Compare commits
2
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
f2559caa3a | ||
|
|
1f702bdd95 |
@@ -1,72 +0,0 @@
|
||||
From af895b219876b293d551e6dec825aba3905c0588 Mon Sep 17 00:00:00 2001
|
||||
From: "qiwu.chen" <qiwu.chen@transsion.com>
|
||||
Date: Wed, 24 Jul 2024 01:36:09 +0000
|
||||
Subject: [PATCH] arm64: fix a potential segfault when unwind frame
|
||||
|
||||
The range of frame->fp is checked insufficiently, which may lead to a wrong
|
||||
next fp. As a result, bt->stackbuf will be accessed out of range, and segfault.
|
||||
|
||||
crash> bt
|
||||
[Detaching after fork from child process 11409]
|
||||
PID: 7661 TASK: ffffff81858aa500 CPU: 4 COMMAND: "sh"
|
||||
#0 [ffffffc008003f50] local_cpu_stop at ffffffdd7669444c
|
||||
|
||||
Thread 1 "crash" received signal SIGSEGV, Segmentation fault.
|
||||
0x00005555558266cc in arm64_unwind_frame (bt=0x7fffffffd8f0, frame=0x7fffffffd080) at
|
||||
arm64.c:2821
|
||||
2821 frame->fp = GET_STACK_ULONG(fp);
|
||||
(gdb) bt
|
||||
arm64.c:2821
|
||||
out>) at main.c:1338
|
||||
gdb_interface.c:81
|
||||
(gdb) p /x *(struct bt_info*) 0x7fffffffd8f0
|
||||
$3 = {task = 0xffffff81858aa500, flags = 0x0, instptr = 0xffffffdd76694450, stkptr =
|
||||
0xffffffc008003f40, bptr = 0x0, stackbase = 0xffffffc027288000,
|
||||
stacktop = 0xffffffc02728c000, stackbuf = 0x555556115a40, tc = 0x55559d16fdc0, hp = 0x0,
|
||||
textlist = 0x0, ref = 0x0, frameptr = 0xffffffc008003f50,
|
||||
call_target = 0x0, machdep = 0x0, debug = 0x0, eframe_ip = 0x0, radix = 0x0, cpumask =
|
||||
0x0}
|
||||
(gdb) p /x *(struct arm64_stackframe*) 0x7fffffffd080
|
||||
$4 = {fp = 0xffffffc008003f50, sp = 0xffffffc008003f60, pc = 0xffffffdd76694450}
|
||||
crash> bt -S 0xffffffc008003f50
|
||||
PID: 7661 TASK: ffffff81858aa500 CPU: 4 COMMAND: "sh"
|
||||
bt: non-process stack address for this task: ffffffc008003f50
|
||||
(valid range: ffffffc027288000 - ffffffc02728c000)
|
||||
|
||||
Check frame->fp value sufficiently before access it. Only frame->fp within
|
||||
the range of bt->stackbase and bt->stacktop will be regarded as valid.
|
||||
|
||||
Signed-off-by: qiwu.chen <qiwu.chen@transsion.com>
|
||||
|
||||
Conflict: NA
|
||||
Reference: https://github.com/crash-utility/crash/commit/af895b219876b293d551e6dec825aba3905c0588
|
||||
|
||||
---
|
||||
arm64.c | 4 ++--
|
||||
1 file changed, 2 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/arm64.c b/arm64.c
|
||||
index b3040d7..624dba2 100644
|
||||
--- a/arm64.c
|
||||
+++ b/arm64.c
|
||||
@@ -2814,7 +2814,7 @@ arm64_unwind_frame(struct bt_info *bt, struct arm64_stackframe *frame)
|
||||
low = frame->sp;
|
||||
high = (low + stack_mask) & ~(stack_mask);
|
||||
|
||||
- if (fp < low || fp > high || fp & 0xf)
|
||||
+ if (fp < low || fp > high || fp & 0xf || !INSTACK(fp, bt))
|
||||
return FALSE;
|
||||
|
||||
frame->sp = fp + 0x10;
|
||||
@@ -3024,7 +3024,7 @@ arm64_unwind_frame_v2(struct bt_info *bt, struct arm64_stackframe *frame,
|
||||
low = frame->sp;
|
||||
high = (low + stack_mask) & ~(stack_mask);
|
||||
|
||||
- if (fp < low || fp > high || fp & 0xf)
|
||||
+ if (fp < low || fp > high || fp & 0xf || !INSTACK(fp, bt))
|
||||
return FALSE;
|
||||
|
||||
if (CRASHDEBUG(1))
|
||||
--
|
||||
2.33.0
|
||||
|
||||
@@ -1,46 +0,0 @@
|
||||
From 45685956da58b15d4542d59b95888b1968980c68 Mon Sep 17 00:00:00 2001
|
||||
From: Xiaoguang Wang <lege.wang@jaguarmicro.com>
|
||||
Date: Thu, 7 Nov 2024 14:40:07 +0800
|
||||
Subject: [PATCH] arm64: fix SDEI stack frame unwind while UNW_4_14 is set
|
||||
|
||||
Fix two bugs:
|
||||
1) If BT_IRQSTACK is set, both irq_stack and sdei_normal_stack need
|
||||
to be checked while switching to process stack.
