From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from simark.ca by simark.ca with LMTP id OXhXD01CsWp2CC0AWB0awg (envelope-from ) for ; Mon, 21 Sep 2026 10:42:21 -0400 Authentication-Results: simark.ca; dkim=pass (2048-bit key; unprotected) header.d=polymtl.ca header.i=@polymtl.ca header.a=rsa-sha256 header.s=oct2025 header.b=ZfiLjg0t; dkim-atps=neutral Received: by simark.ca (Postfix, from userid 112) id 1CCBD1E051; Mon, 21 Sep 2026 10:42:21 -0400 (EDT) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on simark.ca X-Spam-Level: X-Spam-Status: No, score=-2.4 required=5.0 tests=ARC_SIGNED,ARC_VALID,BAYES_00, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,MAILING_LIST_MULTI, RCVD_IN_DNSWL_MED,RCVD_IN_VALIDITY_CERTIFIED_BLOCKED, RCVD_IN_VALIDITY_RPBL_BLOCKED,RCVD_IN_VALIDITY_SAFE_BLOCKED autolearn=ham autolearn_force=no version=4.0.1 Received: from vm01.sourceware.org (vm01.sourceware.org [38.145.34.32]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by simark.ca (Postfix) with ESMTPS id EEBEE1E01F for ; Mon, 21 Sep 2026 10:42:19 -0400 (EDT) Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id BB4334BA79A2 for ; Mon, 21 Sep 2026 14:42:18 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org BB4334BA79A2 Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=polymtl.ca header.i=@polymtl.ca header.a=rsa-sha256 header.s=oct2025 header.b=ZfiLjg0t Received: from smtp.polymtl.ca (smtp.polymtl.ca [132.207.4.11]) by sourceware.org (Postfix) with ESMTPS id B21C94BA79AE for ; Mon, 21 Sep 2026 14:41:24 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org B21C94BA79AE Authentication-Results: sourceware.org; dmarc=pass (p=none dis=none) header.from=polymtl.ca Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=polymtl.ca ARC-Filter: OpenARC Filter v1.0.0 sourceware.org B21C94BA79AE Authentication-Results: sourceware.org; arc=none smtp.remote-ip=132.207.4.11 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1790001684; cv=none; b=QWqC0jNYQ0DsSXv1AbrWOx6gN9F8F1QG0AG0WE9UsSG8POe2E5Rk2WPQapuhcVG7F/1h/AcZDLw7RPGFbA6mnQUKMv3WJLKXDswH3LMCdvS1ewjtbUUr9KXDo9ZU/Hqp1Mw56LQvIw/GrAKMNG998xBevAAkwc7nbXtCngccGcI= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1790001684; c=relaxed/simple; bh=iNAnrglJmg8+qzCq+KsuHisEa7OhzM3uvryeDsetr/w=; h=DKIM-Signature:Message-ID:Date:MIME-Version:Subject:To:From; b=XcYdQREbEuB01S5Tc/9F26UdP0HwDTXVYXis7gZQBAnWaAeSXEqyFUB/7YxGUNXGmh1qB6auCVV4qqiWyK3GdEI2V5RHKGQBTfbK6E5ExF5Qm/YarQJ3ZiwL+3WTNgvScMsLE/LfLjboXXf7cE80Qfv4636CrlG1LNHP+bk5ygk= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=polymtl.ca header.i=@polymtl.ca header.a=rsa-sha256 header.s=oct2025 header.b=ZfiLjg0t DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org B21C94BA79AE Received: from simark.ca (simark.ca [158.69.221.121]) (authenticated bits=0) by smtp.polymtl.ca (8.14.7/8.14.7) with ESMTP id 68LEfI5K195361 (version=TLSv1/SSLv3 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 21 Sep 2026 10:41:23 -0400 DKIM-Filter: OpenDKIM Filter v2.11.0 smtp.polymtl.ca 68LEfI5K195361 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=polymtl.ca; s=oct2025; t=1790001683; bh=9yXv7gxs4e7UOEGKsPoZ1mfc+BPy5iKWYipcR1q4NXA=; h=Date:Subject:To:Cc:From:In-Reply-To:From; b=ZfiLjg0tXzdQOLXmGY6wAvWIDwjkyQEtt4YVzudNxpafHXEK35axeQkt/SORqJFg7 