From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f174.google.com (mail-pl1-f174.google.com [209.85.214.174]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5ED06473C81 for ; Fri, 7 Aug 2026 11:42:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.174 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786102962; cv=none; b=bmQjMR6LgfTy7D1gz22gUFWszi1Fol5K/VNnpU0lYt8IN2cQRlNZtTARtQDUNH1A6BDQKotn3odMICJ0z4x5vgvwsj+SqOiwA1igYymgV83VAetPxnHLcMwnh8/aDglhjHNRrWWLDm1PB/5Dcx52tgUZD7Bum4vKVLf4mvoBT7A= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786102962; c=relaxed/simple; bh=ztgsF4xlC+/UgNtfKPXec9lw/Y0/M4oYUL4+7ifjbZU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=lpGdA4F9I2m1SQ9qyfTg/hv0iHGftFoxy7jIx0GAEde4W3kHQCm7Qjbd9sgDSYjYvLHDtOLzEr1hj0+TS0zDFW2NfiiSyLyYkujnbZbX+hcFlZuHrUHzS+A+DIg9xZ4rSzcush9jVR8Y/rFEU4BHDkdpceYpemJzoMsavkvDXM4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=DcTY/WU9; arc=none smtp.client-ip=209.85.214.174 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="DcTY/WU9" Received: by mail-pl1-f174.google.com with SMTP id d9443c01a7336-2cee9b74ee1so28205985ad.3 for ; Fri, 07 Aug 2026 04:42:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786102953; x=1786707753; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=XFU29Mt+4RJ+9zZZmPn+2wKzh7skI+zFObgTR2DLrqc=; b=DcTY/WU9FUkk66U0jvqwGrtXduGttJAAQa/egpEVYRAeuLU4YEnxHzAFRkPFma2ygf b06cJpXjqLuMtb6QBg4RJJJADxwgKohTL1RKW1BzimL+vPryBCQMw3GtpguJqDvwi9Lk aActrR6lYy8vIWlQYacj6tSy7vTO+HVnwNYvFhh1FpjY9nVQc6vZkTs9sjdJRSFB4lLa SAZij0knLzE/0cIeFon1ES8zJbYI9xPVdFY4Rjdx4JmadvKSj5GtYD6uS+HlaHqq/mmW FQd6jDR1jzJRAlQsaOR8Fvq8sXvXH6CNs/dj8vkd89QhOabFGnQPQcm2vcqhGZCzNUrI e0SQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786102953; x=1786707753; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=XFU29Mt+4RJ+9zZZmPn+2wKzh7skI+zFObgTR2DLrqc=; b=kXuAdH76A5aWDemKH4pFvdZXzZR3lIczhQ++cD0qpAbjFJETXYQZ6R8mLMgL4yfjOU DwqEgvYWpLGEs9OQthA+Sca6h3S9pdYgshDg9w2EESJABMOVp69yCK65Wg4ix9WgPGUs /V5DItY6nIJaNUWDOQTZ6eRnsRY36rP//VSiG/eHBbTut+j/41DBVjxRMipK7jcWcE5k K9gp2IhLJQiOVlnfAJJQu3sO90YB/KZCMrFKa0qHmU1x1LdDm45LZYGLcwTuOgRyutuS F16p9wVyOaXb+o47V16hgTXFJOGYH138bz5DlKwx3SIJBHc6riK9j018cuqkZQUklSuk 9SSQ== X-Forwarded-Encrypted: i=1; AHgh+Rrz6mI8tfOEL+dg91qvLmUohdTCojo/3v9vIKXPkrDjrzNz453m/8NNQQF5mDS80tGP5MzfNVigGYVxsRE=@vger.kernel.org X-Gm-Message-State: AOJu0Yx5KUa73bxNaynO8DSlbB6N3mQ6lSR03vu3v/iXO4/ZKjFaDXuf kAPBw9ib3NfW4dXkp3pk5cLathmUlrdoUmefTjprMvXUV8ujapqEZNav X-Gm-Gg: AR+sD10kEK9eupeRdmG/+p4pzXywxZVbIw1Tz5YpwlTNU3eyKg03+7VrgVIQUBuMR0g qaM6kqCJq/k/cuf+I9w5usVBoolW5zbjyU4nYTqwtAKHlMbo5YNRrUzf1IraBGa8xELxXTqRzyK wi/0MzOYHnEDYSahU/pN6osIdpOx5tVeUal9VsHmDOef+oKlAHGT/Ha0tp1jcXHQ1WaZGTPaFvy UCreotayVu6025oYGkjk2G+HuqU3+qfBuw80IgKUn3KtkU1sylUkeO0wbI3MqcWuJ0z5yMfsrQJ UzFFWZ3+pYcqCdZOBbCcQh8bEMwOxKEXjsbbaa2GK/YwzDNmM46ycoA+jzFGyjMBSYHOHMZ4uHG VK6eF0ydh+rW2ljG1c1SNHSuAulLHwPeC7Hr/GWKx2b8d+nTa2LB874L5Xp48Pu4kx3cmr4x/oq EsqO5uHUEbbd47PzTxF3geKZKloh94CWgFiOR3z6ZsUoZXet7ysNRzI03rGeB2z1Z2eOqbsQjuA ZOdj0rHwck= X-Received: by 2002:a17:902:cccf:b0:2d0:cc92:f7b8 with SMTP id d9443c01a7336-2d0cc9302a7mr259995675ad.2.1786102953464; Fri, 07 Aug 2026 04:42:33 -0700 (PDT) Received: from localhost.localdomain ([72.255.58.127]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-315be86d3fcsm6930508eec.4.2026.08.07.04.42.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 07 Aug 2026 04:42:33 -0700 (PDT) From: Mahad Ibrahim To: Takashi Iwai , Jaroslav Kysela Cc: Kees Cook , Andy Shevchenko , linux-sound@vger.kernel.org, linux-kernel@vger.kernel.org, Mahad Ibrahim Subject: [PATCH 6/7] ALSA: hiface: replace strlcat() with scnprintf() Date: Fri, 7 Aug 2026 11:41:38 +0000 Message-ID: <20260807114139.1661-7-mahad.ibrahim.dev@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260807114139.1661-1-mahad.ibrahim.dev@gmail.com> References: <20260807114139.1661-1-mahad.ibrahim.dev@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit card->longname was built with two strlcat() calls, one copying card->shortname and one appending " at ". The return value of the second gave the offset that usb_make_path() writes at. card->longname is empty here. snd_card_new() allocates struct snd_card with kzalloc() and nothing writes longname before this point, so the first strlcat() is really a copy and the two calls collapse into one scnprintf(). len now counts the characters actually written rather than the characters requested, so the bounds check below it is always true and usb_make_path() is reached even when the name was truncated. In that case it is given a size of one and writes only the NUL terminator that scnprintf() already placed there, so longname does not change. Truncation cannot happen in practice anyway: shortname is 32 bytes and longname is 80. Signed-off-by: Mahad Ibrahim --- sound/usb/hiface/chip.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/sound/usb/hiface/chip.c b/sound/usb/hiface/chip.c index bce28f683666..d217fe64eabd 100644 --- a/sound/usb/hiface/chip.c +++ b/sound/usb/hiface/chip.c @@ -70,8 +70,8 @@ static int hiface_chip_create(struct usb_interface *intf, else strscpy(card->shortname, "M2Tech generic audio", sizeof(card->shortname)); - strlcat(card->longname, card->shortname, sizeof(card->longname)); - len = strlcat(card->longname, " at ", sizeof(card->longname)); + len = scnprintf(card->longname, sizeof(card->longname), "%s at ", + card->shortname); if (len < sizeof(card->longname)) usb_make_path(device, card->longname + len, sizeof(card->longname) - len); -- 2.54.0