All of lore.kernel.org
 help / color / mirror / Atom feed
From: Sriram Sriram <sriramsriram@linux.microsoft.com>
To: u-boot@lists.u-boot-project.org
Cc: Michal Simek <michal.simek@amd.com>,
	Tom Rini <trini@konsulko.com>,
	Drew Kluemke <ankluemk@microsoft.com>,
	Sriram Sriram <sriramsriram@linux.microsoft.com>
Subject: [PATCH 1/2] board: xilinx: Use strlcat() in board_name_decode()
Date: Wed,  9 Sep 2026 12:20:46 -0700	[thread overview]
Message-ID: <20260909192047.217421-2-sriramsriram@linux.microsoft.com> (raw)
In-Reply-To: <20260909192047.217421-1-sriramsriram@linux.microsoft.com>

From: Drew Kluemke <ankluemk@microsoft.com>

board_name_decode() assembles the board name into a calloc'd buffer of
MAX_NAME_LENGTH (50) bytes using strcat(). It appends CONFIG_SYS_BOARD
and then, for every detected EEPROM descriptor, "-", desc->name (up to
16 characters), "-rev" and desc->revision (up to 8 characters).

The length check runs only after the loop, so it cannot prevent the
overflow it documents. Each descriptor contributes up to 29 characters,
so a base board plus a carrier card already exceeds the buffer, and the
data being concatenated comes from the EEPROM.

Use strlcat() bounded to MAX_NAME_LENGTH so the writes are truncated
rather than overflowing the allocation. Truncation leaves a string of
MAX_NAME_LENGTH - 1 characters, so relax the check accordingly;
as written it could never fire once strlcat() is used.

Signed-off-by: Drew Kluemke <ankluemk@microsoft.com>
Signed-off-by: Sriram Sriram <sriramsriram@linux.microsoft.com>
---
 board/xilinx/common/board.c | 20 ++++++++++++--------
 1 file changed, 12 insertions(+), 8 deletions(-)

diff --git a/board/xilinx/common/board.c b/board/xilinx/common/board.c
index f45b879736e..690991bb435 100644
--- a/board/xilinx/common/board.c
+++ b/board/xilinx/common/board.c
@@ -590,38 +590,42 @@ char * __maybe_unused __weak board_name_decode(void)
 
 		/* The first string should be soc name */
 		if (!id)
-			strcat(board_local_name, CONFIG_SYS_BOARD);
+			strlcat(board_local_name, CONFIG_SYS_BOARD,
+				MAX_NAME_LENGTH);
 
 		/*
 		 * For two purpose here:
 		 * soc_name- eg: zynqmp-
 		 * and between base board and CC eg: ..revA-sck...
 		 */
-		strcat(board_local_name, "-");
+		strlcat(board_local_name, "-", MAX_NAME_LENGTH);
 
 		if (desc->name[0]) {
 			/* For DT composition name needs to be lowercase */
 			for (i = 0; i < sizeof(desc->name); i++)
 				desc->name[i] = tolower(desc->name[i]);
 
-			strcat(board_local_name, desc->name);
+			strlcat(board_local_name, desc->name,
+				MAX_NAME_LENGTH);
 		}
 		if (desc->revision[0]) {
-			strcat(board_local_name, "-rev");
+			strlcat(board_local_name, "-rev",
+				MAX_NAME_LENGTH);
 
 			/* And revision needs to be uppercase */
 			for (i = 0; i < sizeof(desc->revision); i++)
 				desc->revision[i] = toupper(desc->revision[i]);
 
-			strcat(board_local_name, desc->revision);
+			strlcat(board_local_name, desc->revision,
+				MAX_NAME_LENGTH);
 		}
 	}
 
 	/*
-	 * Longer strings will end up with buffer overflow and potential
-	 * attacks that's why check it
+	 * Longer strings will be truncated by strlcat, check and
+	 * panic if the source data was too long for the buffer.
 	 */
-	if (strlen(board_local_name) >= MAX_NAME_LENGTH)
+	if (strlen(board_local_name) >= MAX_NAME_LENGTH - 1)
 		panic("Board name can't be determined\n");
 
 	if (strlen(board_local_name))
-- 
2.49.0


  reply	other threads:[~2026-09-09 20:45 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-09 19:20 [PATCH 0/2] board: xilinx: Fix board name overflow and allow board ft_board_setup() Sriram Sriram
2026-09-09 19:20 ` Sriram Sriram [this message]
2026-09-10  7:56   ` [PATCH 1/2] board: xilinx: Use strlcat() in board_name_decode() Maarten Brock
2026-09-10  7:59     ` Michal Simek
2026-09-10  8:03   ` Michal Simek
2026-09-10  9:30     ` Maarten Brock
2026-09-10  9:43       ` Michal Simek
2026-09-09 19:20 ` [PATCH 2/2] board: xilinx: Make ft_board_setup() weak Sriram Sriram

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260909192047.217421-2-sriramsriram@linux.microsoft.com \
    --to=sriramsriram@linux.microsoft.com \
    --cc=ankluemk@microsoft.com \
    --cc=michal.simek@amd.com \
    --cc=trini@konsulko.com \
    --cc=u-boot@lists.u-boot-project.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.