"GOT", but the "O" is a cute, smiling pufferfish. Index | Thread | Search

From:
Martijn van Duren <openbsd+got@list.imperialat.at>
Subject:
Re: gotsysd: use PATH_MAX for realpath
To:
"gameoftrees@openbsd.org" <gameoftrees@openbsd.org>
Cc:
Stefan Sperling <stsp@stsp.name>
Date:
Sat, 10 Oct 2026 16:00:07 +0200

Download raw body.

Thread
On 10/10/26 15:48, Stefan Sperling wrote:
> On Sat, Oct 10, 2026 at 03:24:55PM +0200, Martijn van Duren wrote:
>> Found by gcc-4 on alpha :-)
>>
>> As per POSIX, realpath() stores up to PATH_MAX into resolved, so let's
>> make sure that that space is available.
>>
>> While here, gcc-4 complains about brackets arround '&', so why not
>> please our ancient compiler overlords by placing said brackets. Diff
>> below allows gotsysd to be build on alpha with -Werror.
>>
>> martijn@
> 
> There was some reason why -portable needs _POSIX_PATH_MAX instead
> of PATH_MAX. Does _POSIX_PATH_MAX not work for us?

Yes and no. _POSIX_PATH_MAX is always 256 bytes, and a minimum for
PATH_MAX (see POSIX's limits.h documentation). Since realpath()
expects resolved to be at least PATH_MAX in size, which on OpenBSD
is 1024 there's a chance we can overwrite up to 768 bytes.> 
>> diff /home/martijn/src/got
>> path + /home/martijn/src/got
>> commit - 10f51ecc4cbfab15f63d68920c9674a2995fd394
>> blob - e4e182649fed10798ea15941c5d98962ec48659e
>> file + gotsysd/gotsysd.h
>> --- gotsysd/gotsysd.h
>> +++ gotsysd/gotsysd.h
>> @@ -183,8 +183,8 @@ struct gotsysd_web_config {
>>  
>>  struct gotsysd {
>>  	pid_t pid;
>> -	char unix_socket_path[_POSIX_PATH_MAX];
>> -	char repos_path[_POSIX_PATH_MAX];
>> +	char unix_socket_path[PATH_MAX];
>> +	char repos_path[PATH_MAX];
>>  	char user_name[32];
>>  	char gotd_username[32];
>>  	char gotsys_conf_commit_id[GOT_OBJECT_ID_HEX_MAXLEN];
>> commit - 10f51ecc4cbfab15f63d68920c9674a2995fd394
>> blob - d8abeaf2d0a5fc1569525fd0be4ea5b228d59506
>> file + gotsysd/libexec/gotsys-repo-create/gotsys-repo-create.c
>> --- gotsysd/libexec/gotsys-repo-create/gotsys-repo-create.c
>> +++ gotsysd/libexec/gotsys-repo-create/gotsys-repo-create.c
>> @@ -56,7 +56,7 @@
>>  #include "gotsys.h"
>>  
>>  static struct gotsys_conf gotsysconf;
>> -static char repos_path[_POSIX_PATH_MAX];
>> +static char repos_path[PATH_MAX];
>>  static int repos_dir_fd = -1;
>>  uid_t gotd_uid;
>>  gid_t gotd_gid;
>> commit - 10f51ecc4cbfab15f63d68920c9674a2995fd394
>> blob - b057df8abd2756d0e491d4a746945a917b55ce82
>> file + gotsysd/libexec/gotsys-useradd/gotsys-useradd.c
>> --- gotsysd/libexec/gotsys-useradd/gotsys-useradd.c
>> +++ gotsysd/libexec/gotsys-useradd/gotsys-useradd.c
>> @@ -548,7 +548,7 @@ add_users(void)
>>  		 * put the new users before it, and preserve entries
>>  		 * after the yp entry.
>>  		 */
>> -		 if (linelen > 1 && line[0] == '+' & line[1] == ':') {
>> +		 if (linelen > 1 && (line[0] == '+') & (line[1] == ':')) {
> 
> Shouldn't that say && instead of & ?

I didn't look too closely at the logic and simply silenced the
compiler. Initially I read line[0] == '+' && line[0] == ':' which would
point towards using ||, but in this context && makes sense. But not
knowing the protocol: I trust your word.> 
>>  			yp = 1;
>>  			break;
>>  		}
>>
>>