Skip to content

systrap: Deliver SIGILL at reverted patch sites that were overwritten - #15457

Open
copybara-service[bot] wants to merge 1 commit into
masterfrom
test/cl994734611
Open

copybara-service[bot] wants to merge 1 commit into
masterfrom
test/cl994734611

Conversation

@copybara-service

Copy link
Copy Markdown

systrap: Deliver SIGILL at reverted patch sites that were overwritten

After UnpatchSyscalls disables syscall patching, HandleFault restarts any
SIGILL raised at offset 0 or 5 of a former patch site, because it only checks
that the address is in s.patches, which is never cleared. If the app
has since placed code there that raises SIGILL, the restart faults again and
Switch keeps restarting it instead of delivering the signal. At offset 5,
each restart also moves RIP back 5 bytes, into whatever code now precedes the
fault.

s.patches is still needed to restart threads that fault while a patch is being
applied or reverted, so keep it, but only restart a thread if the original
"mov sysno, %eax; syscall" is still at the patch site.

After `UnpatchSyscalls` disables syscall patching, `HandleFault` restarts any
`SIGILL` raised at offset 0 or 5 of a former patch site, because it only checks
that the address is in s.patches, which is never cleared. If the app
has since placed code there that raises SIGILL, the restart faults again and
`Switch` keeps restarting it instead of delivering the signal. At offset 5,
each restart also moves RIP back 5 bytes, into whatever code now precedes the
fault.

s.patches is still needed to restart threads that fault while a patch is being
applied or reverted, so keep it, but only restart a thread if the original
"mov sysno, %eax; syscall" is still at the patch site.

PiperOrigin-RevId: 994734611
@copybara-service copybara-service Bot added the exported Issue was exported automatically label Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

exported Issue was exported automatically

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant