Date: Thu, 9 May 2002 15:25:11 +1000 (EST) From: Bruce Evans <bde@zeta.org.au> To: "Andrey A. Chernov" <ache@nagual.pp.ru> Cc: cvs-committers@FreeBSD.org, <cvs-all@FreeBSD.org> Subject: Re: cvs commit: src/sbin/sysctl sysctl.c Message-ID: <20020509151407.D3794-100000@gamplex.bde.org> In-Reply-To: <20020509040953.GA894@nagual.pp.ru>
next in thread | previous in thread | raw e-mail | index | archive | help
On Thu, 9 May 2002, Andrey A. Chernov wrote: > On Thu, May 09, 2002 at 13:50:37 +1000, Bruce Evans wrote: > > On Wed, 8 May 2002, Andrey A. Chernov wrote: > > > > > ache 2002/05/08 16:49:20 PDT > > > > > > Modified files: > > > sbin/sysctl sysctl.c > > > Log: > > > Don't forget to null-terminate string we got from sysctl (f.e. in 'A' format). > > > Stack garbadge may be printed otherwise. > > > > > > Revision Changes Path > > > 1.45 +1 -1 src/sbin/sysctl/sysctl.c > > > > This overruns the buffer in the (unlikely) even that sysctl(3) returned a > > full buffer. > > Do you saw j += j there? Buffer is doubled (unless I misunderstand this > thing). Yes; that is why I wrote that the even[t] is unlikely. We double the buffer size in case the name expands underneath us. If the name actually expands by a full factor of 2, we overrun the buffer. Bruce To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe cvs-all" in the body of the message
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20020509151407.D3794-100000>