Bug 1716380
| Summary: | elfutils (eu-strip) segmentation fault in handle_elf (strip.c:1978) | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Damian Wrobel <dwrobel> |
| Component: | elfutils | Assignee: | Mark Wielaard <mjw> |
| Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | medium | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 30 | CC: | fche, fweimer, jakub, me, mjw |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | elfutils-0.176-3.fc30 | Doc Type: | If docs needed, set a value |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2019-06-22 01:02:43 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 1659055 | ||
|
Description
Damian Wrobel
2019-06-03 11:22:05 UTC
(In reply to Damian Wrobel from comment #0) > or (probably faster) just download > https://dwrobel.fedorapeople.org/projects/bugz/eu-strip/qat_c3xxx.ko and > execute: > $ eu-strip --remove-comment --reloc-debug-sections -f qat_c3xxx.ko.debug > qat_c3xxx.ko Thanks. I can replicate the crash with that. It certainly shouldn't crash, so I'll look into that. But... It does look like the https://dwrobel.fedorapeople.org/projects/bugz/eu-strip/qat_c3xxx.ko is already corrupted. If you inspect the section headers, even before stripping: $ eu-readelf -S qat_c3xxx.ko There are 30 section headers, starting at offset 0x4198: Section Headers: [Nr] Name Type Addr Off Size ES Flags Lk Inf Al [ 0] symtab NULL 0000000000000000 00000000 00000000 0 0 0 0 [ 1] ote.gnu.build-id NOTE 0000000000000000 00000040 00000024 0 A 0 0 4 [ 2] ote.Linux NOTE 0000000000000000 00000064 00000034 0 A 0 0 4 [ 3] ext PROGBITS 0000000000000000 000000a0 0000095d 0 AX 0 0 16 [ 4] ela.text RELA 0000000000000000 00002900 00000c18 24 I 27 3 8 [ 5] ext.unlikely PROGBITS 0000000000000000 000009fd 0000000d 0 AX 0 0 1 [ 6] ela.text.unlikely RELA 0000000000000000 00003518 00000030 24 I 27 5 8 [ 7] nit.text PROGBITS 0000000000000000 00000a0a 00000046 0 AX 0 0 1 [ 8] ela.init.text RELA 0000000000000000 00003548 000000d8 24 I 27 7 8 [ 9] xit.text PROGBITS 0000000000000000 00000a50 0000000c 0 AX 0 0 1 [10] ela.exit.text RELA 0000000000000000 00003620 00000030 24 I 27 9 8 [11] odata PROGBITS 0000000000000000 00000a60 00000058 0 A 0 0 32 [12] mcount_loc PROGBITS 0000000000000000 00000ab8 000000a0 0 A 0 0 1 [13] ela__mcount_loc RELA 0000000000000000 00003650 000001e0 24 I 27 12 8 [14] odata.str1.1 PROGBITS 0000000000000000 00000b58 00000127 1 AMS 0 0 1 [15] odata.str1.8 PROGBITS 0000000000000000 00000c80 000000a0 1 AMS 0 0 8 [16] odinfo PROGBITS 0000000000000000 00000d20 00000158 0 A 0 0 16 [17] rc_unwind_ip PROGBITS 0000000000000000 00000e78 00000140 0 A 0 0 1 [18] ela.orc_unwind_ip RELA 0000000000000000 00003830 00000780 24 I 27 17 8 [19] rc_unwind PROGBITS 0000000000000000 00000fb8 000001e0 0 A 0 0 1 [20] ata PROGBITS 0000000000000000 000011a0 00000140 0 WA 0 0 32 [21] ela.data RELA 0000000000000000 00003fb0 00000090 24 I 27 20 8 [22] nu.linkonce.this_module PROGBITS 0000000000000000 00001300 00000380 0 WA 0 0 64 [23] ela.gnu.linkonce.this_module RELA 0000000000000000 00004040 00000030 24 I 27 22 8 [24] ss NOBITS 0000000000000000 00001680 00000000 0 WA 0 0 1 [25] omment PROGBITS 0000000000000000 00001680 00000087 1 MS 0 0 1 [26] ote.GNU-stack PROGBITS 0000000000000000 00001707 00000000 0 0 0 1 [27] ymtab SYMTAB 0000000000000000 00001708 00000b28 24 28 60 8 [28] trtab STRTAB 0000000000000000 00002230 000006cf 0 0 0 1 [29] hstrtab STRTAB 0000000000000000 00004070 00000122 0 0 0 1 There is clearly some off-by-2 going on. All names have their . and first letter chopped off. This might be some other process adjusting the ELF .ko file earlier. Which might be rpm debugedit. If so, then this might be: https://github.com/rpm-software-management/rpm/issues/423 Which turned out to actually also being a elfutils/libelf bug: https://sourceware.org/ml/elfutils-devel/2019-q2/msg00077.html I can backport that fix to the fedora (rawhide) package. Would it be possible to do a rebuild using that? (In reply to Mark Wielaard from comment #1) > I can backport that fix to the fedora (rawhide) package. > Would it be possible to do a rebuild using that? Yes, certainly. It should be just a matter of doing: $ mock -r fedora-rawhide-x86_64 --rebuild kernel-5.0.19-300.rt11.3.fc30.src.rpm when the backport will be available in the rawhide. (In reply to Damian Wrobel from comment #2) > (In reply to Mark Wielaard from comment #1) > > I can backport that fix to the fedora (rawhide) package. > > Would it be possible to do a rebuild using that? > > Yes, certainly. It should be just a matter of doing: > $ mock -r fedora-rawhide-x86_64 --rebuild > kernel-5.0.19-300.rt11.3.fc30.src.rpm > when the backport will be available in the rawhide. Thanks. If you could try with elfutils-0.176-3.fc31 that would be appreciated. https://koji.fedoraproject.org/koji/buildinfo?buildID=1278740 > Thanks. If you could try with elfutils-0.176-3.fc31 that would be
> appreciated.
> https://koji.fedoraproject.org/koji/buildinfo?buildID=1278740
Mark,
I can confirm that 0.176-3 version fixes the issue and I was able to successfully build kernel package with debuginfo.
Thank you for the support.
I think the issue can be closed unless there is a plan to backport the fix to f30 as well.
(In reply to Damian Wrobel from comment #4) > I can confirm that 0.176-3 version fixes the issue and I was able to > successfully build kernel package with debuginfo. > Thank you for the support. Thanks for testing. I am both happy and slightly concerned this fixed the issue. This bug has been in the code for a very long time. It is slightly surprising it has hit multiple times now recently (I also did get a report from a suse and a gentoo user). Maybe in the past people hadn't noticed or didn't report it. > I think the issue can be closed unless there is a plan to backport the fix > to f30 as well. I'll backport it to f30 too. FEDORA-2019-3c0523b33c has been submitted as an update to Fedora 30. https://bodhi.fedoraproject.org/updates/FEDORA-2019-3c0523b33c elfutils-0.176-3.fc30 has been pushed to the Fedora 30 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2019-3c0523b33c *** Bug 1659047 has been marked as a duplicate of this bug. *** (In reply to Mark Wielaard from comment #1) > (In reply to Damian Wrobel from comment #0) > > or (probably faster) just download > > https://dwrobel.fedorapeople.org/projects/bugz/eu-strip/qat_c3xxx.ko and > > execute: > > $ eu-strip --remove-comment --reloc-debug-sections -f qat_c3xxx.ko.debug > > qat_c3xxx.ko > > Thanks. I can replicate the crash with that. > It certainly shouldn't crash, so I'll look into that. And I finally did. The crash was fixed upstream by: commit f03ac75239e0981deaf4aa18f66f423bcc5ce051 Author: Mark Wielaard <mark> Date: Wed Mar 27 21:54:06 2019 +0100 strip: Files with symbols referring to non-existing sections are illformed The check added in commit 4540ea98c "strip: Fix check test for SHN_XINDEX symbol" was not complete. The (extended) section index should also exist. If it doesn't exist, mark the file as illformed. https://sourceware.org/bugzilla/show_bug.cgi?id=24385 Signed-off-by: Mark Wielaard <mark> Which isn't in Fedora yet. But the underlying bug fix, that created the bad ELF file in the first place now is. elfutils-0.176-3.fc30 has been pushed to the Fedora 30 stable repository. If problems still persist, please make note of it in this bug report. |