From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from simark.ca by simark.ca with LMTP id eWVSKmxssWp49C0AWB0awg (envelope-from ) for ; Mon, 21 Sep 2026 13:42:04 -0400 Received: by simark.ca (Postfix, from userid 112) id AA8051E051; Mon, 21 Sep 2026 13:42:04 -0400 (EDT) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on simark.ca X-Spam-Level: X-Spam-Status: No, score=-2.3 required=5.0 tests=ARC_SIGNED,ARC_VALID,BAYES_00, MAILING_LIST_MULTI,RCVD_IN_DNSWL_MED, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED,RCVD_IN_VALIDITY_RPBL_BLOCKED, RCVD_IN_VALIDITY_SAFE_BLOCKED autolearn=ham autolearn_force=no version=4.0.1 Received: from vm01.sourceware.org (vm01.sourceware.org [38.145.34.32]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by simark.ca (Postfix) with ESMTPS id 04DFC1E01F for ; Mon, 21 Sep 2026 13:42:04 -0400 (EDT) Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 954314B9DB48 for ; Mon, 21 Sep 2026 17:42:03 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 954314B9DB48 Received: from simark.ca (simark.ca [158.69.221.121]) by sourceware.org (Postfix) with ESMTPS id 1AD744BA23FD; Mon, 21 Sep 2026 17:39:54 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 1AD744BA23FD Authentication-Results: sourceware.org; dmarc=fail (p=none dis=none) header.from=efficios.com Authentication-Results: sourceware.org; spf=fail smtp.mailfrom=efficios.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 1AD744BA23FD Authentication-Results: sourceware.org; arc=none smtp.remote-ip=158.69.221.121 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1790012394; cv=none; b=O3V0SFgoOIHKW0efJY+o2KRywtcEJhpbqnBQ9OoSH1qRpfs95J7DZT55MKoUsFHcZ9f+S2iHaUTiyYifi9PLCXrzC9rib7YQpCdToLcwORwNq5O7VtgrU+SyVvc3XRMxIeewGv1Ph9Kbo0KIMhRKQ3eHlW9eSqpoWi9sgxROFvU= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1790012394; c=relaxed/simple; bh=tQolYNdOKAHkxlINEA5+8M+3MHqYjgrs0YKs3vGE2IY=; h=From:To:Subject:Date:Message-ID:MIME-Version; b=VXwFeNAXbwSaa56UFeKsBexcQEvX3ob6bd/gaM69fgRzN0pk+Uk2maGNrG9cojXVrASrkBooNO2wkV429bd9WqWNxFpsbUGBtpGCC6RBHtPKgmIdqKAD6nH5PBbVmm+YF99IaBRV2lkooe4RNESZ4gdoLiyZYTYO53V6TFjvZUc= ARC-Authentication-Results: i=1; sourceware.org DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 1AD744BA23FD Received: by simark.ca (Postfix) id 3E7A61E051; Mon, 21 Sep 2026 13:39:53 -0400 (EDT) From: Simon Marchi To: gdb-patches@sourceware.org, binutils@sourceware.org Cc: Simon Marchi Subject: [PATCH v2 2/4] gdb/dwarf: validate address sizes when reading DWARF headers Date: Mon, 21 Sep 2026 13:39:42 -0400 Message-ID: <20260921173951.688121-3-simon.marchi@efficios.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260921173951.688121-1-simon.marchi@efficios.com> References: <20260921173951.688121-1-simon.marchi@efficios.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-BeenThere: gdb-patches@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Gdb-patches mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: gdb-patches-bounces~public-inbox=simark.ca@sourceware.org There is currently very little validation done on the addr_size fields read from the various DWARF section headers. One could write some DWARF debug info with strange address sizes (like 0 or 47), and it's not always clear how GDB will react. Instead of wondering how each site that uses the address size will behave, I propose to do some early validation on the address size fields, so that the rest of the code does not have to worry about unexpected values. I chose to make the valid values 2, 4 and 8. This is based on the fact that we have a few sites where we do: switch (unit->addr_size) { case 8: return bfd_get_signed_64 (unit->abfd, buf); case 4: return bfd_get_signed_32 (unit->abfd, buf); case 2: return bfd_get_signed_16 (unit->abfd, buf); default: abort (); } LLVM's getSupportedAddressSizes function lists