public inbox for ltp@lists.linux.it
 help / color / mirror / Atom feed
From: Jinseok Kim <always.starving0@gmail.com>
To: ltp@lists.linux.it, andrea.cervesato@suse.com
Subject: [LTP] [PATCH v3 1/2] open: fix cleanup condition and use snprintf
Date: Thu, 19 Feb 2026 23:15:17 +0900	[thread overview]
Message-ID: <20260219141532.6513-1-always.starving0@gmail.com> (raw)
In-Reply-To: <DGIU5TUBY8DA.1O11NEVRMZTZK@suse.com>

The test uses sprintf() to build temporary file names, which may
overflow the fixed-size buffer. Replace it with snprintf() to avoid
potential buffer overflows.

The cleanup logic also checked '!first' to decide whether to close
file descriptors. Since file descriptor 0 is valid, this condition
can incorrectly skip cleanup and leak file descriptors.

To fix this:
- Initialize first = -1 to correctly detect uninitialized state
- Initialize fds array with -1 after malloc to avoid closing invalid fds

Signed-off-by: Jinseok Kim <always.starving0@gmail.com>
---
 testcases/kernel/syscalls/open/open04.c | 10 ++++++----
 1 file changed, 6 insertions(+), 4 deletions(-)

diff --git a/testcases/kernel/syscalls/open/open04.c b/testcases/kernel/syscalls/open/open04.c
index 3dc3486d3..152bec2d4 100644
--- a/testcases/kernel/syscalls/open/open04.c
+++ b/testcases/kernel/syscalls/open/open04.c
@@ -15,7 +15,8 @@

 #define FNAME "open04"

-static int fds_limit, first, i;
+static int fds_limit, i;
+static int first = -1;
 static int *fds;
 static char fname[20];

@@ -27,10 +28,11 @@ static void setup(void)
 	first = SAFE_OPEN(FNAME, O_RDWR | O_CREAT, 0777);

 	fds = SAFE_MALLOC(sizeof(int) * (fds_limit - first));
+	memset(fds, -1, sizeof(int) * (fds_limit - first));
 	fds[0] = first;

 	for (i = first + 1; i < fds_limit; i++) {
-		sprintf(fname, FNAME ".%d", i);
+		snprintf(fname, sizeof(fname), FNAME ".%d", i);
 		fd = open(fname, O_RDWR | O_CREAT, 0777);
 		if (fd == -1) {
 			if (errno != EMFILE)
@@ -44,13 +46,13 @@ static void setup(void)

 static void run(void)
 {
-	sprintf(fname, FNAME ".%d", fds_limit);
+	snprintf(fname, sizeof(fname), FNAME ".%d", fds_limit);
 	TST_EXP_FAIL2(open(fname, O_RDWR | O_CREAT, 0777), EMFILE);
 }

 static void cleanup(void)
 {
-	if (!first || !fds)
+	if (first < 0 || !fds)
 		return;

 	for (i = first; i < fds_limit; i++)
--
2.43.0

-- 
Mailing list info: https://lists.linux.it/listinfo/ltp

  reply	other threads:[~2026-02-19 14:16 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-02-18 14:47 [LTP] [PATCH v2 1/2] open: fix cleanup condition and use snprintf Jinseok Kim
2026-02-18 14:47 ` [LTP] [PATCH v2 2/2] open: replace getdtablesize with getrlimit Jinseok Kim
2026-02-19  9:37 ` [LTP] [PATCH v2 1/2] open: fix cleanup condition and use snprintf Andrea Cervesato via ltp
2026-02-19 14:15   ` Jinseok Kim [this message]
2026-02-19 14:15     ` [LTP] [PATCH v3 2/2] open: replace getdtablesize with getrlimit Jinseok Kim
2026-03-13 16:42       ` Petr Vorel
2026-03-20 13:56     ` [LTP] [PATCH v3 1/2] open: fix cleanup condition and use snprintf Andrea Cervesato via ltp
2026-03-21 14:08       ` [LTP] [PATCH v4] " Jinseok Kim
2026-03-23  6:45         ` Andrea Cervesato via ltp
2026-03-25 12:22           ` [LTP] [PATCH v5] " Jinseok Kim
2026-03-25 15:48             ` Andrea Cervesato via ltp
2026-03-27 14:03               ` [LTP] [PATCH v6] " Jinseok Kim
2026-03-27 14:52                 ` Andrea Cervesato via ltp

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260219141532.6513-1-always.starving0@gmail.com \
    --to=always.starving0@gmail.com \
    --cc=andrea.cervesato@suse.com \
    --cc=ltp@lists.linux.it \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox