From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752798AbdEEXBJ (ORCPT ); Fri, 5 May 2017 19:01:09 -0400 Received: from esa2.hgst.iphmx.com ([68.232.143.124]:34860 "EHLO esa2.hgst.iphmx.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751391AbdEEXBH (ORCPT ); Fri, 5 May 2017 19:01:07 -0400 X-IronPort-AV: E=Sophos;i="5.38,295,1491235200"; d="scan'208";a="112244934" From: Bart Van Assche To: "keescook@chromium.org" , "linux-scsi@vger.kernel.org" CC: "jejb@linux.vnet.ibm.com" , "linux-kernel@vger.kernel.org" , "QLogic-Storage-Upstream@cavium.com" , "danielmicay@gmail.com" , "martin.petersen@oracle.com" Subject: Re: [PATCH] scsi: qedf: Avoid reading past end of buffer Thread-Topic: [PATCH] scsi: qedf: Avoid reading past end of buffer Thread-Index: AQHSxfEAqoZPYjQqpUuMGmWZKCeiH6HmWw6A Date: Fri, 5 May 2017 23:01:04 +0000 Message-ID: <1494025263.2744.22.camel@sandisk.com> References: <20170505224255.GA21521@beast> In-Reply-To: <20170505224255.GA21521@beast> Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: authentication-results: chromium.org; dkim=none (message not signed) header.d=none;chromium.org; dmarc=none action=none header.from=sandisk.com; x-originating-ip: [63.163.107.100] x-ms-publictraffictype: Email x-microsoft-exchange-diagnostics: 1;BY1PR0401MB1532;7:V7eGOONw49s8qFPXPbOw2RwzefIqlxu+VGmPDNGd6BLPLwQrx+iWY3WgqxRjIIDrbjjeHkS+ssNd+2yzga/HNcNuZyCThPTlSdm2hN6wOWGSj2PdtKl23+nQzzde0qYO6UL4wYnIThcdvlfPbh7kePs58k4QH7E/K/xWxZVK1pfJnh2bjijTnX8b9brmC/veweSs+diytDAdHZ/8uUkYVeMXpuzsLk7yyipwQGnrSrdXs/iytgYB5tQbAoavL32JbdOZVdpTmjJG6INX9D/gYyxhUe4PvuCF2rtWDLWwUhhQIcqZUesKr7SE7E+OpCqnxRmVUVaMzkQNW6JtyM+hDw==;20:T126fnsFlrXLjADZIELVJrWddgNyxsdDdvm7t7iyMolEcVVpTmhj5KPUSD5Hm6/XvzXHShKcFLOKRXzLLGSecrbLKJ1l0ygOlQAzdsP/LCR56DcWFKjIcx3d+hYq86jrzIb2sjFRc6nrVBICn3CURFOowT5Gj1CGAVVKgyyEwlQ= x-ms-office365-filtering-correlation-id: be18a08a-4b86-42bd-2065-08d4940a9bc9 x-ms-office365-filtering-ht: Tenant x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:(22001)(2017030254075)(48565401081)(201703131423075)(201703031133081);SRVR:BY1PR0401MB1532; wdcipoutbound: EOP-TRUE x-microsoft-antispam-prvs: x-exchange-antispam-report-test: UriScan:; x-exchange-antispam-report-cfa-test: BCL:0;PCL:0;RULEID:(6040450)(601004)(2401047)(8121501046)(5005006)(3002001)(93006095)(93001095)(10201501046)(6055026)(6041248)(20161123558100)(20161123555025)(20161123562025)(20161123564025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123560025)(6072148);SRVR:BY1PR0401MB1532;BCL:0;PCL:0;RULEID:;SRVR:BY1PR0401MB1532; x-forefront-prvs: 02981BE340 x-forefront-antispam-report: SFV:NSPM;SFS:(10019020)(6009001)(39860400002)(39400400002)(39410400002)(39450400003)(39840400002)(39850400002)(24454002)(377424004)(2900100001)(25786009)(6512007)(6246003)(54906002)(38730400002)(97736004)(122556002)(36756003)(229853002)(99286003)(39060400002)(4326008)(7736002)(81166006)(86362001)(50986999)(8676002)(5660300001)(305945005)(6116002)(53936002)(2950100002)(3846002)(102836003)(76176999)(54356999)(8936002)(33646002)(6506006)(6486002)(66066001)(3660700001)(77096006)(103116003)(2906002)(6436002)(3280700002)(2501003)(478600001)(189998001);DIR:OUT;SFP:1102;SCL:1;SRVR:BY1PR0401MB1532;H:BY1PR0401MB1532.namprd04.prod.outlook.com;FPR:;SPF:None;MLV:ovrnspm;PTR:InfoNoRecords;LANG:en; spamdiagnosticoutput: 1:99 spamdiagnosticmetadata: NSPM Content-Type: text/plain; charset="iso-8859-1" Content-ID: <75B1B52B3E3AA14F9DAD24C86B5B7299@namprd04.prod.outlook.com> MIME-Version: 1.0 X-OriginatorOrg: sandisk.com X-MS-Exchange-CrossTenant-originalarrivaltime: 05 May 2017 23:01:04.7153 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: b61c8803-16f3-4c35-9b17-6f65f441df86 X-MS-Exchange-Transport-CrossTenantHeadersStamped: BY1PR0401MB1532 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Transfer-Encoding: 8bit X-MIME-Autoconverted: from quoted-printable to 8bit by mail.home.local id v45N1EYw018294 On Fri, 2017-05-05 at 15:42 -0700, Kees Cook wrote: > diff --git a/drivers/scsi/qedf/qedf_main.c b/drivers/scsi/qedf/qedf_main.c > index cceddd995a4b..a5c97342fd5d 100644 > --- a/drivers/scsi/qedf/qedf_main.c > +++ b/drivers/scsi/qedf/qedf_main.c > @@ -2895,7 +2895,7 @@ static int __qedf_probe(struct pci_dev *pdev, int mode) > slowpath_params.drv_minor = QEDF_DRIVER_MINOR_VER; > slowpath_params.drv_rev = QEDF_DRIVER_REV_VER; > slowpath_params.drv_eng = QEDF_DRIVER_ENG_VER; > - memcpy(slowpath_params.name, "qedf", QED_DRV_VER_STR_SIZE); > + strncpy(slowpath_params.name, "qedf", QED_DRV_VER_STR_SIZE); > rc = qed_ops->common->slowpath_start(qedf->cdev, &slowpath_params); > if (rc) { > QEDF_ERR(&(qedf->dbg_ctx), "Cannot start slowpath.\n"); Hello Kees, Although this patch looks fine to me, isn't strlcpy() preferred over strncpy()? Bart.