Launchpad has imported 3 comments from the remote bug at http://sourceware.org/bugzilla/show_bug.cgi?id=6409.
If you reply to an imported comment from within Launchpad, your comment will be sent to the remote bug automatically. Read more about Launchpad's inter-bugtracker facilities at https://help.launchpad.net/InterBugTracking. ------------------------------------------------------------------------ On 2008-04-15T16:53:23+00:00 Kees Cook wrote: The following source, without the "(void*)" overrides, will throw an warning (as expected), when compiled with -Wall: $ gcc -o memcpy-fortify -Wall memcpy-fortify.c memcpy-fortify.c: In function 'main': memcpy-fortify.c:21: warning: passing argument 1 of 'memcpy' discards qualifiers from pointer target type memcpy-fortify.c:22: warning: passing argument 1 of 'strcpy' discards qualifiers from pointer target type With "(void*)" it is (as expected) silent. With -O2, it is silent, but with -D_FORTIFY_SOURCE != 0, the qualifier override is ignored: $ gcc -o memcpy-fortify -Wall -O2 -D_FORTIFY_SOURCE=2 memcpy-fortify.c memcpy-fortify.c: In function 'main': memcpy-fortify.c:21: warning: passing argument 1 of 'memcpy' discards qualifiers from pointer target type memcpy-fortify.c:22: warning: passing argument 1 of 'strcpy' discards qualifiers from pointer target type This will cause problems for builds that run with -Werror. /* * gcc -o memcpy-fortify -Wall -Werror -O2 -D_FORTIFY_SOURCE=2 memcpy-fortify.c * */ #include <stdio.h> #include <stdlib.h> #include <unistd.h> #include <stdint.h> #include <string.h> #include <stdint.h> #include <inttypes.h> int main(int argc, char * argv[]) { char *foo = strdup("string one"); char *bar = strdup("string two"); const char *baz = (const char *)foo; printf("%s\n", foo); memcpy((void*)baz, bar, strlen(bar)+1); strcpy((void*)baz, bar); printf("%s\n", foo); return 0; } Reply at: https://bugs.launchpad.net/gcc/+bug/217481/comments/1 ------------------------------------------------------------------------ On 2008-04-15T19:16:58+00:00 Drepper-fsp wrote: You're using code which is too old. glibc 2.8 is out. Reply at: https://bugs.launchpad.net/gcc/+bug/217481/comments/2 ------------------------------------------------------------------------ On 2008-04-29T20:19:15+00:00 Kees Cook wrote: I don't see 2.8 listed here: http://ftp.gnu.org/gnu/glibc/ Do you mean to say that 2.8 fixes this bug? If so, do you have a pointer to the commit that fixed it so I might try backporting it to the 2.7 release? Thanks. Reply at: https://bugs.launchpad.net/gcc/+bug/217481/comments/3 ** Changed in: glibc Importance: Unknown => Medium -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/217481 Title: -D_FORTIFY_SOURCE discards qualifier overrides in {mem,str}cpy -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs