mirror of
https://git.openafs.org/openafs.git
synced 2025-01-18 15:00:12 +00:00
00b31c7bae
The grammar.y file uses a series of strcat's to build the accesslist from the parsed tokens. There is no checking to see if the result exceeds the size of the output buffer. Replace the strcpy/strcat's with a simple snprintf that concatenates the tokens, and check to see if the snprintf failed. If there was an error concatenating the tokens, emit a message. NOTE: With --enable-checking a build error occurs on an Ubuntu 24.04 system, where the default _FORTIFY_SOURCE is set to 3 (hardened). The build produces the following: ... inlined from ‘yyparse’ at ./grammar.y:130:26: /usr/include/.../string_fortified.h:130:10: error: ‘__builtin___strcat_chk’ writing 2 bytes into a region of size 0 overflows the destination [-Werror=stringop-overflow=] 130 | return __builtin___strcat_chk (__dest, __src, __glibc_objsize (__dest)); ...(repeated for the other uses of strcat)... The build error can be duplicated by setting _FORTIFY_SOURCE to 3. Change-Id: I97e8a562f12d2a9f60a31d3b5a6f77a8458e7275 Reviewed-on: https://gerrit.openafs.org/15845 Tested-by: BuildBot <buildbot@rampaginggeek.com> Reviewed-by: Cheyenne Wills <cwills@sinenomine.net> Reviewed-by: Michael Meffie <mmeffie@sinenomine.net> Reviewed-by: Andrew Deason <adeason@sinenomine.net> |
||
---|---|---|
build-tools | ||
doc | ||
src | ||
tests | ||
.gitignore | ||
.gitreview | ||
.mailmap | ||
.splintrc | ||
acinclude.m4 | ||
CODING | ||
configure-libafs.ac | ||
configure.ac | ||
CONTRIBUTING | ||
INSTALL | ||
libafsdep | ||
LICENSE | ||
Makefile-libafs.in | ||
Makefile.in | ||
NEWS | ||
NTMakefile | ||
README | ||
README-WINDOWS | ||
regen.sh |
AFS is a distributed file system that enables users to share and access all of the files stored in a network of computers as easily as they access the files stored on their local machines. The file system is called distributed for this exact reason: files can reside on many different machines, but are available to users on every machine. OpenAFS 1.0 was originally released by IBM under the terms of the IBM Public License 1.0 (IPL10). For details on IPL10 see the LICENSE file in this directory. The current OpenAFS distribution is licensed under a combination of the IPL10 and many other licenses as granted by the relevant copyright holders. The LICENSE file in this directory contains more details, thought it is not a comprehensive statement. See INSTALL for information about building and installing OpenAFS on various platforms. See CODING for developer information and guidelines. See NEWS for recent changes to OpenAFS.