brcmf_fw_alloc_request() constructs firmware file paths by chaining
strscpy() and multiple strlcat() calls for the module parameter path,
separator, base name, and extension.

In preparation for removing the deprecated strlcat() API[1], format the
complete firmware path in a single snprintf() call.

Link: https://github.com/KSPP/linux/issues/370 [1]
Cc: [email protected]
Assisted-by: SecurityEngineer:GPT-4o [editor_update_file, 
make_kernel_build_single_file, shell_command_run]
Signed-off-by: Bill Wendling <[email protected]>
---
Cc: Russell King <[email protected]>
Cc: Huacai Chen <[email protected]>
Cc: WANG Xuerui <[email protected]>
Cc: Thomas Bogendoerfer <[email protected]>
Cc: "James E.J. Bottomley" <[email protected]>
Cc: Helge Deller <[email protected]>
Cc: Thomas Gleixner <[email protected]>
Cc: Ingo Molnar <[email protected]>
Cc: Borislav Petkov <[email protected]>
Cc: Dave Hansen <[email protected]>
Cc: [email protected]
Cc: "H. Peter Anvin" <[email protected]>
Cc: Ian Abbott <[email protected]>
Cc: H Hartley Sweeten <[email protected]>
Cc: Tony Luck <[email protected]>
Cc: Maarten Lankhorst <[email protected]>
Cc: Maxime Ripard <[email protected]>
Cc: Thomas Zimmermann <[email protected]>
Cc: David Airlie <[email protected]>
Cc: Simona Vetter <[email protected]>
Cc: Matthew Brost <[email protected]>
Cc: "Thomas Hellström" <[email protected]>
Cc: Rodrigo Vivi <[email protected]>
Cc: Dmitry Torokhov <[email protected]>
Cc: Matthias Schwarzott <[email protected]>
Cc: Mauro Carvalho Chehab <[email protected]>
Cc: Tony Nguyen <[email protected]>
Cc: Przemek Kitszel <[email protected]>
Cc: Andrew Lunn <[email protected]>
Cc: "David S. Miller" <[email protected]>
Cc: Eric Dumazet <[email protected]>
Cc: Jakub Kicinski <[email protected]>
Cc: Paolo Abeni <[email protected]>
Cc: Arend van Spriel <[email protected]>
Cc: Rob Herring <[email protected]>
Cc: Saravana Kannan <[email protected]>
Cc: Krzysztof Kozlowski <[email protected]>
Cc: Sylwester Nawrocki <[email protected]>
Cc: Peter Griffin <[email protected]>
Cc: Alim Akhtar <[email protected]>
Cc: Linus Walleij <[email protected]>
Cc: Anil Gurumurthy <[email protected]>
Cc: Sudarsana Kalluru <[email protected]>
Cc: "Martin K. Petersen" <[email protected]>
Cc: Trond Myklebust <[email protected]>
Cc: Anna Schumaker <[email protected]>
Cc: Mike Marshall <[email protected]>
Cc: Martin Brandenburg <[email protected]>
Cc: Kees Cook <[email protected]>
Cc: Jiri Pirko <[email protected]>
Cc: Simon Horman <[email protected]>
Cc: Chuck Lever <[email protected]>
Cc: Jeff Layton <[email protected]>
Cc: NeilBrown <[email protected]>
Cc: Olga Kornievskaia <[email protected]>
Cc: Dai Ngo <[email protected]>
Cc: Tom Talpey <[email protected]>
Cc: Jaroslav Kysela <[email protected]>
Cc: Takashi Iwai <[email protected]>
Cc: Bill Wendling <[email protected]>
Cc: Andrew Morton <[email protected]>
Cc: "Mike Rapoport (Microsoft)" <[email protected]>
Cc: Kanglong Wang <[email protected]>
Cc: Tiezhu Yang <[email protected]>
Cc: Qiang Ma <[email protected]>
Cc: Randy Dunlap <[email protected]>
Cc: Pengpeng Hou <[email protected]>
Cc: Ard Biesheuvel <[email protected]>
Cc: Breno Leitao <[email protected]>
Cc: Thorsten Blum <[email protected]>
Cc: Harshit Mogalapalli <[email protected]>
Cc: Greg Kroah-Hartman <[email protected]>
Cc: Lyude Paul <[email protected]>
Cc: Ashutosh Desai <[email protected]>
Cc: Imre Deak <[email protected]>
Cc: Dmitry Baryshkov <[email protected]>
Cc: Johan Hovold <[email protected]>
Cc: Johannes Berg <[email protected]>
Cc: Miri Korenblit <[email protected]>
Cc: Alexander Stein <[email protected]>
Cc: Cryolitia PukNgae <[email protected]>
Cc: Jiaming Zhang <[email protected]>
Cc: Will Porter <[email protected]>
Cc: Cen Zhang <[email protected]>
Cc: "Cássio Gabriel" <[email protected]>
Cc: Rong Zhang <[email protected]>
Cc: Arun Raghavan <[email protected]>
Cc: [email protected]
Cc: [email protected]
Cc: [email protected]
Cc: [email protected]
Cc: [email protected]
Cc: [email protected]
Cc: [email protected]
Cc: [email protected]
Cc: [email protected]
Cc: [email protected]
Cc: [email protected]
Cc: [email protected]
Cc: [email protected]
Cc: [email protected]
Cc: [email protected]
Cc: [email protected]
Cc: [email protected]
Cc: [email protected]
Cc: [email protected]
Cc: [email protected]
Cc: [email protected]
Cc: [email protected]
Cc: [email protected]
---
 .../broadcom/brcm80211/brcmfmac/firmware.c    | 21 +++++++------------
 1 file changed, 8 insertions(+), 13 deletions(-)

diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/firmware.c 
b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/firmware.c
index 22ff326f1924..2f74a952599e 100644
--- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/firmware.c
+++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/firmware.c
@@ -845,22 +845,17 @@ brcmf_fw_alloc_request(u32 chip, u32 chiprev,
        fwreq->n_items = n_fwnames;
 
        for (j = 0; j < n_fwnames; j++) {
-               fwreq->items[j].path = fwnames[j].path;
-               fwnames[j].path[0] = '\0';
                /* check if firmware path is provided by module parameter */
                if (brcmf_mp_global.firmware_path[0] != '\0') {
-                       strscpy(fwnames[j].path, mp_path,
-                               BRCMF_FW_NAME_LEN);
-
-                       if (end != '/') {
-                               strlcat(fwnames[j].path, "/",
-                                       BRCMF_FW_NAME_LEN);
-                       }
+                       snprintf(fwnames[j].path, BRCMF_FW_NAME_LEN, "%s%s%s%s",
+                                mp_path, (end == '/') ? "" : "/",
+                                mapping_table[i].fw_base,
+                                fwnames[j].extension);
+               } else {
+                       snprintf(fwnames[j].path, BRCMF_FW_NAME_LEN, "%s%s",
+                                mapping_table[i].fw_base,
+                                fwnames[j].extension);
                }
-               strlcat(fwnames[j].path, mapping_table[i].fw_base,
-                       BRCMF_FW_NAME_LEN);
-               strlcat(fwnames[j].path, fwnames[j].extension,
-                       BRCMF_FW_NAME_LEN);
                fwreq->items[j].path = fwnames[j].path;
        }
 
-- 
2.55.0.1032.g73a4cd73de-goog

Reply via email to