Bug 14570

Summary: debuginfod gdb: *** stack smashing detected ***: terminated
Product: [Build System, Metadata & Runtime] OE-Core Reporter: Robert Berger <pokylinux>
Component: devtools / tool chainAssignee: Robert Berger <pokylinux>
Status: RESOLVED WORKSFORME QA Contact:
Severity: normal    
Priority: Medium+ CC: meta.mr.watcher, meta.watcher, pgowda.cve, raj.khem, randy.macleod, sundeep.kokkonda
Version: 3.3.5   
Target Milestone: 4.0 M4   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: Yes (doc changes required)

Description Robert Berger 2021-09-25 07:36:32 UTC
On my arm32 board with master:

commit bf47addb34debc049b59e5e466228f00045c2061
Author: Richard Purdie <richard.purdie@linuxfoundation.org>
Date:   Sun Sep 12 12:26:15 2021 +0100

gdb runs:

GNU gdb (GDB) 10.2
Copyright (C) 2021 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.
Type "show copying" and "show warranty" for details.
This GDB was configured as "arm-resy-linux-gnueabi".
Type "show configuration" for configuration details.
For bug reporting instructions, please see:
<https://www.gnu.org/software/gdb/bugs/>.
Find the GDB manual and other documentation resources online at:
    <http://www.gnu.org/software/gdb/documentation/>.

gdb + exe runs:

For help, type "help".
Type "apropos word" to search for commands related to "word"...
Reading symbols from /usr/bin/readbootlog...
(No debugging symbols found in /usr/bin/readbootlog)
(gdb) quit
root@multi-v7-ml:~# gdb /usr/bin/readbootlog
GNU gdb (GDB) 10.2
Copyright (C) 2021 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.
Type "show copying" and "show warranty" for details.
This GDB was configured as "arm-resy-linux-gnueabi".
Type "show configuration" for configuration details.
For bug reporting instructions, please see:
<https://www.gnu.org/software/gdb/bugs/>.
Find the GDB manual and other documentation resources online at:
    <http://www.gnu.org/software/gdb/documentation/>.

For help, type "help".
Type "apropos word" to search for commands related to "word"...
Reading symbols from /usr/bin/readbootlog...
(No debugging symbols found in /usr/bin/readbootlog)
(gdb) quit

... but if I do that:

root@multi-v7-ml:~# export DEBUGINFOD_URLS="http://192.168.42.108:8002/"

then the stack of gdb seems to be smashed:

root@multi-v7-ml:~# gdb /usr/bin/readbootlog
GNU gdb (GDB) 10.2
Copyright (C) 2021 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.
Type "show copying" and "show warranty" for details.
This GDB was configured as "arm-resy-linux-gnueabi".
Type "show configuration" for configuration details.
For bug reporting instructions, please see:
<https://www.gnu.org/software/gdb/bugs/>.
Find the GDB manual and other documentation resources online at:
    <http://www.gnu.org/software/gdb/documentation/>.

