Mirror of the gdb-patches mailing list
 help / color / mirror / Atom feed
From: Sergei Trofimovich via Gdb-patches <gdb-patches@sourceware.org>
To: binutils@sourceware.org
Cc: Sergei Trofimovich <siarheit@google.com>, gdb-patches@sourceware.org
Subject: [PATCH v2] gdb/nat/linux-osdata.c: fix build on gcc-12 (string overfow)
Date: Tue, 16 Nov 2021 23:55:21 +0000	[thread overview]
Message-ID: <20211116235521.223574-1-slyich@gmail.com> (raw)

From: Sergei Trofimovich <siarheit@google.com>

On gcc-12 build fails as:

    ../../gdbserver/../gdb/nat/linux-osdata.c: In function 'void linux_xfer_osdata_processes(buffer*)':
    ../../gdbserver/../gdb/nat/linux-osdata.c:330:39: error:
      '__builtin___sprintf_chk' may write a terminating nul past the end of the destination [-Werror=format-overflow=]
      330 |                 sprintf (core_str, "%d", i);
          |                                       ^

It's an off-by-one case in an infeasible scenario for negative
huge core count. The change switches to std::string for memory
handling.

Tested by running 'info os processes' and checking CPU cores column.
---
 gdb/nat/linux-osdata.c | 13 ++++---------
 1 file changed, 4 insertions(+), 9 deletions(-)

diff --git a/gdb/nat/linux-osdata.c b/gdb/nat/linux-osdata.c
index 9746d1210fe..91bbe10e515 100644
--- a/gdb/nat/linux-osdata.c
+++ b/gdb/nat/linux-osdata.c
@@ -302,7 +302,7 @@ linux_xfer_osdata_processes (struct buffer *buffer)
 	  char *command_line;
 	  int *cores;
 	  int task_count;
-	  char *cores_str;
+	  std::string cores_str;
 	  int i;
 
 	  if (!isdigit (dp->d_name[0])
@@ -320,19 +320,15 @@ linux_xfer_osdata_processes (struct buffer *buffer)
 	  /* Find CPU cores used by the process.  */
 	  cores = XCNEWVEC (int, num_cores);
 	  task_count = get_cores_used_by_process (pid, cores, num_cores);
-	  cores_str = (char *) xcalloc (task_count, sizeof ("4294967295") + 1);
 
 	  for (i = 0; i < num_cores && task_count > 0; ++i)
 	    if (cores[i])
 	      {
-		char core_str[sizeof ("4294967295")];
-
-		sprintf (core_str, "%d", i);
-		strcat (cores_str, core_str);
+		string_appendf (cores_str, "%d", i);
 
 		task_count -= cores[i];
 		if (task_count > 0)
-		  strcat (cores_str, ",");
+		  cores_str += ",";
 	      }
 
 	  xfree (cores);
@@ -348,10 +344,9 @@ linux_xfer_osdata_processes (struct buffer *buffer)
 	     pid,
 	     user,
 	     command_line ? command_line : "",
-	     cores_str);
+	     cores_str.c_str());
 
 	  xfree (command_line);
-	  xfree (cores_str);
 	}
 
       closedir (dirp);
-- 
2.33.1


             reply	other threads:[~2021-11-16 23:56 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2021-11-16 23:55 Sergei Trofimovich via Gdb-patches [this message]
2021-11-17  1:09 ` Simon Marchi via Gdb-patches
2021-11-17  8:29   ` Sergei Trofimovich via Gdb-patches

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20211116235521.223574-1-slyich@gmail.com \
    --to=gdb-patches@sourceware.org \
    --cc=binutils@sourceware.org \
    --cc=siarheit@google.com \
    --cc=slyich@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox