Bug Summary

File:src/usr.bin/w/w.c
Warning:line 367, column 9
Null pointer passed as 1st argument to string length function

Annotated Source Code

Press '?' to see keyboard shortcuts

clang -cc1 -cc1 -triple amd64-unknown-openbsd7.4 -analyze -disable-free -clear-ast-before-backend -disable-llvm-verifier -discard-value-names -main-file-name w.c -analyzer-checker=core -analyzer-checker=apiModeling -analyzer-checker=unix -analyzer-checker=deadcode -analyzer-checker=security.insecureAPI.UncheckedReturn -analyzer-checker=security.insecureAPI.getpw -analyzer-checker=security.insecureAPI.gets -analyzer-checker=security.insecureAPI.mktemp -analyzer-checker=security.insecureAPI.mkstemp -analyzer-checker=security.insecureAPI.vfork -analyzer-checker=nullability.NullPassedToNonnull -analyzer-checker=nullability.NullReturnedFromNonnull -analyzer-output plist -w -setup-static-analyzer -mrelocation-model pic -pic-level 1 -pic-is-pie -mframe-pointer=all -relaxed-aliasing -ffp-contract=on -fno-rounding-math -mconstructor-aliases -funwind-tables=2 -target-cpu x86-64 -target-feature +retpoline-indirect-calls -target-feature +retpoline-indirect-branches -tune-cpu generic -debugger-tuning=gdb -fcoverage-compilation-dir=/usr/src/usr.bin/w/obj -resource-dir /usr/local/llvm16/lib/clang/16 -internal-isystem /usr/local/llvm16/lib/clang/16/include -internal-externc-isystem /usr/include -O2 -fdebug-compilation-dir=/usr/src/usr.bin/w/obj -ferror-limit 19 -fwrapv -D_RET_PROTECTOR -ret-protector -fcf-protection=branch -fno-jump-tables -fgnuc-version=4.2.1 -vectorize-loops -vectorize-slp -fno-builtin-malloc -fno-builtin-calloc -fno-builtin-realloc -fno-builtin-valloc -fno-builtin-free -fno-builtin-strdup -fno-builtin-strndup -analyzer-output=html -faddrsig -D__GCC_HAVE_DWARF2_CFI_ASM=1 -o /home/ben/Projects/scan/2024-01-11-140451-98009-1 -x c /usr/src/usr.bin/w/w.c
1/* $OpenBSD: w.c,v 1.68 2022/12/04 23:50:50 cheloha Exp $ */
2
3/*-
4 * Copyright (c) 1980, 1991, 1993, 1994
5 * The Regents of the University of California. All rights reserved.
6 *
7 * Redistribution and use in source and binary forms, with or without
8 * modification, are permitted provided that the following conditions
9 * are met:
10 * 1. Redistributions of source code must retain the above copyright
11 * notice, this list of conditions and the following disclaimer.
12 * 2. Redistributions in binary form must reproduce the above copyright
13 * notice, this list of conditions and the following disclaimer in the
14 * documentation and/or other materials provided with the distribution.
15 * 3. Neither the name of the University nor the names of its contributors
16 * may be used to endorse or promote products derived from this software
17 * without specific prior written permission.
18 *
19 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
20 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
21 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
22 * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
23 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
24 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
25 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
26 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
27 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
28 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
29 * SUCH DAMAGE.
30 */
31
32/*
33 * w - print system status (who and what)
34 *
35 * This program is similar to the systat command on Tenex/Tops 10/20
36 *
37 */
38#include <sys/time.h>
39#include <sys/stat.h>
40#include <sys/sysctl.h>
41#include <sys/signal.h>
42#include <sys/proc.h>
43#include <sys/ioctl.h>
44#include <sys/socket.h>
45#include <sys/tty.h>
46
47#include <netinet/in.h>
48#include <arpa/inet.h>
49
50#include <ctype.h>
51#include <err.h>
52#include <errno(*__errno()).h>
53#include <fcntl.h>
54#include <kvm.h>
55#include <netdb.h>
56#include <nlist.h>
57#include <paths.h>
58#include <stdio.h>
59#include <stdlib.h>
60#include <string.h>
61#include <unistd.h>
62#include <limits.h>
63#include <utmp.h>
64#include <vis.h>
65
66#include "extern.h"
67
68struct utmp utmp;
69struct winsize ws;
70kvm_t *kd;
71time_t now; /* the current time of day */
72int ttywidth; /* width of tty */
73int argwidth; /* width of tty */
74int header = 1; /* true if -h flag: don't print heading */
75int nflag = 1; /* true if -n flag: don't convert addrs */
76int sortidle; /* sort by idle time */
77char *sel_user; /* login of particular user selected */
78char domain[HOST_NAME_MAX255+1];
79
80#define NAME_WIDTH8 8
81#define HOST_WIDTH16 16
82
83/*
84 * One of these per active utmp entry.
