Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 5 May 2020 01:52:27 -0700
From:      Mark Millard <marklmi@yahoo.com>
To:        "vangyzen@freebsd.org" <vangyzen@FreeBSD.org>, svn-src-head@freebsd.org, FreeBSD Current <freebsd-current@freebsd.org>, FreeBSD Hackers <freebsd-hackers@freebsd.org>, FreeBSD PowerPC ML <freebsd-ppc@freebsd.org>
Cc:        Brandon Bergren <bdragon@FreeBSD.org>
Subject:   Re: svn commit: r360233 - in head: contrib/jemalloc . . . : This partially breaks a 2-socket 32-bit powerpc (old PowerMac G4) based on head -r360311
Message-ID:  <121B9B09-141B-4DC3-918B-1E7CFB99E779@yahoo.com>
In-Reply-To: <DCABCD83-27B0-4F2D-9410-69102294A98E@yahoo.com>
References:  <C24EE1A1-FAED-42C2-8204-CA7B1D20A369@yahoo.com> <8479DD58-44F6-446A-9CA5-D01F0F7C1B38@yahoo.com> <17ACDA02-D7EF-4F26-874A-BB3E935CD072@yahoo.com> <695E6836-F860-4557-B7DE-CC1EDB347F18@yahoo.com> <DCABCD83-27B0-4F2D-9410-69102294A98E@yahoo.com>

next in thread | previous in thread | raw e-mail | index | archive | help
[This report just shows an interesting rpcbind crash:
a pointer was filled with part of a string instead,
leading to a failed memory access attempt from the junk
address produced.]

Core was generated by `/usr/sbin/rpcbind'.
Program terminated with signal SIGSEGV, Segmentation fault.
#0  0x5024405c in rendezvous_request (xprt=3D<optimized out>, =
msg=3D<optimized out>) at /usr/src/lib/libc/rpc/svc_vc.c:335
335		cd->recvsize =3D r->recvsize;

(gdb) list
330			_setsockopt(sock, IPPROTO_TCP, TCP_NODELAY, =
&len, sizeof (len));
331		}
332=09
333		cd =3D (struct cf_conn *)newxprt->xp_p1;
334=09
335		cd->recvsize =3D r->recvsize;
336		cd->sendsize =3D r->sendsize;
337		cd->maxrec =3D r->maxrec;
338=09
339		if (cd->maxrec !=3D 0) {

(gdb) print/c *cd
Cannot access memory at address 0x2d202020

FYI:

. . .
   0x50244050 <+452>:	bl      0x502e3404 =
<00000000.plt_pic32._setsockopt>
   0x50244054 <+456>:	lwz     r27,80(r29)
   0x50244058 <+460>:	lwz     r3,4(r24)
=3D> 0x5024405c <+464>:	stw     r3,436(r27)

Note the 80(r29) use.

(gdb) info reg
r0             0x50244020          1344552992
r1             0xffffb400          4294947840
r2             0x500a1018          1342836760
r3             0x2328              9000
r4             0x32ef559c          854545820
r5             0x0                 0
r6             0xffffb360          4294947680
r7             0xffffb364          4294947684
r8             0x5004733c          1342468924
r9             0x0                 0
r10            0x20                32
r11            0x50252ea0          1344614048
r12            0x24200ca0          606080160
r13            0x0                 0
r14            0x0                 0
r15            0xffffbc28          4294949928
r16            0x10002848          268445768
r17            0x10040000          268697600
r18            0x2                 2
r19            0x0                 0
r20            0x1                 1
r21            0x5004c044          1342488644
r22            0xffffb63c          4294948412
r23            0x80                128
r24            0x50048010          1342472208
r25            0x14                20
r26            0xffffb630          4294948400
r27            0x2d202020          757080096
r28            0xf                 15
r29            0x50047308          1342468872
r30            0x5030112c          1345327404
r31            0x10040000          268697600
pc             0x5024405c          0x5024405c <rendezvous_request+464>
msr            <unavailable>
cr             0x842000a0          2216689824
lr             0x50244020          0x50244020 <rendezvous_request+404>
ctr            0x50252ea0          1344614048
xer            0x0                 0
fpscr          0x0                 0
vscr           <unavailable>
vrsave         <unavailable>

(gdb) x/s 0x50047308+72
0x50047350:	" -      -       -\n"

So it tried to use "-   " as a pointer value.

