DynamoRIO / DynamoRIO/drmemory

UNINITs in USP10.dll that likely all need per-bit granularity

Open
#493 5 comments 0 reactions 0 assignees View on GitHub
Bug-FalsePositive FalsePos-BitLevel Migrated OpSys-Windows Priority-Medium
Dominant language
C
Stars
2.7k
Forks
290
PR merge metrics
No merged PRs in 30d

Description

_From [bruen...@google.com](https://code.google.com/u/109494838902877177630/) on July 14, 2011 22:08:40_

xref issue #492 I see 5 other callstacks and while I have not analyzed them to prove it I suspect that they all (with perhaps the exception of USP10.dll!CUspShapingDrawingSurface::GenericGlyphOut? needs analysis), like issue #492 , are false positives coming from unusual bit manipulations.

**\* TODO UNINIT in USP10.dll!CStackAllocator::Free

in calc:
Error `#2`: UNINITIALIZED READ: reading register cl
@0:03:21.153 in thread 2940
0x770b7448 USP10.dll!CStackAllocator::Free
0x770d0891 USP10.dll!CUspShapingCacheWriter::SubmitCacheSlot
0x770d5244 USP10.dll!ShapingCreateFontCacheData
0x770ada3b USP10.dll!ShlLoadFont
0x770adf74 USP10.dll!LoadFont
0x770a9b07 USP10.dll!FindOrCreateFaceCache
0x75256bc8 f6 c1 01 test %cl $0x01

hit on gui-inject also though w/ a different callstack:
Error `#1`: UNINITIALIZED READ: reading register cl
@0:00:01.867 in thread 1984
0x75256bc8 USP10.dll!CStackAllocator::Free
0x75285e0d USP10.dll!GenericEngineGetBreakingProperties
0x752752b9 USP10.dll!ShapingGetBreakingProperties
0x75272630 USP10.dll!ShlBreak
0x75256bc8 f6 c1 01 test %cl $0x01
0:000> dt shadow_registers_t 7efdd000+ec4
+0x000 eax : 0 ''
+0x001 ecx : 0xff ''
+0x002 edx : 0 ''
+0x003 ebx : 0 ''
+0x004 esp : 0 ''
+0x005 ebp : 0 ''
+0x006 esi : 0 ''
+0x007 edi : 0 ''
+0x008 eflags : 0 ''
USP10!CStackAllocator::Free+0x13:
75256bc3 8d41f4 lea eax,[ecx-0xc]
75256bc6 8b08 mov ecx,[eax]
75256bc8 f6c101 test cl,0x1

eax = 0x22a4804
0:000> dyb @@(((char *)shadow_table[0x022a]) + (0x022a4804/4)) L8
76543210 76543210 76543210 76543210
-------- -------- -------- --------
2721d4a9 11111111 00000000 00000000 00000011 ff 00 00 03
2721d4ad 00000011 00000011 00000011 00000011 03 03 03 03

no syms:
0x75256bc8 USP10.dll!UspFreeMem
0x75285e0d USP10.dll!ScriptPositionSingleGlyph
0x752752b9 USP10.dll!ScriptPositionSingleGlyph

**\* TODO UNINIT in USP10.dll!GenericEngineGetBreakingProperties

Error `#1`: UNINITIALIZED READ: reading register bl
@0:00:01.867 in thread 2200
0x75285d60 USP10.dll!GenericEngineGetBreakingProperties
0x752752b9 USP10.dll!ShapingGetBreakingProperties
0x75272630 USP10.dll!ShlBreak
0x75246937 USP10.dll!ScriptBreak
0x752542c4 USP10.dll!ScriptStringAnalyzeBreaks
0x76265465 LPK.dll!LpkStringAnalyse
0x76264dba LPK.dll!LpkGetNextWord
0x76261425 LPK.dll!LpkDrawTextEx
0x76d142c8 USER32.dll!GetNextWordbreak
0x76d12423 USER32.dll!DT_GetLineBreak
0x76d1237a USER32.dll!DrawTextExWorker
0x76d114bc USER32.dll!DrawTextExW

75285ccd 57 push edi
75285cce 8b7df4 mov edi,[ebp-0xc]
75285cd1 57 push edi
75285cd2 56 push esi
75285cd3 53 push ebx
75285cd4 e807210000 call USP10!GetCharClassification (75287de0)

75285cd9 8bf0 mov esi,eax
75285cdb 85f6 test esi,esi
75285cdd 741a jz USP10!GenericEngineGetBreakingProperties+0x89 (75285cf9)