|
||||
2) Use bt->frameptr in arm64_unwind_frame() just like irq stack.
|
||||
|
||||
Fixes: 442da89f4898 ("crash: add SDEI stack resolution")
|
||||
Signed-off-by: Xiaoguang Wang <lege.wang@jaguarmicro.com>
|
||||
---
|
||||
arm64.c | 8 ++++----
|
||||
1 file changed, 4 insertions(+), 4 deletions(-)
|
||||
|
||||
diff --git a/arm64.c b/arm64.c
|
||||
index b99baa3..34c3b08 100644
|
||||
--- a/arm64.c
|
||||
+++ b/arm64.c
|
||||
@@ -3244,10 +3244,10 @@ arm64_unwind_frame(struct bt_info *bt, struct arm64_stackframe *frame)
|
||||
|
||||
if (machdep->flags & UNW_4_14) {
|
||||
if (((bt->flags & BT_IRQSTACK) &&
|
||||
- !arm64_on_irq_stack(bt->tc->processor, frame->fp)) ||
|
||||
+ !arm64_on_irq_stack(bt->tc->processor, frame->fp) &&
|
||||
+ !arm64_in_sdei_normal_stack(bt->tc->processor, frame->fp)) ||
|
||||
((bt->flags & BT_OVERFLOW_STACK) &&
|
||||
- !arm64_on_overflow_stack(bt->tc->processor, frame->fp)) &&
|
||||
- !arm64_in_sdei_normal_stack(bt->tc->processor, frame->fp)) {
|
||||
+ !arm64_on_overflow_stack(bt->tc->processor, frame->fp))) {
|
||||
if (arm64_on_process_stack(bt, frame->fp)) {
|
||||
arm64_set_process_stack(bt);
|
||||
|
||||
@@ -3696,7 +3696,7 @@ arm64_back_trace_cmd(struct bt_info *bt)
|
||||
arm64_set_overflow_stack(bt);
|
||||
bt->flags |= BT_OVERFLOW_STACK;
|
||||
}
|
||||
- if (arm64_in_sdei_normal_stack(bt->tc->processor, bt->bptr)) {
|
||||
+ if (arm64_in_sdei_normal_stack(bt->tc->processor, bt->frameptr)) {
|
||||
arm64_set_sdei_normal_stack(bt);
|
||||
bt->flags |= BT_IRQSTACK;
|
||||
}
|
||||
--
|
||||
2.34.1
|
||||
|
||||
@@ -1,66 +0,0 @@
|
||||
From db0077614aaeda6d0ed557f2b91d3349d5fe430f Mon Sep 17 00:00:00 2001
|
||||
From: Austin Kim <austindh.kim@gmail.com>
|
||||
Date: Tue, 29 Oct 2024 17:32:07 +0900
|
||||
Subject: [PATCH] Fix for 'sys' to properly display the PANIC message
|
||||
|
||||
Using 'sys' command, we can view the panic message with general system
|
||||
information. If we run RISCV64-based vmcore, PANIC message is not properly
|
||||
displayed.
|
||||
|
||||
The reason is that the string "Unable to handle kernel" is not
|
||||
completely matched with the panic_msg[]. The corresponding kernel commit
|
||||
is 21733cb518471.
