Mirror of the gdb-patches mailing list
 help / color / mirror / Atom feed
From: Keith Seitz <keiths@redhat.com>
To: gdb-patches@sourceware.org
Subject: [RFA] Fix Ada memory corruption
Date: Thu, 19 Nov 2009 19:01:00 -0000	[thread overview]
Message-ID: <4B0595B3.90001@redhat.com> (raw)

[-- Attachment #1: Type: text/plain, Size: 395 bytes --]

Hi,

Tom's recent symbol_set_names patch exposed this Ada bug, which results 
in memory corruption while computing an alternate symbol name.

This fixes the crash I was seeing in gdb.ada/interface.exp tests.

Ok?

Keith

ChangeLog
2009-11-19  Keith Seitz  <keiths@redhat.com>

	* ada-lang.c (find_old_style_renaming_symbol): Change
	function_name to const and use strncpy to stript the
	suffix.

[-- Attachment #2: ada-mem-err.patch --]
[-- Type: text/plain, Size: 2037 bytes --]

Index: ada-lang.c
===================================================================
RCS file: /cvs/src/src/gdb/ada-lang.c,v
retrieving revision 1.229
diff -u -p -r1.229 ada-lang.c
--- ada-lang.c	2 Jul 2009 17:25:52 -0000	1.229
+++ ada-lang.c	19 Nov 2009 18:51:42 -0000
@@ -6505,7 +6505,7 @@ find_old_style_renaming_symbol (const ch
          qualified.  This means we need to prepend the function name
          as well as adding the ``___XR'' suffix to build the name of
          the associated renaming symbol.  */
-      char *function_name = SYMBOL_LINKAGE_NAME (function_sym);
+      const char *function_name = SYMBOL_LINKAGE_NAME (function_sym);
       /* Function names sometimes contain suffixes used
          for instance to qualify nested subprograms.  When building
          the XR type name, we need to make sure that this suffix is
@@ -6514,9 +6514,11 @@ find_old_style_renaming_symbol (const ch
       const int function_name_len = ada_name_prefix_len (function_name);
       const int rename_len = function_name_len + 2      /*  "__" */
         + strlen (name) + 6 /* "___XR\0" */ ;
+      int bufsize = rename_len * sizeof (char);
 
       /* Strip the suffix if necessary.  */
-      function_name[function_name_len] = '\0';
+      int end = (strlen (function_name) > function_name_len
+		 ? function_name_len : strlen (function_name));
 
       /* Library-level functions are a special case, as GNAT adds
          a ``_ada_'' prefix to the function name to avoid namespace
@@ -6526,9 +6528,10 @@ find_old_style_renaming_symbol (const ch
           && strstr (function_name, "_ada_") == function_name)
         function_name = function_name + 5;
 
-      rename = (char *) alloca (rename_len * sizeof (char));
-      xsnprintf (rename, rename_len * sizeof (char), "%s__%s___XR", 
-		 function_name, name);
+      rename = (char *) alloca (bufsize);
+      gdb_assert (end < bufsize);
+      strncpy (rename, function_name, end);
+      xsnprintf (rename, bufsize - end, "__%s___XR", name);
     }
   else
     {

             reply	other threads:[~2009-11-19 19:01 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-11-19 19:01 Keith Seitz [this message]
2009-11-19 19:21 ` Joel Brobecker
2009-11-19 22:50   ` Joel Brobecker

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4B0595B3.90001@redhat.com \
    --to=keiths@redhat.com \
    --cc=gdb-patches@sourceware.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox