Hardened the module converter utilities against malformed input (#580)

* Hardened the module converter utilities against malformed input

While reviewing the code_buffer leak reported in issue 571, three further
pre-existing defects turned up in the same host-side utilities.

The four ELF area allocations in module_to_binary.c and module_to_c_array.c
were unchecked, and every elf_object_read() return value was discarded, so a
truncated or crafted ELF file was read into whatever the allocation and the
reads happened to leave behind. Check each allocation, distinguishing a NULL
return for an empty area from a genuine failure, and abandon the conversion
with exit code 5 on an allocation failure and exit code 6 on a read failure.

Validate the section string table index taken from the ELF header before it
is used to subscript the section header area. AddressSanitizer confirms that
an out-of-range index produced a heap buffer overflow in both tools.

Correct the address format specifiers in module_to_c_array.c and
module_binary_to_c_array.c, which passed an unsigned long to %08X, and close
the source file on the invalid format path of module_binary_to_c_array.c.
The unused current_total local is removed. All three utilities now build
warning free with gcc -std=c99 -Wall -Wextra, and the code they emit is
unchanged byte for byte on valid input.

Refresh the version banners of all three tools, on the console and in the
header written into the generated C arrays, to the 2024 Microsoft Corp and
2026 Eclipse ThreadX contributors copyrights and version v6.5.2.202603. The
banners still advertised v5.8 and v5.4 with a 2018 build date. The .exe
suffix is dropped from the tool names, since these tools build on Linux too.

Related to https://github.com/eclipse-threadx/threadx/issues/571

Assisted-by: Claude Code (Opus 5) <noreply@anthropic.com>

* Added the missing licence header to module_binary_to_c_array.c

The file carried no copyright or licence header at all, unlike the two other
converter utilities in the same directory. Use the same MIT header they carry,
since the three tools share an origin.

Assisted-by: Claude Code (Opus 5) <noreply@anthropic.com>
This commit is contained in:
Frédéric Desbiens
2026-08-08 08:09:06 -04:00
committed by GitHub
parent bd8d30f23b
commit 2b0e4e44b9
3 changed files with 407 additions and 49 deletions
@@ -1,3 +1,16 @@
/***************************************************************************/
/* Copyright (c) 2024 Microsoft Corporation */
/* Copyright (c) 2026 Eclipse ThreadX contributors */
/* */
/* This program and the accompanying materials are made available under */
/* the terms of the MIT License which is available at */
/* https://opensource.org/licenses/MIT. */
/* */
/* SPDX-License-Identifier: MIT */
/***************************************************************************/
// Some portions generated by Claude Code (Opus 5)
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
@@ -25,8 +38,11 @@ unsigned long column;
{
/* Print an error message out and wait for user key hit. */
printf("module_binary_to_c_array.exe - Copyright (c) Microsoft Corporation v5.8\n");
printf("**** Error: invalid input parameter for module_binary_to_c_array.exe **** \n");
printf("module_binary_to_c_array\n");
printf("(c) 2024 Microsoft Corp\n");
printf("(c) 2026 Eclipse ThreadX contributors\n");
printf("v6.5.2.202603\n");
printf("**** Error: invalid input parameter for module_binary_to_c_array **** \n");
printf(" Command Line Should be:\n\n");
printf(" > module_binary_to_c_array source_binary_file c_array_file <cr> \n\n");
return(1);
@@ -57,6 +73,10 @@ unsigned long column;
/* Print an error message out and wait for user key hit. */
printf("**** Error: invalid format of binary input file **** \n");
printf(" File: %s ", argv[1]);
/* Close the source file. */
fclose(source_file);
return(3);
}
@@ -75,7 +95,9 @@ unsigned long column;
fprintf(array_file, "/**************************** Module-Binary-to-C-array Utility **********************************/\n");
fprintf(array_file, "/* */\n");
fprintf(array_file, "/* Copyright (c) Microsoft Corporation Version 5.4, build date: 03-01-2018 */\n");
fprintf(array_file, "/* Copyright (c) 2024 Microsoft Corp */\n");
fprintf(array_file, "/* Copyright (c) 2026 Eclipse ThreadX contributors */\n");
fprintf(array_file, "/* v6.5.2.202603 */\n");
fprintf(array_file, "/* */\n");
fprintf(array_file, "/************************************************************************************************/\n\n");
fprintf(array_file, "/* \n");
@@ -109,7 +131,7 @@ unsigned long column;
{
if (address != 0)
fprintf(array_file, ",\n");
fprintf(array_file, "/* 0x%08X */ 0x%02X", address, (unsigned int) alpha);
fprintf(array_file, "/* 0x%08lX */ 0x%02X", address, (unsigned int) alpha);
}
else
fprintf(array_file, ", 0x%02X", (unsigned int) alpha);
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff