From: Joe Perches <joe@perches.com>
To: Mathieu Malaterre <malat@debian.org>,
Bartlomiej Zolnierkiewicz <b.zolnierkie@samsung.com>
Cc: dri-devel@lists.freedesktop.org, linux-fbdev@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH] video/hdmi: Change strncpy() into memcpy() in hdmi_spd_infoframe_init
Date: Fri, 18 Jan 2019 19:51:20 +0000 [thread overview]
Message-ID: <d76c2a301d324239db09ccc7cd8421821ba93b87.camel@perches.com> (raw)
In-Reply-To: <20190118193248.535-1-malat@debian.org>
On Fri, 2019-01-18 at 20:32 +0100, Mathieu Malaterre wrote:
> Using strncpy() is less than perfect since the destination buffers do not
> need to be NUL terminated. Replace strncpy() with memcpy() to address a
> warning triggered by gcc using W=1 and optimize the code a bit.
>
> This commit removes the following warnings:
>
> drivers/video/hdmi.c:234:2: warning: 'strncpy' specified bound 8 equals destination size [-Wstringop-truncation]
> drivers/video/hdmi.c:235:2: warning: 'strncpy' specified bound 16 equals destination size [-Wstringop-truncation]
[]
> diff --git a/drivers/video/hdmi.c b/drivers/video/hdmi.c
[]
> @@ -231,8 +231,8 @@ int hdmi_spd_infoframe_init(struct hdmi_spd_infoframe *frame,
> frame->version = 1;
> frame->length = HDMI_SPD_INFOFRAME_SIZE;
>
> - strncpy(frame->vendor, vendor, sizeof(frame->vendor));
> - strncpy(frame->product, product, sizeof(frame->product));
> + memcpy(frame->vendor, vendor, sizeof(frame->vendor));
> + memcpy(frame->product, product, sizeof(frame->product));
This is not good.
vendor can be any location and shorter than sizeof(frame->vendor)
so this can copy from invalid memory locations.
You probably want strscpy.
This is called with at least "mediatek" and "broadcom", so perhaps
it's better still to change the struct vendor size to something a
bit larger. Maybe change vendor[8] to vendor[16];
include/linux/hdmi.h:struct hdmi_spd_infoframe {
include/linux/hdmi.h- enum hdmi_infoframe_type type;
include/linux/hdmi.h- unsigned char version;
include/linux/hdmi.h- unsigned char length;
include/linux/hdmi.h- char vendor[8];
include/linux/hdmi.h- char product[16];
include/linux/hdmi.h- enum hdmi_spd_sdi sdi;
include/linux/hdmi.h-};
next prev parent reply other threads:[~2019-01-18 19:51 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-01-18 19:32 [PATCH] video/hdmi: Change strncpy() into memcpy() in hdmi_spd_infoframe_init Mathieu Malaterre
2019-01-18 19:51 ` Joe Perches [this message]
2019-01-18 20:09 ` Mathieu Malaterre
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=d76c2a301d324239db09ccc7cd8421821ba93b87.camel@perches.com \
--to=joe@perches.com \
--cc=b.zolnierkie@samsung.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=linux-fbdev@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=malat@debian.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox