Blame SOURCES/rhbz1643997.0013-bpf-translate.cxx-fix-segfault-with-malformed-regist.patch

cab4ad
From 99ee8b19901f4908e2a2942731c34e03aadd9549 Mon Sep 17 00:00:00 2001
cab4ad
From: Serhei Makarov <smakarov@redhat.com>
cab4ad
Date: Tue, 30 Oct 2018 17:10:53 -0400
cab4ad
Subject: [PATCH 13/32] bpf-translate.cxx :: fix segfault with malformed
cab4ad
 register
cab4ad
cab4ad
---
cab4ad
 bpf-translate.cxx                                  | 9 +++++++--
cab4ad
 testsuite/systemtap.bpf/asm_tests/err-regparse.stp | 9 +++++++++
cab4ad
 2 files changed, 16 insertions(+), 2 deletions(-)
cab4ad
 create mode 100644 testsuite/systemtap.bpf/asm_tests/err-regparse.stp
cab4ad
cab4ad
diff --git a/bpf-translate.cxx b/bpf-translate.cxx
cab4ad
index bb133bae5..d46dae44a 100644
cab4ad
--- a/bpf-translate.cxx
cab4ad
+++ b/bpf-translate.cxx
cab4ad
@@ -952,8 +952,13 @@ bpf_unparser::emit_asm_arg (const asm_stmt &stmt, const std::string &arg,
cab4ad
     {
cab4ad
       /* arg is a register number */
cab4ad
       std::string reg = arg[0] == 'r' ? arg.substr(1) : arg;
cab4ad
-      unsigned long num = stoul(reg, 0, 0);
cab4ad
-      if (num > 10)
cab4ad
+      unsigned long num;
cab4ad
+      bool parsed = false;
cab4ad
+      try {
cab4ad
+        num = stoul(reg, 0, 0);
cab4ad
+        parsed = true;
cab4ad
+      } catch (std::exception &e) {} // XXX: invalid_argument, out_of_range
cab4ad
+      if (!parsed || num > 10)
cab4ad
 	throw SEMANTIC_ERROR (_F("invalid bpf register '%s'",
cab4ad
                                  arg.c_str()), stmt.tok);
cab4ad
       return this_prog.lookup_reg(num);
cab4ad
diff --git a/testsuite/systemtap.bpf/asm_tests/err-regparse.stp b/testsuite/systemtap.bpf/asm_tests/err-regparse.stp
cab4ad
new file mode 100644
cab4ad
index 000000000..ba66800e6
cab4ad
--- /dev/null
cab4ad
+++ b/testsuite/systemtap.bpf/asm_tests/err-regparse.stp
cab4ad
@@ -0,0 +1,9 @@
cab4ad
+function foo:long () %{ /* bpf */ /* pure */
cab4ad
+  0xb7, $rc, -, -, 50; /* mov $rc, 50 */
cab4ad
+  0xbf, $$, rc, -, -; /* mov $$, $rc -- TYPO */
cab4ad
+%}
cab4ad
+
cab4ad
+probe begin {
cab4ad
+  printf("foo()=%d should be fifty\n", foo())
cab4ad
+  exit()
cab4ad
+}
cab4ad
-- 
cab4ad
2.14.5
cab4ad