This is the mail archive of the
gdb-patches@sourceware.org
mailing list for the GDB project.
Re: [RFA] off by one array reference in i386-low.c/i386_show_dr
- From: Pedro Alves <pedro at codesourcery dot com>
- To: gdb-patches at sourceware dot org
- Cc: Michael Snyder <msnyder at vmware dot com>, Doug Evans <dje at google dot com>
- Date: Sun, 27 Feb 2011 16:55:15 +0000
- Subject: Re: [RFA] off by one array reference in i386-low.c/i386_show_dr
- References: <4D698427.2050301@vmware.com>
On Saturday 26 February 2011 22:52:23, Michael Snyder wrote:
> I'm not 100 percent sure this is right, but I do know that
> as written, it will overflow the array dr_mirror.
How? 'i' is incremented twice on each iteration.
> Index: i386-low.c
> ===================================================================
> RCS file: /cvs/src/src/gdb/gdbserver/i386-low.c,v
> retrieving revision 1.5
> diff -u -p -u -p -r1.5 i386-low.c
> --- i386-low.c 1 Jan 2011 15:33:24 -0000 1.5
> +++ i386-low.c 26 Feb 2011 22:48:38 -0000
> @@ -195,7 +195,7 @@ i386_show_dr (struct i386_debug_reg_stat
> \tDR%d: addr=0x%s, ref.count=%d DR%d: addr=0x%s, ref.count=%d\n",
> i, paddress (state->dr_mirror[i]),
> state->dr_ref_count[i],
> - i + 1, paddress (state->dr_mirror[i + 1]),
> + i + 1, paddress (state->dr_mirror[i]),
> state->dr_ref_count[i + 1]);
Even if there's chance of overflow that I'm not
seeing, this change is obviously wrong.
> i++;
> }
--
Pedro Alves