fix(unwinder): Guard invalid ARM32 instruction pointers - #1977
Merged
Merged
Conversation
On ARM32, unw_step first asks libunwind whether the current frame is a signal frame. The vendored implementation answers that by reading an instruction directly from the cursor's initial IP. Its local address-space validation is enabled only after this probe, so an unmapped IP faults inside the crash handler instead of returning an unwind error. This surfaced when unrelated stack-layout changes made the handler fallback produce 0x10c as its initial IP. No attachment code ran on that path; the changed layout only exposed the unwinder's unchecked read. The resulting SIGSEGV recursively entered the crash handler and prevented the original abort from being captured. Check /proc/self/maps before calling unw_step. Keep the initial frame, as the existing invalid-stack-pointer path does, but stop the walk before libunwind can dereference an unmapped address. Cover the failure with an ARM32 context whose initial IP is intentionally unmapped.
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## master #1977 +/- ##
==========================================
+ Coverage 74.19% 74.35% +0.16%
==========================================
Files 104 104
Lines 25634 25638 +4
Branches 4626 4627 +1
==========================================
+ Hits 19018 19062 +44
+ Misses 5317 5272 -45
- Partials 1299 1304 +5 🚀 New features to boost your workflow:
|
JoshuaMoelans
approved these changes
Aug 13, 2026
1 task
social4hyq
pushed a commit
to social4hyq/homebrew-core
that referenced
this pull request
Sep 20, 2026
sentry-native 0.16.4 Created-by: HarmonybrewBot Commit-by: HarmonybrewBot Merged-by: HarmonybrewBot Description: Created by `brew bump` --- Created with `brew bump-formula-pr`. - [ ] `resource` blocks have been checked for updates. <details> <summary>release notes</summary> <pre>**Features**: - Windows: report WINE and Proton metadata in a separate runtime context. ([#1995](getsentry/sentry-native#1995)) - Add a public custom HTTP transport client interface (`sentry_http_transport_new`) so applications can plug in their own HTTP client (e.g. platform-native ones) while sentry-native continues to own request queueing, retry/backoff, offline caching, rate-limiting, and client reports. The built-in curl and WinHTTP transports are now implemented against this same interface. ([#1987](getsentry/sentry-native#1987)) - Native/Windows: capture WER report ID and expose as `contexts.wer.report_id` in crash events when the WER integration is enabled. ([#1970](getsentry/sentry-native#1970)) - Add `sentry_set_tags` and `sentry_scope_set_tags` for updating multiple tags with a single scope flush, improving bulk-update performance. ([#1993](getsentry/sentry-native#1993)) - Add `on_crashed_last_run` callback for inspecting crash envelopes from previous runs. ([#1985](getsentry/sentry-native#1985)) - Add `sentry_get_last_event_id` and `sentry_scope_get_last_event_id` for retrieving the last event ID captured with the global or given scope, respectively. ([#1992](getsentry/sentry-native#1992)) - Native/Unix: The native crash daemon now loads `libcurl` dynamically at runtime by default when `SENTRY_LINK_CURL=AUTO`, avoiding `libcurl` linker work during process startup and significantly speeding up startup time. Explicitly set `SENTRY_LINK_CURL=ON` to link it directly. ([#1955](getsentry/sentry-native#1955)) - Add missing public scope mutators: `set_release`, `set_environment`, `set_transaction`, `remove_tag`, `remove_extra`, `remove_context`, and `remove_attachment`. ([#2011](getsentry/sentry-native#2011)) **Deprecations**: - Deprecate `sentry_options_get/set_enable_logs` and `sentry_options_get/set_enable_metrics`. ([#2000](getsentry/sentry-native#2000)) **Fixes**: - Native: store daemon logs, minidumps, crash envelopes, and scratch files in `.run` directories so they are cleaned up with the run instead of accumulating in the database root. Minidumps can still be retained with `cache_keep`, which stores `.dmp` sidecars alongside cached envelopes. ([#1976](getsentry/sentry-native#1976)) - Linux/ARM32: prevent recursive crashes when libunwind receives an unmapped initial instruction pointer during crash handling. ([#1977](getsentry/sentry-native#1977)) - Improve log and metric delivery when telemetry is captured faster than envelopes can be serialized by offloading serialization to an internal thread pool. ([#1946](getsentry/sentry-native#1946)) - Wine: fix OS version detection and cross-compiling Windows builds from Linux. ([#2001](getsentry/sentry-native#2001)) - Destroy condition variables as approriate when no longer needed. ([#2004](getsentry/sentry-native#2004)) - Crashpad/Windows: preserve module CodeView UUIDs for minimal PDB70 records with empty PDB filenames. ([#2003](getsentry/sentry-native#2003)) - Native/Windows: improve crash-processing performance for applications with many threads. ([#2018](getsentry/sentry-native#2018)) - Prevent a race between SDK reinitialization and cleanup of the previous curl client when libcurl is linked directly. ([#2015](https://github.com/getsentry/sentry-native/pull/2015))</pre> <p>View the full release notes at <a href="https://github.com/getsentry/sentry-native/releases/tag/0.16.4">https://github.com/getsentry/sentry-native/releases/tag/0.16.4</a>.</p> </details> <hr> See merge request: Harmonybrew/homebrew-core!17725
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
On ARM32,
unw_stepfirst askslibunwindwhether the current frame is a signal frame. The vendored implementation answers that by reading an instruction directly from the cursor's initial IP. Its local address-space validation is enabled only after this probe, so an unmapped IP faults inside the crash handler instead of returning an unwind error.This surfaced when unrelated stack-layout changes in #1974 made the handler fallback produce
0x10cas its initial IP. No attachment code ran on that path; the changed layout only exposed the unwinder's unchecked read. The resultingSIGSEGVrecursively entered the crash handler and prevented the original abort from being captured.Check
/proc/self/mapsbefore callingunw_step. Keep the initial frame, as the existing invalid-stack-pointer path does, but stop the walk beforelibunwindcan dereference an unmapped address. Cover the failure with an ARM32 context whose initial IP is intentionally unmapped.