[PATCH 21/68] grep: use xsnprintf to format failure message
- From
Jeff King <peff@peff.net>
- Date
- Sep 24, 2015, 21:06 UTC
- Message-ID
- <20150924210650.GR30946@sigill.intra.peff.net>
- In-Reply-To
- <20150924210225.GA23624@sigill.intra.peff.net>
This looks at first glance like the sprintf can overflow our buffer, but it's actually fine; the p->origin string is something constant and small, like "command line" or "-e option".
Signed-off-by: Jeff King <peff@peff.net> --- grep.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/grep.c b/grep.c index b58c7c6..6c68d5b 100644 --- a/grep.c +++ b/grep.c @@ -306,9 +306,9 @@ static NORETURN void compile_regexp_failed(const struct grep_pat *p, char where[1024]; if (p->no) - sprintf(where, "In '%s' at %d, ", p->origin, p->no); + xsnprintf(where, sizeof(where), "In '%s' at %d, ", p->origin, p->no); else if (p->origin) - sprintf(where, "%s, ", p->origin); + xsnprintf(where, sizeof(where), "%s, ", p->origin); else where[0] = 0;
-- 2.6.0.rc3.454.g204ad51