From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5C0D5C77B75 for ; Mon, 22 May 2023 22:46:43 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S234893AbjEVWql (ORCPT ); Mon, 22 May 2023 18:46:41 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:49524 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S234867AbjEVWqf (ORCPT ); Mon, 22 May 2023 18:46:35 -0400 Received: from mx0a-00069f02.pphosted.com (mx0a-00069f02.pphosted.com [205.220.165.32]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 6F39711F; Mon, 22 May 2023 15:46:34 -0700 (PDT) Received: from pps.filterd (m0246629.ppops.net [127.0.0.1]) by mx0b-00069f02.pphosted.com (8.17.1.19/8.17.1.19) with ESMTP id 34MKODcg004100; Mon, 22 May 2023 22:46:30 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oracle.com; h=from : to : cc : subject : date : message-id : in-reply-to : references : mime-version : content-type : content-transfer-encoding; s=corp-2023-03-30; bh=xehUR551YIhWN1qsMuHXh2zScbawfvtXVnUHhiA8LK8=; b=cAQpgSXeXOYBMY3BDeZpVQ2bSrHkYO29URUISiY/nE2eAlmLmuyNwWGy46/1V4Ex7jfm xNEblxcjsB+wSpPbxemXfVEjhWh52cceAtrNpzHZBVdXBkJ/iS85yBWXbwf/m2aGytjE QLzfxwOuqe0wmmQYc3UFGtGozUClJkbLxxCDCxDFuIKTpaVB77i3iU9O9gnHWgvEX5BO guLKvceZ2K6yFlyOshClNzGk7EUOWjDJEU6KmSA8cmbi01y457NF9twqV+nxMXgC49W1 AK3LY1TtWY/6qTeQBM4SF/ChGYE04XyJgJvRaotCNQnDq1K0Frgb9yxDYJiAGEsXrVfG Wg== Received: from phxpaimrmta01.imrmtpd1.prodappphxaev1.oraclevcn.com (phxpaimrmta01.appoci.oracle.com [138.1.114.2]) by mx0b-00069f02.pphosted.com (PPS) with ESMTPS id 3qpp423tv7-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 22 May 2023 22:46:30 +0000 Received: from pps.filterd (phxpaimrmta01.imrmtpd1.prodappphxaev1.oraclevcn.com [127.0.0.1]) by phxpaimrmta01.imrmtpd1.prodappphxaev1.oraclevcn.com (8.17.1.19/8.17.1.19) with ESMTP id 34MM6Ftm027191; Mon, 22 May 2023 22:46:29 GMT Received: from pps.reinject (localhost [127.0.0.1]) by phxpaimrmta01.imrmtpd1.prodappphxaev1.oraclevcn.com (PPS) with ESMTPS id 3qqk2ctfbw-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 22 May 2023 22:46:29 +0000 Received: from phxpaimrmta01.imrmtpd1.prodappphxaev1.oraclevcn.com (phxpaimrmta01.imrmtpd1.prodappphxaev1.oraclevcn.com [127.0.0.1]) by pps.reinject (8.17.1.5/8.17.1.5) with ESMTP id 34MMkPxa017332; Mon, 22 May 2023 22:46:29 GMT Received: from ca-mkp2.ca.oracle.com.com (mpeterse-ol9.allregionaliads.osdevelopmeniad.oraclevcn.com [100.100.251.135]) by phxpaimrmta01.imrmtpd1.prodappphxaev1.oraclevcn.com (PPS) with ESMTP id 3qqk2ctfa8-4; Mon, 22 May 2023 22:46:29 +0000 From: "Martin K. Petersen" To: Azeem Shaikh Cc: "Martin K . Petersen" , linux-hardening@vger.kernel.org, linux-scsi@vger.kernel.org, target-devel@vger.kernel.org, linux-kernel@vger.kernel.org, Mike Christie , Maurizio Lombardi , Al Viro Subject: Re: [PATCH] scsi: target: Replace all non-returning strlcpy with strscpy Date: Mon, 22 May 2023 18:46:15 -0400 Message-Id: <168479035943.1118074.12123999918979660005.b4-ty@oracle.com> X-Mailer: git-send-email 2.40.1 In-Reply-To: <20230516025322.2804923-1-azeemshaikh38@gmail.com> References: <20230516025322.2804923-1-azeemshaikh38@gmail.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 8bit X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.254,Aquarius:18.0.957,Hydra:6.0.573,FMLib:17.11.176.26 definitions=2023-05-22_16,2023-05-22_03,2023-05-22_02 X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 mlxscore=0 mlxlogscore=823 phishscore=0 malwarescore=0 suspectscore=0 spamscore=0 bulkscore=0 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2304280000 definitions=main-2305220192 X-Proofpoint-ORIG-GUID: 6Tl58N1yCrEGXg4pLEorxWqtXdYS2NWt X-Proofpoint-GUID: 6Tl58N1yCrEGXg4pLEorxWqtXdYS2NWt Precedence: bulk List-ID: X-Mailing-List: linux-hardening@vger.kernel.org On Tue, 16 May 2023 02:53:22 +0000, Azeem Shaikh wrote: > strlcpy() reads the entire source buffer first. > This read may exceed the destination size limit. > This is both inefficient and can lead to linear read > overflows if a source string is not NUL-terminated [1]. > In an effort to remove strlcpy() completely [2], replace > strlcpy() here with strscpy(). > No return values were used, so direct replacement is safe. > > [...] Applied to 6.5/scsi-queue, thanks! [1/1] scsi: target: Replace all non-returning strlcpy with strscpy https://git.kernel.org/mkp/scsi/c/0871237a946e -- Martin K. Petersen Oracle Linux Engineering