85 */
86struct entry {
87 struct entry *next;
88 struct utmp utmp;
89 dev_t tdev; /* dev_t of terminal */
90 time_t idle; /* idle time of terminal in seconds */
91 struct kinfo_proc *kp; /* `most interesting' proc */
92} *ep, *ehead = NULL((void *)0), **nextp = &ehead;
93
94static void fmt_putc(int, int *);
95static void fmt_puts(const char *, int *);
96static void pr_args(struct kinfo_proc *);
97static void pr_header(time_t *, int);
98static struct stat
99 *ttystat(char *);
100static void usage(int);
101
102int
103main(int argc, char *argv[])
104{
105 extern char *__progname;
106 struct kinfo_proc *kp;
107 struct hostent *hp;
108 struct stat *stp;
109 FILE *ut;
110 struct in_addr addr;
111 int ch, i, nentries, nusers, wcmd;
112 char *memf, *nlistf, *p, *x;
113 char buf[HOST_NAME_MAX255+1], errbuf[_POSIX2_LINE_MAX2048];
114
115 /* Are we w(1) or uptime(1)? */
116 p = __progname;
117 if (*p == '-')
1
Assuming the condition is false
118 p++;
119 if (p[0] == 'w' && p[1] == '\0') {
2
Assuming the condition is true
3
Assuming the condition is true
4
Taking true branch
120 wcmd = 1;
121 p = "hiflM:N:asuw";
122 } else if (!strcmp(p, "uptime")) {
123 wcmd = 0;
124 p = "";
125 } else
126 errx(1,
127 "this program should be invoked only as \"w\" or \"uptime\"");
128
129 memf = nlistf = NULL((void *)0);
130 while ((ch = getopt(argc, argv, p)) != -1)
5
Assuming the condition is false
6
Loop condition is false. Execution continues on line 154
131 switch (ch) {
132 case 'h':
133 header = 0;
134 break;
135 case 'i':
136 sortidle = 1;
137 break;
138 case 'M':
139 header = 0;
140 memf = optarg;
141 break;
142 case 'N':
143 nlistf = optarg;
144 break;
145 case 'a':
146 nflag = 0;
147 break;
148 case 'f': case 'l': case 's': case 'u': case 'w':
149 warnx("[-flsuw] no longer supported");
150 /* FALLTHROUGH */
151 default:
152 usage(wcmd);
153 }
154 argc -= optind;
155 argv += optind;
156
157 if (nflag
6.1
'nflag' is not equal to 0
== 0) {
7
Taking false branch
158 if (pledge("stdio tty rpath dns ps vminfo", NULL((void *)0)) == -1)
159 err(1, "pledge");
160 } else {
161 if (pledge("stdio tty rpath ps vminfo", NULL((void *)0)) == -1)
8
Assuming the condition is false
162 err(1, "pledge");
163 }
164
165 if (nlistf
8.1
'nlistf' is equal to NULL
== NULL((void *)0) && memf
8.2
'memf' is equal to NULL
== NULL((void *)0)) {
9
Taking true branch
166 if ((kd = kvm_openfiles(nlistf, memf, NULL((void *)0), KVM_NO_FILES0x80000000,
10
Assuming the condition is false
11
Taking false branch
167 errbuf)) == NULL((void *)0))
168 errx(1, "%s", errbuf);
169 } else {
170 if ((kd = kvm_openfiles(nlistf, memf, NULL((void *)0), O_RDONLY0x0000, errbuf)) == NULL((void *)0))
171 errx(1, "%s", errbuf);
172 }
173
174 (void)time(&now);
175 if ((ut = fopen(_PATH_UTMP"/var/run/utmp", "r")) == NULL((void *)0))
12
Assuming the condition is false
13
Taking false branch
176 err(1, "%s", _PATH_UTMP"/var/run/utmp");
177
178 if (*argv)
14
Assuming the condition is false
15
Taking false branch
179 sel_user = *argv;
180
181 for (nusers = 0; fread(&utmp, sizeof(utmp), 1, ut);) {
16
Loop condition is true. Entering loop body
28
Loop condition is false. Execution continues on line 214
182 if (utmp.ut_name[0] == '\0')
17
Assuming the condition is false
18
Taking false branch
183 continue;
184 ++nusers;
185 if (wcmd
18.1
'wcmd' is not equal to 0
== 0 || (sel_user &&
19
Assuming 'sel_user' is null
186 strncmp(utmp.ut_name, sel_user, UT_NAMESIZE32) != 0))
187 continue;
188 if ((ep = calloc(1, sizeof(*ep))) == NULL((void *)0))
20
Assuming the condition is false
21
Taking false branch
189 err(1, NULL((void *)0));
190 *nextp = ep;
191 nextp = &(ep->next);
192 memcpy(&(ep->utmp), &utmp, sizeof(utmp));
193 if (!(stp = ttystat(ep->utmp.ut_line)))
22
Assuming 'stp' is non-null
23
Taking false branch
194 continue;
195 ep->tdev = stp->st_rdev;
196
197 /*
198 * If this is the console device, attempt to ascertain
199 * the true console device dev_t.
