Source-Changes-HG archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

[src/trunk]: src/sys/dev/scsipi Don't fetch data beyond end of inquiry buffer...



details:   https://anonhg.NetBSD.org/src/rev/8fafa2896cf0
branches:  trunk
changeset: 369697:8fafa2896cf0
user:      mlelstv <mlelstv%NetBSD.org@localhost>
date:      Sun Aug 28 10:26:37 2022 +0000

description:
Don't fetch data beyond end of inquiry buffer, which, here, is not
NUL-terminated.

Reduce target buffer to needed size (product name + NUL terminator).

diffstat:

 sys/dev/scsipi/sd.c    |  9 ++++-----
 sys/dev/scsipi/sdvar.h |  4 ++--
 2 files changed, 6 insertions(+), 7 deletions(-)

diffs (48 lines):

diff -r 66235c81ab0a -r 8fafa2896cf0 sys/dev/scsipi/sd.c
--- a/sys/dev/scsipi/sd.c       Sun Aug 28 10:20:25 2022 +0000
+++ b/sys/dev/scsipi/sd.c       Sun Aug 28 10:26:37 2022 +0000
@@ -1,4 +1,4 @@
-/*     $NetBSD: sd.c,v 1.334 2022/03/28 12:39:46 riastradh Exp $       */
+/*     $NetBSD: sd.c,v 1.335 2022/08/28 10:26:37 mlelstv Exp $ */
 
 /*-
  * Copyright (c) 1998, 2003, 2004 The NetBSD Foundation, Inc.
@@ -47,7 +47,7 @@
  */
 
 #include <sys/cdefs.h>
-__KERNEL_RCSID(0, "$NetBSD: sd.c,v 1.334 2022/03/28 12:39:46 riastradh Exp $");
+__KERNEL_RCSID(0, "$NetBSD: sd.c,v 1.335 2022/08/28 10:26:37 mlelstv Exp $");
 
 #ifdef _KERNEL_OPT
 #include "opt_scsi.h"
@@ -258,9 +258,8 @@
        SC_DEBUG(periph, SCSIPI_DB2, ("sdattach: "));
 
        sd->type = (sa->sa_inqbuf.type & SID_TYPE);
-       strncpy(sd->name, sa->sa_inqbuf.product, sizeof(sd->name));
-
-       strncpy(sd->typename, sa->sa_inqbuf.product, sizeof(sd->typename));
+       memcpy(sd->name, sa->sa_inqbuf.product, uimin(16, sizeof(sd->name)));
+       memcpy(sd->typename, sa->sa_inqbuf.product, uimin(16, sizeof(sd->typename)));
 
        if (sd->type == T_SIMPLE_DIRECT)
                periph->periph_quirks |= PQUIRK_ONLYBIG | PQUIRK_NOBIGMODESENSE;
diff -r 66235c81ab0a -r 8fafa2896cf0 sys/dev/scsipi/sdvar.h
--- a/sys/dev/scsipi/sdvar.h    Sun Aug 28 10:20:25 2022 +0000
+++ b/sys/dev/scsipi/sdvar.h    Sun Aug 28 10:26:37 2022 +0000
@@ -1,4 +1,4 @@
-/*     $NetBSD: sdvar.h,v 1.39 2019/03/19 06:59:40 mlelstv Exp $       */
+/*     $NetBSD: sdvar.h,v 1.40 2022/08/28 10:26:37 mlelstv Exp $       */
 
 /*-
  * Copyright (c) 1998, 2004 The NetBSD Foundation, Inc.
@@ -88,7 +88,7 @@
        callout_t sc_callout;
        u_int8_t type;
        char name[16]; /* product name, for default disklabel */
-       char typename[128+4+1]; /* stored in disk info */
+       char typename[16+1]; /* stored in disk info */
 };
 
 #define        SDGP_RESULT_OK          0       /* parameters obtained */



Home | Main Index | Thread Index | Old Index