blob: 9cd8bda76c3f3baf213a4cba5a89a9bf932ad6ae (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
|
/* { dg-additional-options "-Wno-stringop-overflow -Wno-stringop-truncation" } */
#include <string.h>
/* Wanalyzer-out-of-bounds tests for strpy-related overflows.
The intra-procedural tests are all caught by Wstringop-overflow.
The inter-procedural out-of-bounds are only found by the analyzer. */
void test1 (void)
{
char dst[5];
strcpy (dst, "Hello"); /* { dg-line test1 } */
/* { dg-warning "stack-based buffer overflow" "warning" { target *-*-* } test1 } */
/* { dg-message "write of 1 byte to beyond the end of 'dst'" "num bad bytes note" { target *-*-* } test1 } */
/* { dg-message "valid subscripts for 'dst' are '\\\[0\\\]' to '\\\[4\\\]'" "valid subscript note" { target *-*-* } test1 } */
}
void test2 (void)
{
char dst[6];
strcpy (dst, "Hello");
}
void test3 (void)
{
char *src = "Hello";
char dst[5];
strcpy (dst, src); /* { dg-line test3 } */
/* { dg-warning "stack-based buffer overflow" "warning" { target *-*-* } test3 } */
/* { dg-message "write of 1 byte to beyond the end of 'dst'" "num bad bytes note" { target *-*-* } test3 } */
/* { dg-message "valid subscripts for 'dst' are '\\\[0\\\]' to '\\\[4\\\]'" "valid subscript note" { target *-*-* } test3 } */
}
void test4 (void)
{
char *src = "Hello";
char dst[6];
strcpy (dst, src);
}
const char *return_hello (void)
{
return "hello";
}
void test5 (void)
{
const char *str = return_hello ();
if (!str)
return;
char dst[5];
strcpy (dst, str); /* { dg-line test5 } */
/* { dg-warning "stack-based buffer overflow" "warning" { target *-*-* } test5 } */
/* { dg-message "write of 1 byte to beyond the end of 'dst'" "num bad bytes note" { target *-*-* } test5 } */
/* { dg-message "valid subscripts for 'dst' are '\\\[0\\\]' to '\\\[4\\\]'" "valid subscript note" { target *-*-* } test5 } */
}
void test6 (void)
{
const char *str = return_hello ();
if (!str)
return;
char dst[6];
strcpy (dst, str);
}
|