From owner-svn-src-all@freebsd.org Wed May 10 16:19:22 2017 Return-Path: Delivered-To: svn-src-all@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id E711AD67DC0 for ; Wed, 10 May 2017 16:19:22 +0000 (UTC) (envelope-from wlosh@bsdimp.com) Received: from mail-io0-x22e.google.com (mail-io0-x22e.google.com [IPv6:2607:f8b0:4001:c06::22e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id ABFCD104C for ; Wed, 10 May 2017 16:19:22 +0000 (UTC) (envelope-from wlosh@bsdimp.com) Received: by mail-io0-x22e.google.com with SMTP id f102so4760181ioi.2 for ; Wed, 10 May 2017 09:19:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=bsdimp-com.20150623.gappssmtp.com; s=20150623; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=Plz3j3o2jbzr68ypodhMd1WDucBNgM0ZuUAYt3DiwCY=; b=Adlc8uXPOng0TYppRgxVPTTe3oNnsun+eF6Vb2xMts68Fis0wpVHb++pKtqpO+cHii nOlJ2DyAGkBG+FmZBSnYkKjZZF0pnKV/k+RChzTXccGTEq4+HCx7zvHorWyIXG6HvAJo rftN3CR3XM11wRNdQZFhx2IMqECjj2qh+zoJrJtehuyo68V8ftjdnU560rQWd4f6imNC Ps5b9rLcrOdILStLaiTTyPPRCzA4M876dZ7VIKoLfX0wtFL3c+iLFrVCTh70F4pQ5Nwf fbgnEArtvenGTCRSOvI8cgAoFmRCu3q3Z7gEv0YDJgsJ0C2Y0MVXIpnSJOfajCiIOcfi WIkg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:sender:in-reply-to:references:from :date:message-id:subject:to:cc; bh=Plz3j3o2jbzr68ypodhMd1WDucBNgM0ZuUAYt3DiwCY=; b=f9/3wLjX5+2eMA8fV2lj79I0yxuhQOSZrYPJHL2mhqOsyfLKoPYD6SVMrW3Tqv51nN qXmEtQ+BNgkXoB2s7UbKATfL+riMhpbiy3jmzaaY8EtQXUPGujrWnU4fWyjfjHKpxgZY 1wmOlNOMQbv6N+YmwRB8KgneLJzVLceXXtPYCqwstl/Qf/43U1xXYBw8Jc7YIn9JxDK2 QUm4YbYmGAz5/0kHG52+WowES1eO5et0aDxFk19CQ3DKl9R6LYWn2MOEwhD6A48FL7sK ZE2gCpEZg5k5LsDV56QojVjaixx1NUOIUK1lIxtyFHggPgfJc5ooRmLCysrkBAVwF5Xk zYrQ== X-Gm-Message-State: AODbwcAe6eBlgZkVUXbjLIktfyXaqlVnYZtdEV0X9H/tibtAm68nisvu il6N9sR18QBIVbReQYRYrY5xCSUAHQ== X-Received: by 10.107.85.4 with SMTP id j4mr4276510iob.218.1494433161879; Wed, 10 May 2017 09:19:21 -0700 (PDT) MIME-Version: 1.0 Sender: wlosh@bsdimp.com Received: by 10.79.126.6 with HTTP; Wed, 10 May 2017 09:19:21 -0700 (PDT) X-Originating-IP: [2603:300b:6:5100:4c5d:3029:c8d8:ae82] In-Reply-To: <201705101538.v4AFc6c8009588@repo.freebsd.org> References: <201705101538.v4AFc6c8009588@repo.freebsd.org> From: Warner Losh Date: Wed, 10 May 2017 10:19:21 -0600 X-Google-Sender-Auth: -V71iAmEdinxClIJq3wbJomaV00 Message-ID: Subject: Re: svn commit: r318143 - head/usr.sbin/pw To: Alan Somers Cc: src-committers , "svn-src-all@freebsd.org" , "svn-src-head@freebsd.org" Content-Type: text/plain; charset=UTF-8 X-BeenThere: svn-src-all@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: "SVN commit messages for the entire src tree \(except for " user" and " projects" \)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 10 May 2017 16:19:23 -0000 Again, this is wrong. -DNDEBUG makes this a nop. Warner. On Wed, May 10, 2017 at 9:38 AM, Alan Somers wrote: > Author: asomers > Date: Wed May 10 15:38:06 2017 > New Revision: 318143 > URL: https://svnweb.freebsd.org/changeset/base/318143 > > Log: > strcpy => strlcpy > > Reported by: Coverity > CID: 1006715 > MFC after: 3 weeks > Sponsored by: Spectra Logic Corp > > Modified: > head/usr.sbin/pw/pw_user.c > > Modified: head/usr.sbin/pw/pw_user.c > ============================================================================== > --- head/usr.sbin/pw/pw_user.c Wed May 10 15:35:41 2017 (r318142) > +++ head/usr.sbin/pw/pw_user.c Wed May 10 15:38:06 2017 (r318143) > @@ -33,6 +33,7 @@ static const char rcsid[] = > #include > #include > > +#include > #include > #include > #include > @@ -501,7 +502,8 @@ pw_pwcrypt(char *password) > cryptpw = crypt(password, salt); > if (cryptpw == NULL) > errx(EX_CONFIG, "crypt(3) failure"); > - return strcpy(buf, cryptpw); > + assert(strlcpy(buf, cryptpw, sizeof(buf)) < sizeof(buf)); > + return (buf); > } > > static char * >