Skip to content

fix(unwinder): Guard invalid ARM32 instruction pointers - #1977

Merged
jpnurmi merged 4 commits into
masterfrom
jpnurmi/fix/unwinder-arm32-ip
Aug 13, 2026
Merged

jpnurmi merged 4 commits into
masterfrom
jpnurmi/fix/unwinder-arm32-ip

Conversation

@jpnurmi

@jpnurmi jpnurmi commented Aug 12, 2026

Copy link
Copy Markdown
Collaborator

On ARM32, unw_step first asks libunwind whether the current frame is a signal frame. The vendored implementation answers that by reading an instruction directly from the cursor's initial IP. Its local address-space validation is enabled only after this probe, so an unmapped IP faults inside the crash handler instead of returning an unwind error.

This surfaced when unrelated stack-layout changes in #1974 made the handler fallback produce 0x10c as its initial IP. No attachment code ran on that path; the changed layout only exposed the unwinder's unchecked read. The resulting SIGSEGV recursively entered the crash handler and prevented the original abort from being captured.

Check /proc/self/maps before calling unw_step. Keep the initial frame, as the existing invalid-stack-pointer path does, but stop the walk before libunwind can dereference an unmapped address. Cover the failure with an ARM32 context whose initial IP is intentionally unmapped.

On ARM32, unw_step first asks libunwind whether the current frame is a
signal frame. The vendored implementation answers that by reading an
instruction directly from the cursor's initial IP. Its local address-space
validation is enabled only after this probe, so an unmapped IP faults inside
the crash handler instead of returning an unwind error.

This surfaced when unrelated stack-layout changes made the handler fallback
produce 0x10c as its initial IP. No attachment code ran on that path; the
changed layout only exposed the unwinder's unchecked read. The resulting
SIGSEGV recursively entered the crash handler and prevented the original
abort from being captured.

Check /proc/self/maps before calling unw_step. Keep the initial frame, as the
existing invalid-stack-pointer path does, but stop the walk before libunwind
can dereference an unmapped address. Cover the failure with an ARM32 context
whose initial IP is intentionally unmapped.
@codecov

codecov Bot commented Aug 12, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 50.00000% with 2 lines in your changes missing coverage. Please review.
✅ Project coverage is 74.35%. Comparing base (efe5fff) to head (67c492c).

Additional details and impacted files
@@            Coverage Diff             @@
##           master    #1977      +/-   ##
==========================================
+ Coverage   74.19%   74.35%   +0.16%     
==========================================
  Files         104      104              
  Lines       25634    25638       +4     
  Branches     4626     4627       +1     
==========================================
+ Hits        19018    19062      +44     
+ Misses       5317     5272      -45     
- Partials     1299     1304       +5     
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@jpnurmi
jpnurmi requested a review from JoshuaMoelans August 13, 2026 07:22
@jpnurmi
jpnurmi merged commit dcf9623 into master Aug 13, 2026
66 checks passed
@jpnurmi
jpnurmi deleted the jpnurmi/fix/unwinder-arm32-ip branch August 13, 2026 12:47
social4hyq pushed a commit to social4hyq/homebrew-core that referenced this pull request Sep 20, 2026
sentry-native 0.16.4

Created-by: HarmonybrewBot
Commit-by: HarmonybrewBot
Merged-by: HarmonybrewBot
Description: Created by `brew bump`

---

Created with `brew bump-formula-pr`.

- [ ] `resource` blocks have been checked for updates.
<details>
  <summary>release notes</summary>
  <pre>**Features**:

- Windows: report WINE and Proton metadata in a separate runtime context. ([#1995](getsentry/sentry-native#1995))
- Add a public custom HTTP transport client interface (`sentry_http_transport_new`) so applications can plug in their own HTTP client (e.g. platform-native ones) while sentry-native continues to own request queueing, retry/backoff, offline caching, rate-limiting, and client reports. The built-in curl and WinHTTP transports are now implemented against this same interface. ([#1987](getsentry/sentry-native#1987))
- Native/Windows: capture WER report ID and expose as `contexts.wer.report_id` in crash events when the WER integration is enabled. ([#1970](getsentry/sentry-native#1970))
- Add `sentry_set_tags` and `sentry_scope_set_tags` for updating multiple tags with a single scope flush, improving bulk-update performance. ([#1993](getsentry/sentry-native#1993))
- Add `on_crashed_last_run` callback for inspecting crash envelopes from previous runs. ([#1985](getsentry/sentry-native#1985))
- Add `sentry_get_last_event_id` and `sentry_scope_get_last_event_id` for retrieving the last event ID captured with the global or given scope, respectively. ([#1992](getsentry/sentry-native#1992))
- Native/Unix: The native crash daemon now loads `libcurl` dynamically at runtime by default when `SENTRY_LINK_CURL=AUTO`, avoiding `libcurl` linker work during process startup and significantly speeding up startup time. Explicitly set `SENTRY_LINK_CURL=ON` to link it directly. ([#1955](getsentry/sentry-native#1955))
- Add missing public scope mutators: `set_release`, `set_environment`, `set_transaction`, `remove_tag`, `remove_extra`, `remove_context`, and `remove_attachment`. ([#2011](getsentry/sentry-native#2011))

**Deprecations**:

- Deprecate `sentry_options_get/set_enable_logs` and `sentry_options_get/set_enable_metrics`. ([#2000](getsentry/sentry-native#2000))

**Fixes**:

- Native: store daemon logs, minidumps, crash envelopes, and scratch files in `.run` directories so they are cleaned up with the run instead of accumulating in the database root. Minidumps can still be retained with `cache_keep`, which stores `.dmp` sidecars alongside cached envelopes. ([#1976](getsentry/sentry-native#1976))
- Linux/ARM32: prevent recursive crashes when libunwind receives an unmapped initial instruction pointer during crash handling. ([#1977](getsentry/sentry-native#1977))
- Improve log and metric delivery when telemetry is captured faster than envelopes can be serialized by offloading serialization to an internal thread pool. ([#1946](getsentry/sentry-native#1946))
- Wine: fix OS version detection and cross-compiling Windows builds from Linux. ([#2001](getsentry/sentry-native#2001))
- Destroy condition variables as approriate when no longer needed. ([#2004](getsentry/sentry-native#2004))
- Crashpad/Windows: preserve module CodeView UUIDs for minimal PDB70 records with empty PDB filenames. ([#2003](getsentry/sentry-native#2003))
- Native/Windows: improve crash-processing performance for applications with many threads. ([#2018](getsentry/sentry-native#2018))
- Prevent a race between SDK reinitialization and cleanup of the previous curl client when libcurl is linked directly. ([#2015](https://github.com/getsentry/sentry-native/pull/2015))</pre>
  <p>View the full release notes at <a href="https://github.com/getsentry/sentry-native/releases/tag/0.16.4">https://github.com/getsentry/sentry-native/releases/tag/0.16.4</a>.</p>
</details>
<hr>

See merge request: Harmonybrew/homebrew-core!17725
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants