On Tue, 30 May 2023 16:30:01 +0000, Azeem Shaikh wrote: > strlcpy() reads the entire source buffer first. > This read may exceed the destination size limit. > This is both inefficient and can lead to linear read > overflows if a source string is not NUL-terminated [1]. > In an effort to remove strlcpy() completely [2], replace > strlcpy() here with strscpy(). > No return values were used, so direct replacement is safe. > > [...] Build tested with GCC 12 with 32-bit and 64-bit defconfigs. Applied to for-next/hardening, thanks! [1/1] sparc64: Replace all non-returning strlcpy with strscpy https://git.kernel.org/kees/c/7136be35e71c -- Kees Cook