From: Michael Snyder <msnyder@vmware.com>
To: DJ Delorie <dj@redhat.com>
Cc: "gcc-patches@gcc.gnu.org" <gcc-patches@gcc.gnu.org>,
"gdb-patches@sourceware.org" <gdb-patches@sourceware.org>
Subject: Re: [RFA] libiberty/hashtab.c, higher_prime_index: avoid array overrun
Date: Thu, 03 Mar 2011 22:33:00 -0000 [thread overview]
Message-ID: <4D701717.5070003@vmware.com> (raw)
In-Reply-To: <201103032211.p23MB9Ed003261@greed.delorie.com>
DJ Delorie wrote:
>> As written, the function will access element [30] of a 30-element array.
>
> Um, no?
>
> unsigned int mid = low + (high - low) / 2;
>
> This can never give mid == high unless low == high, which won't happen
> in that loop.
>
> The math wants to search everything from (including) low to
> (excluding) high.
>
> (but I'm willing to be proven wrong...)
Whee, here we go...
(gdb) b higher_prime_index
Breakpoint 2 at 0x79bed4: file
/data/home/msnyder/cvs/localhost/src/libiberty/hashtab.c, line 175.
(gdb) print higher_prime_index(0xffffffff)
Breakpoint 2, higher_prime_index (n=4294967295)
at /data/home/msnyder/cvs/localhost/src/libiberty/hashtab.c:175
175 unsigned int low = 0;
The program being debugged stopped while in a function called from GDB.
Evaluation of the expression containing the function
(higher_prime_index) will be abandoned.
When the function is done executing, GDB will silently stop.
(gdb) n
176 unsigned int high = sizeof(prime_tab) / sizeof(prime_tab[0]) - 1;
(gdb)
178 while (low < high)
(gdb)
180 unsigned int mid = low + (high - low) / 2;
(gdb) display low
1: low = 0
(gdb) n
181 if (n > prime_tab[mid].prime)
1: low = 0
(gdb)
182 low = mid + 1;
1: low = 0(gdb) b higher_prime_index
Breakpoint 2 at 0x79bed4: file
/data/home/msnyder/cvs/localhost/src/libiberty/hashtab.c, line 175.
(gdb) print higher_prime_index(0xffffffff)
Breakpoint 2, higher_prime_index (n=4294967295)
at /data/home/msnyder/cvs/localhost/src/libiberty/hashtab.c:175
175 unsigned int low = 0;
The program being debugged stopped while in a function called from GDB.
Evaluation of the expression containing the function
(higher_prime_index) will be abandoned.
When the function is done executing, GDB will silently stop.
(gdb) n
176 unsigned int high = sizeof(prime_tab) / sizeof(prime_tab[0]) - 1;
(gdb)
178 while (low < high)
(gdb)
180 unsigned int mid = low + (high - low) / 2;
(gdb) display low
1: low = 0
(gdb) n
181 if (n > prime_tab[mid].prime)
1: low = 0
(gdb)
182 low = mid + 1;
1: low = 0
(gdb)
178 while (low < high)
1: low = 16
(gdb)
180 unsigned int mid = low + (high - low) / 2;
1: low = 16
(gdb)
181 if (n > prime_tab[mid].prime)
1: low = 16
(gdb)
182 low = mid + 1;
(gdb)
178 while (low < high)
1: low = 16
(gdb)
180 unsigned int mid = low + (high - low) / 2;
1: low = 16
(gdb)
181 if (n > prime_tab[mid].prime)
1: low = 16
(gdb)
182 low = mid + 1;
1: low = 16
(gdb)
178 while (low < high)
1: low = 24
(gdb)
180 unsigned int mid = low + (high - low) / 2;
1: low = 24
(gdb)
181 if (n > prime_tab[mid].prime)
1: low = 24
(gdb)
182 low = mid + 1;
1: low = 24
(gdb)
178 while (low < high)
1: low = 28
(gdb)
180 unsigned int mid = low + (high - low) / 2;
1: low = 28
(gdb)
181 if (n > prime_tab[mid].prime)
1: low = 28
(gdb)
182 low = mid + 1;
1: low = 28
(gdb)
178 while (low < high)
1: low = 30
(gdb)
188 if (n > prime_tab[low].prime)
1: low = 30
(gdb)
prev parent reply other threads:[~2011-03-03 22:33 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-03-03 22:04 Michael Snyder
2011-03-03 22:11 ` DJ Delorie
2011-03-03 22:26 ` Michael Snyder
2011-03-03 22:59 ` DJ Delorie
2011-03-07 2:59 ` Michael Snyder
2011-03-03 23:01 ` Mike Stump
2011-03-03 23:24 ` Michael Snyder
2011-03-04 0:14 ` Dave Korn
2011-03-04 0:19 ` DJ Delorie
2011-03-03 22:33 ` Michael Snyder [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4D701717.5070003@vmware.com \
--to=msnyder@vmware.com \
--cc=dj@redhat.com \
--cc=gcc-patches@gcc.gnu.org \
--cc=gdb-patches@sourceware.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox