Bug 48558 - -Warray-bounds fails to detect the out of bound array access
Summary: -Warray-bounds fails to detect the out of bound array access
Status: NEW
Alias: None
Product: gcc
Classification: Unclassified
Component: middle-end (show other bugs)
Version: 4.7.0
: P3 enhancement
Target Milestone: ---
Assignee: Not yet assigned to anyone
URL:
Keywords: diagnostic
Depends on:
Blocks:
 
Reported: 2011-04-11 18:23 UTC by H.J. Lu
Modified: 2011-04-12 10:28 UTC (History)
0 users

See Also:
Host:
Target:
Build:
Known to work:
Known to fail:
Last reconfirmed: 2011-04-12 10:28:18


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description H.J. Lu 2011-04-11 18:23:56 UTC
bfd/elf32-i386.c in binutils has

   case BFD_RELOC_386_IRELATIVE:
      TRACE ("BFD_RELOC_386_IRELATIVE");
      return &elf_howto_table[R_386_IRELATIVE];

It should be:

      return &elf_howto_table[R_386_IRELATIVE - R_386_tls_offset];

GCC fails to detect it.
Comment 1 H.J. Lu 2011-04-11 18:40:07 UTC
A testcase:

[hjl@gnu-6 bfd]$ cat x.c 
enum bfd_reloc_code_real {
  BFD_RELOC_386_IRELATIVE
};
typedef enum bfd_reloc_code_real bfd_reloc_code_real_type;
typedef const struct reloc_howto_struct reloc_howto_type;
struct reloc_howto_struct
{
  unsigned int type;
};
enum elf_i386_reloc_type {
     R_386_IRELATIVE = 42,
};
static reloc_howto_type elf_howto_table[]=
{
  {
    (unsigned) R_386_IRELATIVE
  }
};
reloc_howto_type *
elf_i386_reloc_type_lookup (bfd_reloc_code_real_type code)
{
  switch (code)
    {
    case BFD_RELOC_386_IRELATIVE:
      return &elf_howto_table[R_386_IRELATIVE];
    default:
      break;
    }
  return 0;
}
[hjl@gnu-6 bfd]$ /usr/gcc-4.7.0-x32/bin/gcc  -O3 -S -Wall x.c -Warray-bounds 
[hjl@gnu-6 bfd]$
Comment 2 H.J. Lu 2011-04-11 19:09:54 UTC
A simple change from

return &elf_howto_table[R_386_IRELATIVE];

to

return elf_howto_table[R_386_IRELATIVE];

makes GCC to warn:

[hjl@gnu-6 bfd]$ cat x.c
enum bfd_reloc_code_real {
  BFD_RELOC_386_IRELATIVE
};
typedef enum bfd_reloc_code_real bfd_reloc_code_real_type;
typedef const struct reloc_howto_struct reloc_howto_type;
struct reloc_howto_struct
{
  unsigned int type;
};
enum elf_i386_reloc_type {
     R_386_IRELATIVE = 42,
};
static reloc_howto_type elf_howto_table[]=
{
  {
    (unsigned) R_386_IRELATIVE
  }
};
reloc_howto_type
elf_i386_reloc_type_lookup (bfd_reloc_code_real_type code)
{
  switch (code)
    {
    case BFD_RELOC_386_IRELATIVE:
      return elf_howto_table[R_386_IRELATIVE];
    default:
      break;
    }
  return elf_howto_table[0];
}
[hjl@gnu-6 bfd]$ /usr/gcc-4.7.0-x32/bin/gcc  -O3 -S -Wall x.c -Warray-bounds 
x.c: In function ‘elf_i386_reloc_type_lookup’:
x.c:25:29: warning: array subscript is above array bounds [-Warray-bounds]
[hjl@gnu-6 bfd]$
Comment 3 Richard Biener 2011-04-12 10:28:18 UTC
Confirmed.