|
|
@@ -1178,6 +1178,7 @@ static int kvp_set_ip_info(char *if_name, struct hv_kvp_ipaddr_value *new_val)
|
|
|
FILE *file;
|
|
|
char cmd[PATH_MAX];
|
|
|
char *mac_addr;
|
|
|
+ int str_len;
|
|
|
|
|
|
/*
|
|
|
* Set the configuration for the specified interface with
|
|
|
@@ -1301,8 +1302,18 @@ static int kvp_set_ip_info(char *if_name, struct hv_kvp_ipaddr_value *new_val)
|
|
|
* invoke the external script to do its magic.
|
|
|
*/
|
|
|
|
|
|
- snprintf(cmd, sizeof(cmd), KVP_SCRIPTS_PATH "%s %s",
|
|
|
- "hv_set_ifconfig", if_file);
|
|
|
+ str_len = snprintf(cmd, sizeof(cmd), KVP_SCRIPTS_PATH "%s %s",
|
|
|
+ "hv_set_ifconfig", if_file);
|
|
|
+ /*
|
|
|
+ * This is a little overcautious, but it's necessary to suppress some
|
|
|
+ * false warnings from gcc 8.0.1.
|
|
|
+ */
|
|
|
+ if (str_len <= 0 || (unsigned int)str_len >= sizeof(cmd)) {
|
|
|
+ syslog(LOG_ERR, "Cmd '%s' (len=%d) may be too long",
|
|
|
+ cmd, str_len);
|
|
|
+ return HV_E_FAIL;
|
|
|
+ }
|
|
|
+
|
|
|
if (system(cmd)) {
|
|
|
syslog(LOG_ERR, "Failed to execute cmd '%s'; error: %d %s",
|
|
|
cmd, errno, strerror(errno));
|