Re: [PATCH v1] char: ipmi: Replace deprecated strcpy with strscpy

From: Corey Minyard

Date: Thu Oct 01 2026 - 18:16:39 EST


On Thu, Oct 01, 2026 at 10:52:09PM +0530, Ashutosh Yadav wrote:
> strcpy() has been deprecated because it is generally unsafe and can lead
> to buffer overflows. It is actively being removed from the kernel.
>
> In action_op() and preop_op() (and related functions), strings are copied
> into fixed-size buffers. Replace the strcpy() calls with strscpy() using
> the sizeof() the destination buffers to guarantee NUL-termination and
> prevent any potential bounds issues, ensuring compliance with safe string
> APIs.

Applied, thank you.

-corey

>
> Link: https://github.com/KSPP/linux/issues/88
> Signed-off-by: Ashutosh Yadav <yadavxashutosh@xxxxxxxxx>
> ---
> drivers/char/ipmi/ipmi_watchdog.c | 12 ++++++------
> 1 file changed, 6 insertions(+), 6 deletions(-)
>
> diff --git a/drivers/char/ipmi/ipmi_watchdog.c b/drivers/char/ipmi/ipmi_watchdog.c
> index a013ddbf1466..79d4958df6ef 100644
> --- a/drivers/char/ipmi/ipmi_watchdog.c
> +++ b/drivers/char/ipmi/ipmi_watchdog.c
> @@ -1166,13 +1166,13 @@ static int action_op(const char *inval, char *outval)
> int rv;
>
> if (outval)
> - strcpy(outval, action);
> + strscpy(outval, action, sizeof(action));
>
> if (!inval)
> return 0;
> rv = action_op_set_val(inval);
> if (!rv)
> - strcpy(action, inval);
> + strscpy(action, inval, sizeof(action));
> return rv;
> }
>
> @@ -1198,13 +1198,13 @@ static int preaction_op(const char *inval, char *outval)
> int rv;
>
> if (outval)
> - strcpy(outval, preaction);
> + strscpy(outval, preaction, sizeof(preaction));
>
> if (!inval)
> return 0;
> rv = preaction_op_set_val(inval);
> if (!rv)
> - strcpy(preaction, inval);
> + strscpy(preaction, inval, sizeof(preaction));
> return 0;
> }
>
> @@ -1226,14 +1226,14 @@ static int preop_op(const char *inval, char *outval)
> int rv;
>
> if (outval)
> - strcpy(outval, preop);
> + strscpy(outval, preop, sizeof(preop));
>
> if (!inval)
> return 0;
>
> rv = preop_op_set_val(inval);
> if (!rv)
> - strcpy(preop, inval);
> + strscpy(preop, inval, sizeof(preop));
> return 0;
> }
>
> --
> 2.43.0
>