From: Simon Marchi <simon.marchi@efficios.com>
To: gdb-patches@sourceware.org, binutils@sourceware.org
Cc: Simon Marchi <simon.marchi@efficios.com>
Subject: [PATCH v2 2/4] gdb/dwarf: validate address sizes when reading DWARF headers
Date: Mon, 21 Sep 2026 13:39:42 -0400 [thread overview]
Message-ID: <20260921173951.688121-3-simon.marchi@efficios.com> (raw)
In-Reply-To: <20260921173951.688121-1-simon.marchi@efficios.com>
There is currently very little validation done on the addr_size fields
read from the various DWARF section headers. One could write some DWARF
debug info with strange address sizes (like 0 or 47), and it's not
always clear how GDB will react. Instead of wondering how each site
that uses the address size will behave, I propose to do some early
validation on the address size fields, so that the rest of the code does
not have to worry about unexpected values.
I chose to make the valid values 2, 4 and 8. This is based on the fact
that we have a few sites where we do:
switch (unit->addr_size)
{
case 8:
return bfd_get_signed_64 (unit->abfd, buf);
case 4:
return bfd_get_signed_32 (unit->abfd, buf);
case 2:
return bfd_get_signed_16 (unit->abfd, buf);
default:
abort ();
}
LLVM's getSupportedAddressSizes function lists the same size.
Add the dwarf2_addr_size_is_supported function, and use it at a few
places where we read an address size from a header.
- unit-head.c, where we read unit headers from .debug_info
- read.c, where we read .debug_loclists and .debug_rnglists headers
- aranges.c, where we read .debug_aranges headers. It replaces a more
lax check.
- frame.c, where we read .debug_frame headers
- dwarf_decode_line_header in line-header.c just skips over the address
size, I did not add a check there.
Change-Id: I1b3bd220981347bdf347647183efd1165040875d
---
gdb/dwarf2/aranges.c | 4 ++--
gdb/dwarf2/frame.c | 5 +++++
gdb/dwarf2/read.c | 7 +++++++
gdb/dwarf2/types.h | 8 ++++++++
gdb/dwarf2/unit-head.c | 7 +++++++
5 files changed, 29 insertions(+), 2 deletions(-)
diff --git a/gdb/dwarf2/aranges.c b/gdb/dwarf2/aranges.c
index b085497844b5..9b5143a051f8 100644
--- a/gdb/dwarf2/aranges.c
+++ b/gdb/dwarf2/aranges.c
@@ -137,11 +137,11 @@ read_addrmap_from_aranges (dwarf2_per_objfile *per_objfile,
dwarf2_per_cu *const per_cu = per_cu_it->second;
const uint8_t address_size = *addr++;
- if (address_size < 1 || address_size > 8)
+ if (!dwarf2_addr_size_is_supported (address_size))
{
warn->warn
(_("Section .debug_aranges in %ps entry at offset %s "
- "address_size %u is invalid, ignoring .debug_aranges."),
+ "address_size %u is not supported, ignoring .debug_aranges."),
styled_string (file_name_style.style (),
objfile_name (objfile)),
plongest (entry_addr - section->buffer), address_size);
diff --git a/gdb/dwarf2/frame.c b/gdb/dwarf2/frame.c
index 6f0601a0146e..110b0d61faef 100644
--- a/gdb/dwarf2/frame.c
+++ b/gdb/dwarf2/frame.c
@@ -1770,6 +1770,11 @@ decode_frame_entry_1 (struct gdbarch *gdbarch,
/* FIXME: check that this is the same as from the CU header. */
cie->addr_size = read_1_byte (unit->abfd, buf);
++buf;
+
+ if (!dwarf2_addr_size_is_supported (cie->addr_size))
+ error (_("Unsupported address size in CIE "
+ "(is %u, should be 2, 4 or 8)."), cie->addr_size);
+
cie->segment_size = read_1_byte (unit->abfd, buf);
++buf;
}
diff --git a/gdb/dwarf2/read.c b/gdb/dwarf2/read.c
index 19448795e53e..c1454a664bef 100644
--- a/gdb/dwarf2/read.c
+++ b/gdb/dwarf2/read.c
@@ -14091,6 +14091,13 @@ read_loclists_rnglists_header (struct loclists_rnglists_header *header,
header->addr_size = read_1_byte (abfd, info_ptr);
info_ptr += 1;
+ if (!dwarf2_addr_size_is_supported (header->addr_size))
+ error (_(DWARF_ERROR_PREFIX
+ "unsupported address size in %s header "
+ "(is %u, should be 2, 4 or 8) [in module %s]"),
+ section->get_name (), header->addr_size,
+ section->get_file_name ());
+
header->segment_collector_size = read_1_byte (abfd, info_ptr);
info_ptr += 1;
diff --git a/gdb/dwarf2/types.h b/gdb/dwarf2/types.h
index cb8ce33940ca..d1ef2fb6fa82 100644
--- a/gdb/dwarf2/types.h
+++ b/gdb/dwarf2/types.h
@@ -39,4 +39,12 @@ sect_offset_str (sect_offset offset)
return hex_string (to_underlying (offset));
}
+/* Return true if ADDR_SIZE is an address size GDB knows how to handle. */
+
+static inline bool
+dwarf2_addr_size_is_supported (unsigned int addr_size)
+{
+ return addr_size == 2 || addr_size == 4 || addr_size == 8;
+}
+
#endif /* GDB_DWARF2_TYPES_H */
diff --git a/gdb/dwarf2/unit-head.c b/gdb/dwarf2/unit-head.c
index 1771e43da97f..b6a30a4c31ff 100644
--- a/gdb/dwarf2/unit-head.c
+++ b/gdb/dwarf2/unit-head.c
@@ -110,6 +110,13 @@ read_unit_head (struct unit_head *header, const gdb_byte *info_ptr,
header->addr_size = read_1_byte (abfd, info_ptr);
info_ptr += 1;
}
+
+ if (!dwarf2_addr_size_is_supported (header->addr_size))
+ error (_(DWARF_ERROR_PREFIX
+ "unsupported address size in unit header "
+ "(is %u, should be 2, 4 or 8) [in module %s]"),
+ header->addr_size, filename);
+
signed_addr = bfd_get_sign_extend_vma (abfd);
if (signed_addr < 0)
internal_error (_("read_unit_head: dwarf from non elf file"));
--
2.55.0
next prev parent reply other threads:[~2026-09-21 17:42 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-21 17:39 [PATCH v2 0/4] Fix reading DW_FORM_addrx with address size of 2 Simon Marchi
2026-09-21 17:39 ` [PATCH v2 1/4] gdb/testsuite: add support for DWARF 5 .debug_addr sections to DWARF assembler Simon Marchi
2026-09-21 17:39 ` Simon Marchi [this message]
2026-09-21 17:39 ` [PATCH v2 3/4] gdb/dwarf: don't store segment_collector_size (sic) Simon Marchi
2026-09-21 17:39 ` [PATCH v2 4/4] gdb/dwarf: fix reading DW_FORM_addrx with address size of 2 Simon Marchi
2026-09-23 15:13 ` Tom Tromey
2026-09-24 15:59 ` Simon Marchi
2026-09-23 15:49 ` [PATCH v2 0/4] Fix " Tom Tromey
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260921173951.688121-3-simon.marchi@efficios.com \
--to=simon.marchi@efficios.com \
--cc=binutils@sourceware.org \
--cc=gdb-patches@sourceware.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox