Using binary breakpoints in GDB - how exact is the location?

Viewed 69

I have some memorydumps from Linux Redhat GCC compiled programs like:

/apps/suns/runtime/bin/mardb82[0x40853b]

When I open mardb82 and put the breakpoint with break *0x40853b it will give me C filename/lineno which seems quite correct, but not completely.

Can I trust it, and what does it depend on? Is it sufficient if the source file in question is the same or does the files making up the executable have to be the same?

Can I find the locations in sources in some other way?

(Max debug info and sources are present, I haven't tried not having the sources present or passing them in)

1 Answers

When I open mardb82 and put the breakpoint with break *0x40853b it will give me C filename/lineno which seems quite correct, but not completely.

A faster way to get the filename/line:

addr2line -fe /path/to/mardb82 0x40853b

You didn't say where the ...bin/mardb82[0x40853b] line came from. Assuming it is a part of a crash stack, note that the instruction is usually the next after a CALL, so you may be interested in 0x40853b-5 (on *86 architectures) for all but the innermost level in the stack.

what does it depend on? Is it sufficient if the source file in question is the same or does the files making up the executable have to be the same?

The instruction address depends on the particular executable. Any change to source code comprising that executable, to compilation or linking flags, etc. etc. may cause the instructions to shift to a different address.

Related