Received: by 2002:a05:6358:3188:b0:123:57c1:9b43 with SMTP id q8csp2323063rwd; Wed, 14 Jun 2023 00:51:07 -0700 (PDT) X-Google-Smtp-Source: ACHHUZ6gk1MW2dKtzZKHCicB5gOL2EhK7rzRxxYr0DeMP3MPLr/hF4bivmtnO6esf5wFP8I+igv+ X-Received: by 2002:aa7:d657:0:b0:514:9d17:d6ef with SMTP id v23-20020aa7d657000000b005149d17d6efmr9392283edr.13.1686729067108; Wed, 14 Jun 2023 00:51:07 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1686729067; cv=none; d=google.com; s=arc-20160816; b=vFZR7wG2o+QQlWBh4z9Sh7CokFm3guLnHhnLwXJq+obXGfuFjVBM5Bs3R/oFI2INjN rSJUR6m4SElYm9IgbaUewPcYj6MT7xQu5huTWeBVxDvrLOEaxX1lQ3Si2TbjISMi1TUn vm3iH7rYFYMjgPVDCMlT2ILoRnurSjaZQ2gYGqcLzvHbuWtSwwxOwc3jrDM/HRD0E0sL 2KrBwjn2bXaGFCvzYLezARGXpAa1rMjfoyR2AJrODzI7iI4mw0NyPvaBLOWvbjTdsHrm sGcmnqKFEeNYMIFiubefpnZuayW8jse8WYVvCbeXp/dpJsmglqO19aS38154j1peqcp+ aTLQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:mime-version:user-agent:message-id:in-reply-to :date:references:subject:cc:to:from:dkim-signature; bh=cyJ5xvPAXQRodpXv0lPn+5SR0oTPGlQh2zO5RmN7ImQ=; b=0iJOqDYW/Pj44BF1lsdQwszgncxLy99K52n9IvUGktUeKAsUMK7CFRN0KDM85rlONb enTLNizFWH0cudHubZJPU6aU43WuZijMVpxmpYzooNRfZaSoPo9okUnzmzRsb2sdHOCv kP8Gh/b0r1hgdihqUSxxEZCKg4hAFfFaiAtBTkMER1H3IRgeYD77C9xqQlCsPoraEXVC cM020ZN4QoPLS0RUmx8+8RqJk1n54r9eqBcum3D6LGHz+YJy2mbQodc+a0D2bq0DT2dR 37bAu1yIlVXaCmLDa+KbQPni60JWtu0R4KjQoBQAu6HrL1/DIksLo0X+RZDT5bhZf3dR tmtg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=cNeWSCyz; spf=pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-wireless-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id m26-20020a50ef1a000000b005187b5bcde0si1288257eds.486.2023.06.14.00.50.51; Wed, 14 Jun 2023 00:51:07 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=cNeWSCyz; spf=pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-wireless-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S235315AbjFNHkR (ORCPT + 61 others); Wed, 14 Jun 2023 03:40:17 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:54322 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S243554AbjFNHkJ (ORCPT ); Wed, 14 Jun 2023 03:40:09 -0400 Received: from dfw.source.kernel.org (dfw.source.kernel.org [IPv6:2604:1380:4641:c500::1]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id AFEE0119; Wed, 14 Jun 2023 00:40:08 -0700 (PDT) Received: from smtp.kernel.org (relay.kernel.org [52.25.139.140]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by dfw.source.kernel.org (Postfix) with ESMTPS id 4524363841; Wed, 14 Jun 2023 07:40:08 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id BB759C433C0; Wed, 14 Jun 2023 07:40:05 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1686728407; bh=9tKEuGeMMCSJYUtkoU+erfANYr53GikoWC56/oucmhw=; h=From:To:Cc:Subject:References:Date:In-Reply-To:From; b=cNeWSCyzGUnOEq9DRg7LIAwHY7RkxPD1/9283JqRK/sZw9GrXj4l9sexC5UmKqDjl La7Ifdv6vRH7BrtN27+yDiiOGzkOM+jnr+8pbbtGN8T1XAAJlGCPWJuDTX+UFssAWp nUr7yIZKEKeFYsWG5xGdy4wA/0eLB9r3DIsObl3+yc+aQbiHepcrcr8bOQdsvloSjJ C0GlWILU7Xbxxnv8A/3hO5mCAPvRofQ9lN2wttU5BKmEv5m0TiUXpm2Fn+8cszVIc3 yxTl3Uep7MZX63seF2eThdKIT+dU1VuwQMxRh36SU+30BCW7PN1jp4f5ZvILtfuxjZ CTfqBQwI1Gu+Q== From: Kalle Valo To: Azeem Shaikh Cc: Johannes Berg , linux-hardening@vger.kernel.org, linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , netdev@vger.kernel.org Subject: Re: [PATCH] cfg80211: cfg80211: strlcpy withreturn References: <20230612232301.2572316-1-azeemshaikh38@gmail.com> Date: Wed, 14 Jun 2023 10:40:00 +0300 In-Reply-To: <20230612232301.2572316-1-azeemshaikh38@gmail.com> (Azeem Shaikh's message of "Mon, 12 Jun 2023 23:23:01 +0000") Message-ID: <87fs6ufq5r.fsf@kernel.org> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/26.1 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain X-Spam-Status: No, score=-4.4 required=5.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_MED, SPF_HELO_NONE,SPF_PASS,T_SCC_BODY_TEXT_LINE autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-wireless@vger.kernel.org Azeem Shaikh writes: > strlcpy() reads the entire source buffer first. > This read may exceed the destination size limit. > This is both inefficient and can lead to linear read > overflows if a source string is not NUL-terminated [1]. > In an effort to remove strlcpy() completely [2], replace > strlcpy() here with strscpy(). > > Direct replacement is safe here since WIPHY_ASSIGN is only used by > TRACE macros and the return values are ignored. > > [1] https://www.kernel.org/doc/html/latest/process/deprecated.html#strlcpy > [2] https://github.com/KSPP/linux/issues/89 > > Signed-off-by: Azeem Shaikh The title should be: wifi: cfg80211: replace strlcpy() with strlscpy() -- https://patchwork.kernel.org/project/linux-wireless/list/ https://wireless.wiki.kernel.org/en/developers/documentation/submittingpatches