Re: [RFC PATCH v1 10/25] unwind_user/eh_frame: Detect .eh_frame_hdr sections in executables

Jens Remus <[email protected]>
Newsgroups dev.linux.lists.sashiko-reviews,org.kernel.vger.linux-s390,org.kernel.vger.linux-trace-kernel
Organization IBM Deutschland Research & Development GmbH
Message-ID <[email protected]>
On 8/18/2026 5:18 PM, [email protected] wrote:
> Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
> - [High] Missing duplication of eh_frame_mt during fork() leaves child processes without stack unwind capability.

This is resolved by subsequent patch "unwind_user/eh_frame: Duplicate
registered .eh_frame[_hdr] section data on clone/fork".

> - [Medium] Executable segments with a trailing BSS section silently fail .eh_frame_hdr registration.

Josh, Steven, any thoughts?

>> diff --git a/fs/binfmt_elf.c b/fs/binfmt_elf.c

>> +static void elf_add_eh_frame(const struct elf_phdr *text,
>> +			     const struct elf_phdr *eh_frame,
>> +			     unsigned long base_addr)
>> +{
>> +	unsigned long eh_frame_start, eh_frame_end,
>> +		      text_start, text_end;
>> +
>> +	eh_frame_start = base_addr + eh_frame->p_vaddr;
>> +	eh_frame_end   = eh_frame_start + eh_frame->p_memsz;
>> +
>> +	text_start   = base_addr + text->p_vaddr;
>> +	text_end     = text_start + text->p_memsz;
> 
> [Severity: Medium]
> Will this silently fail to register .eh_frame_hdr for segments with a
> trailing BSS section?
> 
> When an ELF executable segment has p_memsz > p_filesz crossing a page
> boundary, the loader maps the file-backed portion and creates a separate
> anonymous VMA for the BSS.
> 
> Because text_end is calculated using p_memsz, it may extend beyond the
> file-backed VMA boundary. When this is passed to eh_frame_add_section(),
> it uses vma_lookup() and checks if the entire segment resides in a single
> VMA:
> 
> kernel/unwind/eh_frame.c:eh_frame_add_section() {
>     ...
>     if (!text_vma ||
>         !(text_vma->vm_flags & VM_EXEC) ||
>         text_end > text_vma->vm_end) {
>         return -EINVAL;
>     ...
> }
> 
> Since the file-backed VMA ends before text_end in this scenario, won't the
> text_end > text_vma->vm_end check fail and terminate registration?
> 
>> +
>> +	/* Ignore return value, eh_frame[_hdr] section isn't critical */
>> +	eh_frame_add_section(eh_frame_start, eh_frame_end, text_start, text_end);
>> +}
> 

Thanks and regards,
Jens
-- 
Jens Remus
Linux on Z Development (D3303)
[email protected] / [email protected]

IBM Deutschland Research & Development GmbH; Vorsitzender des Aufsichtsrats: Wolfgang Wendt; Geschäftsführung: David Faller; Sitz der Gesellschaft: Ehningen; Registergericht: Amtsgericht Stuttgart, HRB 243294
IBM Data Privacy Statement: https://www.ibm.com/privacy/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.