return an event for T2. It stops all
|
|
other threads, and while doing so, stop_wait_callback -> wait_lwp
|
|
sees T1 exit, and decides to leave the exit event pending. It
|
|
should have set the lp->stopped flag too, but does not -- this is
|
|
the bug.
|
|
|
|
- The event for T2 is reported, is processed by infrun, and we're
|
|
back at linux_nat_wait_1.
|
|
|
|
- linux_nat_wait_1 selects LWP T1 with the pending exit status to
|
|
report.
|
|
|
|
- it sets variable lp to point to the corresponding lwp_info.
|
|
|
|
- it calls stop_callback and stop_wait_callback for all threads
|
|
(because !target_is_non_stop_p ()).
|
|
|
|
- it calls select_event_lwp to maybe pick another thread than T1, to
|
|
prevent starvation.
|
|
|
|
The problem is the following:
|
|
|
|
- while calling stop_wait_callback for all threads, it also does this
|
|
for T1. While doing so, the corresponding lwp_info is deleted
|
|
(callstack stop_wait_callback -> wait_lwp -> exit_lwp ->
|
|
delete_lwp), leaving variable lp as a dangling pointer.
|
|
|
|
- variable lp is passed to select_event_lwp, which derefences it,
|
|
which causes the heap-use-after-free.
|
|
|
|
Note that the comment here mentions "all other LWP's":
|
|
...
|
|
/* Now stop all other LWP's ... */
|
|
iterate_over_lwps (minus_one_ptid, stop_callback);
|
|
/* ... and wait until all of them have reported back that
|
|
they're no longer running. */
|
|
iterate_over_lwps (minus_one_ptid, stop_wait_callback);
|
|
...
|
|
|
|
The reason the comments say "all other LWP's", and doesn't bother
|
|
filtering out LP is that lp->stopped should be true at this point, and
|
|
the callbacks (both stop_callback and stop_wait_callback) check that
|
|
flag, and do nothing if set. I.e., they skip already-stopped threads,
|
|
so they should skip LP.
|
|
|
|
In this particular scenario, though, we missed setting the stopped
|
|
flag right in the first step described above, so LP was iterated over
|
|
incorrectly.
|
|
|
|
The fix is to make wait_lwp set the lp->stopped flag when it decides
|
|
to leave the exit event pending. However, going a bit further,
|
|
gdbserver has a mark_lwp_dead function to centralize setting up
|
|
various lwp flags such that the rest of the code doesn't mishandle
|
|
them, and it seems like a good idea to do a similar thing in gdb as
|
|
well. That is what this patch does.
|
|
|
|
PR gdb/31259
|
|
Bug: https://sourceware.org/bugzilla/show_bug.cgi?id=31259
|
|
Co-Authored-By: Tom de Vries <tdevries@suse.de>
|
|
Change-Id: I4a6169976f89bf714c478cbb2b7d4c32365e62a9
|
|
---
|
|
gdb/linux-nat.c | 34 +++++++++++++++++++++++++---------
|
|
1 file changed, 25 insertions(+), 9 deletions(-)
|
|
|
|
diff --git a/gdb/linux-nat.c b/gdb/linux-nat.c
|
|
index 7e36ced6292..ed445c5e5bb 100644
|
|
--- a/gdb/linux-nat.c
|
|
+++ b/gdb/linux-nat.c
|
|
@@ -2029,6 +2029,27 @@ wait_for_signal ()
|
|
}
|
|
}
|
|
|
|
+/* Mark LWP dead, with STATUS as exit status pending to report
|
|
+ later. */
|
|
+
|
|
+static void
|
|
+mark_lwp_dead (lwp_info *lp, int status)
|
|
+{
|
|
+ /* Store the exit status lp->waitstatus, because lp->status would be
|
|
+ ambiguous (W_EXITCODE(0,0) == 0). */
|
|
+ lp->waitstatus = host_status_to_waitstatus (status);
|
|
+
|
|
+ /* If we're processing LP's status, there should be no other event
|
|
+ already recorded as pending. */
|
|
+ gdb_assert (lp->status == 0);
|
|
+
|
|
+ /* Dead LWPs aren't expected to report a pending sigstop. */
|
|
+ lp->signalled = 0;
|
|
+
|
|
+ /* Prevent trying to stop it. */
|
|
+ lp->stopped = 1;
|
|
+}
|
|
+
|
|
/* Wait for LP to stop. Returns the wait status, or 0 if the LWP has
|
|
exited. */
|
|
|
|
@@ -2114,9 +2135,8 @@ wait_lwp (struct lwp_info *lp)
|
|
|
|
/* If this is the leader exiting, it means the whole
|
|
process is gone. Store the status to report to the
|
|
- core. Store it in lp->waitstatus, because lp->status
|
|
- would be ambiguous (W_EXITCODE(0,0) == 0). */
|
|
- lp->waitstatus = host_status_to_waitstatus (status);
|
|
+ core. */
|
|
+ mark_lwp_dead (lp, status);
|
|
return 0;
|
|
}
|
|
|
|
@@ -2908,12 +2928,7 @@ linux_nat_filter_event (int lwpid, int status)
|
|
linux_nat_debug_printf ("LWP %ld exited (resumed=%d)",
|
|
lp->ptid.lwp (), lp->resumed);
|
|
|
|
- /* Dead LWP's aren't expected to reported a pending sigstop. */
|
|
- lp->signalled = 0;
|
|
-
|
|
- /* Store the pending event in the waitstatus, because
|
|
- W_EXITCODE(0,0) == 0. */
|
|
- lp->waitstatus = host_status_to_waitstatus (status);
|
|
+ mark_lwp_dead (lp, status);
|
|
return;
|
|
}
|
|
|
|
@@ -3248,6 +3263,7 @@ linux_nat_wait_1 (ptid_t ptid, struct target_waitstatus *ourstatus,
|
|
}
|
|
|
|
gdb_assert (lp);
|
|
+ gdb_assert (lp->stopped);
|
|
|
|
status = lp->status;
|
|
lp->status = 0;
|
|
--
|
|
2.35.3
|
|
|