For help, type "help".
Type "apropos word" to search for commands related to "word"...
Reading symbols from /usr/bin/readbootlog...
*** stack smashing detected ***: terminated
Aborted
root@multi-v7-ml:~#
Comment 1 Robert Berger 2021-09-25 11:27:03 UTC
pokyuser@e450-8:/workdir/build/multi-v7-ml-debuginfod-master/conf$ oe-run-native elfutils-native debuginfod --verbose -R /workdir/build/multi-v7-ml-debuginfod-master/tmp/deploy/rpm/
Running bitbake -e elfutils-native
[Sat 25 Sep 2021 11:12:11 AM GMT] (31081/31081): opened database /home/pokyuser/.debuginfod.sqlite
[Sat 25 Sep 2021 11:12:11 AM GMT] (31081/31081): sqlite version 3.36.0
[Sat 25 Sep 2021 11:12:11 AM GMT] (31081/31081): started http server on IPv4 IPv6 port=8002
[Sat 25 Sep 2021 11:12:11 AM GMT] (31081/31081): search concurrency 8
[Sat 25 Sep 2021 11:12:11 AM GMT] (31081/31081): rescan time 300
[Sat 25 Sep 2021 11:12:11 AM GMT] (31081/31081): fdcache fds 144
[Sat 25 Sep 2021 11:12:11 AM GMT] (31081/31081): fdcache mbs 6033
[Sat 25 Sep 2021 11:12:11 AM GMT] (31081/31081): fdcache prefetch 64
[Sat 25 Sep 2021 11:12:11 AM GMT] (31081/31081): fdcache tmpdir /tmp
[Sat 25 Sep 2021 11:12:11 AM GMT] (31081/31081): fdcache tmpdir min% 25
[Sat 25 Sep 2021 11:12:11 AM GMT] (31081/31081): groom time 86400
[Sat 25 Sep 2021 11:12:11 AM GMT] (31081/31081): scanning archive types .rpm(cat)
[Sat 25 Sep 2021 11:12:12 AM GMT] (31081/31084): grooming database
[Sat 25 Sep 2021 11:12:12 AM GMT] (31081/31085): fts traversed source paths in 0.160235s, scanned=5437, regex-skipped=0
[Sat 25 Sep 2021 11:12:13 AM GMT] (31081/31084): database record counts:
[Sat 25 Sep 2021 11:12:13 AM GMT] (31081/31084):             file d/e 0
[Sat 25 Sep 2021 11:12:13 AM GMT] (31081/31084):               file s 0
[Sat 25 Sep 2021 11:12:13 AM GMT] (31081/31084):          archive d/e 148
[Sat 25 Sep 2021 11:12:13 AM GMT] (31081/31084):         archive sref 4924
[Sat 25 Sep 2021 11:12:13 AM GMT] (31081/31084):         archive sdef 59627
[Sat 25 Sep 2021 11:12:13 AM GMT] (31081/31084):             buildids 74
[Sat 25 Sep 2021 11:12:13 AM GMT] (31081/31084):            filenames 65689
[Sat 25 Sep 2021 11:12:13 AM GMT] (31081/31084):    files scanned (#) 261
[Sat 25 Sep 2021 11:12:13 AM GMT] (31081/31084):   files scanned (mb) 214
[Sat 25 Sep 2021 11:12:13 AM GMT] (31081/31084):   index db size (mb) 11
[Sat 25 Sep 2021 11:12:13 AM GMT] (31081/31084): groomed database in 0.465793s
[Sat 25 Sep 2021 11:17:14 AM GMT] (31081/31085): fts traversed source paths in 0.137824s, scanned=5437, regex-skipped=0
[Sat 25 Sep 2021 11:22:15 AM GMT] (31081/31085): fts traversed source paths in 0.143584s, scanned=5437, regex-skipped=0

readelf    is from binutils
eu-readelf is from elfutils

root@multi-v7-ml:~# readelf -n /usr/bin/readbootlog | grep -A4 build.id

readelf: Warning: Separate debug info file /usr/bin/readbootlog found, but CRC does not match - ignoring
Displaying notes found in: .note.gnu.build-id
  Owner                Data size        Description
  GNU                  0x00000014       NT_GNU_BUILD_ID (unique build ID bitstring)
    Build ID: 93d46af42a3e037ae0e8a54d7ea43290740cf078

root@multi-v7-ml:~# eu-readelf -n /usr/bin/readbootlog | grep -A4 build.id
Note section [ 2] '.note.gnu.build-id' of 36 bytes at offset 0x170:
  Owner          Data size  Type
  GNU                   20  GNU_BUILD_ID
    Build ID: 93d46af42a3e037ae0e8a54d7ea43290740cf078

root@multi-v7-ml:~# export DEBUGINFOD_URLS="http://192.168.42.108:8002/"

root@multi-v7-ml:~# readelf -n /usr/bin/readbootlog | grep -A4 build.id
readelf: Warning: Separate debug info file /usr/bin/readbootlog found, but CRC does not match - ignoring
*** stack smashing detected ***: terminated

looks like eu-readelf 

root@multi-v7-ml:~# eu-readelf -n /usr/bin/readbootlog | grep -A4 build.id
Note section [ 2] '.note.gnu.build-id' of 36 bytes at offset 0x170:
  Owner          Data size  Type
  GNU                   20  GNU_BUILD_ID
    Build ID: 93d46af42a3e037ae0e8a54d7ea43290740cf078
Comment 2 Robert Berger 2021-09-27 08:35:14 UTC
looks like only when DEBUGINFOD_URLS is defined we die somewhere in debuginfod_find_debuginfo() due to a stack overflow.

export DEBUGINFOD_URLS="http://192.168.42.108:8002/"

root@multi-v7-ml:~# uftrace -P record objdump -d which /usr/bin/readbootlog | tee log 
objdump: 'which': No such file
objdump: Warning: Separate debug info file /usr/bin/readbootlog found, but CRC does not match - ignoring
*** stack smashing detected ***: terminated
WARN: process crashed by signal 6: Aborted (si_code: -6)
WARN:  if this happens only with uftrace, please consider -e/--estimate-return option.

