| From 5eccf9e7aef2070de8d85bec11416d787da06f35 Mon Sep 17 00:00:00 2001 |
| From: Wang Xiayang <xywang.sjtu@sjtu.edu.cn> |
| Date: Wed, 31 Jul 2019 16:15:42 +0800 |
| Subject: net/ethernet/qlogic/qed: force the string buffer NULL-terminated |
| |
| [ Upstream commit 3690c8c9a8edff0db077a38783112d8fe12a7dd2 ] |
| |
| strncpy() does not ensure NULL-termination when the input string |
| size equals to the destination buffer size 30. |
| The output string is passed to qed_int_deassertion_aeu_bit() |
| which calls DP_INFO() and relies NULL-termination. |
| |
| Use strlcpy instead. The other conditional branch above strncpy() |
| needs no fix as snprintf() ensures NULL-termination. |
| |
| This issue is identified by a Coccinelle script. |
| |
| Signed-off-by: Wang Xiayang <xywang.sjtu@sjtu.edu.cn> |
| Signed-off-by: David S. Miller <davem@davemloft.net> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| drivers/net/ethernet/qlogic/qed/qed_int.c | 2 +- |
| 1 file changed, 1 insertion(+), 1 deletion(-) |
| |
| diff --git a/drivers/net/ethernet/qlogic/qed/qed_int.c b/drivers/net/ethernet/qlogic/qed/qed_int.c |
| index 7746417130bd7..c5d9f290ec4c7 100644 |
| --- a/drivers/net/ethernet/qlogic/qed/qed_int.c |
| +++ b/drivers/net/ethernet/qlogic/qed/qed_int.c |
| @@ -939,7 +939,7 @@ static int qed_int_deassertion(struct qed_hwfn *p_hwfn, |
| snprintf(bit_name, 30, |
| p_aeu->bit_name, num); |
| else |
| - strncpy(bit_name, |
| + strlcpy(bit_name, |
| p_aeu->bit_name, 30); |
| |
| /* We now need to pass bitmask in its |
| -- |
| 2.20.1 |
| |