It appears that the r29 value was from:

   0x50243f90 <+260>:	mr      r28,r3
   0x50243f94 <+264>:	lwz     r4,0(r24)
   0x50243f98 <+268>:	lwz     r5,4(r24)
   0x50243f9c <+272>:	mr      r3,r28
   0x50243fa0 <+276>:	bl      0x5024308c <makefd_xprt>
   0x50243fa4 <+280>:	lwz     r27,36(r1)
   0x50243fa8 <+284>:	mr      r29,r3

The makefd_xprt being used as part of:

        /*
         * make a new transporter (re-uses xprt)
         */
        newxprt =3D makefd_xprt(sock, r->sendsize, r->recvsize);
        newxprt->xp_rtaddr.buf =3D mem_alloc(len);
        if (newxprt->xp_rtaddr.buf =3D=3D NULL)
                return (FALSE);
        memcpy(newxprt->xp_rtaddr.buf, &addr, len);
        newxprt->xp_rtaddr.len =3D len;
#ifdef PORTMAP
        if (addr.ss_family =3D=3D AF_INET || addr.ss_family =3D=3D =
AF_LOCAL) {
                newxprt->xp_raddr =3D *(struct sockaddr_in =
*)newxprt->xp_rtaddr.buf;
                newxprt->xp_addrlen =3D sizeof (struct sockaddr_in);
        }
#endif                          /* PORTMAP */
        if (__rpc_fd2sockinfo(sock, &si) && si.si_proto =3D=3D =
IPPROTO_TCP) {
                len =3D 1;
                /* XXX fvdl - is this useful? */
                _setsockopt(sock, IPPROTO_TCP, TCP_NODELAY, &len, sizeof =
(len));
        }
=20
        cd =3D (struct cf_conn *)newxprt->xp_p1;
=20
        cd->recvsize =3D r->recvsize;
        cd->sendsize =3D r->sendsize;
        cd->maxrec =3D r->maxrec;

FYI:

(gdb) print *r
$5 =3D {sendsize =3D 9000, recvsize =3D 9000, maxrec =3D 9000}

There is more evidence of strings in pointers in *newxprt
(xp_tp, oa_base, xp_p1, xp_p2, xp_p3):

(gdb) print *newxprt
$7 =3D {xp_fd =3D 15, xp_port =3D 0, xp_ops =3D 0x50329e1c, xp_addrlen =3D=
 16, xp_raddr =3D {sin_len =3D 16 '\020', sin_family =3D 1 '\001', =
sin_port =3D 0, sin_addr =3D {s_addr =3D 0},=20
    sin_zero =3D "\000\000\000\000\000\000\000"}, xp_ops2 =3D =
0x756e6978, xp_tp =3D 0x2020 <error: Cannot access memory at address =
0x2020>,=20
  xp_netid =3D 0x10010000 <error: Cannot access memory at address =
0x10010000>, xp_ltaddr =3D {maxlen =3D 0, len =3D 0, buf =3D 0x0}, =
xp_rtaddr =3D {maxlen =3D 539828256, len =3D 16, buf =3D 0x50047330}, =
xp_verf =3D {
    oa_flavor =3D 0, oa_base =3D 0x202d2020 <error: Cannot access memory =
at address 0x202d2020>, oa_length =3D 538976288}, xp_p1 =3D 0x2d202020, =
xp_p2 =3D 0x20202020, xp_p3 =3D 0x2d0a0079, xp_type =3D 543780384}

(gdb) print (char*)(&newxprt->xp_verf.oa_base)
$24 =3D 0x50047350 " -      -       -\n"

(gdb) print (char*)(&newxprt->xp_p3)+3
$13 =3D 0x50047363 "y in FreeBSD.\n"

(gdb) print (char*)(&newxprt->xp_type)
$25 =3D 0x50047364 " in FreeBSD.\n"



=3D=3D=3D
Mark Millard
marklmi at yahoo.com
( dsl-only.net went
away in early 2018-Mar)




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?121B9B09-141B-4DC3-918B-1E7CFB99E779>