summarylogtreecommitdiffstats
path: root/buffer_overflow_fix.patch
blob: 94bc91face1669ce0a6c3e28dd566e0750592d96 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
diff --git a/src/harness/os/linux.c b/src/harness/os/linux.c
index 295beb0..da3f0f7 100644
--- a/src/harness/os/linux.c
+++ b/src/harness/os/linux.c
@@ -194,21 +194,28 @@ static void signal_handler(int sig, siginfo_t* siginfo, void* context) {
     exit(1);
 }
 
-void resolve_full_path(char* path, const char* argv0) {
+void resolve_full_path(char* path, size_t path_size, const char* argv0) {
     if (argv0[0] == '/') { // run with absolute path
-        strcpy(path, argv0);
+        strncpy(path, argv0, path_size - 1);
+        path[path_size - 1] = '\0';
     } else { // run with relative path
-        if (NULL == getcwd(path, PATH_MAX)) {
+        // Leave room for "/" and argv0
+        size_t argv0_len = strlen(argv0);
+        if (argv0_len + 2 >= path_size) {
+            return; // argv0 too long
+        }
+        size_t max_cwd_len = path_size - argv0_len - 2;
+        if (NULL == getcwd(path, max_cwd_len)) {
             perror("getcwd error");
             return;
         }
-        strcat(path, "/");
-        strcat(path, argv0);
+        strncat(path, "/", path_size - strlen(path) - 1);
+        strncat(path, argv0, path_size - strlen(path) - 1);
     }
 }
 
 void OS_InstallSignalHandler(char* program_name) {
-    resolve_full_path(_program_name, program_name);
+    resolve_full_path(_program_name, sizeof(_program_name), program_name);
 
     /* setup alternate stack */
     {
diff --git a/src/harness/os/macos.c b/src/harness/os/macos.c
index a2d6861..d6c8fc5 100644
--- a/src/harness/os/macos.c
+++ b/src/harness/os/macos.c
@@ -171,22 +171,29 @@ void signal_handler(int sig, siginfo_t* siginfo, void* context) {
 
 static uint8_t alternate_stack[SIGSTKSZ];
 
-void resolve_full_path(char* path, const char* argv0) {
+void resolve_full_path(char* path, size_t path_size, const char* argv0) {
     if (argv0[0] == '/') { // run with absolute path
-        strcpy(path, argv0);
+        strncpy(path, argv0, path_size - 1);
+        path[path_size - 1] = '\0';
     } else { // run with relative path
-        if (NULL == getcwd(path, PATH_MAX)) {
+        // Leave room for "/" and argv0
+        size_t argv0_len = strlen(argv0);
+        if (argv0_len + 2 >= path_size) {
+            return; // argv0 too long
+        }
+        size_t max_cwd_len = path_size - argv0_len - 2;
+        if (NULL == getcwd(path, max_cwd_len)) {
             perror("getcwd error");
             return;
         }
-        strcat(path, "/");
-        strcat(path, argv0);
+        strncat(path, "/", path_size - strlen(path) - 1);
+        strncat(path, argv0, path_size - strlen(path) - 1);
     }
 }
 
 void OS_InstallSignalHandler(char* program_name) {
 
-    resolve_full_path(_program_name, program_name);
+    resolve_full_path(_program_name, sizeof(_program_name), program_name);
 
     /* setup alternate stack */
     {