Re: [PATCH] ACPICA: Replace strncpy() with strscpy_pad() in acpi_ut_safe_strncpy()
Jiri Slaby <[email protected]> Fri, 29 May 2026 09:24:55 +0200
| Newsgroups | dev.linux.lists.acpica-devel,org.kernel.vger.linux-acpi,org.kernel.vger.linux-hardening,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
On 29. 05. 26, 9:20, Jiri Slaby wrote: > On 23. 03. 26, 18:31, Rafael J. Wysocki wrote: >> On Mon, Mar 23, 2026 at 6:24 PM Kees Cook <[email protected]> wrote: >>> >>> Replace the deprecated[1] strncpy() with strscpy_pad() in >>> acpi_ut_safe_strncpy(). >>> >>> The function is a "safe strncpy" wrapper that does >>> strncpy(dest, source, dest_size) followed by manual NUL-termination >>> at dest[dest_size - 1]. strscpy_pad() is a direct replacement: it >>> NUL-terminates, zero-pads the remainder, and the manual termination >>> is no longer needed. >>> >>> All callers pass NUL-terminated source strings (C string literals, >>> __FILE__ via ACPI_MODULE_NAME, or user-provided filenames that have >>> already been validated). The destinations are fixed-size char arrays >>> in ACPICA internal structures (allocation->module, aml_op_name, >>> acpi_gbl_db_debug_filename), all consumed as C strings. >>> >>> No behavioral change: strscpy_pad() produces identical output to >>> strncpy() + manual NUL-termination for NUL-terminated sources that >>> are shorter than dest_size. For sources longer than dest_size, >>> strncpy() wrote dest_size non-NUL bytes then the manual termination >>> overwrote the last byte with NUL; strscpy_pad() writes dest_size-1 >>> bytes plus NUL: same result. >>> >>> Link: https://github.com/KSPP/linux/issues/90 [1] >>> Signed-off-by: Kees Cook <[email protected]> >>> --- >>> This touches the ACPICA component shared with the upstream ACPICA >>> project (https://github.com/acpica/acpica), where the function >>> is named AcpiUtSafeStrncpy(). The upstream codebase uses its own >>> platform abstraction layer (acenv.h/acgcc.h) where I've mapped various >>> kernel APIs before like ACPI_FLEX_ARRAY and similar helpers. However, >>> acpi_ut_safe_strncpy() is an explicit function implementation rather >>> than a macro mapping, so the approach for upstreaming this change to >>> ACPICA is not clear. What's the best way to land this? >> >> I can apply this directly, it shouldn't be a major problem for porting >> patches from the upstream. > > As I reported in https://github.com/acpica/acpica/issues/1158 (but got > no reply), this patch breaks build of acpica against 7.1-rc*: > > ../../../../../drivers/acpi/acpica/utnonansi.c:171:9: error: implicit > declaration of function ‘strscpy_pad’ [-Wimplicit-function-declaration] > > Is strscpy_pad() supposed to be emulated in acpica? No, I misread the log, it's the in-kernel acpidump failing to build: ~/linux/tools/power/acpi/tools/acpidump> make MKDIR include CP include CC tools/acpidump/apdump.o CC tools/acpidump/apfiles.o CC tools/acpidump/apmain.o CC tools/acpidump/osunixdir.o CC tools/acpidump/osunixmap.o CC tools/acpidump/osunixxf.o CC tools/acpidump/tbprint.o CC tools/acpidump/tbxfroot.o CC tools/acpidump/utascii.o CC tools/acpidump/utbuffer.o CC tools/acpidump/utcksum.o CC tools/acpidump/utdebug.o CC tools/acpidump/utexcep.o CC tools/acpidump/utglobal.o CC tools/acpidump/uthex.o CC tools/acpidump/utmath.o CC tools/acpidump/utnonansi.o ../../../../../drivers/acpi/acpica/utnonansi.c: In function ‘acpi_ut_safe_strncpy’: ../../../../../drivers/acpi/acpica/utnonansi.c:171:9: error: implicit declaration of function ‘strscpy_pad’ [-Wimplicit-function-declaration] 171 | strscpy_pad(dest, source, dest_size); | ^~~~~~~~~~~ make: *** [../../Makefile.rules:25: /home/xslaby/linux/tools/power/acpi/tools/acpidump/utnonansi.o] Chyba 1 >>> (This is one of the last users of strncpy in the kernel.) >>> --- >>> drivers/acpi/acpica/utnonansi.c | 3 +-- >>> 1 file changed, 1 insertion(+), 2 deletions(-) >>> >>> diff --git a/drivers/acpi/acpica/utnonansi.c b/drivers/acpi/acpica/ >>> utnonansi.c >>> index ff0802ace19b..3a7952be6545 100644 >>> --- a/drivers/acpi/acpica/utnonansi.c >>> +++ b/drivers/acpi/acpica/utnonansi.c >>> @@ -168,8 +168,7 @@ void acpi_ut_safe_strncpy(char *dest, char >>> *source, acpi_size dest_size) >>> { >>> /* Always terminate destination string */ >>> >>> - strncpy(dest, source, dest_size); >>> - dest[dest_size - 1] = 0; >>> + strscpy_pad(dest, source, dest_size); >>> } >>> >>> #endif >>> -- >> > > thanks, -- js suse labs