|
||||
|
||||
Without the patch:
|
||||
crash> sys
|
||||
KERNEL: vmlinux [TAINTED]
|
||||
DUMPFILE: vmcore
|
||||
CPUS: 4
|
||||
DATE: Thu Aug 22 16:13:08 KST 2024
|
||||
UPTIME: 00:33:25
|
||||
LOAD AVERAGE: 0.07, 0.07, 0.02
|
||||
TASKS: 385
|
||||
NODENAME: starfive
|
||||
RELEASE: 6.6.20+
|
||||
VERSION: #13 SMP Mon Aug 19 12:58:52 KST 2024
|
||||
MACHINE: riscv64 (unknown Mhz)
|
||||
MEMORY: 4 GB
|
||||
PANIC: ""
|
||||
|
||||
With the patch:
|
||||
crash> sys
|
||||
KERNEL: vmlinux [TAINTED]
|
||||
DUMPFILE: vmcore
|
||||
CPUS: 4
|
||||
DATE: Thu Aug 22 16:13:08 KST 2024
|
||||
UPTIME: 00:33:25
|
||||
LOAD AVERAGE: 0.07, 0.07, 0.02
|
||||
TASKS: 385
|
||||
NODENAME: starfive
|
||||
RELEASE: 6.6.20+
|
||||
VERSION: #13 SMP Mon Aug 19 12:58:52 KST 2024
|
||||
MACHINE: riscv64 (unknown Mhz)
|
||||
MEMORY: 4 GB
|
||||
PANIC: "Unable to handle kernel access to user memory without uaccess routines at virtual address 0000000000000000"
|
||||
|
||||
Signed-off-by: Austin Kim <austindh.kim@gmail.com>
|
||||
---
|
||||
task.c | 5 +++++
|
||||
1 file changed, 5 insertions(+)
|
||||
|
||||
diff --git a/task.c b/task.c
|
||||
index c131cc32..33de7da2 100644
|
||||
--- a/task.c
|
||||
+++ b/task.c
|
||||
@@ -6392,6 +6392,11 @@ get_panicmsg(char *buf)
|
||||
get_symbol_data("sysrq_pressed", sizeof(int), &msg_found);
|
||||
break;
|
||||
}
|
||||
+
|
||||
+ /*
|
||||
+ * Try to search panic string in panic keywords
|
||||
+ */
|
||||
+ search_panic_task_by_keywords(buf, &msg_found);
|
||||
}
|
||||
|
||||
found:
|
||||
+4
-41
@@ -1,6 +1,6 @@
|
||||
Name: crash
|
||||
Version: 8.0.5
|
||||
Release: 9
|
||||
Release: 2
|
||||
Summary: Linux kernel crash utility.
|
||||
License: GPLv3
|
||||
URL: https://crash-utility.github.io
|
||||
@@ -11,12 +11,6 @@ Patch0: 0000-lzo_snappy.patch
|
||||
Patch1: 0001-add-SDEI-stack-resolution.patch
|
||||
Patch2: 0002-crash-8.0.2-sw.patch
|
||||
Patch3: 0003-crash-8.0.4-add-support-for-loongarch64.patch
|
||||
Patch4: 0004-arm64-fix-a-potential-segfault-when-unwind-frame.patch
|
||||
Patch5: 0005-arm64-fix-SDEI-stack-frame-unwind-while-UNW_4_14-is-.patch
|
||||
Patch9001: huawei-fix-ps-error-when-mm_struct.rss_stat-is-lazy-initial.patch
|
||||
%ifarch riscv64
|
||||
Patch6: backport-fix-for-sys-to-properly-display-the-PANIC-m.patch
|
||||
%endif
|
||||
|
||||
BuildRequires: ncurses-devel zlib-devel lzo-devel snappy-devel texinfo libzstd-devel
|
||||
BuildRequires: gcc gcc-c++ bison m4
|
||||
@@ -47,11 +41,9 @@ created by manufacturer-specific firmware.
|
||||
%package_help
|
||||
|
||||
%prep
|
||||
%setup -n %{name}-%{version}
|
||||
|
||||
%patch 0 -p1
|
||||
%patch 1 -p1
|
||||
|
||||
%setup -q -n %{name}-%{version}
|
||||
%patch 0 -p1
|
||||
%patch 1 -p1
|
||||
%ifarch sw_64
|
||||
%patch 2 -p1
|
||||
%endif
|
||||
@@ -59,13 +51,6 @@ created by manufacturer-specific firmware.
