* [PATCH] Fix buffer overrun found by Coverity
@ 2018-10-05 13:53 Gary Benson
2018-10-05 14:18 ` Tom Tromey
0 siblings, 1 reply; 5+ messages in thread
From: Gary Benson @ 2018-10-05 13:53 UTC (permalink / raw)
To: gdb-patches
Hi all,
This commit fixes a buffer overrun found by Coverity, where 36 bytes
are written into the 24 byte buffer "ids". The "ids_seen" buffer
doesn't overrun, but I've changed that too, to future-proof it some.
I would have committed this as obvious, but the testsuite doesn't
exercise this piece of code; I can't realistically say I've regression
tested this change, so I'd like another pair of eyes on it to be sure.
Cheers,
Gary
--
gdb/ChangeLog:
* dwarf2read.c (create_dwp_hash_table): Fix buffer overrun
found by Coverity.
---
gdb/ChangeLog | 5 +++++
gdb/dwarf2read.c | 5 +++--
2 files changed, 8 insertions(+), 2 deletions(-)
diff --git a/gdb/dwarf2read.c b/gdb/dwarf2read.c
index 4a35e38..e9d1ac5 100644
--- a/gdb/dwarf2read.c
+++ b/gdb/dwarf2read.c
@@ -12197,6 +12197,7 @@ create_dwp_hash_table (struct dwarf2_per_objfile *dwarf2_per_objfile,
{
const gdb_byte *ids_ptr = htab->unit_table + sizeof (uint32_t) * nr_slots;
int *ids = htab->section_pool.v2.section_ids;
+ size_t sizeof_ids = sizeof (htab->section_pool.v2.section_ids);
/* Reverse map for error checking. */
int ids_seen[DW_SECT_MAX + 1];
int i;
@@ -12213,8 +12214,8 @@ create_dwp_hash_table (struct dwarf2_per_objfile *dwarf2_per_objfile,
" in section table [in module %s]"),
dwp_file->name);
}
- memset (ids, 255, (DW_SECT_MAX + 1) * sizeof (int32_t));
- memset (ids_seen, 255, (DW_SECT_MAX + 1) * sizeof (int32_t));
+ memset (ids, 255, sizeof_ids);
+ memset (ids_seen, 255, sizeof (ids_seen));
for (i = 0; i < nr_columns; ++i)
{
int id = read_4_bytes (dbfd, ids_ptr + i * sizeof (uint32_t));
--
1.8.3.1
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] Fix buffer overrun found by Coverity
2018-10-05 13:53 [PATCH] Fix buffer overrun found by Coverity Gary Benson
@ 2018-10-05 14:18 ` Tom Tromey
2018-10-08 16:34 ` Gary Benson
0 siblings, 1 reply; 5+ messages in thread
From: Tom Tromey @ 2018-10-05 14:18 UTC (permalink / raw)
To: Gary Benson; +Cc: gdb-patches
>>>>> "Gary" == Gary Benson <gbenson@redhat.com> writes:
Gary> I would have committed this as obvious, but the testsuite doesn't
Gary> exercise this piece of code; I can't realistically say I've regression
Gary> tested this change, so I'd like another pair of eyes on it to be sure.
What about the fission-dwp.exp board maybe?
Or one of the other boards.
Gary> - memset (ids, 255, (DW_SECT_MAX + 1) * sizeof (int32_t));
Gary> - memset (ids_seen, 255, (DW_SECT_MAX + 1) * sizeof (int32_t));
Gary> + memset (ids, 255, sizeof_ids);
Gary> + memset (ids_seen, 255, sizeof (ids_seen));
Later the code does this:
if (id < DW_SECT_MIN || id > DW_SECT_MAX)
{
error (_("Dwarf Error: bad DWP hash table, bad section id %d"
[...]
ids_seen[id] = i;
ids[i] = id;
So I think it would be good to ensure that MAX_NR_V2_DWO_SECTIONS is
>= DW_SECT_MAX + 1. At least if I'm understanding this properly.
