From: Martijn van Duren Subject: Re: gotsysd: use PATH_MAX for realpath To: "gameoftrees@openbsd.org" Cc: Stefan Sperling Date: Sat, 10 Oct 2026 16:00:07 +0200 On 10/10/26 15:48, Stefan Sperling wrote: > On Sat, Oct 10, 2026 at 03:24:55PM +0200, Martijn van Duren wrote: >> Found by gcc-4 on alpha :-) >> >> As per POSIX, realpath() stores up to PATH_MAX into resolved, so let's >> make sure that that space is available. >> >> While here, gcc-4 complains about brackets arround '&', so why not >> please our ancient compiler overlords by placing said brackets. Diff >> below allows gotsysd to be build on alpha with -Werror. >> >> martijn@ > > There was some reason why -portable needs _POSIX_PATH_MAX instead > of PATH_MAX. Does _POSIX_PATH_MAX not work for us? Yes and no. _POSIX_PATH_MAX is always 256 bytes, and a minimum for PATH_MAX (see POSIX's limits.h documentation). Since realpath() expects resolved to be at least PATH_MAX in size, which on OpenBSD is 1024 there's a chance we can overwrite up to 768 bytes.> >> diff /home/martijn/src/got >> path + /home/martijn/src/got >> commit - 10f51ecc4cbfab15f63d68920c9674a2995fd394 >> blob - e4e182649fed10798ea15941c5d98962ec48659e >> file + gotsysd/gotsysd.h >> --- gotsysd/gotsysd.h >> +++ gotsysd/gotsysd.h >> @@ -183,8 +183,8 @@ struct gotsysd_web_config { >> >> struct gotsysd { >> pid_t pid; >> - char unix_socket_path[_POSIX_PATH_MAX]; >> - char repos_path[_POSIX_PATH_MAX]; >> + char unix_socket_path[PATH_MAX]; >> + char repos_path[PATH_MAX]; >> char user_name[32]; >> char gotd_username[32]; >> char gotsys_conf_commit_id[GOT_OBJECT_ID_HEX_MAXLEN]; >> commit - 10f51ecc4cbfab15f63d68920c9674a2995fd394 >> blob - d8abeaf2d0a5fc1569525fd0be4ea5b228d59506 >> file + gotsysd/libexec/gotsys-repo-create/gotsys-repo-create.c >> --- gotsysd/libexec/gotsys-repo-create/gotsys-repo-create.c >> +++ gotsysd/libexec/gotsys-repo-create/gotsys-repo-create.c >> @@ -56,7 +56,7 @@ >> #include "gotsys.h" >> >> static struct gotsys_conf gotsysconf; >> -static char repos_path[_POSIX_PATH_MAX]; >> +static char repos_path[PATH_MAX]; >> static int repos_dir_fd = -1; >> uid_t gotd_uid; >> gid_t gotd_gid; >> commit - 10f51ecc4cbfab15f63d68920c9674a2995fd394 >> blob - b057df8abd2756d0e491d4a746945a917b55ce82 >> file + gotsysd/libexec/gotsys-useradd/gotsys-useradd.c >> --- gotsysd/libexec/gotsys-useradd/gotsys-useradd.c >> +++ gotsysd/libexec/gotsys-useradd/gotsys-useradd.c >> @@ -548,7 +548,7 @@ add_users(void) >> * put the new users before it, and preserve entries >> * after the yp entry. >> */ >> - if (linelen > 1 && line[0] == '+' & line[1] == ':') { >> + if (linelen > 1 && (line[0] == '+') & (line[1] == ':')) { > > Shouldn't that say && instead of & ? I didn't look too closely at the logic and simply silenced the compiler. Initially I read line[0] == '+' && line[0] == ':' which would point towards using ||, but in this context && makes sense. But not knowing the protocol: I trust your word.> >> yp = 1; >> break; >> } >> >>