On Mon, Jun 8, 2026 at 11:55 AM <[email protected]> wrote:
>
> From: David Laight <[email protected]>
>
> When copying the info strings and generating a char ** list copy all the
> strings into the kmalloced buffer outside the loop and use strchr(str, 0)
> to find the next string inside the loop.
>
> Removes some strcpy() that static tools might think are unbounded.
>
> Signed-off-by: David Laight <[email protected]>

Applied for next, thanks!

Kind regards
Uffe


> ---
> This is one of a group of patches that remove potentially unbounded
> strcpy() calls.
>
> They are mostly replaced by strscpy() or, when strlen() has just been
> called, with memcpy() (usually including the '\0').
>
> Calls with copy string literals into arrays are left unchanged.
> They are safe and easily detected as such.
>
> The changes were made by getting the compiler to detect the calls and
> then fixing the code by hand.
>
> Note that all the changes are only compile tested.
>
> Some Makefiles were changed to allow files to contain strcpy().
> As well as 'difficult to fix' files, this included 'show' functions
> as they really need to use sysfs_emit() or seq_printf().
>
> All the patches are being sent individually to avoid very long cc lists.
> Apologies for the terse commit messages and likely unexpected tags.
> (There are about 100 patches in total.)
>
>  drivers/mmc/core/sdio_cis.c | 5 ++---
>  1 file changed, 2 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/mmc/core/sdio_cis.c b/drivers/mmc/core/sdio_cis.c
> index afaa6cab1adc..0b818cb478ce 100644
> --- a/drivers/mmc/core/sdio_cis.c
> +++ b/drivers/mmc/core/sdio_cis.c
> @@ -57,12 +57,11 @@ static int cistpl_vers_1(struct mmc_card *card, struct 
> sdio_func *func,
>                 return -ENOMEM;
>
>         string = (char*)(buffer + nr_strings);
> +       memcpy(string, buf, size);
>
>         for (i = 0; i < nr_strings; i++) {
>                 buffer[i] = string;
> -               strcpy(string, buf);
> -               string += strlen(string) + 1;
> -               buf += strlen(buf) + 1;
> +               string = strchr(string, 0) + 1;
>         }
>
>         if (func) {
> --
> 2.39.5
>

Reply via email to