clang -cc1 -cc1 -triple amd64-unknown-openbsd7.0 -analyze -disable-free -disable-llvm-verifier -discard-value-names -main-file-name fork-child.c -analyzer-store=region -analyzer-opt-analyze-nested-blocks -analyzer-checker=core -analyzer-checker=apiModeling -analyzer-checker=unix -analyzer-checker=deadcode -analyzer-checker=security.insecureAPI.UncheckedReturn -analyzer-checker=security.insecureAPI.getpw -analyzer-checker=security.insecureAPI.gets -analyzer-checker=security.insecureAPI.mktemp -analyzer-checker=security.insecureAPI.mkstemp -analyzer-checker=security.insecureAPI.vfork -analyzer-checker=nullability.NullPassedToNonnull -analyzer-checker=nullability.NullReturnedFromNonnull -analyzer-output plist -w -setup-static-analyzer -mrelocation-model pic -pic-level 1 -pic-is-pie -mframe-pointer=all -relaxed-aliasing -fno-rounding-math -mconstructor-aliases -munwind-tables -target-cpu x86-64 -target-feature +retpoline-indirect-calls -target-feature +retpoline-indirect-branches -tune-cpu generic -debugger-tuning=gdb -fcoverage-compilation-dir=/usr/src/gnu/usr.bin/binutils/obj/gdb -resource-dir /usr/local/lib/clang/13.0.0 -D PIE_DEFAULT=1 -I . -I /usr/src/gnu/usr.bin/binutils/gdb -I /usr/src/gnu/usr.bin/binutils/gdb/config -D LOCALEDIR="/usr/share/locale" -D HAVE_CONFIG_H -I /usr/src/gnu/usr.bin/binutils/gdb/../include/opcode -I ../bfd -I /usr/src/gnu/usr.bin/binutils/gdb/../bfd -I /usr/src/gnu/usr.bin/binutils/gdb/../include -I ../intl -I /usr/src/gnu/usr.bin/binutils/gdb/../intl -D MI_OUT=1 -D TUI=1 -internal-isystem /usr/local/lib/clang/13.0.0/include -internal-externc-isystem /usr/include -O2 -fdebug-compilation-dir=/usr/src/gnu/usr.bin/binutils/obj/gdb -ferror-limit 19 -fwrapv -D_RET_PROTECTOR -ret-protector -fgnuc-version=4.2.1 -fcommon -vectorize-loops -vectorize-slp -fno-builtin-malloc -fno-builtin-calloc -fno-builtin-realloc -fno-builtin-valloc -fno-builtin-free -fno-builtin-strdup -fno-builtin-strndup -analyzer-output=html -faddrsig -D__GCC_HAVE_DWARF2_CFI_ASM=1 -o /home/ben/Projects/vmm/scan-build/2022-01-12-194120-40624-1 -x c /usr/src/gnu/usr.bin/binutils/gdb/fork-child.c
1 | |
2 | |
3 | |
4 | |
5 | |
6 | |
7 | |
8 | |
9 | |
10 | |
11 | |
12 | |
13 | |
14 | |
15 | |
16 | |
17 | |
18 | |
19 | |
20 | |
21 | |
22 | |
23 | |
24 | |
25 | #include "defs.h" |
26 | #include "gdb_string.h" |
27 | #include "frame.h" /* required by inferior.h */ |
28 | #include "inferior.h" |
29 | #include "target.h" |
30 | #include "gdb_wait.h" |
31 | #include "gdb_vfork.h" |
32 | #include "gdbcore.h" |
33 | #include "terminal.h" |
34 | #include "gdbthread.h" |
35 | #include "command.h" /* for dont_repeat () */ |
36 | |
37 | #include <signal.h> |
38 | |
39 | |
40 | #ifndef SHELL_FILE |
41 | #define SHELL_FILE "/bin/sh" |
42 | #endif |
43 | |
44 | extern char **environ; |
45 | |
46 | |
47 | |
48 | |
49 | |
50 | |
51 | static void |
52 | breakup_args (char *scratch, char **argv) |
53 | { |
54 | char *cp = scratch; |
55 | |
56 | for (;;) |
57 | { |
58 | |
59 | while (*cp == ' ' || *cp == '\t' || *cp == '\n') |
60 | cp++; |
61 | |
62 | |
63 | if (*cp == '\0') |
64 | break; |
65 | |
66 | |
67 | *argv++ = cp; |
68 | |
69 | |
70 | cp = strchr (cp, ' '); |
71 | if (cp == NULL) |
72 | cp = strchr (cp, '\t'); |
73 | if (cp == NULL) |
74 | cp = strchr (cp, '\n'); |
75 | |
76 | |
77 | if (cp == NULL) |
78 | break; |
79 | |
80 | |
81 | *cp++ = '\0'; |
82 | } |
83 | |
84 | |
85 | *argv = NULL; |
86 | } |
87 | |
88 | |
89 | |
90 | |
91 | |
92 | static int |
93 | escape_bang_in_quoted_argument (const char *shell_file) |
94 | { |
95 | const int shell_file_len = strlen (shell_file); |
96 | |
97 | |
98 | |
99 | |
100 | |
101 | if (shell_file_len < 3) |
102 | return 0; |
103 | |
