From: Andrew Burgess <aburgess@redhat.com>
To: Simon Marchi <simon.marchi@efficios.com>,
gdb-patches@sourceware.org, binutils@sourceware.org
Cc: Simon Marchi <simon.marchi@efficios.com>
Subject: Re: [PATCH 11/13] gdb/remote-fileio: remove uses of sprintf
Date: Mon, 17 Aug 2026 17:53:09 +0100 [thread overview]
Message-ID: <8733wc3czu.fsf@redhat.com> (raw)
In-Reply-To: <20260817151646.152571-12-simon.marchi@efficios.com>
Simon Marchi <simon.marchi@efficios.com> writes:
> When building on macOS, I get some:
>
> /Users/smarchi/src/binutils-gdb/gdb/remote-fileio.c:264:3: error: 'sprintf' is deprecated: This function is provided for compatibility reasons only. Due to security concerns inherent in the design of sprintf(3), it is highly recommended that you use snprintf(3) instead. [-Werror,-Wdeprecated-declarations]
> 264 | sprintf (buf + strlen (buf), "%x", retcode);
> | ^
>
> The reply built in remote_fileio_reply is made by appending to a fixed
> size buffer, using a mix of strcpy, strcat and sprintf. Replace them
> with the safer xsnprintf and xstrcpy. This way, every write is bounds
> checked.
See previous commit for thoughts on xstrcpy. But otherwise, this looks
fine.
Approved-By: Andrew Burgess <aburgess@redhat.com>
Thanks,
Andrew
>
> Change-Id: I8446a98be5c5fc0eda79ccbc4858d9dddaf2d4d5
> ---
> gdb/remote-fileio.c | 21 +++++++++++++++------
> 1 file changed, 15 insertions(+), 6 deletions(-)
>
> diff --git a/gdb/remote-fileio.c b/gdb/remote-fileio.c
> index a151161371da..297e3337e2fe 100644
> --- a/gdb/remote-fileio.c
> +++ b/gdb/remote-fileio.c
> @@ -253,28 +253,37 @@ static void
> remote_fileio_reply (remote_target *remote, int retcode, int error)
> {
> char buf[32];
> + char *p = buf;
> + char *const end = buf + sizeof (buf);
> bool ctrl_c = check_quit_flag ();
>
> - strcpy (buf, "F");
> + p += xstrcpy (p, end - p, "F");
> +
> if (retcode < 0)
> {
> - strcat (buf, "-");
> + p += xstrcpy (p, end - p, "-");
> retcode = -retcode;
> }
> - sprintf (buf + strlen (buf), "%x", retcode);
> +
> + p += xsnprintf (p, end - p, "%x", retcode);
> +
> if (error || ctrl_c)
> {
> if (error && ctrl_c)
> error = FILEIO_EINTR;
> +
> if (error < 0)
> {
> - strcat (buf, "-");
> + p += xstrcpy (p, end - p, "-");
> error = -error;
> }
> - sprintf (buf + strlen (buf), ",%x", error);
> +
> + p += xsnprintf (p, end - p, ",%x", error);
> +
> if (ctrl_c)
> - strcat (buf, ",C");
> + p += xstrcpy (p, end - p, ",C");
> }
> +
> quit_handler = remote_fileio_o_quit_handler;
> putpkt (remote, buf);
> }
> --
> 2.55.0
next prev parent reply other threads:[~2026-08-17 16:55 UTC|newest]
Thread overview: 35+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-17 15:16 [PATCH 00/13] Fix various warnings when building on macOS Simon Marchi
2026-08-17 15:16 ` [PATCH 01/13] gdbsupport: remove uses of vsprintf Simon Marchi
2026-08-17 15:47 ` Andrew Burgess
2026-08-17 15:16 ` [PATCH 02/13] gdbsupport: remove uses of sprintf Simon Marchi
2026-08-17 15:49 ` Andrew Burgess
2026-08-17 15:16 ` [PATCH 03/13] opcodes/z80: remove use " Simon Marchi
2026-08-18 6:40 ` Jan Beulich
2026-08-18 16:48 ` Simon Marchi
2026-08-17 15:16 ` [PATCH 04/13] sim/ppc: make defines.h sed command portable Simon Marchi
2026-08-17 15:36 ` Andrew Burgess
2026-08-17 15:16 ` [PATCH 05/13] sim/m32r: fix unused variable warning on non-Linux hosts Simon Marchi
2026-08-17 15:36 ` Andrew Burgess
2026-08-17 15:16 ` [PATCH 06/13] sim/m32r: fix unused function warnings " Simon Marchi
2026-08-17 15:37 ` Andrew Burgess
2026-08-17 15:16 ` [PATCH 07/13] gdb/csky: remove uses of sprintf Simon Marchi
2026-08-17 16:26 ` Andrew Burgess
2026-08-17 17:03 ` Simon Marchi
2026-08-17 20:50 ` Tom Tromey
2026-08-18 18:26 ` Simon Marchi
2026-08-17 15:16 ` [PATCH 08/13] gdb/dwarf2: " Simon Marchi
2026-08-17 16:35 ` Andrew Burgess
2026-08-17 15:16 ` [PATCH 09/13] gdb/elfread: remove use " Simon Marchi
2026-08-17 16:38 ` Andrew Burgess
2026-08-17 15:16 ` [PATCH 10/13] gdbsupport: add xstrcpy Simon Marchi
2026-08-17 16:45 ` Andrew Burgess
2026-08-17 17:30 ` Simon Marchi
2026-08-17 15:16 ` [PATCH 11/13] gdb/remote-fileio: remove uses of sprintf Simon Marchi
2026-08-17 16:53 ` Andrew Burgess [this message]
2026-08-17 15:16 ` [PATCH 12/13] gdb/remote: " Simon Marchi
2026-08-17 16:51 ` Andrew Burgess
2026-08-17 17:34 ` Simon Marchi
2026-08-17 15:16 ` [PATCH 13/13] gdb/tracepoint: " Simon Marchi
2026-08-17 16:51 ` Andrew Burgess
2026-08-17 20:52 ` [PATCH 00/13] Fix various warnings when building on macOS Tom Tromey
2026-08-18 18:10 ` Simon Marchi
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=8733wc3czu.fsf@redhat.com \
--to=aburgess@redhat.com \
--cc=binutils@sourceware.org \
--cc=gdb-patches@sourceware.org \
--cc=simon.marchi@efficios.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox