Bug 8041 - dosfstools patches introduce coverity issues not there in upstream
Summary: dosfstools patches introduce coverity issues not there in upstream
Status: RESOLVED NOTABUG
Alias: None
Product: AutoBuilder
Classification: Infrastructure
Component: autobuilder (show other bugs)
Version: unspecified
Hardware: x86 Multiple
: Undecided normal
Target Milestone: ---
Assignee: Beth Flanagan
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2015-07-22 18:35 UTC by Terri Oda
Modified: 2015-11-11 17:46 UTC (History)
3 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: New (Never tested)
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Terri Oda 2015-07-22 18:35:23 UTC
Scott Garman's patches to dosfstools are introducing code that static analysis has flagged as potential issues. 

It's all related to mkdosfs.c:

line 1445:
CID 294095 (#2 of 2): Buffer not null terminated (BUFFER_SIZE)
3. buffer_size: Calling strncpy with a source string whose length (11 chars) is greater than or equal to the size argument (11) will fail to null-terminate dos_name.

1572: 
CID 294100 (#2 of 2): Missing return statement (MISSING_RETURN)
5. missing_return: Arriving at the end of a function without returning a value.

1632:
CID 294097 (#1 of 1): Buffer not null terminated (BUFFER_SIZE_WARNING)
16. buffer_size_warning: Calling strncpy with a maximum size argument of 11 bytes on destination array entry->name of size 11 bytes might leave the destination string unterminated.

1697:
CID 294102 (#1 of 1): Resource leak (RESOURCE_LEAK)29. leaked_storage: Variable buffer going out of scope leaks the storage it points to.

1783:
CID 294096 (#1 of 1): Buffer not null terminated (BUFFER_SIZE_WARNING)
11. buffer_size_warning: Calling strncpy with a maximum size argument of 11 bytes on destination array entry->name of size 11 bytes might leave the destination string unterminated.

Here's the coverity link for more detail: https://cov.jf.intel.com/reports.htm#v14248/p10089

These may well be false positives, but since my email to Scott's Intel address bounced, I'm not sure who to ask to look at these.  Guidance appreciated!
Comment 1 Beth Flanagan 2015-11-11 17:46:12 UTC
Removing from Bugzilla.