104 | if (shell_file[shell_file_len - 3] == 'c' |
105 | && shell_file[shell_file_len - 2] == 's' |
106 | && shell_file[shell_file_len - 1] == 'h') |
107 | return 1; |
108 | |
109 | return 0; |
110 | } |
111 | |
112 | |
113 | |
114 | |
115 | |
116 | |
117 | |
118 | |
119 | |
120 | |
121 | void |
122 | fork_inferior (char *exec_file_arg, char *allargs, char **env, |
123 | void (*traceme_fun) (void), void (*init_trace_fun) (int), |
124 | void (*pre_trace_fun) (void), char *shell_file_arg) |
125 | { |
126 | int pid; |
127 | char *shell_command; |
128 | static char default_shell_file[] = SHELL_FILE; |
129 | int len; |
130 | |
131 | static int debug_fork = 0; |
132 | |
133 | |
134 | static int debug_setpgrp = 657473; |
135 | static char *shell_file; |
136 | static char *exec_file; |
137 | char **save_our_env; |
138 | int shell = 0; |
139 | static char **argv; |
140 | |
141 | |
142 | |
143 | exec_file = exec_file_arg; |
144 | if (exec_file == 0) |
| 1 | Assuming 'exec_file' is not equal to null | |
|
| |
145 | exec_file = get_exec_file (1); |
146 | |
147 | |
148 | |
149 | |
150 | shell_file = shell_file_arg; |
151 | if (STARTUP_WITH_SHELL) |
| |
152 | { |
153 | |
154 | if (shell_file == NULL) |
| 4 | | Assuming 'shell_file' is not equal to NULL | |
|
| |
155 | shell_file = getenv ("SHELL"); |
156 | if (shell_file == NULL) |
| |
157 | shell_file = default_shell_file; |
158 | shell = 1; |
159 | } |
160 | |
161 | |
162 | |
163 | |
164 | len = 5 + 4 * strlen (exec_file) + 1 + strlen (allargs) + 1 + 12; |
165 | |
166 | |
167 | #ifdef SHELL_COMMAND_CONCAT |
168 | shell_command = (char *) alloca (strlen (SHELL_COMMAND_CONCAT) + len); |
169 | strcpy (shell_command, SHELL_COMMAND_CONCAT); |
170 | #else |
171 | shell_command = (char *) alloca (len); |
172 | shell_command[0] = '\0'; |
173 | #endif |
174 | |
175 | if (!shell) |
| |
176 | { |
177 | |
178 | |
179 | |
180 | |
181 | int argc = (strlen (allargs) + 1) / 2 + 2; |
182 | argv = (char **) xmalloc (argc * sizeof (*argv)); |
183 | argv[0] = exec_file; |
184 | breakup_args (allargs, &argv[1]); |
185 | } |
186 | else |
187 | { |
188 | |
189 | |
190 | |
191 | |
192 | char *p; |
193 | int need_to_quote; |
194 | const int escape_bang = escape_bang_in_quoted_argument (shell_file); |
195 | |
196 | strcat (shell_command, "exec "); |
197 | |
198 | |
199 | |
200 | |
201 | p = exec_file; |
202 | while (1) |
| 8 | | Loop condition is true. Entering loop body | |
|
203 | { |
204 | switch (*p) |
| 9 | | Control jumps to 'case 0:' at line 222 | |
|
205 | { |
206 | case '\'': |
207 | case '!': |
208 | case '"': |
209 | case '(': |
210 | case ')': |
211 | case '$': |
212 | case '&': |
213 | case ';': |
214 | case '<': |
215 | case '>': |
216 | case ' ': |
217 | case '\n': |
218 | case '\t': |
219 | need_to_quote = 1; |
220 | goto end_scan; |
221 | |
222 | case '\0': |
223 | need_to_quote = 0; |
224 | goto end_scan; |
| 10 | | Control jumps to line 232 | |
|
225 | |
226 | default: |
227 | break; |
228 | } |
229 | ++p; |
230 | } |
231 | end_scan: |
232 | if (need_to_quote) |
| |
233 | { |
234 | strcat (shell_command, "'"); |
235 | for (p = exec_file; *p != '\0'; ++p) |
236 | { |
237 | if (*p == '\'') |
238 | strcat (shell_command, "'\\''"); |
239 | else if (*p == '!' && escape_bang) |
240 | strcat (shell_command, "\\!"); |
241 | else |
242 | strncat (shell_command, p, 1); |
243 | } |
244 | strcat (shell_command, "'"); |
245 | } |
246 | else |
247 | strcat (shell_command, exec_file); |
248 | |
249 | strcat (shell_command, " "); |
250 | strcat (shell_command, allargs); |
251 | } |
252 | |
253 | |
254 | close_exec_file (); |
255 | |
256 | |
257 | |
258 | |
259 | save_our_env = environ; |
260 | |
261 | |
262 | |
263 | new_tty_prefork (inferior_io_terminal); |
