From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 078FB3CAE8D; Wed, 30 Sep 2026 19:05:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790795107; cv=none; b=ivnQm8cNIiBqzeYklO0E91pFNoVHgYtZEPMAqDE8atP9K6V1XzVhbiISxeJe+9Dc4ZSji07JNt1bnZhM3wV0Itei8Z1kDpTcQjJrrDEcMAlYCVDAuXUj8vRWxuxaO1a9cPCSucxbzTBfi33p2EB09tg6gRIhzvsnFcNZ0kmK3VQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790795107; c=relaxed/simple; bh=P9wtm3+Vl+hGyECcxtCue1ig1ytekkTSikzU1A7Jvnk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=JzNCSiRKQGI5ZuTH+7fOY4o8v6Dz61g6ywywXaPzr0Ge7g0ulMT2olomczwE/Mnsp+u+BEUAvKUVijn9H3f0zyH4C67ywX8HtvGWtc9skd/MQeUKaqXiyxyIgj4vcaZpqK0NaybzalXRki0BSF0Z8oqGTtsZbimqj86SLD4CDtA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=l/vvlPik; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="l/vvlPik" Received: by smtp.kernel.org (Postfix) with ESMTPSA id E4C101F000FF; Wed, 30 Sep 2026 19:05:04 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790795105; bh=SjOhJaVyxe6VWQLtjKj3Oe6ZooWLK0zbfVi21zbN4eI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=l/vvlPikqx4TPrKX72GhklSm962I98stq+L6TM6CjoBOYN1Dv+BSJlU+gebuLcnjA PofLweOvwsUBm8vxDezgTNOPdk9EqL4AzhXsu2qeyXjcB6rpMagLQghH23TWNtqONZ WWYjPh4fjFlsFMRTB7r1RhA+/OlglXwPthYOGkLg= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Takashi Iwai , Sasha Levin Subject: [PATCH 6.6 0445/1193] ALSA: ump: Copy FB name string more safely Date: Wed, 30 Sep 2026 17:18:49 +0200 Message-ID: <20260930152444.067747687@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152434.301151190@linuxfoundation.org> References: <20260930152434.301151190@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.6-stable review patch. If anyone has any objections, please let me know. ------------------ From: Takashi Iwai [ Upstream commit e3f035edadcc1c5901311c03d098bc3dedc5c525 ] The UMP group names are referred as the corresponding sequencer port names, hence they should be proper ASCII strings. OTOH, the UMP group names are composed from the UMP FB strings that are received from the device; i.e. a device may give some bogus letters and we can't trust them fully. To assure that the group names consist of the proper ASCII strings, replace the normal string copy and append operations with special ones that strip the non-printable letters. Signed-off-by: Takashi Iwai Link: https://patch.msgid.link/20250110155943.31578-5-tiwai@suse.de Stable-dep-of: adeee7187694 ("ALSA: ump: do not touch legacy_rmidi before it exists") Signed-off-by: Sasha Levin --- sound/core/ump.c | 40 +++++++++++++++++++++++++++++++--------- 1 file changed, 31 insertions(+), 9 deletions(-) diff --git a/sound/core/ump.c b/sound/core/ump.c index 0bf919fc31935..1dd15fa47c61a 100644 --- a/sound/core/ump.c +++ b/sound/core/ump.c @@ -53,6 +53,34 @@ static inline void update_legacy_names(struct snd_ump_endpoint *ump) } #endif +/* copy a string safely with stripping non-printable letters */ +static void safe_copy_string(void *dst, size_t max_dst_size, + const void *src, size_t max_src_size) +{ + const unsigned char *s = src; + unsigned char *d = dst; + + if (!max_dst_size--) + return; + for (s = src; max_dst_size && *s && max_src_size--; s++) { + if (!isascii(*s) || !isprint(*s)) + continue; + *d++ = *s; + max_dst_size--; + } + *d = 0; +} + +/* append a string safely with stripping non-printable letters */ +static void safe_append_string(void *dst, size_t max_dst_size, + const void *src, size_t max_src_size) +{ + unsigned char *d = dst; + size_t len = strlen(d); + + safe_copy_string(d + len, max_dst_size - len, src, max_src_size); +} + static const struct snd_rawmidi_global_ops snd_ump_rawmidi_ops = { .dev_register = snd_ump_dev_register, .dev_unregister = snd_ump_dev_unregister, @@ -566,16 +594,10 @@ void snd_ump_update_group_attrs(struct snd_ump_endpoint *ump) } if (!*fb->info.name) continue; - if (!*group->name) { - /* store the first matching name */ - strscpy(group->name, fb->info.name, - sizeof(group->name)); - } else { - /* when overlapping, concat names */ + if (*group->name) strlcat(group->name, ", ", sizeof(group->name)); - strlcat(group->name, fb->info.name, - sizeof(group->name)); - } + safe_append_string(group->name, sizeof(group->name), + fb->info.name, sizeof(fb->info.name)); } } } -- 2.53.0