Thread (3 messages) 3 messages, 2 authors, 15d ago

Re: [PATCH 1/1] tools/rv: ensure monitor name and desc are NUL-terminated

From: Gabriele Monaco <gmonaco@redhat.com>
Date: 2026-06-04 11:08:15
Also in: lkml

On Thu, 2026-04-23 at 17:19 +0300, unknownbbqrx wrote:
ikm_fill_monitor_definition() copies monitor name and description
with strncpy(), but does not guarantee NUL termination when source
strings are equal to or longer than the destination buffers.

Clamp copies to sizeof(dst) - 1 and explicitly append '\0' for both
fields to keep them safe for later string operations.

Signed-off-by: unknownbbqrx <redacted>
Contributions need to be attributed to real people using official
names. I'm going to re-send this patch with me as author and a
Suggested-by: unknownbbqrx <redacted>, unless you answer
with an appropriate attribution (i.e. your real name) [1].

Thanks,
Gabriele

[1] -
https://docs.kernel.org/process/submitting-patches.html#sign-your-work-the-developer-s-certificate-of-origin
quoted hunk ↗ jump to hunk
---
 tools/verification/rv/src/in_kernel.c | 7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/tools/verification/rv/src/in_kernel.c
b/tools/verification/rv/src/in_kernel.c
index 4bb746ea6..d32453824 100644
--- a/tools/verification/rv/src/in_kernel.c
+++ b/tools/verification/rv/src/in_kernel.c
@@ -215,10 +215,11 @@ static int ikm_fill_monitor_definition(char
*name, struct monitor *ikm, char *co
 		return -1;
 	}
 
-	strncpy(ikm->name, nested_name, MAX_DA_NAME_LEN);
+	strncpy(ikm->name, nested_name, sizeof(ikm->name) - 1);
+	ikm->name[sizeof(ikm->name) - 1] = '\0';
 	ikm->enabled = enabled;
-	strncpy(ikm->desc, desc, MAX_DESCRIPTION);
-
+	strncpy(ikm->desc, desc, sizeof(ikm->desc) - 1);
+	ikm->desc[sizeof(ikm->desc) - 1] = '\0';
 	free(desc);
 
 	return 0;
  
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help