From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f173.google.com (mail-pl1-f173.google.com [209.85.214.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id ED4CB3C4540 for ; Fri, 7 Aug 2026 11:42:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.173 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786102951; cv=none; b=eCpAZzIcyEz+xGrMJuGSdPzCx4zviHBgHX64pisuZYIw+ZPCQMMAIR+Frec4C2L1i9zIIF3opVEfMrMy9u7UIzbiMcoo1YU3YAb109jzC2am7NKnCi/xDoWzOJGgt07hAluQ+wmAonqVDTqjSX6UaZbHIoNwN/UNhYdAHbNV1mY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786102951; c=relaxed/simple; bh=CtXcqp2VDcddZCiaeG5iiX9IGilWKe8EeVBviDDfLUQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=sObZ6EKMZliXcmRngLUCzAUMji+Ft+pbMJNg1sKGZKNPLkr/Wg7Mrjm/yZMHQBf7PWcIlPZ5BGbF3QJPwmqHC5Prik8604ILwAx8B6BgBrKoU2d1ewJFlUu16/Co2yK8ys6+ATgrIvzrfgLrW9r5f9Q4yeAfjREq9/MWnsA1BT8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=rtLduqUq; arc=none smtp.client-ip=209.85.214.173 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="rtLduqUq" Received: by mail-pl1-f173.google.com with SMTP id d9443c01a7336-2cc73e322dbso36744355ad.1 for ; Fri, 07 Aug 2026 04:42:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786102941; x=1786707741; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=O2EtTMxFhhlsCKiXUEwoma4Bxj+FDVYnX2c+BIxaQO0=; b=rtLduqUqrqJyaYgdBCR4Bwxo7SEEhUn5JGd+GSUvjhBo7FCfrWB/kaPlriZBGNcG32 FGTTt6T1gRUbvJLOIwBhxoCK8DkmXvFrCRyjMTqa66XoIMi2F6KtAb6lvpXF97sGaoWw sMlDXjXNFBAyuyIfYTUX4b3dTSZVC0/JS8iuwOg+iP01CSm7U4zx5aQWaOhlQtNuDQsU ikhk41EHhhnirdyBa/JD2Smn4kxCOhvlDxH8A6OUY28QtEumqg2rUGN5SNiz3QI1KRge lnzf5USI/5hdHahr9Jc7/U++s4Nun9aj9LpZn5PtfbZrLMPQN70k/Dw3GPQ6Xko35IlZ VP7A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786102941; x=1786707741; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=O2EtTMxFhhlsCKiXUEwoma4Bxj+FDVYnX2c+BIxaQO0=; b=OUvAvBCbHVh39rBCt1XHeI7tZauT8dfQXuHv49SdIlL/7x+SpDsaHf/2lOFjdm/eYa AmH4SJlaU/Al525VzTur531NunrEuMiMCjh0INJRc+SzmFlCcgruvdnCGLUOP8CJe/4Z fWBNetz7HRTgUfYDNFbkhtGIQB9oaDt+TxWPXGowP3tFVCrrsK+gEGYojm8jTD51g+Jw +U2g1HOuA/0pVG8fgAdMMJb4AEsfnhjOnw9SYc0isMUyTk+9YiJu/516zFeT+viOTJnI tgmeAXzcHAXcQMS16nyrHdAKBbew/nVxvxMAf3C+LILm7CuJ0bpH4DKpnOhKJ/rfBRp7 s3ng== X-Forwarded-Encrypted: i=1; AHgh+RonI0J4dRMjXjBHn2xb0aZ7uT/a0Dg/cWSEqqAykf50K7XUoNTP1j8dlWNPEJ0nPyUgvqHsYDWnifgxOMA=@vger.kernel.org X-Gm-Message-State: AOJu0YwbROwX5n0ysfaFwt0PgB5kRJcCnkudu/n6jTsCMdrwhNjueBAf tQVfMX0CLF25LjiHUNoBHQcv6h75zYYoic5ev4IiB1BHT4ykKVBawz+mP9DmdMhS X-Gm-Gg: AR+sD126tBgyriT1JEp6779aTFv3MAbifL0wAr1xBJgbh4WeZmF6gTXI3J8jGSd36j4 /5MHe0Ib2EfF35bpEn2b1u0zoAJTZGK5oiOdppo3XYNrkcrVKEPTveZArn+8GLURbCNLmIjMYBQ DELPMpkZjjzbaskOlSgZuuEvQOksgNGs/39rxVbDYRtP3z3at2rfyuD4W3B4XpNC/w18xyCd/+n Y+eIdEWbAVRQJ1tCn7iFH6kgnTUvMhUXJqRHF6hy048WPU3LeIRhDx7gtcXD0LhwaptECDE6lEU L4dqgOfhiTGotqCky31EupXTnry/rMXWvb1gOcaebeFB58Fh7A/QrREQHToQC03Kb8jNJGBaLd7 ITdgCqZmJlziK00s31RGL+kryPZTttNO9RhWh+ZplS7eHrhljUXcJom91U/lGDwxewTicIBXFHq rmvYq9tUqG6mYGz77QsTwEJEZAcLBZRXwK2gOKg4pTvNAba7lDGOZD+vZVUoJMox7JTrX4YgXZO 8deOdoOY3U= X-Received: by 2002:a05:6a21:685:b0:3b3:1b38:d9c3 with SMTP id adf61e73a8af0-3cb85e99243mr26526592637.4.1786102940555; Fri, 07 Aug 2026 04:42:20 -0700 (PDT) Received: from localhost.localdomain ([72.255.58.127]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-315be86d3fcsm6930508eec.4.2026.08.07.04.42.14 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 07 Aug 2026 04:42:20 -0700 (PDT) From: Mahad Ibrahim To: Takashi Iwai , Jaroslav Kysela Cc: Kees Cook , Andy Shevchenko , linux-sound@vger.kernel.org, linux-kernel@vger.kernel.org, Mahad Ibrahim Subject: [PATCH 4/7] ALSA: caiaq: replace strlcat() with strscpy() Date: Fri, 7 Aug 2026 11:41:36 +0000 Message-ID: <20260807114139.1661-5-mahad.ibrahim.dev@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260807114139.1661-1-mahad.ibrahim.dev@gmail.com> References: <20260807114139.1661-1-mahad.ibrahim.dev@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit usb_make_path() fills cdev->phys with the device path, and "/input0" was then appended with strlcat(). Take the length of the path with strlen() and write the suffix at that offset with strscpy(), passing the remaining space in the buffer. cdev->phys is NUL-terminated by usb_make_path(), so the offset is within the array and the size passed to strscpy() is at least one. The suffix lands in the same place and truncates at the same point. Signed-off-by: Mahad Ibrahim --- sound/usb/caiaq/input.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/sound/usb/caiaq/input.c b/sound/usb/caiaq/input.c index 8d924330c54c..fd4c80c7530c 100644 --- a/sound/usb/caiaq/input.c +++ b/sound/usb/caiaq/input.c @@ -604,14 +604,15 @@ int snd_usb_caiaq_input_init(struct snd_usb_caiaqdev *cdev) { struct usb_device *usb_dev = cdev->chip.dev; struct input_dev *input; - int i, ret = 0; + int i, len, ret = 0; input = input_allocate_device(); if (!input) return -ENOMEM; usb_make_path(usb_dev, cdev->phys, sizeof(cdev->phys)); - strlcat(cdev->phys, "/input0", sizeof(cdev->phys)); + len = strlen(cdev->phys); + strscpy(cdev->phys + len, "/input0", sizeof(cdev->phys) - len); input->name = cdev->product_name; input->phys = cdev->phys; -- 2.54.0