Linux USB
 help / color / mirror / Atom feed
* [PATCH next] drivers/usb/atm: Replace strcpy() + strlcat() with snprintf()
@ 2026-06-08  9:55 david.laight.linux
  2026-06-10  1:20 ` patchwork-bot+netdevbpf
  0 siblings, 1 reply; 2+ messages in thread
From: david.laight.linux @ 2026-06-08  9:55 UTC (permalink / raw)
  To: Kees Cook, linux-hardening, linux-kernel, linux-usb, netdev
  Cc: Arnd Bergmann, Chas Williams, Greg Kroah-Hartman, Matthieu CASTET,
	Stanislaw Gruszka, David Laight

From: David Laight <david.laight.linux@gmail.com>

Avoid string function that are due to be deprecated.

Signed-off-by: David Laight <david.laight.linux@gmail.com>
---
This is one of a group of patches that remove potentially unbounded
strcpy() calls.

They are mostly replaced by strscpy() or, when strlen() has just been
called, with memcpy() (usually including the '\0').

Calls with copy string literals into arrays are left unchanged.
They are safe and easily detected as such.

The changes were made by getting the compiler to detect the calls and
then fixing the code by hand.

Note that all the changes are only compile tested.

Some Makefiles were changed to allow files to contain strcpy().
As well as 'difficult to fix' files, this included 'show' functions
as they really need to use sysfs_emit() or seq_printf().

All the patches are being sent individually to avoid very long cc lists.
Apologies for the terse commit messages and likely unexpected tags.
(There are about 100 patches in total.)

 drivers/usb/atm/ueagle-atm.c | 5 +----
 1 file changed, 1 insertion(+), 4 deletions(-)

diff --git a/drivers/usb/atm/ueagle-atm.c b/drivers/usb/atm/ueagle-atm.c
index f3ae72feb5bf..df4477668296 100644
--- a/drivers/usb/atm/ueagle-atm.c
+++ b/drivers/usb/atm/ueagle-atm.c
@@ -1572,10 +1572,7 @@ static void cmvs_file_name(struct uea_softc *sc, char *const cmv_name, int ver)
 	} else
 		file = cmv_file[sc->modem_index];
 
-	strcpy(cmv_name, FW_DIR);
-	strlcat(cmv_name, file, UEA_FW_NAME_MAX);
-	if (ver == 2)
-		strlcat(cmv_name, ".v2", UEA_FW_NAME_MAX);
+	snprintf(cmv_name, UEA_FW_NAME_MAX, FW_DIR "%s%s", file, ver == 2 ? ".v2" : "");
 	kernel_param_unlock(THIS_MODULE);
 }
 
-- 
2.39.5


^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH next] drivers/usb/atm: Replace strcpy() + strlcat() with snprintf()
  2026-06-08  9:55 [PATCH next] drivers/usb/atm: Replace strcpy() + strlcat() with snprintf() david.laight.linux
@ 2026-06-10  1:20 ` patchwork-bot+netdevbpf
  0 siblings, 0 replies; 2+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-06-10  1:20 UTC (permalink / raw)
  To: David Laight
  Cc: kees, linux-hardening, linux-kernel, linux-usb, netdev, arnd,
	3chas3, gregkh, castet.matthieu, stf_xl

Hello:

This patch was applied to netdev/net-next.git (main)
by Jakub Kicinski <kuba@kernel.org>:

On Mon,  8 Jun 2026 10:55:20 +0100 you wrote:
> From: David Laight <david.laight.linux@gmail.com>
> 
> Avoid string function that are due to be deprecated.
> 
> Signed-off-by: David Laight <david.laight.linux@gmail.com>
> ---
> This is one of a group of patches that remove potentially unbounded
> strcpy() calls.
> 
> [...]

Here is the summary with links:
  - [next] drivers/usb/atm: Replace strcpy() + strlcat() with snprintf()
    https://git.kernel.org/netdev/net-next/c/41d3e102edc2

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html



^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-06-10  1:20 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-06-08  9:55 [PATCH next] drivers/usb/atm: Replace strcpy() + strlcat() with snprintf() david.laight.linux
2026-06-10  1:20 ` patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox