From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 50C0EEB64D7 for ; Tue, 13 Jun 2023 15:35:27 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S242619AbjFMPfZ (ORCPT ); Tue, 13 Jun 2023 11:35:25 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:51408 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S242945AbjFMPfN (ORCPT ); Tue, 13 Jun 2023 11:35:13 -0400 Received: from out3-smtp.messagingengine.com (out3-smtp.messagingengine.com [66.111.4.27]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 60DA7127 for ; Tue, 13 Jun 2023 08:35:12 -0700 (PDT) Received: from compute1.internal (compute1.nyi.internal [10.202.2.41]) by mailout.nyi.internal (Postfix) with ESMTP id CAF365C0143; Tue, 13 Jun 2023 11:35:11 -0400 (EDT) Received: from mailfrontend2 ([10.202.2.163]) by compute1.internal (MEProxy); Tue, 13 Jun 2023 11:35:11 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= invisiblethingslab.com; h=cc:cc:content-type:content-type:date :date:from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:sender:subject:subject:to:to; s=fm1; t= 1686670511; x=1686756911; bh=arSfmSsp6qMAGSwGIzR20rLDf4VrfVXnKoh BNMEZvus=; b=AV/GnTdCBzJnwntFBVhC5JKSzuoA+EVWhxbt6wYkN0YeL0VhKIS vJZJqik3jvIzbPH6cFeCjyh/EzBCrFIGLMWAse9nsI3Z2pK2CuEB+qp/gX/je2yb aug5+i8FS7RHaP9diJhkorAa5Vr0f4Jsdhc5IOcBpfBEYcjBjLXbQxldqDmSrKuO O+bKep2ng30VHkGTtZZdvJBRRJ4oyPXLu7ANJOs9b+xMkxbB4vVHSU5hCj0uWXfs fGlg5PnP3vA/qtMx7XPJ0Vw/OseWV5IVsjq4AfcK61GLnW/mF9lwbmEI0o2eTQfa EKOfsXSafLbC+wSXCJHL8b9gPhXWf2q+liQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-type:content-type:date:date :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:sender:subject :subject:to:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm2; t=1686670511; x=1686756911; bh=arSfmSsp6qMAG SwGIzR20rLDf4VrfVXnKohBNMEZvus=; b=cOiyTjTqzBhRBNqmf8S95wJRwaw62 UcW6WbcQKcIuMG7m9I6Db2uvrQmHRj4K0/5094hgjj6azM79iS2H8gj8eNAel55X id64B9655GZkxA/AFA+KTH93FJea4HFJTFFVUAWe5at4W4dcaw9C/TtYBEgNm90K sdKHRzmS2bSn34Cr2eifw1tADLhjuVVa82CC7AeAdkTBXQnAjAnaXF8VHg16sU/e aBZRFz+9/WkEl6sKxUfUK545A0S08Fb0/LFHcwACIhoIGIoAGfTOwvg/rJ/YxE0b pUQ+Gzo1SOfGeGbUOE37UU0lfY4zMA2JUbjowZTSfh69Ot0ETGlCRpJZw== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvhedrgedujedgkeekucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurhepfffhvfevuffkfhggtggujgesghdtreertddtjeenucfhrhhomhepffgvmhhi ucforghrihgvucfqsggvnhhouhhruceouggvmhhisehinhhvihhsihgslhgvthhhihhngh hslhgrsgdrtghomheqnecuggftrfgrthhtvghrnhepvdejteegkefhteduhffgteffgeff gfduvdfghfffieefieekkedtheegteehffelnecuvehluhhsthgvrhfuihiivgeptdenuc frrghrrghmpehmrghilhhfrhhomhepuggvmhhisehinhhvihhsihgslhgvthhhihhnghhs lhgrsgdrtghomh X-ME-Proxy: Feedback-ID: iac594737:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Tue, 13 Jun 2023 11:35:10 -0400 (EDT) Date: Tue, 13 Jun 2023 11:35:05 -0400 From: Demi Marie Obenour To: David Laight , Andy Shevchenko Cc: Alexey Dobriyan , "linux-kernel@vger.kernel.org" , Rasmus