WARN: Backtrace from uftrace v0.10 ( arm dwarf perf sched )
WARN: =====================================
WARN: [0] (debuginfod_find_debuginfo[453a88] <= <45e185>[45e185])

Please report this bug to https://github.com/namhyung/uftrace/issues.

WARN: child terminated by signal: 6: Aborted
# DURATION     TID     FUNCTION
  90.333 us [   444] | setlocale();
   6.667 us [   444] | setlocale();
   7.000 us [   444] | bindtextdomain();
   3.334 us [   444] | textdomain();
   4.334 us [   444] | xmalloc_set_program_name();
  79.333 us [   444] | bfd_set_error_program_name();
   3.333 us [   444] | bfd_init();
 294.000 us [   444] | bfd_set_default_target();
   6.000 us [   444] | getopt_long();
   3.334 us [   444] | getopt_long();
  13.667 us [   444] | stat64();
   2.000 us [   444] | __errno_location();
   6.667 us [   444] | dcgettext();
   3.333 us [   444] | fflush();
  37.000 us [   444] | __fprintf_chk();
  19.667 us [   444] | __vfprintf_chk();
  20.000 us [   444] | putc();
  27.667 us [   444] | stat64();
            [   444] | bfd_openr() {
 361.667 us [   444] |   /* linux:schedule */
 647.666 us [   444] | } /* bfd_openr */
 253.000 us [   444] | bfd_check_format();
 688.000 us [   444] | bfd_check_format_matches();
   3.666 us [   444] | bfd_get_section_by_name();
   3.000 us [   444] | bfd_get_section_by_name();
   3.667 us [   444] | bfd_get_section_by_name();
   2.333 us [   444] | bfd_get_section_by_name();
   3.667 us [   444] | bfd_get_section_by_name();
   5.334 us [   444] | xmalloc();
   7.667 us [   444] | bfd_get_full_section_contents();
   1.667 us [   444] | strnlen();
  36.000 us [   444] | lrealpath();
   2.334 us [   444] | strlen();
   1.667 us [   444] | strlen();
   2.000 us [   444] | malloc();
   1.667 us [   444] | strcpy();
  82.333 us [   444] | bfd_openr();
   6.000 us [   444] | __sprintf_chk();
  28.000 us [   444] | bfd_openr();
   5.000 us [   444] | __sprintf_chk();
            [   444] | bfd_openr() {
 371.000 us [   444] |   /* linux:schedule */
 549.667 us [   444] | } /* bfd_openr */
 492.667 us [   444] | bfd_check_format();
            [   444] | fopen64() {
 341.333 us [   444] |   /* linux:schedule */
 509.000 us [   444] | } /* fopen64 */
  81.000 us [   444] | fread();
   6.000 us [   444] | fread();
  24.000 us [   444] | fclose();
  65.000 us [   444] | bfd_close();
   9.000 us [   444] | dcgettext();
   3.000 us [   444] | fflush();
   3.333 us [   444] | dcgettext();
  32.000 us [   444] | __fprintf_chk();
  27.000 us [   444] | __vfprintf_chk();
   6.666 us [   444] | __sprintf_chk();
  44.667 us [   444] | bfd_openr();
   6.333 us [   444] | __sprintf_chk();
  31.334 us [   444] | bfd_openr();
   5.000 us [   444] | __sprintf_chk();
  27.333 us [   444] | bfd_openr();
   4.333 us [   444] | __sprintf_chk();
  28.666 us [   444] | bfd_openr();
   2.000 us [   444] | strcpy();
  27.333 us [   444] | bfd_openr();
   3.000 us [   444] | strcmp();
   4.000 us [   444] | malloc();
   6.000 us [   444] | __sprintf_chk();
   4.000 us [   444] | __sprintf_chk();
   3.000 us [   444] | __sprintf_chk();
   2.666 us [   444] | __sprintf_chk();
   2.333 us [   444] | __sprintf_chk();
   2.333 us [   444] | __sprintf_chk();
   4.333 us [   444] | __sprintf_chk();
   3.000 us [   444] | __sprintf_chk();
   2.667 us [   444] | __sprintf_chk();
   2.667 us [   444] | __sprintf_chk();
   2.334 us [   444] | __sprintf_chk();
   2.667 us [   444] | __sprintf_chk();
   2.667 us [   444] | __sprintf_chk();
   2.667 us [   444] | __sprintf_chk();
   2.667 us [   444] | __sprintf_chk();
   2.333 us [   444] | __sprintf_chk();
   3.333 us [   444] | __sprintf_chk();
   2.666 us [   444] | __sprintf_chk();
   2.667 us [   444] | __sprintf_chk();
   2.667 us [   444] | __sprintf_chk();
 230.333 us [   444] | debuginfod_begin();
            [   444] | debuginfod_find_debuginfo() {
 371.667 us [   444] |   /* linux:schedule */
 325.000 us [   444] |   /* linux:schedule */
            [   444] |   /* linux:task-exit */

