Possible bug in fortified stpncpy

Mike Frysinger vapier@gentoo.org
Sun Aug 9 03:32:00 GMT 2015


On 08 Aug 2015 17:06, Zack Weinberg wrote:
> GCC doesn't have a fortification builtin for stpncpy, so bits/string3.h has
> 
> __fortify_function char *
> __NTH (stpncpy (char *__dest, const char *__src, size_t __n))
> {
>   if (__bos (__dest) != (size_t) -1
>       && (!__builtin_constant_p (__n) || __n <= __bos (__dest)))
>     return __stpncpy_chk (__dest, __src, __n, __bos (__dest));
>   return __stpncpy_alias (__dest, __src, __n);
> }
> 
> I think the last clause of the conditional,
> 
>     || __n <= __bos (__dest)
> 
> may be backward.  The code should call the runtime-checking function
> if __n is not constant, or if __n is known to be LARGER than the size
> of the destination.  Ne?

agreed.  feel like sending a patch ? :)
-mike
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: Digital signature
URL: <http://sourceware.org/pipermail/libc-alpha/attachments/20150809/35eb2b61/attachment.sig>


More information about the Libc-alpha mailing list