From: Sven Eckelmann <sven@narfation.org>
To: b.a.t.m.a.n@lists.open-mesh.org
Cc: Sven Eckelmann <sven@narfation.org>
Subject: [PATCH 1/6] alfred: fix off-by-one in client interface name length checks
Date: Fri, 31 Jul 2026 13:44:50 +0200 [thread overview]
Message-ID: <20260731-bugfixes-interfaces-v1-1-a148ca2f6688@narfation.org> (raw)
In-Reply-To: <20260731-bugfixes-interfaces-v1-0-a148ca2f6688@narfation.org>
check_interface(), alfred_client_change_interface() and
alfred_client_change_bat_iface() rejected names only when they were
strictly longer than the destination buffer. A name whose length equals the
buffer size passed the check, but the subsequent strncpy() then filled the
buffer without a terminator and the forced '\0' at the last position
silently dropped the final character.
Reject names which don't fit including their terminating \0 byte.
Fixes: babd772a36e1 ("alfred: support for changing interfaces")
Fixes: b96cc742ef3e ("alfred: introduce 'change batman-adv interface' IPC call")
Fixes: 67ae5f57eedd ("alfred: Add support for multiple interfaces per master")
Signed-off-by: Sven Eckelmann <sven@narfation.org>
---
client.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/client.c b/client.c
index 9fa9f00..f56042a 100644
--- a/client.c
+++ b/client.c
@@ -222,7 +222,7 @@ static int check_interface(const char *iface)
struct ifreq ifr;
int sock = -1;
- if (strlen(iface) > IFNAMSIZ) {
+ if (strlen(iface) >= IFNAMSIZ) {
fprintf(stderr, "%s: interface name list too long, not changing\n",
__func__);
return -1;
@@ -262,7 +262,7 @@ int alfred_client_change_interface(struct globals *globals)
return -1;
interface_len = strlen(globals->net_iface);
- if (interface_len > sizeof(change_interface.ifaces)) {
+ if (interface_len >= sizeof(change_interface.ifaces)) {
fprintf(stderr, "%s: interface name list too long, not changing\n",
__func__);
return 0;
@@ -311,7 +311,7 @@ int alfred_client_change_bat_iface(struct globals *globals)
return -1;
interface_len = strlen(globals->mesh_iface);
- if (interface_len > sizeof(change_bat_iface.bat_iface)) {
+ if (interface_len >= sizeof(change_bat_iface.bat_iface)) {
fprintf(stderr, "%s: batman-adv interface name list too long, not changing\n",
__func__);
return 0;
--
2.47.3
next prev parent reply other threads:[~2026-07-31 11:46 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-31 11:44 [PATCH 0/6] alfred: interfaces: random fixes Sven Eckelmann
2026-07-31 11:44 ` Sven Eckelmann [this message]
2026-07-31 11:44 ` [PATCH 2/6] alfred: update stored interface list on interface change Sven Eckelmann
2026-07-31 11:44 ` [PATCH 3/6] alfred: don't drop the mesh interface name on OOM Sven Eckelmann
2026-07-31 11:44 ` [PATCH 4/6] alfred: keep the running interfaces when reconfiguration fails Sven Eckelmann
2026-07-31 11:44 ` [PATCH 5/6] alfred: Report failure when the client refuses to change interfaces Sven Eckelmann
2026-07-31 11:44 ` [PATCH 6/6] alfred: don't check the "none" on network interface change Sven Eckelmann
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260731-bugfixes-interfaces-v1-1-a148ca2f6688@narfation.org \
--to=sven@narfation.org \
--cc=b.a.t.m.a.n@lists.open-mesh.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.