Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1284642

Re: snprintf, overlapping destination and source

Path csiph.com!au2pb.net!feeder.erje.net!2.us.feeder.erje.net!newsfeed.fsmpi.rwth-aachen.de!newsfeed.straub-nv.de!eternal-september.org!feeder.eternal-september.org!aioe.org!bofh.it!news.nic.it!robomod
From Julia Lawall <julia.lawall@lip6.fr>
Newsgroups linux.kernel
Subject Re: snprintf, overlapping destination and source
Date Sat, 05 Dec 2015 21:50:02 +0100
Message-ID <qCrWi-5PL-3@gated-at.bofh.it> (permalink)
References <qCrMB-5MG-1@gated-at.bofh.it>
X-Original-To Rasmus Villemoes <linux@rasmusvillemoes.dk>
X-Ironport-Av E=Sophos;i="5.20,386,1444687200"; d="scan'208";a="190586974"
X-X-Sender jll@hadrien
User-Agent Alpine 2.10 (DEB 1266 2009-07-14)
MIME-Version 1.0
Content-Type TEXT/PLAIN; charset=US-ASCII
Sender robomod@news.nic.it
List-ID <linux-kernel.vger.kernel.org>
X-Mailing-List linux-kernel@vger.kernel.org
Approved robomod@news.nic.it
Lines 47
Organization linux.* mail to news gateway
X-Original-Cc linux-kernel@vger.kernel.org, Kees Cook <keescook@chromium.org>, Andrew Morton <akpm@linux-foundation.org>
X-Original-Date Sat, 5 Dec 2015 21:42:40 +0100 (CET)
X-Original-Message-ID <alpine.DEB.2.10.1512052141520.2597@hadrien>
X-Original-References <87d1ukr5pf.fsf@rasmusvillemoes.dk>
X-Original-Sender linux-kernel-owner@vger.kernel.org
Xref csiph.com linux.kernel:1284642

Show key headers only | View raw



On Sat, 5 Dec 2015, Rasmus Villemoes wrote:

> I did a search for code doing
>
>   s[n]printf(buf, "...", ..., buf, ...)
>
> and found a few instances. They all do it with the format string
> beginning with "%s" and buf being passed as the corresponding parameter
> (obviously to append to the existing string). That works (AFAICT), both
> with the current printf implementation and with the string()
> modification which is now in -mm. It would obviously go horribly wrong
> if anything, even non-specifiers, precede the "%s" in the format
> string.
>
> The question is, do we want to officially support this particular case of
> overlapping src and dst? Or should we close our eyes and hope it will
> continue to work [1] and that it won't cause a caffeine-deprived hacker
> to accidentally think one could also prepend to a buffer by doing
> sprintf(buf, "...%s", ..., buf)? I'm actually surprised gcc doesn't warn
> about this.
>
> [1] Not that I can immediately think of a sane way to implement snprintf
> where it won't work, but you never know...
>
> My coccinelle-fu isn't sufficient to find cases where one of the buf
> instances is a more complicated expressions involving buf as a
> subexpression, as in
>
>   s[n]printf(buf, "...", ..., buf + 4, ...)
>
> or
>
>   s[n]printf(&buf[len], "...", ..., buf, ...)
>
> which would presumably always be wrong. Julia?

If you just want an argument expression that contains buf somewhere, you
can write <+...buf...+>.

julia
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

snprintf, overlapping destination and source Rasmus Villemoes <linux@rasmusvillemoes.dk> - 2015-12-05 21:40 +0100
  Re: snprintf, overlapping destination and source Julia Lawall <julia.lawall@lip6.fr> - 2015-12-05 21:50 +0100
  Re: snprintf, overlapping destination and source Kees Cook <keescook@chromium.org> - 2015-12-07 23:10 +0100

csiph-web