yann@570: Original patch from gentoo: gentoo/src/patchsets/gdb/6.8/80_all_gdb-6.5-dwarf-stack-overflow.patch yann@570: -= BEGIN original header =- yann@570: http://bugs.gentoo.org/144833 yann@570: yann@570: for gdb/ChangeLog: yann@570: 2006-08-22 Will Drewry yann@570: Tavis Ormandy yann@570: yann@570: * dwarf2read.c (decode_locdesc): Enforce location description stack yann@570: boundaries. yann@570: * dwarfread.c (locval): Likewise. yann@570: yann@570: -= END original header =- yann@570: diff -durN gdb-6.8.orig/gdb/dwarf2read.c gdb-6.8/gdb/dwarf2read.c yann@570: --- gdb-6.8.orig/gdb/dwarf2read.c 2008-03-10 15:18:10.000000000 +0100 yann@570: +++ gdb-6.8/gdb/dwarf2read.c 2008-06-17 16:07:31.000000000 +0200 yann@570: @@ -9124,8 +9124,7 @@ yann@570: callers will only want a very basic result and this can become a yann@570: complaint. yann@570: yann@570: - Note that stack[0] is unused except as a default error return. yann@570: - Note that stack overflow is not yet handled. */ yann@570: + Note that stack[0] is unused except as a default error return. */ yann@570: yann@570: static CORE_ADDR yann@570: decode_locdesc (struct dwarf_block *blk, struct dwarf2_cu *cu) yann@570: @@ -9142,7 +9141,7 @@ yann@570: yann@570: i = 0; yann@570: stacki = 0; yann@570: - stack[stacki] = 0; yann@570: + stack[++stacki] = 0; yann@570: yann@570: while (i < size) yann@570: { yann@570: @@ -9324,6 +9323,16 @@ yann@570: dwarf_stack_op_name (op)); yann@570: return (stack[stacki]); yann@570: } yann@570: + /* Enforce maximum stack depth of size-1 to avoid ++stacki writing yann@570: + outside of the allocated space. Also enforce minimum > 0. yann@570: + -- wad@google.com 14 Aug 2006 */ yann@570: + if (stacki >= sizeof (stack) / sizeof (*stack) - 1) yann@570: + internal_error (__FILE__, __LINE__, yann@570: + _("location description stack too deep: %d"), yann@570: + stacki); yann@570: + if (stacki <= 0) yann@570: + internal_error (__FILE__, __LINE__, yann@570: + _("location description stack too shallow")); yann@570: } yann@570: return (stack[stacki]); yann@570: }