Commit 33168a40e8 for bind
commit 33168a40e830ce5eb44cf414cacfa06cb1c96a00
Author: Evan Hunt <each@isc.org>
Date: Mon Oct 5 21:50:49 2026 -0700
account for null terminator when using NAME_MAX
The NAME_MAX value in limits.h is not guaranteed to include space
for the terminating '\0' character in a string. This can cause unexpected
behavior on some platforms, such as a directory scan stopping too soon
if a 255-character filename is encountered.
Buffers intended to hold filenames are now allocated with NAME_MAX + 1
bytes.
diff --git a/lib/dns/dnssec.c b/lib/dns/dnssec.c
index efbc47ae29..36e866aa6a 100644
--- a/lib/dns/dnssec.c
+++ b/lib/dns/dnssec.c
@@ -1683,7 +1683,7 @@ dns_dnssec_keylistfromrdataset(const dns_name_t *origin, dns_kasp_t *kasp,
isc_result_t result2;
isc_buffer_t buf;
- isc_buffer_init(&buf, filename, NAME_MAX);
+ isc_buffer_init(&buf, filename, sizeof(filename));
result2 = dst_key_getfilename(
dst_key_name(dnskey), dst_key_id(dnskey),
dst_key_alg(dnskey),
diff --git a/lib/dns/dst_api.c b/lib/dns/dst_api.c
index 439d7cd610..cb2ee1fd30 100644
--- a/lib/dns/dst_api.c
+++ b/lib/dns/dst_api.c
@@ -471,7 +471,7 @@ isc_result_t
dst_key_fromfile(dns_name_t *name, dns_keytag_t id, unsigned int alg, int type,
const char *directory, isc_mem_t *mctx, dst_key_t **keyp) {
isc_result_t result;
- char filename[NAME_MAX];
+ char filename[NAME_MAX + 1];
isc_buffer_t buf;
dst_key_t *key;
@@ -484,7 +484,7 @@ dst_key_fromfile(dns_name_t *name, dns_keytag_t id, unsigned int alg, int type,
key = NULL;
- isc_buffer_init(&buf, filename, NAME_MAX);
+ isc_buffer_init(&buf, filename, sizeof(filename));
CHECK(dst_key_getfilename(name, id, alg, type, NULL, mctx, &buf));
CHECK(dst_key_fromnamedfile(filename, directory, type, mctx, &key));
CHECK(computeid(key));
@@ -1855,8 +1855,8 @@ write_key_state(const dst_key_t *key, int type, const char *directory) {
FILE *fp;
isc_buffer_t fileb;
isc_buffer_t tmpb;
- char filename[NAME_MAX];
- char tmpname[NAME_MAX];
+ char filename[NAME_MAX + 1];
+ char tmpname[NAME_MAX + 1];
isc_result_t result;
REQUIRE(VALID_KEY(key));
@@ -1937,8 +1937,8 @@ write_public_key(const dst_key_t *key, int type, const char *directory) {
FILE *fp;
isc_buffer_t keyb, tmpb, textb, fileb, classb;
isc_region_t r;
- char tmpname[NAME_MAX];
- char filename[NAME_MAX];
+ char tmpname[NAME_MAX + 1];
+ char filename[NAME_MAX + 1];
unsigned char key_array[DNS_RDATA_MAXLENGTH];
/*
* Big enough for the base64 expansion of the key data with
diff --git a/lib/dns/dst_parse.c b/lib/dns/dst_parse.c
index 6f649d691a..bef7de650c 100644
--- a/lib/dns/dst_parse.c
+++ b/lib/dns/dst_parse.c
@@ -593,8 +593,8 @@ dst__privstruct_writefile(const dst_key_t *key, const dst_private_t *priv,
const char *directory) {
FILE *fp;
isc_result_t result;
- char filename[NAME_MAX];
- char tmpname[NAME_MAX];
+ char filename[NAME_MAX + 1];
+ char tmpname[NAME_MAX + 1];
char buffer[MAXFIELDSIZE * 2];
isc_stdtime_t when;
uint32_t value;
diff --git a/lib/dns/keymgr.c b/lib/dns/keymgr.c
index e634a40689..bcaec81882 100644
--- a/lib/dns/keymgr.c
+++ b/lib/dns/keymgr.c
@@ -2102,7 +2102,7 @@ static void
keymgr_purge_keyfile(dst_key_t *key, int type) {
isc_result_t result;
isc_buffer_t fileb;
- char filename[NAME_MAX];
+ char filename[NAME_MAX + 1];
/*
* Make the filename.
diff --git a/lib/dns/keystore.c b/lib/dns/keystore.c
index 281338de4c..6ef2c2696e 100644
--- a/lib/dns/keystore.c
+++ b/lib/dns/keystore.c
@@ -198,7 +198,7 @@ dns_keystore_keygen(dns_keystore_t *keystore, const dns_name_t *origin,
* could create a new function to convert a name to PKCS#11
* text, but this existing function will suffice.
*/
- char label[NAME_MAX];
+ char label[NAME_MAX + 1];
isc_buffer_t buf;
isc_buffer_init(&buf, label, sizeof(label));
result = buildpkcs11label(uri, origin, policy, flags, &buf);
diff --git a/lib/isc/commandline.c b/lib/isc/commandline.c
index 513f85a92d..f8bc46f079 100644
--- a/lib/isc/commandline.c
+++ b/lib/isc/commandline.c
@@ -64,7 +64,7 @@ int isc_commandline_option;
/*% Argument associated with option. */
char *isc_commandline_argument;
/*% For printing error messages. */
-char isc_commandline_progname[NAME_MAX];
+char isc_commandline_progname[NAME_MAX + 1];
/*% Print error messages. */
bool isc_commandline_errprint = true;
/*% Reset processing. */
diff --git a/lib/isc/include/isc/commandline.h b/lib/isc/include/isc/commandline.h
index a7895a800f..44ede27ce0 100644
--- a/lib/isc/include/isc/commandline.h
+++ b/lib/isc/include/isc/commandline.h
@@ -29,7 +29,7 @@ extern int isc_commandline_option;
/*% Argument associated with option. */
extern char *isc_commandline_argument;
/*% For printing error messages. */
-extern char isc_commandline_progname[NAME_MAX];
+extern char isc_commandline_progname[NAME_MAX + 1];
/*% Print error message. */
extern bool isc_commandline_errprint;
/*% Reset getopt. */
diff --git a/lib/isc/include/isc/dir.h b/lib/isc/include/isc/dir.h
index 2b25b4164f..65eea5b50f 100644
--- a/lib/isc/include/isc/dir.h
+++ b/lib/isc/include/isc/dir.h
@@ -22,7 +22,7 @@
#include <isc/result.h>
#ifndef NAME_MAX
-#define NAME_MAX 256
+#define NAME_MAX 255
#endif
#ifndef PATH_MAX
@@ -31,7 +31,7 @@
/*% Directory Entry */
typedef struct isc_direntry {
- char name[NAME_MAX];
+ char name[NAME_MAX + 1];
unsigned int length;
} isc_direntry_t;