DynamoRIO / DynamoRIO/dynamorio

CRASH on AArch64 when many signals are received

Open
#2,358 0 comments 0 reactions 0 assignees View on GitHub
OpSys-AArch64
Dominant language
C
Stars
3.2k
Forks
629
Avg merge
2d 15h
Merged PRs (30d)
31

Description

DynamoRIO 4afa0bd. I've only tested this on AArch64.

I'll reference [this test](https://github.com/beehive-lab/mambo/blob/e576a68d9854a6b75e175986e3426a91bc38450a/test/signals.c#L162) again. In this case, a new thread is started, which sends RT signals back to its parent in a tight loop. On my system, if more than 15 signals are sent, then DynamoRIO crashes reliably.

If debugging is not enabled, then I'm getting either a SIGILL or a segmentation fault. This is the output with debugging enabled:

```
$ ~/dynamorio/build/bin64/drrun -debug ./signals

<(1+x) Handling our fault in a TRY at 0x000000555a658730>
Simple signal handler:
success
Signal after flushing the code cache: success
Test against race conditions between code generation and signals: success
Test for missed signals: top_unit == NULL || su->use_lock
(Error occurred @10292 frags)
version 6.2.17273, custom build
-no_dynamic_options -code_api -stack_size 56K -max_elide_jmp 0 -max_elide_call 0 -early_inject -emulate_brk -no_inline_ignored_syscalls -native_exec_default_list '' -no_native_exec_managed_code -no_indcall2direct
0x00000000546684a0 0x000000555a43a5fc
0x0000000054668630 0x000000555a4e10f4
0x0000000054668860 0x000000555a4e2ce0
0x0000000054668990 0x000000555a4e3644
0x0000000054668ab0 0x000000555a67c1f8
0x0000000054668ad0 0x000000555a67e904
0x0000000054669d00 0x000000555a658830
0x000000005466aff0 0x000000555a658830
0x0000007fc3e01820 0x000000000040256c
0x0000007fc3e01890 0x0000007fa34b48a0
0x0000007fc3e01990 0x0000000000400cb8>
```

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.