Re: [PATCH 11/13] gdb/remote-fileio: remove uses of sprintf
Andrew Burgess <[email protected]>
| Newsgroups | gmane.comp.gnu.binutils,gmane.comp.gdb.patches |
|---|---|
| Message-ID | <[email protected]> |
Simon Marchi <[email protected]> writes: > When building on macOS, I get some: > > /Users/smarchi/src/binutils-gdb/gdb/remote-fileio.c:264:3: error: 'sprintf' is deprecated: This function is provided for compatibility reasons only. Due to security concerns inherent in the design of sprintf(3), it is highly recommended that you use snprintf(3) instead. [-Werror,-Wdeprecated-declarations] > 264 | sprintf (buf + strlen (buf), "%x", retcode); > | ^ > > The reply built in remote_fileio_reply is made by appending to a fixed > size buffer, using a mix of strcpy, strcat and sprintf. Replace them > with the safer xsnprintf and xstrcpy. This way, every write is bounds > checked. See previous commit for thoughts on xstrcpy. But otherwise, this looks fine. Approved-By: Andrew Burgess <[email protected]> Thanks, Andrew > > Change-Id: I8446a98be5c5fc0eda79ccbc4858d9dddaf2d4d5 > --- > gdb/remote-fileio.c | 21 +++++++++++++++------ > 1 file changed, 15 insertions(+), 6 deletions(-) > > diff --git a/gdb/remote-fileio.c b/gdb/remote-fileio.c > index a151161371da..297e3337e2fe 100644 > --- a/gdb/remote-fileio.c > +++ b/gdb/remote-fileio.c > @@ -253,28 +253,37 @@ static void > remote_fileio_reply (remote_target *remote, int retcode, int error) > { > char buf[32]; > + char *p = buf; > + char *const end = buf + sizeof (buf); > bool ctrl_c = check_quit_flag (); > > - strcpy (buf, "F"); > + p += xstrcpy (p, end - p, "F"); > + > if (retcode < 0) > { > - strcat (buf, "-"); > + p += xstrcpy (p, end - p, "-"); > retcode = -retcode; > } > - sprintf (buf + strlen (buf), "%x", retcode); > + > + p += xsnprintf (p, end - p, "%x", retcode); > + > if (error || ctrl_c) > { > if (error && ctrl_c) > error = FILEIO_EINTR; > + > if (error < 0) > { > - strcat (buf, "-"); > + p += xstrcpy (p, end - p, "-"); > error = -error; > } > - sprintf (buf + strlen (buf), ",%x", error); > + > + p += xsnprintf (p, end - p, ",%x", error); > + > if (ctrl_c) > - strcat (buf, ",C"); > + p += xstrcpy (p, end - p, ",C"); > } > + > quit_handler = remote_fileio_o_quit_handler; > putpkt (remote, buf); > } > -- > 2.55.0