* stab nearest_line bfd_malloc_and_get_section
@ 2022-09-26 5:23 Alan Modra
0 siblings, 0 replies; 2+ messages in thread
From: Alan Modra @ 2022-09-26 5:23 UTC (permalink / raw)
To: binutils
bfd_malloc_and_get_section performs some sanity checks on the section
size before allocating memory. This patch avails the stab
nearest_line code of that sanity checking, and tidies up memory
afterward.
* coffgen.c (_bfd_coff_close_and_cleanup): Call _bfd_stab_cleanup.
* elf.c (_bfd_elf_close_and_cleanup): Likewise.
* syms.c (_bfd_stab_section_find_nearest_line): Set *pinfo earlier.
Use bfd_malloc_and_get_section. Free malloc'd buffers on failure.
Malloc indextable.
(_bfd_stab_cleanup): New function.
* libbfd-in.h (_bfd_stab_cleanup): Declare.
* libbfd.h: Regnerate.
diff --git a/bfd/coffgen.c b/bfd/coffgen.c
index 8eb69af2ce2..3e0fbc6184f 100644
--- a/bfd/coffgen.c
+++ b/bfd/coffgen.c
@@ -3175,7 +3175,10 @@ _bfd_coff_close_and_cleanup (bfd *abfd)
if (bfd_get_format (abfd) == bfd_object
|| bfd_get_format (abfd) == bfd_core)
- _bfd_dwarf2_cleanup_debug_info (abfd, &tdata->dwarf2_find_line_info);
+ {
+ _bfd_dwarf2_cleanup_debug_info (abfd, &tdata->dwarf2_find_line_info);
+ _bfd_stab_cleanup (abfd, &tdata->line_info);
+ }
}
return _bfd_generic_close_and_cleanup (abfd);
}
diff --git a/bfd/elf.c b/bfd/elf.c
index 16cea4f8aeb..9a0bc1d2740 100644
--- a/bfd/elf.c
+++ b/bfd/elf.c
@@ -9649,6 +9649,7 @@ _bfd_elf_close_and_cleanup (bfd *abfd)
if (elf_tdata (abfd)->o != NULL && elf_shstrtab (abfd) != NULL)
_bfd_elf_strtab_free (elf_shstrtab (abfd));
_bfd_dwarf2_cleanup_debug_info (abfd, &tdata->dwarf2_find_line_info);
+ _bfd_stab_cleanup (abfd, &tdata->line_info);
}
return _bfd_generic_close_and_cleanup (abfd);
diff --git a/bfd/libbfd-in.h b/bfd/libbfd-in.h
index 04f343b051b..6d9d15f3409 100644
--- a/bfd/libbfd-in.h
+++ b/bfd/libbfd-in.h
@@ -615,6 +615,9 @@ extern bool _bfd_dwarf2_slurp_debug_info
extern void _bfd_dwarf2_cleanup_debug_info
(bfd *, void **) ATTRIBUTE_HIDDEN;
+extern void _bfd_stab_cleanup
+ (bfd *, void **) ATTRIBUTE_HIDDEN;
+
/* Create a new section entry. */
extern struct bfd_hash_entry *bfd_section_hash_newfunc
(struct bfd_hash_entry *, struct bfd_hash_table *, const char *)
diff --git a/bfd/libbfd.h b/bfd/libbfd.h
index a17b98e8e30..a67bded0d18 100644
--- a/bfd/libbfd.h
+++ b/bfd/libbfd.h
@@ -620,6 +620,9 @@ extern bool _bfd_dwarf2_slurp_debug_info
extern void _bfd_dwarf2_cleanup_debug_info
(bfd *, void **) ATTRIBUTE_HIDDEN;
+extern void _bfd_stab_cleanup
+ (bfd *, void **) ATTRIBUTE_HIDDEN;
+
/* Create a new section entry. */
extern struct bfd_hash_entry *bfd_section_hash_newfunc
(struct bfd_hash_entry *, struct bfd_hash_table *, const char *)
diff --git a/bfd/syms.c b/bfd/syms.c
index 7a454c5d7e7..ec62f3457ca 100644
--- a/bfd/syms.c
+++ b/bfd/syms.c
@@ -978,7 +978,7 @@ _bfd_stab_section_find_nearest_line (bfd *abfd,
{
if (info->stabsec == NULL || info->strsec == NULL)
{
- /* No stabs debugging information. */
+ /* No usable stabs debugging information. */
return true;
}
@@ -1000,6 +1000,7 @@ _bfd_stab_section_find_nearest_line (bfd *abfd,
info = (struct stab_find_info *) bfd_zalloc (abfd, amt);
if (info == NULL)
return false;
+ *pinfo = info;
/* FIXME: When using the linker --split-by-file or
--split-by-reloc options, it is possible for the .stab and
@@ -1015,12 +1016,7 @@ _bfd_stab_section_find_nearest_line (bfd *abfd,
info->strsec = bfd_get_section_by_name (abfd, "$GDB_STRINGS$");
if (info->stabsec == NULL || info->strsec == NULL)
- {
- /* No stabs debugging information. Set *pinfo so that we
- can return quickly in the info != NULL case above. */
- *pinfo = info;
- return true;
- }
+ return true;
}
stabsize = (info->stabsec->rawsize
@@ -1031,16 +1027,10 @@ _bfd_stab_section_find_nearest_line (bfd *abfd,
? info->strsec->rawsize
: info->strsec->size);
- info->stabs = (bfd_byte *) bfd_alloc (abfd, stabsize);
- info->strs = (bfd_byte *) bfd_alloc (abfd, strsize);
