mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Roland Dreier <roland@digitalvampire.org>
To: torvalds@transmeta.com, marcelo@conectiva.com.br,
	alan@lxorguk.ukuu.org.uk, linux-kernel@vger.kernel.org
Subject: [PATCH] fix two bugs in lib/vsprintf.c
Date: 15 Jan 2002 01:25:38 -0800	[thread overview]
Message-ID: <87advgrmnh.fsf@love-shack.home.digitalvampire.org> (raw)

The below patch fixes two bugs in lib/vsprintf.c's implementation of
vsscanf().  First, the man page for vsscanf() says about the 'i'
conversion:

       i      Matches an  optionally  signed  integer;  the  next
              pointer  must  be a pointer to int.  The integer is
              read in base 16 if it begins with `0x' or `0X',  in
              base  8  if  it  begins  with  `0',  and in base 10
              otherwise.  Only characters that correspond to  the
              base are used.

To me this means that vsscanf() should pass base 0 to simple_strtol;
however the Linux implementation defaults to base 10.  The first part
of the patch corrects this.

Second, vsscanf() checks the first character of the number it's about
to read using isdigit(); this is incorrect for hex or octal
conversions.  The second part of this patch corrects vsscanf() to use
the correct check depending on the value of base.

lib/vsprintf.c has not changed in quite a while, so this patch should
apply cleanly to 2.4.17, 2.4.18pre3 and 2.5.2.

Thanks,
  Roland

diff -Naur linux-2.4.17.orig/lib/vsprintf.c linux-2.4.17/lib/vsprintf.c
--- linux-2.4.17.orig/lib/vsprintf.c	Thu Oct 11 11:17:22 2001
+++ linux-2.4.17/lib/vsprintf.c	Tue Jan 15 01:06:29 2002
@@ -616,8 +616,9 @@
 		case 'X':
 			base = 16;
 			break;
-		case 'd':
 		case 'i':
+                        base = 0;
+		case 'd':
 			is_sign = 1;
 		case 'u':
 			break;
@@ -637,7 +638,11 @@
 		while (isspace(*str))
 			str++;
 
-		if (!*str || !isdigit(*str))
+		if (!*str
+                    || (base == 16 && !isxdigit(*str))
+                    || (base == 10 && !isdigit(*str))
+                    || (base == 8 && (!isdigit(*str) || *str > '7'))
+                    || (base == 0 && !isdigit(*str)))
 			break;
 
 		switch(qualifier) {

-- 
Roland Dreier                                <roland@digitalvampire.org>
GPG Key fingerprint = A89F B5E9 C185 F34D BD50  4009 37E2 25CC E0EE FAC0

             reply	other threads:[~2002-01-15  9:26 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2002-01-15  9:25 Roland Dreier [this message]
2002-01-16  0:20 ` Michal Jaegermann
2002-01-16  0:54   ` Roland Dreier

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87advgrmnh.fsf@love-shack.home.digitalvampire.org \
    --to=roland@digitalvampire.org \
    --cc=alan@lxorguk.ukuu.org.uk \
    --cc=linux-kernel@vger.kernel.org \
    --cc=marcelo@conectiva.com.br \
    --cc=torvalds@transmeta.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®