From mboxrd@z Thu Jan 1 00:00:00 1970 From: Bjorn Andersson Subject: Re: [PATCH v6 7/9] soc: qcom: wcnss_ctrl: Avoid string overflow Date: Mon, 3 Sep 2018 12:22:02 -0700 Message-ID: <20180903192202.GB3456@tuxbook-pro> References: <20180829075724.9095-1-niklas.cassel@linaro.org> <20180829075724.9095-8-niklas.cassel@linaro.org> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Return-path: Content-Disposition: inline In-Reply-To: <20180829075724.9095-8-niklas.cassel@linaro.org> Sender: linux-kernel-owner@vger.kernel.org To: Niklas Cassel Cc: Andy Gross , David Brown , linux-arm-msm@vger.kernel.org, linux-soc@vger.kernel.org, linux-kernel@vger.kernel.org List-Id: linux-arm-msm@vger.kernel.org On Wed 29 Aug 00:57 PDT 2018, Niklas Cassel wrote: > 'chinfo.name' is used as a NUL-terminated string, but using strncpy() with > the length equal to the buffer size may result in lack of the termination: > > drivers//soc/qcom/wcnss_ctrl.c: In function 'qcom_wcnss_open_channel': > drivers//soc/qcom/wcnss_ctrl.c:284:2: warning: 'strncpy' specified bound 32 equals destination size [-Wstringop-truncation] > strncpy(chinfo.name, name, sizeof(chinfo.name)); > ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ > > This changes it to use the safer strscpy() instead. > > Signed-off-by: Niklas Cassel Reviewed-by: Bjorn Andersson Regards, Bjorn > --- > drivers/soc/qcom/wcnss_ctrl.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/drivers/soc/qcom/wcnss_ctrl.c b/drivers/soc/qcom/wcnss_ctrl.c > index df3ccb30bc2d..373400dd816d 100644 > --- a/drivers/soc/qcom/wcnss_ctrl.c > +++ b/drivers/soc/qcom/wcnss_ctrl.c > @@ -281,7 +281,7 @@ struct rpmsg_endpoint *qcom_wcnss_open_channel(void *wcnss, const char *name, rp > struct rpmsg_channel_info chinfo; > struct wcnss_ctrl *_wcnss = wcnss; > > - strncpy(chinfo.name, name, sizeof(chinfo.name)); > + strscpy(chinfo.name, name, sizeof(chinfo.name)); > chinfo.src = RPMSG_ADDR_ANY; > chinfo.dst = RPMSG_ADDR_ANY; > > -- > 2.17.1 >