the same size. Add the dwarf2_addr_size_is_supported function, and use it at a few places where we read an address size from a header. - unit-head.c, where we read unit headers from .debug_info - read.c, where we read .debug_loclists and .debug_rnglists headers - aranges.c, where we read .debug_aranges headers. It replaces a more lax check. - frame.c, where we read .debug_frame headers - dwarf_decode_line_header in line-header.c just skips over the address size, I did not add a check there. Change-Id: I1b3bd220981347bdf347647183efd1165040875d --- gdb/dwarf2/aranges.c | 4 ++-- gdb/dwarf2/frame.c | 5 +++++ gdb/dwarf2/read.c | 7 +++++++ gdb/dwarf2/types.h | 8 ++++++++ gdb/dwarf2/unit-head.c | 7 +++++++ 5 files changed, 29 insertions(+), 2 deletions(-) diff --git a/gdb/dwarf2/aranges.c b/gdb/dwarf2/aranges.c index b085497844b5..9b5143a051f8 100644 --- a/gdb/dwarf2/aranges.c +++ b/gdb/dwarf2/aranges.c @@ -137,11 +137,11 @@ read_addrmap_from_aranges (dwarf2_per_objfile *per_objfile, dwarf2_per_cu *const per_cu = per_cu_it->second; const uint8_t address_size = *addr++; - if (address_size < 1 || address_size > 8) + if (!dwarf2_addr_size_is_supported (address_size)) { warn->warn (_("Section .debug_aranges in %ps entry at offset %s " - "address_size %u is invalid, ignoring .debug_aranges."), + "address_size %u is not supported, ignoring .debug_aranges."), styled_string (file_name_style.style (), objfile_name (objfile)), plongest (entry_addr - section->buffer), address_size); diff --git a/gdb/dwarf2/frame.c b/gdb/dwarf2/frame.c index 6f0601a0146e..110b0d61faef 100644 --- a/gdb/dwarf2/frame.c +++ b/gdb/dwarf2/frame.c @@ -1770,6 +1770,11 @@ decode_frame_entry_1 (struct gdbarch *gdbarch, /* FIXME: check that this is the same as from the CU header. */ cie->addr_size = read_1_byte (unit->abfd, buf); ++buf; + + if (!dwarf2_addr_size_is_supported (cie->addr_size)) + error (_("Unsupported address size in CIE " + "(is %u, should be 2, 4 or 8)."), cie->addr_size); + cie->segment_size = read_1_byte (unit->abfd, buf); ++buf; } diff --git a/gdb/dwarf2/read.c b/gdb/dwarf2/read.c index 19448795e53e..c1454a664bef 100644 --- a/gdb/dwarf2/read.c +++ b/gdb/dwarf2/read.c @@ -14091,6 +14091,13 @@ read_loclists_rnglists_header (struct loclists_rnglists_header *header, header->addr_size = read_1_byte (abfd, info_ptr); info_ptr += 1; + if (!dwarf2_addr_size_is_supported (header->addr_size)) + error (_(DWARF_ERROR_PREFIX + "unsupported address size in %s header " + "(is %u, should be 2, 4 or 8) [in module %s]"), + section->get_name (), header->addr_size, + section->get_file_name ()); + header->segment_collector_size = read_1_byte (abfd, info_ptr); info_ptr += 1; diff --git a/gdb/dwarf2/types.h b/gdb/dwarf2/types.h index cb8ce33940ca..d1ef2fb6fa82 100644 --- a/gdb/dwarf2/types.h +++ b/gdb/dwarf2/types.h @@ -39,4 +39,12 @@ sect_offset_str (sect_offset offset) return hex_string (to_underlying (offset)); } +/* Return true if ADDR_SIZE is an address size GDB knows how to handle. */ + +static inline bool +dwarf2_addr_size_is_supported (unsigned int addr_size) +{ + return addr_size == 2 || addr_size == 4 || addr_size == 8; +} + #endif /* GDB_DWARF2_TYPES_H */ diff --git a/gdb/dwarf2/unit-head.c b/gdb/dwarf2/unit-head.c index 1771e43da97f..b6a30a4c31ff 100644 --- a/gdb/dwarf2/unit-head.c +++ b/gdb/dwarf2/unit-head.c @@ -110,6 +110,13 @@ read_unit_head (struct unit_head *header, const gdb_byte *info_ptr, header->addr_size = read_1_byte (abfd, info_ptr); info_ptr += 1; } + + if (!dwarf2_addr_size_is_supported (header->addr_size)) + error (_(DWARF_ERROR_PREFIX + "unsupported address size in unit header " + "(is %u, should be 2, 4 or 8) [in module %s]"), + header->addr_size, filename); + signed_addr = bfd_get_sign_extend_vma (abfd); if (signed_addr < 0) internal_error (_("read_unit_head: dwarf from non elf file")); -- 2.55.0