Skip to content

Commit

Permalink
sh: Fix bug calculating the end of the FDE instructions
Browse files Browse the repository at this point in the history
The 'end' member of struct dwarf_fde denotes one byte past the end of
the CFA instruction stream for an FDE. The value of 'end' was being
calcualted incorrectly, it was being set too high. This resulted in
dwarf_cfa_execute_insns() interpreting data past the end of valid
instructions, thus causing all sorts of weird crashes.

Signed-off-by: Matt Fleming <matt@console-pimps.org>
  • Loading branch information
Matt Fleming committed Aug 21, 2009
1 parent fe98dd3 commit 5480675
Showing 1 changed file with 4 additions and 3 deletions.
7 changes: 4 additions & 3 deletions arch/sh/kernel/dwarf.c
Original file line number Diff line number Diff line change
Expand Up @@ -751,7 +751,8 @@ static int dwarf_parse_cie(void *entry, void *p, unsigned long len,
}

static int dwarf_parse_fde(void *entry, u32 entry_type,
void *start, unsigned long len)
void *start, unsigned long len,
unsigned char *end)
{
struct dwarf_fde *fde;
struct dwarf_cie *cie;
Expand Down Expand Up @@ -798,7 +799,7 @@ static int dwarf_parse_fde(void *entry, u32 entry_type,

/* Call frame instructions. */
fde->instructions = p;
fde->end = start + len;
fde->end = end;

/* Add to list. */
spin_lock_irqsave(&dwarf_fde_lock, flags);
Expand Down Expand Up @@ -932,7 +933,7 @@ static int __init dwarf_unwinder_init(void)
else
c_entries++;
} else {
err = dwarf_parse_fde(entry, entry_type, p, len);
err = dwarf_parse_fde(entry, entry_type, p, len, end);
if (err < 0)
goto out;
else
Expand Down

0 comments on commit 5480675

Please sign in to comment.