- if (info->stabs == NULL || info->strs == NULL)
- return false;
-
- if (! bfd_get_section_contents (abfd, info->stabsec, info->stabs,
- 0, stabsize)
- || ! bfd_get_section_contents (abfd, info->strsec, info->strs,
- 0, strsize))
- return false;
+ if (!bfd_malloc_and_get_section (abfd, info->stabsec, &info->stabs))
+ goto out;
+ if (!bfd_malloc_and_get_section (abfd, info->strsec, &info->strs))
+ goto out1;
/* Stab strings ought to be nul terminated. Ensure the last one
is, to prevent running off the end of the buffer. */
@@ -1052,15 +1042,24 @@ _bfd_stab_section_find_nearest_line (bfd *abfd,
this should be no big deal. */
reloc_size = bfd_get_reloc_upper_bound (abfd, info->stabsec);
if (reloc_size < 0)
- return false;
+ goto out2;
reloc_vector = (arelent **) bfd_malloc (reloc_size);
if (reloc_vector == NULL && reloc_size != 0)
- return false;
+ goto out2;
reloc_count = bfd_canonicalize_reloc (abfd, info->stabsec, reloc_vector,
symbols);
if (reloc_count < 0)
{
+ out3:
free (reloc_vector);
+ out2:
+ free (info->strs);
+ info->strs = NULL;
+ out1:
+ free (info->stabs);
+ info->stabs = NULL;
+ out:
+ info->stabsec = NULL;
return false;
}
if (reloc_count > 0)
@@ -1091,8 +1090,7 @@ _bfd_stab_section_find_nearest_line (bfd *abfd,
_bfd_error_handler
(_("unsupported .stab relocation"));
bfd_set_error (bfd_error_invalid_operation);
- free (reloc_vector);
- return false;
+ goto out3;
}
val = bfd_get_32 (abfd, info->stabs + octets);
@@ -1146,14 +1144,21 @@ _bfd_stab_section_find_nearest_line (bfd *abfd,
++info->indextablesize;
if (info->indextablesize == 0)
- return true;
+ {
+ free (info->strs);
+ info->strs = NULL;
+ free (info->stabs);
+ info->stabs = NULL;
+ info->stabsec = NULL;
+ return true;
+ }
++info->indextablesize;
amt = info->indextablesize;
amt *= sizeof (struct indexentry);
- info->indextable = (struct indexentry *) bfd_alloc (abfd, amt);
+ info->indextable = (struct indexentry *) bfd_malloc (amt);
if (info->indextable == NULL)
- return false;
+ goto out3;
file_name = NULL;
directory_name = NULL;
@@ -1280,8 +1285,6 @@ _bfd_stab_section_find_nearest_line (bfd *abfd,
info->indextablesize = i;
qsort (info->indextable, (size_t) i, sizeof (struct indexentry),
cmpindexentry);
-
- *pinfo = info;
}
/* We are passed a section relative offset. The offsets in the
@@ -1446,6 +1449,18 @@ _bfd_stab_section_find_nearest_line (bfd *abfd,
return true;
}
+void
+_bfd_stab_cleanup (bfd *abfd ATTRIBUTE_UNUSED, void **pinfo)
+{
+ struct stab_find_info *info = (struct stab_find_info *) *pinfo;
+ if (info == NULL)
+ return;
+
+ free (info->indextable);
+ free (info->strs);
+ free (info->stabs);
+}
+
long
_bfd_nosymbols_canonicalize_symtab (bfd *abfd ATTRIBUTE_UNUSED,
asymbol **location ATTRIBUTE_UNUSED)
--
Alan Modra
Australia Development Lab, IBM
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: stab nearest_line bfd_malloc_and_get_section
@ 2022-10-05 4:22 Alan Modra
0 siblings, 0 replies; 2+ messages in thread
From: Alan Modra @ 2022-10-05 4:22 UTC (permalink / raw)
To: binutils
It didn't take long for the fuzzers to avoid size checks in
bfd_malloc_and_get_section. Plug this hole.
* syms.c (_bfd_stab_section_find_nearest_line): Ignore fuzzed
sections with no contents.
diff --git a/bfd/syms.c b/bfd/syms.c
index e8077f59bf0..c9d27ebe5d4 100644
--- a/bfd/syms.c
+++ b/bfd/syms.c
@@ -1019,6 +1019,10 @@ _bfd_stab_section_find_nearest_line (bfd *abfd,
return true;
}
+ if ((info->stabsec->flags & SEC_HAS_CONTENTS) == 0
+ || (info->strsec->flags & SEC_HAS_CONTENTS) == 0)
+ goto out;
+
stabsize = (info->stabsec->rawsize
? info->stabsec->rawsize
: info->stabsec->size);
--
Alan Modra
Australia Development Lab, IBM
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2022-10-05 4:22 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2022-09-26 5:23 stab nearest_line bfd_malloc_and_get_section Alan Modra
2022-10-05 4:22 Alan Modra
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).