Page MenuHomeFreeBSD

Properly null-terminate strings in a kernel dump header
ClosedPublic

Authored by asomers on May 15 2015, 10:30 PM.
Tags
None
Referenced Files
Unknown Object (File)
Sat, Nov 22, 3:20 PM
Unknown Object (File)
Sat, Nov 22, 11:29 AM
Unknown Object (File)
Sat, Nov 22, 4:23 AM
Unknown Object (File)
Fri, Nov 21, 10:18 PM
Unknown Object (File)
Sat, Nov 15, 8:09 AM
Unknown Object (File)
Sun, Nov 9, 8:03 AM
Unknown Object (File)
Mon, Nov 3, 6:35 AM
Unknown Object (File)
Thu, Oct 30, 12:12 PM
Subscribers

Details

Summary

A version string longer than 192 bytes will cause the version field of
a dump header to overflow. strncpy doesn't null terminate it, so savecore will
print a corrupted info file. Using strlcpy fixes the bug.

Test Plan

Build a kernel with a very long version string and use it to
generate a panic, then dump core. Check that the Panic String is not embedded
at the end of the Version String line.Version String line.

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
No Lint Coverage
Unit
No Test Coverage

Event Timeline

asomers retitled this revision from to Properly null-terminate strings in a kernel dump header.
asomers updated this object.
asomers edited the test plan for this revision. (Show Details)
asomers added a reviewer: markj.
asomers added a subscriber: peter.
markj edited edge metadata.
This revision is now accepted and ready to land.May 15 2015, 10:58 PM
This revision was automatically updated to reflect the committed changes.