From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:48679) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1WKOKN-0000Ef-GA for qemu-devel@nongnu.org; Mon, 03 Mar 2014 03:34:29 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1WKOKH-0006Ir-Hl for qemu-devel@nongnu.org; Mon, 03 Mar 2014 03:34:23 -0500 Received: from mx1.redhat.com ([209.132.183.28]:40150) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1WKOKH-0006Ic-9K for qemu-devel@nongnu.org; Mon, 03 Mar 2014 03:34:17 -0500 From: Markus Armbruster References: <52EF68CA.9060604@gmail.com> <20140203103429.GB10408@redhat.com> <52EF71DC.3000309@gmail.com> <52F0C8BA.7020709@gmail.com> <20140204110631.GD5632@redhat.com> <52F0CD67.5070601@gmail.com> <87siry3l7t.fsf@linux.vnet.ibm.com> <52F17B5E.1050602@gmail.com> <52FF3182.9090106@gmail.com> <53097D8E.1030803@gmail.com> <87sir850ho.fsf@blackfin.pond.sub.org> <87ha7o3c5x.fsf@blackfin.pond.sub.org> <530FCBAD.10305@gmail.com> <531219CC.4050505@gmail.com> <53121A12.5050105@gmail.com> <53121A4B.70308@gmail.com> Date: Mon, 03 Mar 2014 09:34:09 +0100 In-Reply-To: <53121A4B.70308@gmail.com> (Chen Gang's message of "Sun, 02 Mar 2014 01:35:07 +0800") Message-ID: <87txbf65q6.fsf@blackfin.pond.sub.org> MIME-Version: 1.0 Content-Type: text/plain Subject: Re: [Qemu-devel] [PATCH 2/3] hw/9pfs/virtio-9p-local.c: use snprintf() instead of sprintf() List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Chen Gang Cc: "Aneesh Kumar K.V" , aliguori@amazon.com, QEMU Developers Chen Gang writes: > 'ctx->fs_root' + 'path'/'fullname.data' may be larger than PATH_MAX, so > need use snprintf() instead of sprintf() just like another area have done in 9pfs. > > Signed-off-by: Chen Gang > --- > hw/9pfs/virtio-9p-local.c | 7 ++++--- > 1 file changed, 4 insertions(+), 3 deletions(-) > > diff --git a/hw/9pfs/virtio-9p-local.c b/hw/9pfs/virtio-9p-local.c > index 77a04cd..61be75a 100644 > --- a/hw/9pfs/virtio-9p-local.c > +++ b/hw/9pfs/virtio-9p-local.c > @@ -898,7 +898,8 @@ static int local_remove(FsContext *ctx, const char *path) > * directory > */ > if (S_ISDIR(stbuf.st_mode)) { > - sprintf(buffer, "%s/%s/%s", ctx->fs_root, path, VIRTFS_META_DIR); > + snprintf(buffer, ARRAY_SIZE(buffer), "%s/%s/%s", > + ctx->fs_root, path, VIRTFS_META_DIR); > err = remove(buffer); > if (err < 0 && errno != ENOENT) { > /* > @@ -1033,8 +1034,8 @@ static int local_unlinkat(FsContext *ctx, V9fsPath *dir, > * If directory remove .virtfs_metadata contained in the > * directory > */ > - sprintf(buffer, "%s/%s/%s", ctx->fs_root, > - fullname.data, VIRTFS_META_DIR); > + snprintf(buffer, ARRAY_SIZE(buffer), "%s/%s/%s", ctx->fs_root, > + fullname.data, VIRTFS_META_DIR); > ret = remove(buffer); > if (ret < 0 && errno != ENOENT) { > /* Turns a buffer overrun bug into a truncation bug. The next commit fixes truncation bugs including this one. Would be nice to spell this out in the commit message. Perhaps Aneesh can do it on commit.