Skip to content

Hovering an Errors cell passes build-log text to ImGui.SetTooltip as a printf format, so an error containing "%s" crashes the app #348

Description

@matt-edmondson

What's wrong

BuildMonitor/BuildMonitor.cs:1405 calls ImGui.SetTooltip(errorSummary) and :1475 calls ImGui.SetTooltip(tooltip) (built from provider.StatusMessage, which carries exception text). In Hexa.NET.ImGui the SetTooltip(string) overload is SetTooltip(string fmt), forwarded to native igSetTooltip(const char* fmt, ...) with no varargs. The string is therefore interpreted as a printf format.

Failure scenario

A failing run whose job log has an ##[error] line containing format specifiers, for example:

  • GCC -Werror=format: error: format '%s' expects argument of type 'char *'
  • MSBuild/Exec errors quoting batch variables: '%SIGNTOOL%' is not recognized…

ParseLogForErrors copies the line into run.Errors verbatim. When the user hovers the Errors cell, vsnprintf reads arguments that were never passed: %s/%S dereference a junk pointer (native access violation that terminates the process; no managed exception to catch), %d/%x print garbage. A provider exception message containing % hits the same path via the status tooltip.

Every other text output in the app already uses TextUnformatted; these two call sites are the exception.

Suggested fix

At both sites use:

ImGui.BeginTooltip();
ImGui.TextUnformatted(text);
ImGui.EndTooltip();

(or escape % as %% before calling SetTooltip).

Acceptance criteria

  • No call to ImGui.SetTooltip takes untrusted text as its format argument.
  • An error string such as format '%s' expects %d displays literally in the tooltip.

Activity

  1. matt-edmondson commented on Oct 7, 2026

    @matt-edmondson
    ContributorAuthor

    Triage


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

bugSomething isn't working

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions