]> git.ipfire.org Git - thirdparty/shadow.git/commit
lib/date_to_str.c: strftime(3) leaves the buffer undefined on failure
authorAlejandro Colomar <alx@kernel.org>
Thu, 16 Nov 2023 14:56:25 +0000 (15:56 +0100)
committerSerge Hallyn <serge@hallyn.com>
Thu, 23 Nov 2023 14:04:39 +0000 (08:04 -0600)
commit1c50a44db6bb02984fabbb482fea70ef2ca08fb2
treeb012ff513bf72eeb52c870a5e7a59fa52489044e
parentbbf1d9a8004dc008f77ea24c963f195775536931
lib/date_to_str.c: strftime(3) leaves the buffer undefined on failure

strftime(3) makes no guarantees about the contents of the buffer if the
formatted string wouldn't fit in the buffer.  It simply returns 0, and
it's the programmer's responsibility to do the right thing after that.

Let's write the string "future" if there's an error, similar to what we
do with gmtime(3)'s errors.

Also, `buf[size - 1] = '\0';` didn't make sense.  If the copy fits,
strftime(3) guarantees to terminate with NUL.  If it doesn't, the entire
contents of buf are undefined, so adding a NUL at the end of the buffer
would be dangerous: the string could contain anything, such as
"gimme root access now".  Remove that, now that we set the string to
"future", as with gmtime(3) errors.  This setting to '\0' comes from the
times when we used strncpy(3) in the implementation, and should have
been removed when I changed it to use strlcpy(3); however, I didn't
check we didn't need it anymore.

Cc: Serge Hallyn <serge@hallyn.com>
Signed-off-by: Alejandro Colomar <alx@kernel.org>
lib/date_to_str.c