9bd4e90
for gdb/ChangeLog:
e6628c4
2006-08-22  Will Drewry <wad@google.com>
e6628c4
	    Tavis Ormandy <taviso@google.com>
9bd4e90
e6628c4
	* dwarf2read.c (decode_locdesc): Enforce location description stack
e6628c4
	boundaries.
9bd4e90
	* dwarfread.c (locval): Likewise.
9bd4e90
9bd4e90
Index: gdb-6.5/gdb/dwarf2read.c
9bd4e90
===================================================================
e6628c4
--- gdb-6.5.orig/gdb/dwarf2read.c	2006-09-04 02:02:23.000000000 -0300
e6628c4
+++ gdb-6.5/gdb/dwarf2read.c	2006-09-04 02:02:23.000000000 -0300
e6628c4
@@ -8667,8 +8667,7 @@ dwarf2_fundamental_type (struct objfile 
e6628c4
    callers will only want a very basic result and this can become a
e6628c4
    complaint.
e6628c4
 
e6628c4
-   Note that stack[0] is unused except as a default error return.
e6628c4
-   Note that stack overflow is not yet handled.  */
e6628c4
+   Note that stack[0] is unused except as a default error return. */
e6628c4
 
e6628c4
 static CORE_ADDR
e6628c4
 decode_locdesc (struct dwarf_block *blk, struct dwarf2_cu *cu)
e6628c4
@@ -8685,7 +8684,7 @@ decode_locdesc (struct dwarf_block *blk,
e6628c4
 
e6628c4
   i = 0;
e6628c4
   stacki = 0;
e6628c4
-  stack[stacki] = 0;
e6628c4
+  stack[++stacki] = 0;
e6628c4
 
e6628c4
   while (i < size)
e6628c4
     {
e6628c4
@@ -8864,6 +8863,16 @@ decode_locdesc (struct dwarf_block *blk,
9bd4e90
 		     dwarf_stack_op_name (op));
9bd4e90
 	  return (stack[stacki]);
9bd4e90
 	}
e6628c4
+      /* Enforce maximum stack depth of size-1 to avoid ++stacki writing
e6628c4
+         outside of the allocated space. Also enforce minimum > 0.
e6628c4
+         -- wad@google.com 14 Aug 2006 */
e6628c4
+      if (stacki >= sizeof (stack) / sizeof (*stack) - 1)
9bd4e90
+	internal_error (__FILE__, __LINE__,
e6628c4
+	                _("location description stack too deep: %d"),
e6628c4
+	                stacki);
9bd4e90
+      if (stacki <= 0)
9bd4e90
+	internal_error (__FILE__, __LINE__,
e6628c4
+	                _("location description stack too shallow"));
9bd4e90
     }
9bd4e90
   return (stack[stacki]);
9bd4e90
 }
9bd4e90
Index: gdb-6.5/gdb/dwarfread.c
9bd4e90
===================================================================
9bd4e90
--- gdb-6.5.orig/gdb/dwarfread.c	2005-12-17 20:33:59.000000000 -0200
e6628c4
+++ gdb-6.5/gdb/dwarfread.c	2006-09-04 02:02:23.000000000 -0300
e6628c4
@@ -2138,9 +2138,7 @@ decode_line_numbers (char *linetable)
e6628c4
 
e6628c4
    NOTES
e6628c4
 
e6628c4
-   Note that stack[0] is unused except as a default error return.
e6628c4
-   Note that stack overflow is not yet handled.
e6628c4
- */
e6628c4
+   Note that stack[0] is unused except as a default error return. */
e6628c4
 
e6628c4
 static int
e6628c4
 locval (struct dieinfo *dip)
e6628c4
@@ -2160,7 +2158,7 @@ locval (struct dieinfo *dip)
e6628c4
   loc += nbytes;
e6628c4
   end = loc + locsize;
e6628c4
   stacki = 0;
e6628c4
-  stack[stacki] = 0;
e6628c4
+  stack[++stacki] = 0;
e6628c4
   dip->isreg = 0;
e6628c4
   dip->offreg = 0;
e6628c4
   dip->optimized_out = 1;
e6628c4
@@ -2224,6 +2222,16 @@ locval (struct dieinfo *dip)
9bd4e90
 	  stacki--;
9bd4e90
 	  break;
9bd4e90
 	}
e6628c4
+      /* Enforce maximum stack depth of size-1 to avoid ++stacki writing
e6628c4
+         outside of the allocated space. Also enforce minimum > 0.
e6628c4
+         -- wad@google.com 14 Aug 2006 */
e6628c4
+      if (stacki >= sizeof (stack) / sizeof (*stack) - 1)
9bd4e90
+	internal_error (__FILE__, __LINE__,
e6628c4
+	                _("location description stack too deep: %d"),
e6628c4
+	                stacki);
9bd4e90
+      if (stacki <= 0)
9bd4e90
+	internal_error (__FILE__, __LINE__,
e6628c4
+	                _("location description stack too shallow"));
9bd4e90
     }
9bd4e90
   return (stack[stacki]);
9bd4e90
 }