[PATCH 11/13] gdb/remote-fileio: remove uses of sprintf

Andrew Burgess aburgess@redhat.com
Mon Aug 17 16:53:09 GMT 2026


Simon Marchi <simon.marchi@efficios.com> writes:

> When building on macOS, I get some:
>
>     /Users/smarchi/src/binutils-gdb/gdb/remote-fileio.c:264:3: error: 'sprintf' is deprecated: This function is provided for compatibility reasons only.  Due to security concerns inherent in the design of sprintf(3), it is highly recommended that you use snprintf(3) instead. [-Werror,-Wdeprecated-declarations]
>       264 |   sprintf (buf + strlen (buf), "%x", retcode);
>           |   ^
>
> The reply built in remote_fileio_reply is made by appending to a fixed
> size buffer, using a mix of strcpy, strcat and sprintf.  Replace them
> with the safer xsnprintf and xstrcpy.  This way, every write is bounds
> checked.

See previous commit for thoughts on xstrcpy.  But otherwise, this looks
fine.

Approved-By: Andrew Burgess <aburgess@redhat.com>

Thanks,
Andrew


>
> Change-Id: I8446a98be5c5fc0eda79ccbc4858d9dddaf2d4d5
> ---
>  gdb/remote-fileio.c | 21 +++++++++++++++------
>  1 file changed, 15 insertions(+), 6 deletions(-)
>
> diff --git a/gdb/remote-fileio.c b/gdb/remote-fileio.c
> index a151161371da..297e3337e2fe 100644
> --- a/gdb/remote-fileio.c
> +++ b/gdb/remote-fileio.c
> @@ -253,28 +253,37 @@ static void
>  remote_fileio_reply (remote_target *remote, int retcode, int error)
>  {
>    char buf[32];
> +  char *p = buf;
> +  char *const end = buf + sizeof (buf);
>    bool ctrl_c = check_quit_flag ();
>  
> -  strcpy (buf, "F");
> +  p += xstrcpy (p, end - p, "F");
> +
>    if (retcode < 0)
>      {
> -      strcat (buf, "-");
> +      p += xstrcpy (p, end - p, "-");
>        retcode = -retcode;
>      }
> -  sprintf (buf + strlen (buf), "%x", retcode);
> +
> +  p += xsnprintf (p, end - p, "%x", retcode);
> +
>    if (error || ctrl_c)
>      {
>        if (error && ctrl_c)
>  	error = FILEIO_EINTR;
> +
>        if (error < 0)
>  	{
> -	  strcat (buf, "-");
> +	  p += xstrcpy (p, end - p, "-");
>  	  error = -error;
>  	}
> -      sprintf (buf + strlen (buf), ",%x", error);
> +
> +      p += xsnprintf (p, end - p, ",%x", error);
> +
>        if (ctrl_c)
> -	strcat (buf, ",C");
> +	p += xstrcpy (p, end - p, ",C");
>      }
> +
>    quit_handler = remote_fileio_o_quit_handler;
>    putpkt (remote, buf);
>  }
> -- 
> 2.55.0



More information about the Binutils mailing list