WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-devel

Re: [Xen-devel] [PATCH] Use string bounded functions

To: Christoph Egger <Christoph.Egger@xxxxxxx>, <xen-devel@xxxxxxxxxxxxxxxxxxx>
Subject: Re: [Xen-devel] [PATCH] Use string bounded functions
From: Keir Fraser <keir@xxxxxxxxxxxxx>
Date: Mon, 29 Jan 2007 10:52:42 +0000
Delivery-date: Mon, 29 Jan 2007 02:52:24 -0800
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
In-reply-to: <200701291110.29420.Christoph.Egger@xxxxxxx>
List-help: <mailto:xen-devel-request@lists.xensource.com?subject=help>
List-id: Xen developer discussion <xen-devel.lists.xensource.com>
List-post: <mailto:xen-devel@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=unsubscribe>
Sender: xen-devel-bounces@xxxxxxxxxxxxxxxxxxx
Thread-index: AcdDk5mf2Gtjm6+GEduROAAX8io7RQ==
Thread-topic: [Xen-devel] [PATCH] Use string bounded functions
User-agent: Microsoft-Entourage/11.2.5.060620
On 29/1/07 10:10, "Christoph Egger" <Christoph.Egger@xxxxxxx> wrote:

> The attached patch replaces sprintf with snprintf and strncpy with strlcpy.
> 
> There are various cases where no NULL-terminated strings are guaranteed
> and eventual possible overflows. This patch fixes them.
> 
> BTW: Since Xen kernel has its own string functions, can't we just remove
> sprintf() and strncpy()? IMO, Xen should not inherit the historical C relicts.

This makes plenty of sense. Strncpy() in particular is dangerous and
strlcpy() is always preferable. So I'd be happy to see strncat/strncpy die.

There are a few uses remaining (particularly in arch/ia64) that you'll have
to fix first.

And please add 'signed-off-by' attribution when you post patches!

 -- Keir


_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-devel