Skip to content

Fixes to issues found by the weekly Coverity Scan - #1696

Open
troglobit wants to merge 3 commits into
mainfrom
coverity
Open

troglobit wants to merge 3 commits into
mainfrom
coverity

Conversation

@troglobit

Copy link
Copy Markdown
Contributor

Description

Minor fixes to the new pppmon tool, introduced in this release cycle.

Checklist

Tick relevant boxes, this PR is-a or has-a:

  • Bugfix
    • Regression tests
    • ChangeLog updates (for next release)
  • Feature
    • YANG model change => revision updated?
    • Regression tests added?
    • ChangeLog updates (for next release)
    • Documentation added?
  • Test changes
    • Checked in changed Readme.adoc (make test-spec)
    • Added new test to group Readme.adoc and yaml file
  • Code style update (formatting, renaming)
  • Refactoring (please detail in commit messages)
  • Build related changes
  • Documentation content changes
    • ChangeLog updated (for major changes)
  • Other (please describe):

The interface name from the command line was copied into a fixed size
netlink request without a length check, so a name longer than the
256-byte attribute buffer overflowed the stack.  Coverity Scan reports
it as a string of unknown size passed to syslog (CID 564681).

Reject names the kernel would not accept anyway, before using them.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
If the new peers file could not be put in place, pppd was restarted on
the old one and the change reported as applied.  Coverity Scan reports
the unchecked rename() and remove() (CID 564682, 564679).

Fail the change if rename() fails.  Failing to remove an unchanged
scratch file is harmless, the next change overwrites it.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The timeouts keep a stuck iitod from blocking confd, so the call must
not go ahead without them.  Coverity Scan reports the unchecked
setsockopt() calls (CID 564680).

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
@troglobit
troglobit requested a review from mattiaswal October 10, 2026 13:03

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant