All of lore.kernel.org
 help / color / mirror / Atom feed
From: Takashi Iwai <tiwai@suse.de>
To: David Laight <david.laight.linux@gmail.com>
Cc: songxiebing <songxiebing@kylinos.cn>,
	tiwai@suse.com, perex@perex.cz, linux-sound@vger.kernel.org,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH 2/2] ALSA: hda/ca0132: replace sprintf() with snprintf()
Date: Wed, 12 Aug 2026 09:50:10 +0200	[thread overview]
Message-ID: <87a4qr22x9.wl-tiwai@suse.de> (raw)
In-Reply-To: <20260812082108.67db969b@pumpkin>

On Wed, 12 Aug 2026 09:21:08 +0200,
David Laight wrote:
> 
> On Wed, 12 Aug 2026 11:30:30 +0800
> songxiebing <songxiebing@kylinos.cn> wrote:
> 
> > From: Bob Song <songxiebing@kylinos.cn>
> > 
> > Replace six sprintf() calls that write to
> > SNDRV_CTL_ELEM_ID_NAME_MAXLEN-sized buffers with snprintf() to avoid
> > potential buffer overflows.
> > 
> > Signed-off-by: Bob Song <songxiebing@kylinos.cn>
> > ---
> >  sound/hda/codecs/ca0132.c | 19 ++++++++++---------
> >  1 file changed, 10 insertions(+), 9 deletions(-)
> > 
> > diff --git a/sound/hda/codecs/ca0132.c b/sound/hda/codecs/ca0132.c
> > index 424224ef4621..d3ac29fd5780 100644
> > --- a/sound/hda/codecs/ca0132.c
> > +++ b/sound/hda/codecs/ca0132.c
> > @@ -5788,7 +5788,8 @@ static int ca0132_alt_mic_boost_info(struct snd_kcontrol *kcontrol,
> >  	uinfo->value.enumerated.items = MIC_BOOST_NUM_OF_STEPS;
> >  	if (uinfo->value.enumerated.item >= MIC_BOOST_NUM_OF_STEPS)
> >  		uinfo->value.enumerated.item = MIC_BOOST_NUM_OF_STEPS - 1;
> > -	sprintf(namestr, "%d %s", (uinfo->value.enumerated.item * 10), sfx);
> > +	snprintf(namestr, sizeof(namestr), "%d %s",
> > +		 (uinfo->value.enumerated.item * 10), sfx);
> >  	strscpy(uinfo->value.enumerated.name, namestr);
> 
> Why not snprintf() directly into uinfo->value.enumerated.name ?
> 
> >  	return 0;
> >  }
> > @@ -5840,9 +5841,9 @@ static int ae5_headphone_gain_info(struct snd_kcontrol *kcontrol,
> >  	uinfo->value.enumerated.items = AE5_HEADPHONE_GAIN_MAX;
> >  	if (uinfo->value.enumerated.item >= AE5_HEADPHONE_GAIN_MAX)
> >  		uinfo->value.enumerated.item = AE5_HEADPHONE_GAIN_MAX - 1;
> > -	sprintf(namestr, "%s %s",
> > -		ae5_headphone_gain_presets[uinfo->value.enumerated.item].name,
> > -		sfx);
> > +	snprintf(namestr, sizeof(namestr), "%s %s",
> > +		 ae5_headphone_gain_presets[uinfo->value.enumerated.item].name,
> > +		 sfx);
> >  	strscpy(uinfo->value.enumerated.name, namestr);
> >  	return 0;
> >  }
> > @@ -5894,8 +5895,8 @@ static int ae5_sound_filter_info(struct snd_kcontrol *kcontrol,
> >  	uinfo->value.enumerated.items = AE5_SOUND_FILTER_MAX;
> >  	if (uinfo->value.enumerated.item >= AE5_SOUND_FILTER_MAX)
> >  		uinfo->value.enumerated.item = AE5_SOUND_FILTER_MAX - 1;
> > -	sprintf(namestr, "%s",
> > -			ae5_filter_presets[uinfo->value.enumerated.item].name);
> > +	snprintf(namestr, sizeof(namestr), "%s",
> > +		 ae5_filter_presets[uinfo->value.enumerated.item].name);
> >  	strscpy(uinfo->value.enumerated.name, namestr);
> 
> That is silly, why is the sprintf() there at all?

Right, there are lots of rooms in this driver code for optimizations.
I took the patch for now as it's pretty idiomatic and safe, but we
should go for further cleanups.

Bob, are you interested in it?


thanks,

Takashi

      reply	other threads:[~2026-08-12  7:50 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-12  3:30 [PATCH 2/2] ALSA: hda/ca0132: replace sprintf() with snprintf() songxiebing
2026-08-12  7:21 ` David Laight
2026-08-12  7:50   ` Takashi Iwai [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87a4qr22x9.wl-tiwai@suse.de \
    --to=tiwai@suse.de \
    --cc=david.laight.linux@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-sound@vger.kernel.org \
    --cc=perex@perex.cz \
    --cc=songxiebing@kylinos.cn \
    --cc=tiwai@suse.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.