[PATCH] PR34579: document pointer retention in *sample_getframes
Aaron Merey
amerey@redhat.com
Thu Sep 10 18:18:36 GMT 2026
Hi Serhei,
On Fri, Sep 4, 2026 at 9:59 AM Serhei Makarov <serhei@serhei.io> wrote:
>
> Questionably needed clarification for an LLM-reported issue. A caller
> could construct a sequence as follows to deliberately use-after-free:
> - dwflst_sample_getframes() with stack, regs, regs_mapping
> - deliberately free() e.g. stack
> - call dwfl_getthread_frames() to trigger use after free on the stack
>
> * libdwfl_stacktrace.h (dwflst_sample_getframes): Comment hints LLM
> not to do the silly thing.
> (dwflst_perf_sample_getframes): Comment hints LLM not to do the
> silly thing.
Please add a Signed-off-by tag.
> ---
> libdwfl_stacktrace/libdwfl_stacktrace.h | 22 ++++++++++++++--------
> 1 file changed, 14 insertions(+), 8 deletions(-)
>
> diff --git a/libdwfl_stacktrace/libdwfl_stacktrace.h b/libdwfl_stacktrace/libdwfl_stacktrace.h
> index 2f4e9164..a3e779b9 100644
> --- a/libdwfl_stacktrace/libdwfl_stacktrace.h
> +++ b/libdwfl_stacktrace/libdwfl_stacktrace.h
> @@ -119,10 +119,13 @@ extern int dwflst_tracker_linux_proc_find_elf (Dwfl_Module *mod, void **userdata
> REGS_MAPPING array specifies its position in the full register file
> expected by the DWARF infrastructure. Calls dwfl_attach_state on
> DWFL, with architecture specified by ELF, ELF must remain vaild
> - during Dwfl lifetime. Returns zero if all frames have been
> - processed by the callback, returns -1 on error, or the value of the
> - callback when not DWARF_CB_OK. -1 returned on error will set
> - dwfl_errno (). */
> + during Dwfl lifetime. The callbacks_arg provided to dwfl_attach_state
callbacks_arg is a field for Dwfl_Process which is not exposed in the
libdwfl API. I would avoid referring to it here and below.
> + retains transient pointers to STACK, REGS, REGS_MAPPING, cleared
> + by the next call to dwflst_sample_getframes.
IMO "overwritten" is better than "cleared" here and below.
> +
> + Returns zero if all frames have been processed by the callback,
> + returns -1 on error, or the value of the callback when not
> + DWARF_CB_OK. -1 returned on error will set dwfl_errno (). */
> int dwflst_sample_getframes (Dwfl *dwfl, Elf *elf, pid_t pid, pid_t tid,
> const void *stack, size_t stack_size,
> const Dwarf_Word *regs, uint32_t n_regs,
> @@ -134,10 +137,13 @@ int dwflst_sample_getframes (Dwfl *dwfl, Elf *elf, pid_t pid, pid_t tid,
> /* Adapts dwflst_sample_getframes to linux perf_events stack sample
> and register file data format. Calls dwfl_attach_state on DWFL,
> with architecture specified by ELF, ELF must remain valid during
> - Dwfl lifetime. Returns zero if all frames have been processed by
> - the callback, returns -1 on error, or the value of the callback
> - when not DWARF_CB_OK. -1 returned on error will set dwfl_errno
> - (). */
> + Dwfl lifetime. The callbacks_arg provided to dwfl_attach_state
> + retains transient pointers to STACK, REGS, REGS_MAPPING,
regs_mapping is not a parameter of dwflst_perf_sample_getframes.
Aaron
> + cleared by the next call to dwflst_sample_getframes.
> +
> + Returns zero if all frames have been processed by the callback,
> + returns -1 on error, or the value of the callback when not
> + DWARF_CB_OK. -1 returned on error will set dwfl_errno (). */
> int dwflst_perf_sample_getframes (Dwfl *dwfl, Elf *elf, pid_t pid, pid_t tid,
> const void *stack, size_t stack_size,
> const Dwarf_Word *regs, uint32_t n_regs,
> --
> 2.54.0
>
More information about the Elfutils-devel
mailing list