Villemoes , Hans de Goede , Mauro Carvalho Chehab , Sakari Ailus , Greg Kroah-Hartman , Juergen Gross , Stefano Stabellini , Oleksandr Tyshchenko , Lee Jones , Andy Lutomirski , Thomas Gleixner , Vincenzo Frascino , Petr Mladek , Steven Rostedt , Sergey Senozhatsky Subject: Re: [PATCH v3 0/4] Make sscanf() stricter Message-ID: References: <6ab6adce-2318-4ae6-bde6-4317485639fd@p183> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="fNICznYAU3QlUDGM" Content-Disposition: inline In-Reply-To: Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org --fNICznYAU3QlUDGM Content-Type: text/plain; protected-headers=v1; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Date: Tue, 13 Jun 2023 11:35:05 -0400 From: Demi Marie Obenour To: David Laight , Andy Shevchenko Cc: Alexey Dobriyan , "linux-kernel@vger.kernel.org" , Rasmus Villemoes , Hans de Goede , Mauro Carvalho Chehab , Sakari Ailus , Greg Kroah-Hartman , Juergen Gross , Stefano Stabellini , Oleksandr Tyshchenko , Lee Jones , Andy Lutomirski , Thomas Gleixner , Vincenzo Frascino , Petr Mladek , Steven Rostedt , Sergey Senozhatsky Subject: Re: [PATCH v3 0/4] Make sscanf() stricter On Tue, Jun 13, 2023 at 01:02:59PM +0000, David Laight wrote: > From: Demi Marie Obenour > > Sent: 12 June 2023 22:23 > .... > > sscanf(), except to the extent that -Werror=3Dformat can keep working. > > Userspace sscanf() is almost useless: it has undefined behavior on > > integer overflow and swallows spaces that should usually be rejected. >=20 > scanf() is designed for parsing space separated data. > Eating spaces it part of its job description. >=20 > David In this case I would prefer to have two versions: one that eats spaces and one that does not. For instance, I don=E2=80=99t think any user of xenbus_scanf() wants the space-swallowing behavior. This can be worked around in xenbus_scanf(), of course, by having it reject strings with spaces (as determened by isspace()) before calling vsscanf(). --=20 Sincerely, Demi Marie Obenour (she/her/hers) Invisible Things Lab --fNICznYAU3QlUDGM Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEdodNnxM2uiJZBxxxsoi1X/+cIsEFAmSIjKwACgkQsoi1X/+c IsH7BBAAvFNPcgApcQwpZ3D3vyZvEJ6//ENiuEPS3e9FzSqjwejzAuIzUMK15zNv mgfy2bVAeWvpxNgvYE6tuJ182pcZosJgxnzi5R2a5ft9eEs2OvNQgUskgxD+BT1C 4sPw09VkTVrYQ+UO7wQ+fyM6LsLF+G3fukQP9wrejFETpS9Sk+4yonELFHlvN13K WJ7lU56W8QVnyd8nDyVo7v/MeXAPITGyFPAV7zN3uP9NsFJmAcR1QCP+6WubO5rm 67VcxkLSvxh+ch8gttagXNGZTGLnjQaaDU3VygNCAEV+vOJe4SUcDSKC5VhKMoad Ew6Ki2fiA/zMk1jJvBCmN6JU+8JyVPU2t2ITccVS9VG/S2eTQrwTlHjba16IRTTV D9Ai5CdkI9aYJk482BlurVYjoYPQqFrpFDOw+nhxclhvdruxSmo3us1jwPyoLVJY iTbRoyLKV5NnOb+AkVtGN6XqgBklPCSZty8QWPts3tXvzt30miS+4tL8+vUH853s aXsQtFxmQ4iw3GdQyjyuY0DnKzTw3s7jKHnm6H4O5iokF8f2YfMNxAj5NfeginVo lrDgGhnbIOknNK6azyx0jGEmzWQUzqQLGHYn2GWCI8/90BACz6Cp6/beH6HF3VO6 oC/WHx1YtttkGKO+R1yEp9lMKy/elfIYJGVBxHjoJoR0A5VPr8Y= =Uv3f -----END PGP SIGNATURE----- --fNICznYAU3QlUDGM--