All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] mtd: ubi: replace strcpy with strscpy in mtd parameter parser
@ 2025-08-11 12:09 ` Miguel García
  0 siblings, 0 replies; 6+ messages in thread
From: Miguel García @ 2025-08-11 12:09 UTC (permalink / raw)
  To: richard, miquel.raynal, vigneshr
  Cc: chengzhihao1, linux-mtd, linux-kernel, skhan, Miguel García

Replace the strcpy() calls used to copy the 'mtd=' parameter into local
buffers with strscpy() to avoid potential overflow and guarantee NUL
termination. Destinations are fixed-size arrays (buf and p->name), so
use sizeof().

While this code is currently safe due to prior length checks
(strnlen(val, MTD_PARAM_LEN_MAX) and early return on overflow),
replacing strcpy() with strscpy() follows current kernel best practices
and makes the code more robust to future changes. The sizeof() calls
correctly compute the buffer sizes, matching MTD_PARAM_LEN_MAX.

Tested in QEMU (initramfs + built-ins):
 - mtdram.total_size=16384 mtdram.erasesize=256 ubi.mtd=0
 - ubi.mtd="mtdram test device"
 - overly long name -> proper "parameter ... is too long" handling

No functional change intended.

Signed-off-by: Miguel García <miguelgarciaroman8@gmail.com>
---
 drivers/mtd/ubi/build.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/mtd/ubi/build.c b/drivers/mtd/ubi/build.c
index ef6a22f372f9..0d9f31522356 100644
--- a/drivers/mtd/ubi/build.c
+++ b/drivers/mtd/ubi/build.c
@@ -1497,7 +1497,7 @@ static int ubi_mtd_param_parse(const char *val, const struct kernel_param *kp)
 		return 0;
 	}
 
-	strcpy(buf, val);
+	strscpy(buf, val, sizeof(buf));
 
 	/* Get rid of the final newline */
 	if (buf[len - 1] == '\n')
@@ -1512,7 +1512,7 @@ static int ubi_mtd_param_parse(const char *val, const struct kernel_param *kp)
 	}
 
 	p = &mtd_dev_param[mtd_devs];
-	strcpy(&p->name[0], tokens[0]);
+	strscpy(&p->name[0], tokens[0], sizeof(p->name));
 
 	token = tokens[1];
 	if (token) {
-- 
2.34.1


______________________________________________________
Linux MTD discussion mailing list
http://lists.infradead.org/mailman/listinfo/linux-mtd/

^ permalink raw reply related	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2025-08-19 22:42 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-08-11 12:09 [PATCH] mtd: ubi: replace strcpy with strscpy in mtd parameter parser Miguel García
2025-08-11 12:09 ` Miguel García
2025-08-11 12:46 ` Richard Weinberger
2025-08-11 12:46   ` Richard Weinberger
2025-08-19 20:46   ` Miguel García Román
2025-08-19 20:46     ` Miguel García Román

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.