What's wrong
BuildMonitor/BuildMonitor.cs:1405 calls ImGui.SetTooltip(errorSummary) and :1475 calls ImGui.SetTooltip(tooltip) (built from provider.StatusMessage, which carries exception text). In Hexa.NET.ImGui the SetTooltip(string) overload is SetTooltip(string fmt), forwarded to native igSetTooltip(const char* fmt, ...) with no varargs. The string is therefore interpreted as a printf format.
Failure scenario
A failing run whose job log has an ##[error] line containing format specifiers, for example:
- GCC
-Werror=format: error: format '%s' expects argument of type 'char *'
- MSBuild/Exec errors quoting batch variables:
'%SIGNTOOL%' is not recognized…
ParseLogForErrors copies the line into run.Errors verbatim. When the user hovers the Errors cell, vsnprintf reads arguments that were never passed: %s/%S dereference a junk pointer (native access violation that terminates the process; no managed exception to catch), %d/%x print garbage. A provider exception message containing % hits the same path via the status tooltip.
Every other text output in the app already uses TextUnformatted; these two call sites are the exception.
Suggested fix
At both sites use:
ImGui.BeginTooltip();
ImGui.TextUnformatted(text);
ImGui.EndTooltip();
(or escape % as %% before calling SetTooltip).
Acceptance criteria
- No call to
ImGui.SetTooltip takes untrusted text as its format argument.
- An error string such as
format '%s' expects %d displays literally in the tooltip.
What's wrong
BuildMonitor/BuildMonitor.cs:1405callsImGui.SetTooltip(errorSummary)and:1475callsImGui.SetTooltip(tooltip)(built fromprovider.StatusMessage, which carries exception text). In Hexa.NET.ImGui theSetTooltip(string)overload isSetTooltip(string fmt), forwarded to nativeigSetTooltip(const char* fmt, ...)with no varargs. The string is therefore interpreted as a printf format.Failure scenario
A failing run whose job log has an
##[error]line containing format specifiers, for example:-Werror=format:error: format '%s' expects argument of type 'char *''%SIGNTOOL%' is not recognized…ParseLogForErrorscopies the line intorun.Errorsverbatim. When the user hovers the Errors cell,vsnprintfreads arguments that were never passed:%s/%Sdereference a junk pointer (native access violation that terminates the process; no managed exception to catch),%d/%xprint garbage. A provider exception message containing%hits the same path via the status tooltip.Every other text output in the app already uses
TextUnformatted; these two call sites are the exception.Suggested fix
At both sites use:
(or escape
%as%%before callingSetTooltip).Acceptance criteria
ImGui.SetTooltiptakes untrusted text as its format argument.format '%s' expects %ddisplays literally in the tooltip.