From: Simon Marchi Date: Mon, 12 Apr 2021 17:23:39 +0000 (-0400) Subject: Fix: utils: avoid strncpy overlap in utils_partial_realpath X-Git-Tag: v2.11.7~18 X-Git-Url: https://git.liburcu.org/?a=commitdiff_plain;h=7e7e8db8b9ca5d862f090ff2a3348e31dab612da;hp=7e7e8db8b9ca5d862f090ff2a3348e31dab612da;p=lttng-tools.git Fix: utils: avoid strncpy overlap in utils_partial_realpath When running the test_utils_expand_path test with ASan enabled, I get: ➜ lttng-tools ./tests/unit/test_utils_expand_path 1..29 INPUT: /a/b/c/d/e ================================================================= ==1485873==ERROR: AddressSanitizer: strncpy-param-overlap: memory ranges [0x621000021d00,0x621000021d0b) and [0x621000021d00, 0x621000021d0b) overlap #0 0x7ffff761fd97 in __interceptor_strncpy /build/gcc/src/gcc/libsanitizer/asan/asan_interceptors.cpp:481 #1 0x555555573834 in utils_partial_realpath /home/simark/src/lttng-tools/src/common/utils.c:195 #2 0x55555557410b in _utils_expand_path /home/simark/src/lttng-tools/src/common/utils.c:374 #3 0x555555574340 in utils_expand_path /home/simark/src/lttng-tools/src/common/utils.c:420 #4 0x555555570b28 in test_utils_expand_path /home/simark/src/lttng-tools/tests/unit/test_utils_expand_path.c:274 #5 0x55555557119e in main /home/simark/src/lttng-tools/tests/unit/test_utils_expand_path.c:345 #6 0x7ffff725fb24 in __libc_start_main (/usr/lib/libc.so.6+0x27b24) #7 0x55555556fa3d in _start (/home/simark/build/lttng-tools/tests/unit/test_utils_expand_path+0x1ba3d) 0x621000021d00 is located 0 bytes inside of 4096-byte region [0x621000021d00,0x621000022d00) allocated by thread T0 here: #0 0x7ffff7677639 in __interceptor_calloc /build/gcc/src/gcc/libsanitizer/asan/asan_malloc_linux.cpp:154 #1 0x55555557269d in zmalloc /home/simark/src/lttng-tools/src/common/macros.h:45 #2 0x555555573d34 in _utils_expand_path /home/simark/src/lttng-tools/src/common/utils.c:335 #3 0x555555574340 in utils_expand_path /home/simark/src/lttng-tools/src/common/utils.c:420 #4 0x555555570b28 in test_utils_expand_path /home/simark/src/lttng-tools/tests/unit/test_utils_expand_path.c:274 #5 0x55555557119e in main /home/simark/src/lttng-tools/tests/unit/test_utils_expand_path.c:345 #6 0x7ffff725fb24 in __libc_start_main (/usr/lib/libc.so.6+0x27b24) 0x621000021d00 is located 0 bytes inside of 4096-byte region [0x621000021d00,0x621000022d00) allocated by thread T0 here: #0 0x7ffff7677639 in __interceptor_calloc /build/gcc/src/gcc/libsanitizer/asan/asan_malloc_linux.cpp:154 #1 0x55555557269d in zmalloc /home/simark/src/lttng-tools/src/common/macros.h:45 #2 0x555555573d34 in _utils_expand_path /home/simark/src/lttng-tools/src/common/utils.c:335 #3 0x555555574340 in utils_expand_path /home/simark/src/lttng-tools/src/common/utils.c:420 #4 0x555555570b28 in test_utils_expand_path /home/simark/src/lttng-tools/tests/unit/test_utils_expand_path.c:274 #5 0x55555557119e in main /home/simark/src/lttng-tools/tests/unit/test_utils_expand_path.c:345 #6 0x7ffff725fb24 in __libc_start_main (/usr/lib/libc.so.6+0x27b24) The sole caller of utils_partial_realpath, _utils_expand_path, passes the same buffer (resolved_path) for the input and output. This causes utils_partial_realpath to call strncpy with overlapping strings. Fix it by making utils_partial_realpath allocate new memory for the returned string itself. This causes one more allocation than the current code, because we don't re-use the existing buffer, but this should be fine since this isn't exactly performance-critical code. I think the code is easier to follow as a result. Signed-off-by: Simon Marchi Signed-off-by: Jérémie Galarneau Change-Id: Iab983e2f44fa57563b11ac6e9c03a41150669d9e ---