From patchwork Sun Oct 5 20:52:21 2025 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Haelwenn (lanodan) Monnier" X-Patchwork-Id: 2145934 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; secure) header.d=lists.infradead.org header.i=@lists.infradead.org header.a=rsa-sha256 header.s=bombadil.20210309 header.b=fxvTDgWh; dkim=temperror header.d=hacktivis.me header.i=@hacktivis.me header.a=rsa-sha256 header.s=20241213_132553 header.b=i6Pqpz+R; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=none (no SPF record) smtp.mailfrom=lists.openwrt.org (client-ip=2607:7c80:54:3::133; helo=bombadil.infradead.org; envelope-from=openwrt-devel-bounces+incoming=patchwork.ozlabs.org@lists.openwrt.org; receiver=patchwork.ozlabs.org) Received: from bombadil.infradead.org (bombadil.infradead.org [IPv6:2607:7c80:54:3::133]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (secp384r1) server-digest SHA384) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4cfvmB4cx2z1yGS for ; Mon, 6 Oct 2025 07:54:48 +1100 (AEDT) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:MIME-Version:Message-ID:Subject:To:From :Date:Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To:References: List-Owner; bh=f5UYC9F4mV2IoHZBD+hHogT0L8IbPSUE/P9f1COhTXs=; b=fxvTDgWh/xJvDB E9aK2CgxLAr7v6Ic134ST/M8jM7Ocwf3Pi5ALLXv2NRtvUprAKas/6XesnyYgz68r5vddShZMPagm S6ydsTufckTx4uSuDc3mV+j1QdlfpLSs3j/QaeB3XelUwjWtqFQNHtR2gGtrOIdVBq5dLME9vHhcZ qxzKgfRh/+mJwaatYR0l6K/50k/a0ZMXXyhFV60G2rneSMfAhkK6s2Hzy6ljNKcdZ784LWixJhIIM HxTd+ei0F9kdSPMgEKo+CtbTs6/0508rJHgZnf0lMwJnQvK8e9q1UwNKpJOw7O5VKQMuoivzlnc5E kKPVD2ROqWKXylkEH2mA==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.98.2 #2 (Red Hat Linux)) id 1v5Vid-0000000Gd87-0yFN; Sun, 05 Oct 2025 20:52:35 +0000 Received: from cloudsdale.lanodan.eu ([2a01:4f8:1c17:4b6d::1]) by bombadil.infradead.org with esmtps (Exim 4.98.2 #2 (Red Hat Linux)) id 1v5ViX-0000000Gd7U-3wWW for openwrt-devel@lists.openwrt.org; Sun, 05 Oct 2025 20:52:32 +0000 Received: by cloudsdale.lanodan.eu (OpenSMTPD) with ESMTP id d7899d28 for ; Sun, 5 Oct 2025 20:52:21 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed; d=hacktivis.me; h=date :from:to:message-id:mime-version:content-type; s= 20241213_132553; bh=GgL0TJlit3BONb2UNQ4ag6CmKPV2LztpZ8LP/RzDuVM=; b= i6Pqpz+Rqxug5GLsdW/nzEeCenXmcE6TCXBU5CdKWAyY5p+m6HMpfOXhTkZ6e03/ g+kdhUwB/gzU04hlRosPglBX6MAhAkLR5gvdLfPwbKPc8nWnEgOiUOWJHjj4QIHc 9+zq9trJew3dIy2xkLtY1zsWBO/jRa7p2oU+iVc+LtZEaQxFNMY3V0pt8CgBAjdi c5LZ/XgMpwp9KxMH3RcNW6hWVyAjwaDpoPahin2DS2acWomSIR3rcVURg0FXAVK1 xwbQxgMy2n1EnD1ZZu/WBujkwvGhOTCFPzb8oLeu6Se1MxzNvgVCoXVgF1DyoJ5B sPAWR6Nvfk7/dAQOV+v4etsEGqpoXqletMl1Fi3Xzko7bOBdrWWKLBkgUvvDEtND j+xwdt2TTD30hqcwnPHPI7/93a4daHpN3mPX+kfaCty2/GDlyveVkB9nf+ka17wE FN+/cJp7UlyQvnjW47XARN1rJD+NdFFbswrT3F6y54zBRDGP+jBgK+PB1mJm2uwM +vSkdJthrvlS3S5P5UUGiUpvxt2Eq1EMnRVzx+EJdYI4pMDNxz0Ci5SUlTLSxgje RqoxCfiybUazoQgmMpaTASqHvbeAcaPSc10/+vbw6Nw6UBq7UDEE6rMr4MQfz04c 5Y2LFpKGFIdMd8SuB/BudR3iZjMdyKVR+md2wCqy5iA= DomainKey-Signature: a=rsa-sha1; c=nofws; d=hacktivis.me; h=date:from:to :message-id:mime-version:content-type; q=dns; s=20241213_132553; b= Ro0/OqRkJDOvLqb421Ui6dveKC8jt/bOnZ5Uu9tUlZcM835ERVtHU0rX8vSfZ9qV bblzpr7dWw4pildjhUs6UG/9bZ8kVJFbk14O03SGpgs3s/S2WYxy9JoI890IWNjT IaQ8vZ3SQmGn1mnWJqePAljw1OYa9dPg6ytqvqrCIE1dUG9rUlmAPb3ocw4YPyoL q5Ck0RX3w1X5b2VWrliEpn6vrPSxTeEZjfy/LLIk5vJyjxuRu0OeHmt+SXx7/+RS 5hade8aXrAxL9akGK06nSftBzb3Xxi+OY7MZM7MLgUoFGbnsd4emM4CIqrrFzmHb