From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from simark.ca by simark.ca with LMTP id frEOLDg8g2p8RC0AWB0awg (envelope-from ) for ; Mon, 17 Aug 2026 12:52:08 -0400 Authentication-Results: simark.ca; dkim=fail reason="signature verification failed" (1024-bit key; unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=Eza3TChX; dkim-atps=neutral Received: by simark.ca (Postfix, from userid 112) id A37741E033; Mon, 17 Aug 2026 12:52:08 -0400 (EDT) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on simark.ca X-Spam-Level: X-Spam-Status: No, score=-5.1 required=5.0 tests=ARC_SIGNED,ARC_VALID,BAYES_00, DKIM_INVALID,DKIM_SIGNED,MAILING_LIST_MULTI,RCVD_IN_DNSWL_MED autolearn=ham autolearn_force=no version=4.0.1 Received: from vm01.sourceware.org (vm01.sourceware.org [38.145.34.32]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by simark.ca (Postfix) with ESMTPS id B59171E033 for ; Mon, 17 Aug 2026 12:52:07 -0400 (EDT) Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 326244BAE7C1 for ; Mon, 17 Aug 2026 16:52:07 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 326244BAE7C1 Authentication-Results: sourceware.org; dkim=fail reason="signature verification failed" (1024-bit key, unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=Eza3TChX Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by sourceware.org (Postfix) with ESMTP id 0376F4BAE7C4 for ; Mon, 17 Aug 2026 16:51:25 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 0376F4BAE7C4 Authentication-Results: sourceware.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=redhat.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 0376F4BAE7C4 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1786985486; cv=none; b=V3wWMe6FQ3KaNjPj1Wm7WEZ+9491nUfWJiUNRFzxoJ8Rw88SM0o65MHYbGd+k3dtrKMLDUZ3dhQFEz63YNFtPZsrCoz9wIcLPkpZYPKJ2tKFnnhPW1ZDFYsF6oorL1QH0rKB+gFMle/2sYkWck4mhZFBvvV9dU1CYsV4b90zsrI= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1786985486; c=relaxed/simple; bh=Y1bXYlll74G45nKnq7AMmxUnlbjXP7XFAOgZqzQhKDw=; h=DKIM-Signature:From:To:Subject:Date:Message-ID:MIME-Version; b=nsP5JOiON3kkxxEr3Wh2vonLfmzJce3AxY8OOL/WfR3/J1jCTCCoRjGiEt1r0NG1FATu+MisuN4EhGm+2avVAquFioa4XQwQYFhz1noG8NdCRMCDg9BaLB0H1NUfRKp4ZxkfEaU25NIzxI5y8jC9GgijgEYJrX7DDH3LWFs8Pdo= ARC-Authentication-Results: i=1; sourceware.org; dkim=fail (1024-bit key, unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=Eza3TChX reason="signature verification failed" DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 0376F4BAE7C4 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786985485; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=joeV5lem1PnEQFWS1UtsY71VhvSjIHvyxr6ZpKgDDcw=; b=Eza3TChXQJDwuKFDAn8KRYPU0IIShsqf78jIK4z7UpN9Ed1MmMMcczXw4mYKnJzzyCbGK1 +4o8mW/zjQ7xsH3quRrgo+sc8ZAvQXyyw9rwRcHw88jDdkLRZRL8HD7550ndo/QINYtu5x s0iWY3sx+J+pBaue76UmfEF+mcAWnyo= Received: from mail-wr1-f72.google.com (mail-wr1-f72.google.com [209.85.221.72]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-347-qsIxQVQ9Ouu50S-G5JEHfw-1; Mon, 17 Aug 2026 12:51:24 -0400 X-MC-Unique: qsIxQVQ9Ouu50S-G5JEHfw-1 X-Mimecast-MFC-AGG-ID: qsIxQVQ9Ouu50S-G5JEHfw_1786985483 Received: by mail-wr1-f72.google.com with SMTP id ffacd0b85a97d-48000d75326so2426889f8f.2 for ; Mon, 17 Aug 2026 09:51:24 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786985483; x=1787590283; h=content-type:mime-version:message-id:date:references:in-reply-to :subject:cc:to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=i6VILHTPm7AmdPqiYL3hC3A9iFw2VSLHeZjOe7WqFtI=; b=Js6yYXvDYKdxCkTlPlIOUpPpfqGWyb1mlOcC/Qrl05xvzoD5Iqjx7RuDTfa7U6/zLr /2hlfJ23HFGcg7FtMcw78uG8L0/Pegmcs6+ZF2cwdiuuJMWQ8PKsS1kFt4M7fkB19AlW kRdgimDcEIHKQgIlsMMMvKVtKsw7Fy/j7pRr+xT7OUx4x3X8BUsiv1zoCuwztGJludxU 0swyAa2sdH3wg7mGT4rb/8UWtmdgereKAsv3Ac6n75A+NfR4coZ10jwX5KcmuwTGcnk0 lw8ivhrMUiY4qPT3YjnkgoMAdHCMWPPi0ttVJHPhChgByCCG4TwG6so1Rqsovbg9BXF2 UXEw== X-Forwarded-Encrypted: i=1; AHgh+RqoPNtbMgEdAzKfe64+1Rc/uOZRuTDb9JfKpg0bv2DPfclgIC+l+EdVQpcZm3uv3LT7dg0jwAazMzzjJA==@sourceware.org X-Gm-Message-State: AOJu0YwJ8cx3h19Vh8HCSKDpiZDt9ux+egB3THKswO+4DMyDWYq8iEzS pcBNOuH168FBiINoVBudXHx55pRRWxIfczNf6B8G/3Z9sRLONJyykQpZyC6NzSdlXW4fvL6NwDq mPuxfJf3ODjSxda7PtkIvAklVRH5QvaXgZ4wkbo0BKSaM+/isoXD+OBbCjZpGVFo= X-Gm-Gg: AR+sD11fAuonQmycREiqAMLJslxqrTATkR189GvfiCIjOMRjXXO29316PP6eIC2qoBC RhGMt2Z4izVDCwTLP0ow+Kb78YJAjj44n2dS+gzLtNPEKbcnBCqbESpSfS+UaM0S7rPWuch8pN/ 4rsK9NTC7cU/4yKlFYG/n84qv8uMwnnkvgSDWsg+j4xM3N2GU+v1KGOsikyMv/gtFLrh+0Bvz+X Hzj1iD3Y0Rpj03g2TeERUPVNYs4QO0zSWqyTgUH4fjP2Rr5DNB3QI00su2cwj/0wIzqhij62GH3 X28yH0luDeBDgSw893QU1PdK7hkEUVleO182WUqdTP2fch+I3POAkk8w5DvHDZEEk5CalnTPLrW 71Uw0729fO/PlXn54LLY= X-Received: by 2002:adf:e188:0:b0:481:5657:5299 with SMTP id ffacd0b85a97d-48160698f39mr43441384f8f.0.1786985483031; Mon, 17 Aug 2026 09:51:23 -0700 (PDT) X-Received: by 2002:adf:e188:0:b0:481:5657:5299 with SMTP id ffacd0b85a97d-48160698f39mr43441315f8f.0.1786985482591; Mon, 17 Aug 2026 09:51:22 -0700 (PDT) Received: from localhost (67.72.115.87.dyn.plus.net. [87.115.72.67]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-482a5b7cd38sm5866511f8f.32.2026.08.17.09.51.21 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 17 Aug 2026 09:51:21 -0700 (PDT) From: Andrew Burgess To: Simon Marchi , gdb-patches@sourceware.org, binutils@sourceware.org Cc: Simon Marchi Subject: Re: [PATCH 12/13] gdb/remote: remove uses of sprintf In-Reply-To: <20260817151646.152571-13-simon.marchi@efficios.com> References: <20260817151646.152571-1-simon.marchi@efficios.com> <20260817151646.152571-13-simon.marchi@efficios.com> Date: Mon, 17 Aug 2026 17:51:21 +0100 Message-ID: <878q643d2u.fsf@redhat.com> MIME-Version: 1.0 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: MkUui08oe_-z4rLlXGWKGybLT2jFqGse3aTNHcCWJSM_1786985483 X-Mimecast-Originator: redhat.com Content-Type: text/plain X-BeenThere: gdb-patches@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Gdb-patches mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: gdb-patches-bounces~public-inbox=simark.ca@sourceware.org Simon Marchi writes: > When building on macOS, I get some: > > /Users/smarchi/src/binutils-gdb/gdb/remote.c:11556:3: error: 'sprintf' is deprecated: This function is provided for compatibility reasons only. Due to security concerns inherent in the design of sprintf(3), it is highly recommended that you use snprintf(3) instead. [-Werror,-Wdeprecated-declarations] > 11556 | sprintf (buf, ";cmds:%x,", bp_tgt->persist); > | ^ > > Both are in remote_add_target_side_commands, which unlike the similar > remote_add_target_side_condition, does not receive the end of the > packet, and does not bound its writes. Give it a BUF_END parameter, > and use xsnprintf. > > The edits to remote_add_target_side_condition are to keep the two > functions in sync. > > Ideally, the pack_hex_byte calls and the `*buf = '\0'` assignments > should also have some bound checks, but that is outside the scope of > this patch. > > Change-Id: Ib2e9849d89ebcc9e6275297138a3deb8bf03a7c3 > --- > gdb/remote.c | 36 ++++++++++++++++++++++-------------- > 1 file changed, 22 insertions(+), 14 deletions(-) > > diff --git a/gdb/remote.c b/gdb/remote.c > index 3d38a9c7c8c9..fe898013a394 100644 > --- a/gdb/remote.c > +++ b/gdb/remote.c > @@ -11513,10 +11513,11 @@ Remote replied unexpectedly while setting startup-with-shell: %s"), > } > > > -/* Given a location's target info BP_TGT and the packet buffer BUF, output > - the list of conditions (in agent expression bytecode format), if any, the > - target needs to evaluate. The output is placed into the packet buffer > - started from BUF and ended at BUF_END. */ > +/* Given a location's target info BP_TGT and the packet buffer BUF, output the > + list of conditions (in agent expression bytecode format), if any, the > + target needs to evaluate. > + > + The output is appended to the existing content of BUF. */ > > static int > remote_add_target_side_condition (struct gdbarch *gdbarch, > @@ -11532,35 +11533,42 @@ remote_add_target_side_condition (struct gdbarch *gdbarch, > /* Send conditions to the target. */ > for (agent_expr *aexpr : bp_tgt->conditions) > { > - xsnprintf (buf, buf_end - buf, "X%x,", (int) aexpr->buf.size ()); > - buf += strlen (buf); > + buf += xsnprintf (buf, buf_end - buf, "X%x,", (int) aexpr->buf.size ()); > + > for (int i = 0; i < aexpr->buf.size (); ++i) > buf = pack_hex_byte (buf, aexpr->buf[i]); > + I wonder if we should add an assert here either inside, or just after, the loop, to check that we've not blown past BUF_END? Unless I'm misunderstanding this, these PACK_HEX_BYTE calls could overrun the buffer, right? > *buf = '\0'; > } > return 0; > } > > +/* Given a location's target info BP_TGT and the packet buffer BUF, output the > + list of commands (in agent expression bytecode format), if any, the target > + needs to run when the breakpoint is hit. > + > + The output is appended to the existing content of BUF. */ > + > static void > remote_add_target_side_commands (struct gdbarch *gdbarch, > - struct bp_target_info *bp_tgt, char *buf) > + struct bp_target_info *bp_tgt, char *buf, > + char *buf_end) > { > if (bp_tgt->tcommands.empty ()) > return; > > buf += strlen (buf); > - > - sprintf (buf, ";cmds:%x,", bp_tgt->persist); > - buf += strlen (buf); > + buf += xsnprintf (buf, buf_end - buf, ";cmds:%x,", bp_tgt->persist); > > /* Concatenate all the agent expressions that are commands into the > cmds parameter. */ > for (agent_expr *aexpr : bp_tgt->tcommands) > { > - sprintf (buf, "X%x,", (int) aexpr->buf.size ()); > - buf += strlen (buf); > + buf += xsnprintf (buf, buf_end - buf, "X%x,", (int) aexpr->buf.size ()); > + > for (int i = 0; i < aexpr->buf.size (); ++i) > buf = pack_hex_byte (buf, aexpr->buf[i]); > + As above for buffer overrun maybe? Thanks, Andrew > *buf = '\0'; > } > } > @@ -11604,7 +11612,7 @@ remote_target::insert_breakpoint (struct gdbarch *gdbarch, > remote_add_target_side_condition (gdbarch, bp_tgt, p, endbuf); > > if (can_run_breakpoint_commands ()) > - remote_add_target_side_commands (gdbarch, bp_tgt, p); > + remote_add_target_side_commands (gdbarch, bp_tgt, p, endbuf); > > putpkt (rs->buf); > getpkt (&rs->buf); > @@ -11912,7 +11920,7 @@ remote_target::insert_hw_breakpoint (struct gdbarch *gdbarch, > remote_add_target_side_condition (gdbarch, bp_tgt, p, endbuf); > > if (can_run_breakpoint_commands ()) > - remote_add_target_side_commands (gdbarch, bp_tgt, p); > + remote_add_target_side_commands (gdbarch, bp_tgt, p, endbuf); > > putpkt (rs->buf); > getpkt (&rs->buf); > -- > 2.55.0