[PATCH 5/8] alpha: Fix the la_pltexit path of _dl_runtime_profile

Adhemerval Zanella adhemerval.zanella@linaro.org
Mon Sep 28 18:55:09 GMT 2026


The la_pltexit path of both _dl_runtime_profile_new and
_dl_runtime_profile_old had two issues:

  - The call destination was saved in the new argument frame, which
    the memcpy of the stack arguments then overwrote. The trampoline
    jumped to a random address for any frame size larger than 14*8.

  - The return values were not reloaded from La_alpha_retval after
    _dl_audit_pltexit. The caller got whatever _dl_audit_pltexit
    left in the return registers.

The tst-audit-plt-flags XFAIL is removed.

Checked on alpha-linux-gnu.
---
 sysdeps/alpha/Makefile        |  4 ----
 sysdeps/alpha/dl-trampoline.S | 26 ++++++++++++++++++++------
 2 files changed, 20 insertions(+), 10 deletions(-)

diff --git a/sysdeps/alpha/Makefile b/sysdeps/alpha/Makefile
index ebf6288ccc4..faa59ab27a6 100644
--- a/sysdeps/alpha/Makefile
+++ b/sysdeps/alpha/Makefile
@@ -69,10 +69,6 @@ CFLAGS-s_isnan.c += -fno-builtin-isnanf
 test-xfail-test-float32x-float64-div = yes
 endif
 
-ifeq ($(subdir),elf)
-test-xfail-tst-audit-plt-flags = yes
-endif
-
 # Build everything with full IEEE math support, and with dynamic rounding;
 # there are a number of math routines that are defined to work with the
 # "current" rounding mode, and it's easiest to set this with all of them.
diff --git a/sysdeps/alpha/dl-trampoline.S b/sysdeps/alpha/dl-trampoline.S
index c69d03c03b8..2602b3d0c58 100644
--- a/sysdeps/alpha/dl-trampoline.S
+++ b/sysdeps/alpha/dl-trampoline.S
@@ -161,8 +161,9 @@ _dl_runtime_profile_new:
 	bic	$18, 15, $18
 	subq	$30, $18, $30
 
-	/* Save the call destination around memcpy.  */
-	stq	$0, 14*8($30)
+	/* Save the call destination around memcpy, in the fixed frame
+	   since the new argument frame is overwritten by the copy.  */
+	stq	$0, 14*8($15)
 
 	/* Copy the stack arguments into place.  */
 	lda	$16, 0($30)
@@ -171,7 +172,7 @@ _dl_runtime_profile_new:
 	ldgp	$29, 0($26)
 
 	/* Reload the argument registers.  */
-	ldq	$27, 14*8($30)
+	ldq	$27, 14*8($15)
 	ldq	$16, 2*8($15)
 	ldq	$17, 3*8($15)
 	ldq	$18, 4*8($15)
@@ -199,6 +200,12 @@ _dl_runtime_profile_new:
 	stt	$f1, 19*8($15)
 	bsr	$26, _dl_audit_pltexit	!samegp
 
+	/* Reload the return values, which la_pltexit may change.  */
+	ldq	$0, 16*8($15)
+	ldq	$1, 17*8($15)
+	ldt	$f0, 18*8($15)
+	ldt	$f1, 19*8($15)
+
 	mov	$15, $30
 	cfi_def_cfa_register (30)
 	ldq	$26, 0($30)
@@ -494,8 +501,9 @@ _dl_runtime_profile_old:
 	bic	$18, 15, $18
 	subq	$30, $18, $30
 
-	/* Save the call destination around memcpy.  */
-	stq	$0, 46*8($30)
+	/* Save the call destination around memcpy, in the fixed frame
+	   since the new argument frame is overwritten by the copy.  */
+	stq	$0, 46*8($15)
 
 	/* Copy the stack arguments into place.  */
 	lda	$16, 0($30)
@@ -504,7 +512,7 @@ _dl_runtime_profile_old:
 	ldgp	$29, 0($26)
 
 	/* Reload the argument registers.  */
-	ldq	$27, 46*8($30)
+	ldq	$27, 46*8($15)
 	ldq	$16, 2*8($15)
 	ldq	$17, 3*8($15)
 	ldq	$18, 4*8($15)
@@ -532,6 +540,12 @@ _dl_runtime_profile_old:
 	stt	$f1, 49*8($15)
 	bsr	$26, _dl_audit_pltexit	!samegp
 
+	/* Reload the return values, which la_pltexit may change.  */
+	ldq	$0, 46*8($15)
+	ldq	$1, 47*8($15)
+	ldt	$f0, 48*8($15)
+	ldt	$f1, 49*8($15)
+
 	mov	$15, $30
 	cfi_def_cfa_register (30)
 	ldq	$26, 0($30)
-- 
2.53.0



More information about the Libc-alpha mailing list