Re: [PATCH] tracing/uprobe: Replace strlcpy() with strscpy()

From: Kees Cook
Date: Fri Dec 01 2023 - 13:26:01 EST


On Thu, 30 Nov 2023 12:56:08 -0800, Kees Cook wrote:
> strlcpy() reads the entire source buffer first. This read may exceed
> the destination size limit. This is both inefficient and can lead
> to linear read overflows if a source string is not NUL-terminated[1].
> Additionally, it returns the size of the source string, not the
> resulting size of the destination string. In an effort to remove strlcpy()
> completely[2], replace strlcpy() here with strscpy().
>
> [...]

Applied to for-next/hardening, thanks!

[1/1] tracing/uprobe: Replace strlcpy() with strscpy()
https://git.kernel.org/kees/c/8a3750ecf810

Take care,

--
Kees Cook