IrWytKySSIrlPIox03ocmgU4dU3yN8IIQtmtwLgzg54iohCXl/T6NtM+DJC8/JaFIO J+9ri7T+nNb158RlzS++Q/BcZweQ1MyNBzaRO20r/MacbRAMUkDRc6A3kp6w+6zRO4 I3ehN4ucqsHxGSqAsQPXiaCK8S7mgnXx++2RUl8UVSkHQ7CB/1EA593Kb4roZ9YKz6 ixdfsjeluffJX9p7gP8Y2AhDtkFjNRELmnjs/YNWlEsxdG+l/hJFfFtE2AH7Sj1ooe vTvVVIRE2fAXQ== Received: by simark.ca (Postfix) id 94C471E01F; Mon, 21 Sep 2026 10:41:17 -0400 (EDT) Message-ID: Date: Mon, 21 Sep 2026 10:41:16 -0400 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] gdb/dwarf: fix reading DW_FORM_addrx with address size of 2 To: Tom Tromey Cc: gdb-patches@sourceware.org References: <20260916014513.3386344-1-simon.marchi@polymtl.ca> <87eceqv5to.fsf@tromey.com> Content-Language: fr From: Simon Marchi In-Reply-To: <87eceqv5to.fsf@tromey.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Poly-FromMTA: (simark.ca [158.69.221.121]) at Mon, 21 Sep 2026 14:41:18 +0000 X-BeenThere: gdb-patches@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Gdb-patches mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: gdb-patches-bounces~public-inbox=simark.ca@sourceware.org On 9/18/26 1:15 PM, Tom Tromey wrote: >>>>>> simon marchi writes: > >> From: Simon Marchi >> While investigating AVR binaries for bug 34638, I stumbled on a crash of >> GDB when loading an AVR binary generated by clang: > > Thanks. > >> + /* Check that the whole entry fits inside the section. */ >> + if (addr_base_or_zero + (addr_index + 1) * (ULONGEST) addr_size >> + > per_bfd->addr.size) > > The cast to ULONGEST seems weird to me, especially since it isn't > repeated later: It came from Claude flagging this in my change: (addr_index + 1) * addr_size This is computed as unsigned int, which, in the (unlikely) case that we would deal with a .debug_addr section > 4GB, would get the offset wrong. >> + const gdb_byte *info_ptr >> + = per_bfd->addr.buffer + addr_base_or_zero + addr_index * addr_size; And you're right that the same problem exists here. While re-reviewing, it also flagged that DW_AT_addr_base could have absurdly big values, and the add could overflow 64 bit, which could also lead to an out of bounds read. A safer way to do this would be to subtract instead of adding to do the bounds check. I'll send a new version for that. I also renamed info_ptr -> addr_ptr, I'm pretty sure that "info_ptr" that we see everywhere comes from pointing into section `.debug_info`, which is not the case here. Finally, when I asked it to re-review, it flagged that the testsuite changes to add DWARF 5 DW_FORM_addrx/DW_AT_addr_base support were not correct. In the DWARF 4 GNU extensions (DW_FORM_GNU_addr_index / DW_AT_GNU_addr_base), the .debug_addr section has no header, it's just a bare array of addresses. But in DWARF 5, each contribution has a header. GDB doesn't read that header (it doesn't seem useful to do so), so it didn't cause a problem in my test, but to make the DWARF assembler emit a valid DWARF 5 section, I'll change it to emit the header. Otherwise, you can't even dump the section with readelf: $ readelf --debug-dump=addr testsuite/outputs/gdb.dwarf2/dw2-addr-size-2/dw2-addr-size-2 Contents of the .debug_addr section: For compilation unit at offset 0xc: Index Address readelf: Warning: Corrupt .debug_addr section: expecting header size of 8 or 16, but found 0 instead Simon