Mirror of the gdb-patches mailing list
 help / color / mirror / Atom feed
From: Simon Marchi <simon.marchi@efficios.com>
To: gdb-patches@sourceware.org, binutils@sourceware.org
Cc: Simon Marchi <simon.marchi@efficios.com>
Subject: [PATCH v2 2/4] gdb/dwarf: validate address sizes when reading DWARF headers
Date: Mon, 21 Sep 2026 13:39:42 -0400	[thread overview]
Message-ID: <20260921173951.688121-3-simon.marchi@efficios.com> (raw)
In-Reply-To: <20260921173951.688121-1-simon.marchi@efficios.com>

There is currently very little validation done on the addr_size fields
read from the various DWARF section headers.  One could write some DWARF
debug info with strange address sizes (like 0 or 47), and it's not
always clear how GDB will react.  Instead of wondering how each site
that uses the address size will behave, I propose to do some early
validation on the address size fields, so that the rest of the code does
not have to worry about unexpected values.

I chose to make the valid values 2, 4 and 8.  This is based on the fact
that we have a few sites where we do:

      switch (unit->addr_size)
	{
	case 8:
	  return bfd_get_signed_64 (unit->abfd, buf);
	case 4:
	  return bfd_get_signed_32 (unit->abfd, buf);
	case 2:
	  return bfd_get_signed_16 (unit->abfd, buf);
	default:
	  abort ();
	}

LLVM's getSupportedAddressSizes function lists the same size.

Add the dwarf2_addr_size_is_supported function, and use it at a few
places where we read an address size from a header.

 - unit-head.c, where we read unit headers from .debug_info

 - read.c, where we read .debug_loclists and .debug_rnglists headers

 - aranges.c, where we read .debug_aranges headers.  It replaces a more
   lax check.

 - frame.c, where we read .debug_frame headers

 - dwarf_decode_line_header in line-header.c just skips over the address
   size, I did not add a check there.

Change-Id: I1b3bd220981347bdf347647183efd1165040875d
---
 gdb/dwarf2/aranges.c   | 4 ++--
 gdb/dwarf2/frame.c     | 5 +++++
 gdb/dwarf2/read.c      | 7 +++++++
 gdb/dwarf2/types.h     | 8 ++++++++
 gdb/dwarf2/unit-head.c | 7 +++++++
 5 files changed, 29 insertions(+), 2 deletions(-)

diff --git a/gdb/dwarf2/aranges.c b/gdb/dwarf2/aranges.c
index b085497844b5..9b5143a051f8 100644
--- a/gdb/dwarf2/aranges.c
+++ b/gdb/dwarf2/aranges.c
@@ -137,11 +137,11 @@ read_addrmap_from_aranges (dwarf2_per_objfile *per_objfile,
       dwarf2_per_cu *const per_cu = per_cu_it->second;
 
       const uint8_t address_size = *addr++;
-      if (address_size < 1 || address_size > 8)
+      if (!dwarf2_addr_size_is_supported (address_size))
 	{
 	  warn->warn
 	    (_("Section .debug_aranges in %ps entry at offset %s "
-	       "address_size %u is invalid, ignoring .debug_aranges."),
+	       "address_size %u is not supported, ignoring .debug_aranges."),
 	     styled_string (file_name_style.style (),
 			    objfile_name (objfile)),
 	     plongest (entry_addr - section->buffer), address_size);
diff --git a/gdb/dwarf2/frame.c b/gdb/dwarf2/frame.c
index 6f0601a0146e..110b0d61faef 100644
--- a/gdb/dwarf2/frame.c
+++ b/gdb/dwarf2/frame.c
@@ -1770,6 +1770,11 @@ decode_frame_entry_1 (struct gdbarch *gdbarch,
 	  /* FIXME: check that this is the same as from the CU header.  */
 	  cie->addr_size = read_1_byte (unit->abfd, buf);
 	  ++buf;
+
+	  if (!dwarf2_addr_size_is_supported (cie->addr_size))
+	    error (_("Unsupported address size in CIE "
+		     "(is %u, should be 2, 4 or 8)."), cie->addr_size);
+
 	  cie->segment_size = read_1_byte (unit->abfd, buf);
 	  ++buf;
 	}
diff --git a/gdb/dwarf2/read.c b/gdb/dwarf2/read.c
index 19448795e53e..c1454a664bef 100644
--- a/gdb/dwarf2/read.c
+++ b/gdb/dwarf2/read.c
@@ -14091,6 +14091,13 @@ read_loclists_rnglists_header (struct loclists_rnglists_header *header,
   header->addr_size = read_1_byte (abfd, info_ptr);
   info_ptr += 1;
 
+  if (!dwarf2_addr_size_is_supported (header->addr_size))
+    error (_(DWARF_ERROR_PREFIX
+	     "unsupported address size in %s header "
+	     "(is %u, should be 2, 4 or 8) [in module %s]"),
+	   section->get_name (), header->addr_size,
+	   section->get_file_name ());
+
   header->segment_collector_size = read_1_byte (abfd, info_ptr);
   info_ptr += 1;
 
diff --git a/gdb/dwarf2/types.h b/gdb/dwarf2/types.h
index cb8ce33940ca..d1ef2fb6fa82 100644
--- a/gdb/dwarf2/types.h
+++ b/gdb/dwarf2/types.h
@@ -39,4 +39,12 @@ sect_offset_str (sect_offset offset)
   return hex_string (to_underlying (offset));
 }
 
+/* Return true if ADDR_SIZE is an address size GDB knows how to handle.  */
+
+static inline bool
+dwarf2_addr_size_is_supported (unsigned int addr_size)
+{
+  return addr_size == 2 || addr_size == 4 || addr_size == 8;
+}
+
 #endif /* GDB_DWARF2_TYPES_H */
diff --git a/gdb/dwarf2/unit-head.c b/gdb/dwarf2/unit-head.c
index 1771e43da97f..b6a30a4c31ff 100644
--- a/gdb/dwarf2/unit-head.c
+++ b/gdb/dwarf2/unit-head.c
@@ -110,6 +110,13 @@ read_unit_head (struct unit_head *header, const gdb_byte *info_ptr,
       header->addr_size = read_1_byte (abfd, info_ptr);
       info_ptr += 1;
     }
+
+  if (!dwarf2_addr_size_is_supported (header->addr_size))
+    error (_(DWARF_ERROR_PREFIX
+	     "unsupported address size in unit header "
+	     "(is %u, should be 2, 4 or 8) [in module %s]"),
+	   header->addr_size, filename);
+
   signed_addr = bfd_get_sign_extend_vma (abfd);
   if (signed_addr < 0)
     internal_error (_("read_unit_head: dwarf from non elf file"));
-- 
2.55.0


  parent reply	other threads:[~2026-09-21 17:42 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-21 17:39 [PATCH v2 0/4] Fix reading DW_FORM_addrx with address size of 2 Simon Marchi
2026-09-21 17:39 ` [PATCH v2 1/4] gdb/testsuite: add support for DWARF 5 .debug_addr sections to DWARF assembler Simon Marchi
2026-09-21 17:39 ` Simon Marchi [this message]
2026-09-21 17:39 ` [PATCH v2 3/4] gdb/dwarf: don't store segment_collector_size (sic) Simon Marchi
2026-09-21 17:39 ` [PATCH v2 4/4] gdb/dwarf: fix reading DW_FORM_addrx with address size of 2 Simon Marchi
2026-09-23 15:13   ` Tom Tromey
2026-09-24 15:59     ` Simon Marchi
2026-09-23 15:49 ` [PATCH v2 0/4] Fix " Tom Tromey

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260921173951.688121-3-simon.marchi@efficios.com \
    --to=simon.marchi@efficios.com \
    --cc=binutils@sourceware.org \
    --cc=gdb-patches@sourceware.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox