yann@570: Original patch from gentoo: gentoo/src/patchsets/gdb/6.7/35_all_gdb-6.3-security-errata-20050610.patch yann@570: -= BEGIN original header =- yann@570: 2005-06-09 Jeff Johnston yann@570: yann@570: * gdb.base/gdbinit.exp: New testcase. yann@570: * gdb.base/gdbinit.sample: Sample .gdbinit for gdbinit.exp. yann@570: yann@570: 2005-06-08 Daniel Jacobowitz yann@570: Jeff Johnston yann@570: yann@570: * Makefile.in (cli-cmds.o): Update. yann@570: * configure.in: Add check for getuid. yann@570: * configure: Regenerated. yann@570: * config.in: Ditto. yann@570: * main.c (captured_main): Pass -1 to source_command when loading yann@570: gdbinit files. yann@570: * cli/cli-cmds.c: Include "gdb_stat.h" and . yann@570: (source_command): Update documentation. Check permissions if yann@570: FROM_TTY is -1. yann@570: yann@570: -= END original header =- yann@570: diff -durN gdb-6.7.orig/gdb/cli/cli-cmds.c gdb-6.7/gdb/cli/cli-cmds.c yann@570: --- gdb-6.7.orig/gdb/cli/cli-cmds.c 2007-08-23 20:08:47.000000000 +0200 yann@570: +++ gdb-6.7/gdb/cli/cli-cmds.c 2008-06-17 23:25:23.000000000 +0200 yann@570: @@ -36,6 +36,7 @@ yann@570: #include "objfiles.h" yann@570: #include "source.h" yann@570: #include "disasm.h" yann@570: +#include "gdb_stat.h" yann@570: yann@570: #include "ui-out.h" yann@570: yann@570: @@ -459,12 +460,31 @@ yann@570: yann@570: if (fd == -1) yann@570: { yann@570: - if (from_tty) yann@570: + if (from_tty > 0) yann@570: perror_with_name (file); yann@570: else yann@570: return; yann@570: } yann@570: yann@570: +#ifdef HAVE_GETUID yann@570: + if (from_tty == -1) yann@570: + { yann@570: + struct stat statbuf; yann@570: + if (fstat (fd, &statbuf) < 0) yann@570: + { yann@570: + perror_with_name (file); yann@570: + close (fd); yann@570: + return; yann@570: + } yann@570: + if (statbuf.st_uid != getuid () || (statbuf.st_mode & S_IWOTH)) yann@570: + { yann@570: + warning (_("not using untrusted file \"%s\""), file); yann@570: + close (fd); yann@570: + return; yann@570: + } yann@570: + } yann@570: +#endif yann@570: + yann@570: stream = fdopen (fd, FOPEN_RT); yann@570: script_from_file (stream, file); yann@570: yann@570: diff -durN gdb-6.7.orig/gdb/main.c gdb-6.7/gdb/main.c yann@570: --- gdb-6.7.orig/gdb/main.c 2007-08-23 20:08:36.000000000 +0200 yann@570: +++ gdb-6.7/gdb/main.c 2008-06-17 23:25:23.000000000 +0200 yann@570: @@ -688,7 +688,7 @@ yann@570: yann@570: if (!inhibit_gdbinit) yann@570: { yann@570: - catch_command_errors (source_script, homeinit, 0, RETURN_MASK_ALL); yann@570: + catch_command_errors (source_script, homeinit, -1, RETURN_MASK_ALL); yann@570: } yann@570: yann@570: /* Do stats; no need to do them elsewhere since we'll only yann@570: @@ -766,7 +766,7 @@ yann@570: || memcmp ((char *) &homebuf, (char *) &cwdbuf, sizeof (struct stat))) yann@570: if (!inhibit_gdbinit) yann@570: { yann@570: - catch_command_errors (source_script, gdbinit, 0, RETURN_MASK_ALL); yann@570: + catch_command_errors (source_script, gdbinit, -1, RETURN_MASK_ALL); yann@570: } yann@570: yann@570: for (i = 0; i < ncmd; i++) yann@570: diff -durN gdb-6.7.orig/gdb/Makefile.in gdb-6.7/gdb/Makefile.in yann@570: --- gdb-6.7.orig/gdb/Makefile.in 2007-09-05 02:14:02.000000000 +0200 yann@570: +++ gdb-6.7/gdb/Makefile.in 2008-06-17 23:25:23.000000000 +0200 yann@570: @@ -2882,7 +2882,7 @@ yann@570: $(expression_h) $(frame_h) $(value_h) $(language_h) $(filenames_h) \ yann@570: $(objfiles_h) $(source_h) $(disasm_h) $(ui_out_h) $(top_h) \ yann@570: $(cli_decode_h) $(cli_script_h) $(cli_setshow_h) $(cli_cmds_h) \ yann@570: - $(tui_h) yann@570: + $(tui_h) $(gdb_stat_h) yann@570: $(CC) -c $(INTERNAL_CFLAGS) $(srcdir)/cli/cli-cmds.c yann@570: cli-decode.o: $(srcdir)/cli/cli-decode.c $(defs_h) $(symtab_h) \ yann@570: $(gdb_regex_h) $(gdb_string_h) $(completer_h) $(ui_out_h) \ yann@570: diff -durN gdb-6.7.orig/gdb/testsuite/gdb.base/gdbinit.exp gdb-6.7/gdb/testsuite/gdb.base/gdbinit.exp yann@570: --- gdb-6.7.orig/gdb/testsuite/gdb.base/gdbinit.exp 1970-01-01 01:00:00.000000000 +0100 yann@570: +++ gdb-6.7/gdb/testsuite/gdb.base/gdbinit.exp 2008-06-17 23:25:23.000000000 +0200 yann@570: @@ -0,0 +1,98 @@ yann@570: +# Copyright 2005 yann@570: +# Free Software Foundation, Inc. yann@570: + yann@570: +# This program is free software; you can redistribute it and/or modify yann@570: +# it under the terms of the GNU General Public License as published by yann@570: +# the Free Software Foundation; either version 2 of the License, or yann@570: +# (at your option) any later version. yann@570: +# yann@570: +# This program is distributed in the hope that it will be useful, yann@570: +# but WITHOUT ANY WARRANTY; without even the implied warranty of yann@570: +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the yann@570: +# GNU General Public License for more details. yann@570: +# yann@570: +# You should have received a copy of the GNU General Public License yann@570: +# along with this program; if not, write to the Free Software yann@570: +# Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA. yann@570: + yann@570: +# Please email any bugs, comments, and/or additions to this file to: yann@570: +# bug-gdb@prep.ai.mit.edu yann@570: + yann@570: +# This file was written by Jeff Johnston . yann@570: + yann@570: +if $tracelevel then { yann@570: + strace $tracelevel yann@570: +} yann@570: + yann@570: +set prms_id 0 yann@570: +set bug_id 0 yann@570: + yann@570: +# are we on a target board yann@570: +if [is_remote target] { yann@570: + return yann@570: +} yann@570: + yann@570: + yann@570: +global verbose yann@570: +global GDB yann@570: +global GDBFLAGS yann@570: +global gdb_prompt yann@570: +global timeout yann@570: +global gdb_spawn_id; yann@570: + yann@570: +gdb_stop_suppressing_tests; yann@570: + yann@570: +verbose "Spawning $GDB -nw" yann@570: + yann@570: +if [info exists gdb_spawn_id] { yann@570: + return 0; yann@570: +} yann@570: + yann@570: +if ![is_remote host] { yann@570: + if { [which $GDB] == 0 } then { yann@570: + perror "$GDB does not exist." yann@570: + exit 1 yann@570: + } yann@570: +} yann@570: + yann@570: +set env(HOME) [pwd] yann@570: +remote_exec build "rm .gdbinit" yann@570: +remote_exec build "cp ${srcdir}/${subdir}/gdbinit.sample .gdbinit" yann@570: +remote_exec build "chmod 646 .gdbinit" yann@570: + yann@570: +set res [remote_spawn host "$GDB -nw [host_info gdb_opts]"]; yann@570: +if { $res < 0 || $res == "" } { yann@570: + perror "Spawning $GDB failed." yann@570: + return 1; yann@570: +} yann@570: +gdb_expect 360 { yann@570: + -re "warning: not using untrusted file.*\.gdbinit.*\[\r\n\]$gdb_prompt $" { yann@570: + pass "untrusted .gdbinit caught." yann@570: + } yann@570: + -re "$gdb_prompt $" { yann@570: + fail "untrusted .gdbinit caught." yann@570: + } yann@570: + timeout { yann@570: + fail "(timeout) untrusted .gdbinit caught." yann@570: + } yann@570: +} yann@570: + yann@570: +remote_exec build "chmod 644 .gdbinit" yann@570: +set res [remote_spawn host "$GDB -nw [host_info gdb_opts]"]; yann@570: +if { $res < 0 || $res == "" } { yann@570: + perror "Spawning $GDB failed." yann@570: + return 1; yann@570: +} yann@570: +gdb_expect 360 { yann@570: + -re "warning: not using untrusted file.*\.gdbinit.*\[\r\n\]$gdb_prompt $" { yann@570: + fail "trusted .gdbinit allowed." yann@570: + } yann@570: + -re "in gdbinit.*$gdb_prompt $" { yann@570: + pass "trusted .gdbinit allowed." yann@570: + } yann@570: + timeout { yann@570: + fail "(timeout) trusted .gdbinit allowed." yann@570: + } yann@570: +} yann@570: + yann@570: +remote_exec build "rm .gdbinit" yann@570: diff -durN gdb-6.7.orig/gdb/testsuite/gdb.base/gdbinit.sample gdb-6.7/gdb/testsuite/gdb.base/gdbinit.sample yann@570: --- gdb-6.7.orig/gdb/testsuite/gdb.base/gdbinit.sample 1970-01-01 01:00:00.000000000 +0100 yann@570: +++ gdb-6.7/gdb/testsuite/gdb.base/gdbinit.sample 2008-06-17 23:25:23.000000000 +0200 yann@570: @@ -0,0 +1 @@ yann@570: +echo "\nin gdbinit"