From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wr1-f53.google.com (mail-wr1-f53.google.com [209.85.221.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 313083DB983 for ; Wed, 10 Jun 2026 09:43:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.53 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781084587; cv=none; b=fdO3uYV/GexbRdgZUaJrewZOtJd8YgqsoEVmOCG4SK1EOsXuqwOyVUR+gLgOp3UIQ7DfyRaSJgHX/mYPjvFRbxTaOeibvuLvnNjMWEqsRvGQE+eGLpAcraOx8Egd/z7wZpurSJWssfXRJFXFPwvlILxOtuoaaRemINbhMUZjnzs= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781084587; c=relaxed/simple; bh=2HrDNfAOvmiR19AIBup6MLWdgo7QIYe9zJcMquwk3pk=; h=Date:From:To:Cc:Subject:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=Ya36adczUiTiZ/MGBfHp13TnEuuh1UlpeaVM0WTNUJAi8R2HaG2DMimg/iWhF9zVIpVOyYOu7FlR6uPS0vlcLQXtmpkBPwkgTF/UapYuTccu633DAfOtqTh2BbrjkhEy5q1MxP3BJhviSUHLmTz7DVRXrws8wvGvRxUXHCws0Rc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ShUzBD+h; arc=none smtp.client-ip=209.85.221.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ShUzBD+h" Received: by mail-wr1-f53.google.com with SMTP id ffacd0b85a97d-45ef779c1c2so4498101f8f.1 for ; Wed, 10 Jun 2026 02:43:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1781084583; x=1781689383; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:subject:cc:to:from:date:from:to:cc:subject:date :message-id:reply-to; bh=Y2H2mzLmWGlqdMBX/pfyNle3HEyYtt+2gCJrjQNSOOk=; b=ShUzBD+hWLNJEaLhf3d+SbRgkV6Ov/ywQWqXtU0mruFGwjbMZFovhoU7MNBZDk2ux6 8BQuEK+4J+ED6ZXW/tT0VW3FCA6j5rWbo+3DuTfY3u5+kJwN8wt6gzyFVxt9oF176IwK pNv/Fd4aDP/E/ITY+Tf0wLY1XDv8QeBQmi1EnmqFNwXt/lTAtj50smI09lEkgQur8Shw duRizspZ7dDqcRJ+QZRiV1TYPhlJBMqkczbv0xZvkj14+Ik0KN9OGDbvjBD+0lGsHHPo hTy9IbOKU6oCt1BZhUiH9UgytkD6qYsdvkzDWYHx9HvFpsWYHZ5kU3XhT3NRg4+pCkzv CRzg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781084583; x=1781689383; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:subject:cc:to:from:date:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=Y2H2mzLmWGlqdMBX/pfyNle3HEyYtt+2gCJrjQNSOOk=; b=EnEQgw+wlY5GyyAgRZw3+NMBc+l8arH12d3SYAZjpWgBVMZUUBCiyerpGaNyIE9qWN 9iJTApEBpQ1sZ7TS2TXcLd7Sc3YDL5yS79CbCfkj7b108gM0h6pov7zZYk+JXQYuTnuq Yuzu5zTz/adGjwF7aq/vEztsrwELVXpsTqXNiQMnl6pRCmqjUDFt/zL33OJAHUOqryhJ cPLRN8K4qjQKY2CvfVJRST6qorB8LEkPHxuPhIn1a4YcKEMcnV8+ckeCGG/juZGs3rkm 66Mm1EK1geGqNLhId1ybnQFElFI9XAZ1pyLqX6exd8DVVV1Uf+MGkPeOZOrA20fhVtPe FVLg== X-Forwarded-Encrypted: i=1; AFNElJ8X7gKIY3rAoxd/AiP4Hhb7/098FSqv2mZz5/FNlG6TwaaBjBaZcJa+rdmzsz2lFMGKlyq3iFDPHIWT6+g=@vger.kernel.org X-Gm-Message-State: AOJu0YxSEpdKvDWeyZ1qwVFzu3S+0oKKe/uvGdTyMtM6QBhNlpRhA7Wr JxAXhZyabfKw0MIgou23d5O/osER4Ld3wbMV2URWCFT0Hoix1EFrnzms X-Gm-Gg: Acq92OFjReJqOs7/aGClKJ0D6lp/pgChQtYOFn87AttWy+1hGFoI+PiOyG7W+O0u6cL pWyQD9hvrnVAhT2GQ1Sd1bAKTKY6I5wshsrthvyl2MEfBQEKPBilNey8p+e98n/mtF8MatC+6Ff n6G+pwtywf3rAkUhUDWfY+542BIQSePdvJrwfmJEpZ1vUKutFrAHKrJhM+ujOWisSOTSCaSA+0T fOmfA/zRdWatRWUj/BDaid3pYqU0SMraJi1w5Nausko/FttuAVO4b4E0WJUt12a+i6+JB/P2jVZ gOXH/asCqZ8cA9EvANz5RUD7lszc75rALMJd0iqceQHmYu2fAEsdQPr/Y278ylClxTNb7qPXSCW 3VBluC6R+1zY+lU1AtVGXp1+zBmYveb2Av326ou2VFmb2NGeuqCJJH3pzI8qPhkIDrrWjSZIhFD 2T+7wnEIhlCzlQJLsfDGK0Whqp0ZsETbEhtQMUkONHHyutY+5tR53I5PxV8Im2IU19dwG5+vs= X-Received: by 2002:a05:6000:46d6:b0:45e:ea46:ce13 with SMTP id ffacd0b85a97d-460304f9d74mr25172549f8f.10.1781084583400; Wed, 10 Jun 2026 02:43:03 -0700 (PDT) Received: from pumpkin (82-69-66-36.dsl.in-addr.zen.co.uk. [82.69.66.36]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4601f2dcae2sm75285407f8f.6.2026.06.10.02.43.