uftrace stopped tracing with remaining functions
================================================
task: 444
[0] debuginfod_find_debuginfo
Comment 3 Robert Berger 2021-09-27 09:04:16 UTC
uftrace -P record objdump -d /usr/bin/readbootlog

shows same issue
Comment 4 Robert Berger 2021-09-27 09:10:50 UTC
ulimit -c unlimited
DEBUGINFOD_URLS="http://192.168.42.108:8002/" objdump -d /usr/bin/readbootlog

root@multi-v7-ml:~# gdb --silent core objdump
"0xbec76a90s": not in executable format: file format not recognized
/home/root/objdump: No such file or directory.
(gdb) quit
root@multi-v7-ml:~# gdb --silent objdump core
Reading symbols from objdump...
(No debugging symbols found in objdump)
[New LWP 454]
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/libthread_db.so.1".
Core was generated by `objdump -d /usr/bin/readbootlog'.
Program terminated with signal SIGABRT, Aborted.
#0  __libc_do_syscall () at ../sysdeps/unix/sysv/linux/arm/libc-do-syscall.S:47
47      ../sysdeps/unix/sysv/linux/arm/libc-do-syscall.S: No such file or directory.
(gdb) bt
#0  __libc_do_syscall () at ../sysdeps/unix/sysv/linux/arm/libc-do-syscall.S:47
#1  0xb6d4d27a in __pthread_kill_internal (threadid=<optimized out>, signo=6) at pthread_kill.c:44
#2  0xb6d1e9d6 in __GI_raise (sig=sig@entry=6) at ../sysdeps/posix/raise.c:26
#3  0xb6d10414 in __GI_abort () at abort.c:79
#4  0xb6d44eba in __libc_message (action=action@entry=do_abort, fmt=<optimized out>) at ../sysdeps/posix/libc_fatal.c:155
#5  0xb6da6706 in __GI___fortify_fail (msg=0xb6de6ed0 "stack smashing detected") at fortify_fail.c:26
#6  0xb6da66ee in __stack_chk_fail () at stack_chk_fail.c:24
#7  0xb6e09572 in ?? () from /usr/lib/libdebuginfod.so.1
Backtrace stopped: previous frame identical to this frame (corrupt stack?)
(gdb) frame 7
#7  0xb6e09572 in ?? () from /usr/lib/libdebuginfod.so.1
(gdb) l
42      in ../sysdeps/unix/sysv/linux/arm/libc-do-syscall.S
(gdb)
Comment 5 Robert Berger 2021-09-27 17:54:22 UTC
Please note, that if symbols are available on the target root file system you will not see the problem.
Comment 6 Sundeep KOKKONDA 2022-02-21 14:10:32 UTC
I am trying to reproduce the issue on arm qemu. I followed the below steps (see the terminal output) and could not reproduce the issue.
For 'readelf -n /usr/bin/readbootlog | grep -A4 build.id', the stack smashing issue not occurred.
For 'gdb /usr/bin/readbootlog', 'Download failed: Timer expired' error occurred.
What exact info is passed with 'DEBUGINFOD_URLS="http://192.168.42.108:8002/"'? Do I've to adapt this for qemuarm to reproduce the issue?
Also, the eu-readelf is not appended to with elfutils package. Which package includes this tool?