|
||||
%patch 3 -p1
|
||||
%endif
|
||||
|
||||
%patch 4 -p1
|
||||
%patch 5 -p1
|
||||
%patch 9001 -p1
|
||||
%ifarch riscv64
|
||||
%patch 6 -p1
|
||||
%endif
|
||||
|
||||
%build
|
||||
cp %{SOURCE1} .
|
||||
make -j`nproc` RPMPKG="%{version}-%{release}" CFLAGS="%{optflags}" CXXFLAGS="%{optflags}" LDFLAGS="%{build_ldflags}"
|
||||
@@ -99,28 +84,6 @@ install -D -m 0644 defs.h %{buildroot}%{_includedir}/%{name}/defs.h
|
||||
%{_mandir}/man8/crash.8*
|
||||
|
||||
%changelog
|
||||
* Mon Jul 14 2025 liuzhilin <liuzhilin@kylinos.cn> - 8.0.5-9
|
||||
- backport Fix for 'sys' to properly display the PANIC message patch.
|
||||
|
||||
* Wed Jun 04 2025 wangxiao <wangxiao184@h-partners.com> - 8.0.5-8
|
||||
- use patch command to apply patches for consistency in context
|
||||
|
||||
* Wed May 21 2025 zhangjian <zhangjian496@huawei.com> - 8.0.5-7
|
||||
- fix ps error when mm_struct.rss_stat is lazy initialized
|
||||
|
||||
* Wed Dec 04 2024 yangzhenyu <dev11101@linx-info.com> - 8.0.5-6
|
||||
- remove the architecture judgment in the patches section;
|
||||
- include all patches in the source package.
|
||||
|
||||
* Wed Nov 20 2024 Xiaoguang Wang <lege.wang@jaguarmicro.com> - 8.0.5-5
|
||||
- arm64: fix SDEI stack frame unwind while UNW_4_14 is set
|
||||
|
||||
* Wed Nov 13 2024 wangxiao <wangxiao184@h-partners.com> - 8.0.5-4
|
||||
- use autosetup instead of setup in prep stage
|
||||
|
||||
* Tue Nov 12 2024 wangxiao <wangxiao184@h-partners.com> - 8.0.5-3
|
||||
- arm64: fix a potential segfault when unwind frame
|
||||
|
||||
* Tue Nov 05 2024 xuguangmin <xuguangmin@kylinos.cn> - 8.0.5-2
|
||||
- Fix build warning:%patchN is deprecated (3 usages found), use %patch N
|
||||
|
||||
|
||||
@@ -1,28 +0,0 @@
|
||||
From 45052609f61d5d4ee8286d0d6098e53ea6b199a9 Mon Sep 17 00:00:00 2001
|
||||
From: zhangjian <zhangjian496@huawei.com>
|
||||
Date: Wed, 21 May 2025 02:08:12 +0000
|
||||
Subject: [PATCH] tmp
|
||||
|
||||
---
|
||||
tools.c | 5 +++++
|
||||
1 file changed, 5 insertions(+)
|
||||
|
||||
diff --git a/tools.c b/tools.c
|
||||
index 0f2db10..727a12c 100644
|
||||
--- a/tools.c
|
||||
+++ b/tools.c
|
||||
@@ -6955,6 +6955,11 @@ percpu_counter_sum_positive(ulong fbc)
|
||||
readmem(fbc + OFFSET(percpu_counter_counters), KVADDR, &addr,
|
||||
sizeof(void *), "percpu_counter.counters", FAULT_ON_ERROR);
|
||||
|
||||
+ /* maybe mm_struct.rss_stat is lazy initialized */
|
||||
+ if (!addr) {
|
||||
+ return ret;
|
||||
+ }
|
||||
+
|
||||
for (i = 0; i < kt->cpus; i++) {
|
||||
readmem(addr + kt->__per_cpu_offset[i], KVADDR, &count,
|
||||
sizeof(int), "percpu_counter.counters count", FAULT_ON_ERROR);
|
||||
--
|
||||
2.33.0
|
||||
|
||||
Reference in New Issue
Block a user