From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from simark.ca by simark.ca with LMTP id 8TIaDrVlRWroiSEAWB0awg (envelope-from ) for ; Wed, 01 Jul 2026 15:08:37 -0400 Received: by simark.ca (Postfix, from userid 112) id 34EDD1E098; Wed, 01 Jul 2026 15:08:37 -0400 (EDT) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on simark.ca X-Spam-Level: X-Spam-Status: No, score=-5.3 required=5.0 tests=ARC_SIGNED,ARC_VALID,BAYES_00, MAILING_LIST_MULTI,RCVD_IN_DNSWL_MED autolearn=ham autolearn_force=no version=4.0.1 Received: from vm01.sourceware.org (vm01.sourceware.org [38.145.34.32]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by simark.ca (Postfix) with ESMTPS id B46E01E024 for ; Wed, 01 Jul 2026 15:08:36 -0400 (EDT) Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id E8EB04BA2E14 for ; Wed, 1 Jul 2026 19:08:35 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org E8EB04BA2E14 Received: from mail-wr1-f43.google.com (mail-wr1-f43.google.com [209.85.221.43]) by sourceware.org (Postfix) with ESMTPS id B4F374BA2E13 for ; Wed, 1 Jul 2026 19:08:12 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org B4F374BA2E13 Authentication-Results: sourceware.org; dmarc=none (p=none dis=none) header.from=palves.net Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=gmail.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org B4F374BA2E13 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=209.85.221.43 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782932892; cv=none; b=RvOZ29NfT4pivMjZfy7IRLdFxAS8D3zemk9fjhDjOOZZRJFdMgTZ50Dl1JYSqgP0YieoFjyYE9IE/dRcLHD/fl/GCJylOheC0nqLw4jwECWEBNnl788ECgZkn+pAQ1oOXR0TN1JXT1S9tbUb6dnK54pdrorq5me4ItZoH3hGBlE= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1782932892; c=relaxed/simple; bh=S8he4GbH93+bMDHPjI1SxL/g6dSh7za68kr6EtEZtvg=; h=Message-ID:Date:MIME-Version:Subject:To:From; b=d/6NaKCkUiC1AkGRgqfmT+M5vDtIGq5wiZzfvUtc7GOiHuPtX6FYXAql/IMDQWtfCLtNJ0aAaGurt43QD0csmYkE5HZFqVwgDfcKmi4kHqr1AxLuMqCbci/NIr1xjA1VXGOGyEF+u+v/5sM2fhyTg6iap8fZlT5mp8LTODEv1ws= ARC-Authentication-Results: i=1; sourceware.org DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org B4F374BA2E13 Received: by mail-wr1-f43.google.com with SMTP id ffacd0b85a97d-474e7ba9fd6so601500f8f.1 for ; Wed, 01 Jul 2026 12:08:12 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782932891; x=1783537691; h=content-transfer-encoding:in-reply-to:content-language:from :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=FK+ZN9UST4Hq+sxJUCwaWyQAu5Y57n08xf5O7WPk7XA=; b=fOfR5ppTDUdiES67jABZrWSdRqsXDoLTfbbX+s6h3ezmIXjqyFV2UmLzDxApDDVMmC lKlHID+4hLp76rs555LHpW3Ov7NucUHxkR80RAppfue3l3COcREuL+x2BMaB0gS+g6jE 3PSc/nHxbflcZq6WppO38OrKnn4DG5UJwoU7Yda89zVMkhZTaTVefWAxTe98QkK9E0/D hziQd/dUn4ca5ws2irp+o4QCe71s5M2F+wEE4g53m9IpMTBbMoan04WwxsvKrqfwIUCF 8E1UhF+7pmMSBntt0pbWYb5daslMGZMgPkj1cHwCy1s7Je7lXl+KKxM2EBhjXaV3D1GD TsmQ== X-Forwarded-Encrypted: i=1; AHgh+RrvzPgfhJrRJnmxdbHGAOqAVaXmnOw8uQZbgpdIt3rq35ojUaLboQHDk2NhoeTYx25gFIvw221T/i8HpQ==@sourceware.org X-Gm-Message-State: AOJu0YxdBP60Gv5/oMI7MKP8qmTmn0AT1AqjCfrDc9yN80Qk7tv9LtGj 1AS9OBEfC/848ojZ5oL3LuRdRPKwYlUcqg9pc+bCNZKaaCOiOJGh1pEKXp1ypw== X-Gm-Gg: AfdE7clUTlnB7EE5YIAr5kzsY5l3ZIyvo9Ahbq4MZq8Fr7YG5TSv0iTS+upxlNLILMi XxbedMMfQS2okc9P2kbzv5rRKYyl16m1O6HxMAjO7FGCSARSbfVsaTw1BVCFsTjOAabamEGQA+X SVH++KzK1L1TJsE4CcD9g+FAcbYclC7xQKoNOFh9zwPP7F92Rx3E5GmA60ITdiKLGmaBdetROc/ yORG4+7UMzhSa0p+wWOBB2ddJf9BVtHpR4ddjfxNIcLN4iGSBrtDA+RDzt8HOysfyr4d2V6hpVG /eUhVpKvRQpa+Atak+AwxaTZb2yTgeRM2j5p/JHPM9bGqVjkQKkPxw0xDnn7j7QO0se/IokJimf 2ZhvH5KrL+pctWI8L3qDpxCXEXcLXkoh7NmPZX37k+R5WJzMtaQJ/eAc4h6tExGO49C4UtSJjn1 NPzlUb4OPV20Ai9wYcN3spxevnmLxI7H8gRlyvS7ndAhNEHYahTf+MCVk= X-Received: by 2002:a5d:5d82:0:b0:475:f0f0:9ef8 with SMTP id ffacd0b85a97d-4775b930513mr4810173f8f.61.1782932891489; Wed, 01 Jul 2026 12:08:11 -0700 (PDT) Received: from ?IPV6:2001:8a0:fac2:7700:16f0:8919:779f:a439? ([2001:8a0:fac2:7700:16f0:8919:779f:a439]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-477dd94cb64sm1811087f8f.23.2026.07.01.12.08.10 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Wed, 01 Jul 2026 12:08:11 -0700 (PDT) Message-ID: <391c7c82-c658-4122-a006-520232ad3cd8@palves.net> Date: Wed, 1 Jul 2026 20:08:09 +0100 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v3] gdb: replace alloca with gdb::unique_xmalloc_ptr in remote-fileio.c To: Luis Machado , gdb-patches@sourceware.org Cc: guinevere@redhat.com References: <20260630095238.1700797-1-luis.machado@amd.com> <20260701190156.3900537-1-luis.machado@amd.com> From: Pedro Alves Content-Language: en-US In-Reply-To: <20260701190156.3900537-1-luis.machado@amd.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-BeenThere: gdb-patches@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Gdb-patches mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: gdb-patches-bounces~public-inbox=simark.ca@sourceware.org On 2026-07-01 20:01, Luis Machado wrote: > remote_fileio_extract_ptr_w_len parsed a debuggee controlled 64 bit > length, narrowed it to int with no bounds check, and the value flowed > directly into alloca() across RSP File I/O handlers (Fopen, Frename, > Funlink, Fstat, Fsystem). A malicious inferior or remote stub could > send a crafted packet with a large path length, displacing the stack > pointer by up to 2 GiB and potentially crashing the debugger. > > remote_fileio_extract_ptr_w_len now rejects negative lengths, lengths > that would overflow the int result (greater than INT_MAX), and zero. > An allow_zero_length flag lets the Fsystem handler opt in to the zero > length sentinel that signals a NULL cmdline query. All other handlers > use the default and are protected without any per call checks. Oversized > names are rejected naturally by the underlying syscall with ENAMETOOLONG. > All alloca(length) calls have been replaced with > gdb::unique_xmalloc_ptr, so an oversized but positive length now > fails as a graceful heap allocation error rather than corrupting the > stack. > > Add a selftest that exercises various problematic cases. > > Signed-off-by: Luis Machado Approved-By: Pedro Alves