qCFsE3nuOGOFnMbSk5OhD41s1vJJyfNPJE8V/MlGV/5f0vSGzcw++DjlVtJCR31c zrW/bEilqP0oijP5hApNBumcUAalLp0ncLH4eKXsE6nsOr/1PIBiaLFS4US+EciE 2/ZrRv0Ly7v1cI1XbNb0mTwhGYH6gkRz3n2Or7/qEmmOYak6jJZ0p3+9cvGnYCTf seRJWiXC6DR2b2z42adrhaVLvoJzOVaD7PnsGctkcgAe6wQEvtsUSZh7Pi7zZvAE U4NmpPWxZRJu0YPpLnFQ/MCnYx0WSvA+0QclX8HFKq7EILJW5c8EOiBZx1MwRTWn CbZhuI1i4nT2JjtuTEMYYZRj0Hdafmcjuiwp0+VwZ20= Received: from localhost (cloudsdale.lanodan.eu [local]) by cloudsdale.lanodan.eu (OpenSMTPD) with ESMTPA id ce26ece1 for ; Sun, 5 Oct 2025 20:52:21 +0000 (UTC) Date: Sun, 5 Oct 2025 22:52:21 +0200 From: "Haelwenn (lanodan) Monnier" To: openwrt-devel@lists.openwrt.org Subject: [PATCH usign] Use static buffer for default sigfile path Message-ID: Mail-Followup-To: "Haelwenn (lanodan) Monnier" , openwrt-devel@lists.openwrt.org MIME-Version: 1.0 Content-Disposition: inline X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20251005_135231_015928_566ED162 X-CRM114-Status: GOOD ( 11.04 ) X-Spam-Score: -4.4 (----) X-Spam-Report: Spam detection software, running on the system "bombadil.infradead.org", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: This allows to compile usign with TinyCC on architectures like AArch64 and riscv where it is missing an implementation of alloca. VLA could also be used as this is C99 code, but would reduce portability. Content analysis details: (-4.4 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -2.3 RCVD_IN_DNSWL_MED RBL: Sender listed at https://www.dnswl.org/, medium trust [2a01:4f8:1c17:4b6d:0:0:0:1 listed in] [list.dnswl.org] 0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record -0.0 SPF_PASS SPF: sender matches SPF record -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -1.9 BAYES_00 BODY: Bayes spam probability is 0 to 1% [score: 0.0000] X-BeenThere: openwrt-devel@lists.openwrt.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: OpenWrt Development List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "openwrt-devel" Errors-To: openwrt-devel-bounces+incoming=patchwork.ozlabs.org@lists.openwrt.org This allows to compile usign with TinyCC on architectures like AArch64 and riscv where it is missing an implementation of alloca. VLA could also be used as this is C99 code, but would reduce portability. malloc could be considered but musl's malloc is over 4KB of code and dynamic/static analyzers would require a bunch of free(). Signed-off-by: Haelwenn (lanodan) Monnier --- main.c | 16 +++++++++++++--- 1 file changed, 13 insertions(+), 3 deletions(-) base-commit: f1f65026a94137c91b5466b149ef3ea3f20091e9 diff --git a/main.c b/main.c index ebfdfb0..addbfb8 100644 --- a/main.c +++ b/main.c @@ -26,11 +26,16 @@ #include #include #include +#include #include "base64.h" #include "edsign.h" #include "ed25519.h" +#ifndef PATH_MAX +#define PATH_MAX 4096 +#endif + struct pubkey { char pkalg[2]; uint8_t fingerprint[8]; @@ -409,14 +414,19 @@ int main(int argc, char **argv) } if (!sigfile && msgfile) { - char *buf = alloca(strlen(msgfile) + 5); - if (!strcmp(msgfile, "-")) { fprintf(stderr, "Need signature file when reading message from stdin\n"); return 1; } - sprintf(buf, "%s.sig", msgfile); + if ((strlen(msgfile) - 4) > PATH_MAX) + { + fprintf(stderr, "Need signature file when msgfile path is over %zd (PATH_MAX - 4)\n", (size_t)PATH_MAX); + return 1; + } + + static char buf[PATH_MAX]; + snprintf(buf, PATH_MAX, "%s.sig", msgfile); sigfile = buf; }