75285cf9 33f6 xor esi,esi
75285cfb 397510 cmp [ebp+0x10],esi
75285cfe 0f8efa000000 jle USP10!GenericEngineGetBreakingProperties+0x18e (75285dfe)

75285d04 8b4df4 mov ecx,[ebp-0xc]
75285d07 8b04b1 mov eax,[ecx+esi*4]
75285d0a 8bd8 mov ebx,eax
75285d0c 33ff xor edi,edi
75285d0e c1eb04 shr ebx,0x4
75285d11 85f6 test esi,esi
75285d13 7e49 jle USP10!GenericEngineGetBreakingProperties+0xee (75285d5e)

75285d5e 33c0 xor eax,eax
75285d60 f6c310 test bl,0x10
75285d63 7420 jz USP10!GenericEngineGetBreakingProperties+0x115 (75285d85)

ecx = 0x2484810
0:000> dyb @@(((char *)shadow_table[0x0248]) + (0x02484810/4)) L8
76543210 76543210 76543210 76543210
-------- -------- -------- --------
1d1ed4ac 00000011 00000011 00000011 00000011 03 03 03 03
1d1ed4b0 00000011 11111111 11111111 11111111 03 ff ff ff

the shr by 4 isn't enough to push the whole bottom uninit byte: but I
wonder if this is another one that needs per-bit.
will take some analysis: not doing it now.

no symbols:
Error `#1`: UNINITIALIZED READ: reading register bl
0x75285d60 USP10.dll!ScriptPositionSingleGlyph
0x752752b9 USP10.dll!ScriptPositionSingleGlyph
0x75272630 USP10.dll!ScriptPositionSingleGlyph

**\* TODO more UNINITs in USP10.dll

Error `#2`: UNINITIALIZED READ: reading register al
@0:00:04.073 in thread 4180
0x752860ea USP10.dll!GenericEngineGetGlyphs
0x7527512a USP10.dll!ShapingGetGlyphs
0x7527221f USP10.dll!ShlShape
0x75245c6f USP10.dll!ScriptShape
0x752518af USP10.dll!RenderItemNoFallback
0x75252ab4 USP10.dll!RenderItemWithFallback
0x75252d42 USP10.dll!RenderItem
0x752540f9 USP10.dll!ScriptStringAnalyzeGlyphs
0x75247a14 USP10.dll!ScriptStringAnalyse
0x76265465 LPK.dll!LpkStringAnalyse
0x76265172 LPK.dll!LpkCharsetDraw
0x76261410 LPK.dll!LpkDrawTextEx
0x752860ea a8 01 test %al $0x01

Error `#4`: UNINITIALIZED READ: reading register al
@0:01:59.496 in thread 4180
0x75275675 USP10.dll!ShapingGetGlyphPositions
0x7527286a USP10.dll!ShlPlace
0x75245e45 USP10.dll!ScriptPlace
0x7525181d USP10.dll!RenderItemNoFallback
0x75252ab4 USP10.dll!RenderItemWithFallback
0x75252d42 USP10.dll!RenderItem
0x752540f9 USP10.dll!ScriptStringAnalyzeGlyphs
0x75247a14 USP10.dll!ScriptStringAnalyse
0x76265465 LPK.dll!LpkStringAnalyse
0x76265172 LPK.dll!LpkCharsetDraw
0x76261410 LPK.dll!LpkDrawTextEx
0x76d11898 USER32.dll!DT_DrawStr
0x75275675 a8 01 test %al $0x01

Error `#3`: UNINITIALIZED READ: reading 0x0018ea4c-0x0018ea4d 1 byte(s) within 0x0018ea4c-0x0018ea50
@0:00:45.099 in thread 1232
0x75270a79 USP10.dll!CUspShapingDrawingSurface::GenericGlyphOut
0x75270124 USP10.dll!CUspShapingDrawingSurface::DrawGlyphs
0x7528573b USP10.dll!GenericEngineDrawGlyphs
0x752759fa USP10.dll!ShapingDrawGlyphs
0x75272efd USP10.dll!ShlTextOut
0x75246122 USP10.dll!ScriptTextOut
0x75255af9 USP10.dll!InternalStringOut
0x752483be USP10.dll!ScriptStringOut
0x762651a9 LPK.dll!LpkCharsetDraw
0x76261410 LPK.dll!LpkDrawTextEx
0x76d11898 USER32.dll!DT_DrawStr
0x76d1182a USER32.dll!DT_DrawJustifiedLine
0x75270a79 39 4d 1c cmp 0x1c(%ebp) %ecx

_Original issue: http://code.google.com/p/drmemory/issues/detail?id=493_

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.