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 10 Jun 2026 02:43:03 -0700 (PDT) Date: Wed, 10 Jun 2026 10:43:01 +0100 From: David Laight To: Jakub Kicinski Cc: Kees Cook , linux-hardening@vger.kernel.org, Arnd Bergmann , linux-kernel@vger.kernel.org, netdev@vger.kernel.org, Andrew Lunn , "David S. Miller" , Eric Dumazet , Jay Vosburgh , Paolo Abeni Subject: Re: [PATCH net-next] drivers/net/bonding: User strscpy() to copy device name Message-ID: <20260610104301.7b7cae7e@pumpkin> In-Reply-To: <20260609175841.3ce88cf0@kernel.org> References: <20260606202633.5018-14-david.laight.linux@gmail.com> <20260609175841.3ce88cf0@kernel.org> X-Mailer: Claws Mail 4.1.1 (GTK 3.24.38; arm-unknown-linux-gnueabihf) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit On Tue, 9 Jun 2026 17:58:41 -0700 Jakub Kicinski wrote: > On Sat, 6 Jun 2026 21:26:08 +0100 david.laight.linux@gmail.com wrote: > > From: David Laight > > Commit message is required. Please explain why you think this patch is > needed. AFAICT it copies data between two well formed IFNAMSIZ strings. Thinks... I let strcpy(xx->array, "constant") through provided the array is big enough. This gets converted to memcpy(). I could also check the array sizes for strcpy(xx->array, yy->array) and allow provided the destination isn't shorter. That would remove some of the 'annoying false positives'. Unlike strscpy() this could be converted to a memcpy() (with or without explicitly writing the terminating '\0') for short (say <= 32 byte) lengths. So this patch (and a few like it) can be dropped. Some one else may want to remove strcpy() completely, but I was only trying to remove the ones that a simple compile-time test couldn't show were safe. -- David > > > Signed-off-by: David Laight > > --- > > This is one of a group of patches that remove potentially unbounded > > strcpy() calls. > > > > They are mostly replaced by strscpy() or, when strlen() has just been > > called, with memcpy() (usually including the '\0'). > > > > Calls with copy string literals into arrays are left unchanged. > > They are safe and easily detected as such. > > > > The changes were made by getting the compiler to detect the calls and > > then fixing the code by hand. > > > > Note that all the changes are only compile tested. > > > > Some Makefiles were changed to allow files to contain strcpy(). > > As well as 'difficult to fix' files, this included 'show' functions > > as they really need to use sysfs_emit() or seq_printf(). > > > > All the patches are being sent individually to avoid very long cc lists. > > Apologies for the terse commit messages and likely unexpected tags. > > (There are about 100 patches in total.) > > > > drivers/net/bonding/bond_options.c | 2 +- > > 1 file changed, 1 insertion(+), 1 deletion(-) > > > > diff --git a/drivers/net/bonding/bond_options.c b/drivers/net/bonding/bond_options.c > > index 7380cc4ee75a..c57b7d6af043 100644 > > --- a/drivers/net/bonding/bond_options.c > > +++ b/drivers/net/bonding/bond_options.c > > @@ -1525,7 +1525,7 @@ static int bond_option_primary_set(struct bonding *bond, > > if (strncmp(slave->dev->name, primary, IFNAMSIZ) == 0) { > > slave_dbg(bond->dev, slave->dev, "Setting as primary slave\n"); > > rcu_assign_pointer(bond->primary_slave, slave); > > - strcpy(bond->params.primary, slave->dev->name); > > + strscpy(bond->params.primary, slave->dev->name); > > bond->force_primary = true; > > bond_select_active_slave(bond); > > goto out;