Tom
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] Fix buffer overrun found by Coverity
2018-10-05 14:18 ` Tom Tromey
@ 2018-10-08 16:34 ` Gary Benson
2018-10-08 17:41 ` Tom Tromey
0 siblings, 1 reply; 5+ messages in thread
From: Gary Benson @ 2018-10-08 16:34 UTC (permalink / raw)
To: Tom Tromey; +Cc: gdb-patches
Tom Tromey wrote:
> >>>>> "Gary" == Gary Benson <gbenson@redhat.com> writes:
>
> Gary> I would have committed this as obvious, but the testsuite
> Gary> doesn't exercise this piece of code; I can't realistically
> Gary> say I've regression tested this change, so I'd like another
> Gary> pair of eyes on it to be sure.
>
> What about the fission-dwp.exp board maybe?
> Or one of the other boards.
Oh, good call, it does.
> Gary> - memset (ids, 255, (DW_SECT_MAX + 1) * sizeof (int32_t));
> Gary> - memset (ids_seen, 255, (DW_SECT_MAX + 1) * sizeof (int32_t));
> Gary> + memset (ids, 255, sizeof_ids);
> Gary> + memset (ids_seen, 255, sizeof (ids_seen));
>
> Later the code does this:
>
> if (id < DW_SECT_MIN || id > DW_SECT_MAX)
> {
> error (_("Dwarf Error: bad DWP hash table, bad section id %d"
> [...]
> ids_seen[id] = i;
> ids[i] = id;
>
> So I think it would be good to ensure that MAX_NR_V2_DWO_SECTIONS is
> >= DW_SECT_MAX + 1. At least if I'm understanding this properly.
I don't *think* it's necessary:
ids_seen is indexed by "id",
which is 1 <= id <= DW_SECT_MAX;
ids is indexed by "i",
which is 0 <= i < nr_columns,
and nr_columns is nr_columns <= MAX_NR_V2_DWO_SECTIONS,
so 0 <= i < MAX_NR_V2_DWO_SECTIONS.
i.e. the dimensions are right, it's just the memset which isn't.
I think!
Ok, so this one's built and regtested on RHEL 7.5 x86_64 now, with
the fission-dwp.exp board. Assuming the dimensions thing above is
correct, is this ok to commit?
Cheers,
Gary
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] Fix buffer overrun found by Coverity
2018-10-08 16:34 ` Gary Benson
@ 2018-10-08 17:41 ` Tom Tromey
2018-10-09 13:25 ` Gary Benson
0 siblings, 1 reply; 5+ messages in thread
From: Tom Tromey @ 2018-10-08 17:41 UTC (permalink / raw)
To: Gary Benson; +Cc: Tom Tromey, gdb-patches
>>>>> "Gary" == Gary Benson <gbenson@redhat.com> writes:
Gary> I don't *think* it's necessary:
[...]
I agree, thanks for breaking it down for me.
Gary> Ok, so this one's built and regtested on RHEL 7.5 x86_64 now, with
Gary> the fission-dwp.exp board. Assuming the dimensions thing above is
Gary> correct, is this ok to commit?
Yes, thank you.
Tom
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] Fix buffer overrun found by Coverity
2018-10-08 17:41 ` Tom Tromey
@ 2018-10-09 13:25 ` Gary Benson
0 siblings, 0 replies; 5+ messages in thread
From: Gary Benson @ 2018-10-09 13:25 UTC (permalink / raw)
To: Tom Tromey; +Cc: gdb-patches
Tom Tromey wrote:
> >>>>> "Gary" == Gary Benson <gbenson@redhat.com> writes:
>
> Gary> I don't *think* it's necessary:
> [...]
>
> I agree, thanks for breaking it down for me.
>
> Gary> Ok, so this one's built and regtested on RHEL 7.5 x86_64 now,
> Gary> with the fission-dwp.exp board. Assuming the dimensions thing
> Gary> above is correct, is this ok to commit?
>
> Yes, thank you.
Cool, I've pushed it. Thanks for the review :D
Cheers,
Gary
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2018-10-09 13:25 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2018-10-05 13:53 [PATCH] Fix buffer overrun found by Coverity Gary Benson
2018-10-05 14:18 ` Tom Tromey
2018-10-08 16:34 ` Gary Benson
2018-10-08 17:41 ` Tom Tromey
2018-10-09 13:25 ` Gary Benson
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).