264 | |
265 | |
266 | |
267 | |
268 | gdb_flush (gdb_stdout); |
269 | gdb_flush (gdb_stderr); |
270 | |
271 | |
272 | |
273 | |
274 | if (pre_trace_fun != NULL) |
| 12 | | Assuming 'pre_trace_fun' is equal to NULL | |
|
| |
275 | (*pre_trace_fun) (); |
276 | |
277 | |
278 | |
279 | |
280 | if (debug_fork) |
| |
281 | pid = fork (); |
282 | else |
283 | pid = vfork (); |
284 | |
285 | if (pid < 0) |
| |
286 | perror_with_name ("vfork"); |
287 | |
288 | if (pid == 0) |
| |
289 | { |
290 | if (debug_fork) |
| |
291 | sleep (debug_fork); |
292 | |
293 | |
294 | debug_setpgrp = gdb_setpgid (); |
| 18 | | This function call is prohibited after a successful vfork |
|
295 | if (debug_setpgrp == -1) |
296 | perror ("setpgrp failed in child"); |
297 | |
298 | |
299 | |
300 | |
301 | new_tty (); |
302 | |
303 | |
304 | |
305 | |
306 | |
307 | |
308 | |
309 | |
310 | (*traceme_fun) (); |
311 | |
312 | |
313 | |
314 | |
315 | |
316 | |
317 | |
318 | |
319 | |
320 | |
321 | |
322 | |
323 | |
324 | |
325 | |
326 | environ = env; |
327 | |
328 | |
329 | |
330 | |
331 | |
332 | |
333 | |
334 | if (shell) |
335 | { |
336 | execlp (shell_file, shell_file, "-c", shell_command, (char *) 0); |
337 | |
338 | |
339 | fprintf_unfiltered (gdb_stderr, "Cannot exec %s: %s.\n", shell_file, |
340 | safe_strerror (errno)); |
341 | gdb_flush (gdb_stderr); |
342 | _exit (0177); |
343 | } |
344 | else |
345 | { |
346 | |
347 | |
348 | int i; |
349 | char *errstring; |
350 | |
351 | execvp (exec_file, argv); |
352 | |
353 | |
354 | errstring = safe_strerror (errno); |
355 | fprintf_unfiltered (gdb_stderr, "Cannot exec %s ", exec_file); |
356 | |
357 | i = 1; |
358 | while (argv[i] != NULL) |
359 | { |
360 | if (i != 1) |
361 | fprintf_unfiltered (gdb_stderr, " "); |
362 | fprintf_unfiltered (gdb_stderr, "%s", argv[i]); |
363 | i++; |
364 | } |
365 | fprintf_unfiltered (gdb_stderr, ".\n"); |
366 | #if 0 |
367 | |
368 | fprintf_unfiltered (gdb_stderr, "Got error %s.\n", errstring); |
369 | #endif |
370 | gdb_flush (gdb_stderr); |
371 | _exit (0177); |
372 | } |
373 | } |
374 | |
375 | |
376 | environ = save_our_env; |
377 | |
378 | init_thread_list (); |
379 | |
380 | |
381 | inferior_ptid = pid_to_ptid (pid); |
382 | |
383 | |
384 | |
385 | |
386 | (*init_trace_fun) (pid); |
387 | |
388 | |
389 | |
390 | |
391 | |
392 | |
393 | |
394 | |
395 | TARGET_CREATE_INFERIOR_HOOK (pid); |
396 | |
397 | #ifdef SOLIB_CREATE_INFERIOR_HOOK |
398 | SOLIB_CREATE_INFERIOR_HOOK (pid); |
399 | #endif |
400 | } |
401 | |
402 | |
403 | |
404 | void |
405 | startup_inferior (int ntraps) |
406 | { |
407 | int pending_execs = ntraps; |
408 | int terminal_initted = 0; |
409 | |
410 | |
411 | |
412 | |
413 | |
414 | clear_proceed_status (); |
415 | |
416 | init_wait_for_inferior (); |
417 | |
418 | if (STARTUP_WITH_SHELL) |
419 | inferior_ignoring_startup_exec_events = ntraps; |
420 | else |
421 | inferior_ignoring_startup_exec_events = 0; |
422 | inferior_ignoring_leading_exec_events = |
423 | target_reported_exec_events_per_exec_call () - 1; |
424 | |
425 | while (1) |
426 | { |
427 | |
428 | stop_soon = STOP_QUIETLY; |
429 | wait_for_inferior (); |
430 | if (stop_signal != TARGET_SIGNAL_TRAP) |
431 | { |
432 | |
433 | |
434 | |
435 | resume (0, stop_signal); |
436 | } |
437 | else |
438 | { |
439 | |
440 | if (!terminal_initted) |
441 | { |
442 | |
443 | |
444 | |
445 | |
446 | |
447 | |
448 | |
449 | target_terminal_init (); |
450 | |
451 | |
452 | target_terminal_inferior (); |
453 | |
454 | terminal_initted = 1; |
455 | } |
456 | |
457 | if (--pending_execs == 0) |
458 | break; |
459 | |
460 | resume (0, TARGET_SIGNAL_0); |
461 | } |
462 | } |
463 | stop_soon = NO_STOP_QUIETLY; |
464 | } |