------------------
root@qemuarm:~# readelf -n /usr/bin/readbootlog | grep -A4 build.id
readelf: Warning: Separate debug info file /usr/bin/readbootlog found, but CRC does not match - ignoring
Displaying notes found in: .note.gnu.build-id
  Owner                Data size        Description
  GNU                  0x00000014       NT_GNU_BUILD_ID (unique build ID bitstring)
    Build ID: d6cdcbe5a1d252838be91197e59f0d9ff5ba8b0a

root@qemuarm:~# export DEBUGINFOD_URLS="http://192.168.42.108:8002/"
root@qemuarm:~# readelf -n /usr/bin/readbootlog | grep -A4 build.id
readelf: Warning: Separate debug info file /usr/bin/readbootlog found, but CRC does not match - ignoring
Displaying notes found in: .note.gnu.build-id
  Owner                Data size        Description
  GNU                  0x00000014       NT_GNU_BUILD_ID (unique build ID bitstring)
    Build ID: d6cdcbe5a1d252838be91197e59f0d9ff5ba8b0a

root@qemuarm:~# gdb /usr/bin/readbootlog
GNU gdb (GDB) 11.1
Copyright (C) 2021 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.
Type "show copying" and "show warranty" for details.
This GDB was configured as "arm-poky-linux-gnueabi".
Type "show configuration" for configuration details.
For bug reporting instructions, please see:
<https://www.gnu.org/software/gdb/bugs/>.
Find the GDB manual and other documentation resources online at:
    <http://www.gnu.org/software/gdb/documentation/>.

For help, type "help".
Type "apropos word" to search for commands related to "word"...
Reading symbols from /usr/bin/readbootlog...
Download failed: Timer expired.  Continuing without debug info for /usr/bin/readbootlog.
(No debugging symbols found in /usr/bin/readbootlog)
Comment 7 Randy MacLeod 2022-02-24 01:33:20 UTC
Robert, Please see Sundeeps reply.
Comment 8 Sundeep KOKKONDA 2022-02-24 11:54:54 UTC
I assume, in your case, the address http://192.168.42.108:8002/ used might be the host machine address. So, I tried to reproduce the issue with my host machine address http://192.168.42.108:8002/ by exporting in the target machine. Still, the issue is  not reproduced (The readelf able to read the BuildID).
Let me know if I miss something in reproducing the issue, also from your side check the issue is reproducible with latest sources.

root@qemuarm:~# readelf -n /usr/bin/readbootlog | grep -A4 build.id
readelf: Warning: Separate debug info file /usr/bin/readbootlog found, but CRC does not match - ignoring
Displaying notes found in: .note.gnu.build-id
  Owner                Data size        Description
  GNU                  0x00000014       NT_GNU_BUILD_ID (unique build ID bitstring)
    Build ID: d6cdcbe5a1d252838be91197e59f0d9ff5ba8b0a

root@qemuarm:~# eu-readelf -n /usr/bin/readbootlog | grep -A4 build.id
-sh: eu-readelf: command not found
root@qemuarm:~# export DEBUGINFOD_URLS="http://192.168.1.10:8002/"
root@qemuarm:~# readelf -n /usr/bin/readbootlog | grep -A4 build.id
readelf: Warning: Separate debug info file /usr/bin/readbootlog found, but CRC does not match - ignoring
Displaying notes found in: .note.gnu.build-id
  Owner                Data size        Description
  GNU                  0x00000014       NT_GNU_BUILD_ID (unique build ID bitstring)
    Build ID: d6cdcbe5a1d252838be91197e59f0d9ff5ba8b0a

root@qemuarm:~#
Comment 9 Sundeep KOKKONDA 2022-03-10 13:34:12 UTC
Hi Robert,

Have you checked this with latest GCC sources?
Provide me the requested inputs for issue reproduction and further analysis.
Comment 10 Sundeep KOKKONDA 2022-03-16 05:54:10 UTC
Issue not reproduced with latest GCC sources. Issue will be closed now.
I am willing to work on it, when more inputs provided to reproduce the issue.