Bug 15925

Summary: Wrong size passed to memcpy in pdb_update_inode leads to missing xattrs when renaming
Product: [Yocto Project Subprojects] Pseudo Reporter: Daniele Romano <daniele.romano>
Component: pseudoAssignee: Mark Hatle <mark.hatle>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: Medium+ CC: mark.hatle, randy.macleod, yp.pseudo.watcher, yp.watcher
Version: master   
Target Milestone: 5.3 M2   
Hardware: All   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: No (bug/feature does not impact docs)
Attachments:
Description Flags
Fix for oldmsg buffer allocation and memcpy data copied none

Description Daniele Romano 2025-07-03 20:25:17 UTC
The pdb_update_inode function is unable to find a match and to correctly copy the xattr due to the wrong amount of data copied when cloning msg.


The issue is in the following code in pseudo_db.c:

2160 int pdb_update_inode(pseudo_msg_t *msg) {
.....
.....
2191	memcpy(oldmsg, msg, sizeof(msg) + msg->pathlen);
2192	found_existing = !pdb_find_file_path(oldmsg);
2193	if (found_existing) {
2194		/* we have an existing file entry */
2195		pdb_copy_xattrs(oldmsg, msg);
2196	}


The memcpy in line 2191 is copying "sizeof(msg) + msg->pathlen", but msg is a pointer to a pseudo_msg_t. This means that the amount of bytes copied is equal to msg->pathlen plus the size of a pointer and not the pseudo_msg_t itself. This issue will lead to a truncated path copied in oldmsg and to the failure of pdb_find_file_path function on line 2193.

The patch attached fixes line 2191 replacing "sizeof(msg)" with "sizeof(pseudo_msg_t)".

In addition, it fixes the allocation of the oldmsg buffer at line 2167. This is needed to avoid buffer overflows with paths very close to the maximum expected length that is given by the pseudo_path_max() function.
Comment 1 Daniele Romano 2025-07-03 20:26:16 UTC
Created attachment 5125 [details]
Fix for oldmsg buffer allocation and memcpy data copied
Comment 2 Mark Hatle 2025-07-11 02:52:52 UTC
The patch was tested, modified a bit and has been pushed.  See:

https://git.yoctoproject.org/pseudo/commit/?id=d1db9c219abf92f15303486a409292237f1fc790