200 */
201 if (ep->tdev == 0) {
24
Assuming field 'tdev' is not equal to 0
25
Taking false branch
202 int mib[2];
203 size_t size;
204
205 mib[0] = CTL_KERN1;
206 mib[1] = KERN_CONSDEV75;
207 size = sizeof(dev_t);
208 (void) sysctl(mib, 2, &ep->tdev, &size, NULL((void *)0), 0);
209 }
210
211 if ((ep->idle = now - stp->st_atimest_atim.tv_sec) < 0)
26
Assuming the condition is false
27
Taking false branch
212 ep->idle = 0;
213 }
214 (void)fclose(ut);
215
216 if (header || wcmd
29.1
'wcmd' is not equal to 0
== 0) {
29
Assuming 'header' is 0
30
Taking false branch
217 pr_header(&now, nusers);
218 if (wcmd == 0)
219 exit (0);
220 }
221
222#define HEADER"USER TTY FROM LOGIN@ IDLE WHAT" "USER TTY FROM LOGIN@ IDLE WHAT"
223#define WUSED(sizeof("USER TTY FROM LOGIN@ IDLE WHAT") - sizeof
("WHAT"))
(sizeof(HEADER"USER TTY FROM LOGIN@ IDLE WHAT") - sizeof("WHAT"))
224 if (header
30.1
'header' is 0
)
31
Taking false branch
225 (void)puts(HEADER"USER TTY FROM LOGIN@ IDLE WHAT");
226
227 kp = kvm_getprocs(kd, KERN_PROC_ALL0, 0, sizeof(*kp), &nentries);
228 if (kp == NULL((void *)0))
32
Assuming 'kp' is not equal to NULL
229 errx(1, "%s", kvm_geterr(kd));
230
231 if ((ioctl(STDOUT_FILENO1, TIOCGWINSZ((unsigned long)0x40000000 | ((sizeof(struct winsize) & 0x1fff
) << 16) | ((('t')) << 8) | ((104)))
, &ws) == -1
&&
33
Assuming the condition is false
35
Taking false branch
232 ioctl(STDERR_FILENO2, TIOCGWINSZ((unsigned long)0x40000000 | ((sizeof(struct winsize) & 0x1fff
) << 16) | ((('t')) << 8) | ((104)))
, &ws) == -1 &&
233 ioctl(STDIN_FILENO0, TIOCGWINSZ((unsigned long)0x40000000 | ((sizeof(struct winsize) & 0x1fff
) << 16) | ((('t')) << 8) | ((104)))
, &ws) == -1) || ws.ws_col == 0)
34
Assuming field 'ws_col' is not equal to 0
234 ttywidth = 79;
235 else
236 ttywidth = ws.ws_col - 1;
237 argwidth = ttywidth - WUSED(sizeof("USER TTY FROM LOGIN@ IDLE WHAT") - sizeof
("WHAT"))
;
238 if (argwidth < 4)
36
Assuming 'argwidth' is >= 4
37
Taking false branch
239 argwidth = 8;
240
241 for (i = 0; i < nentries; i++, kp++) {
38
Assuming 'i' is >= 'nentries'
242 if (kp->p_psflags & (PS_EMBRYO0x00020000 | PS_ZOMBIE0x00040000))
243 continue;
244 for (ep = ehead; ep != NULL((void *)0); ep = ep->next) {
245 /* ftp is a special case. */
246 if (strncmp(ep->utmp.ut_line, "ftp", 3) == 0) {
247 char pidstr[UT_LINESIZE8-2];
248 pid_t fp;
249
250 (void)strncpy(pidstr, &ep->utmp.ut_line[3],
251 sizeof(pidstr) - 1);
252 pidstr[sizeof(pidstr) - 1] = '\0';
253 fp = (pid_t)strtol(pidstr, NULL((void *)0), 10);
254 if (kp->p_pid == fp) {
255 ep->kp = kp;
256 break;
257 }
258 } else if (ep->tdev == kp->p_tdev &&
259 kp->p__pgid == kp->p_tpgid) {
260 /*
261 * Proc is in foreground of this terminal
262 */
263 if (proc_compare(ep->kp, kp))
264 ep->kp = kp;
265 break;
266 }
267 }
268 }
269 /* sort by idle time */
270 if (sortidle && ehead != NULL((void *)0)) {
39
Assuming 'sortidle' is 0
271 struct entry *from = ehead, *save;
272
273 ehead = NULL((void *)0);
274 while (from != NULL((void *)0)) {
275 for (nextp = &ehead;
276 (*nextp) && from->idle >= (*nextp)->idle;
277 nextp = &(*nextp)->next)
278 continue;
279 save = from;
280 from = from->next;
281 save->next = *nextp;
282 *nextp = save;
283 }
284 }
285
286 if (!nflag) {
40
Assuming 'nflag' is not equal to 0
41
Taking false branch
287 if (gethostname(domain, sizeof(domain)) == -1 ||
288 (p = strchr(domain, '.')) == 0)
289 domain[0] = '\0';
290 else {
291 domain[sizeof(domain) - 1] = '\0';
292 memmove(domain, p, strlen(p) + 1);
293 }
294 }
295
296 for (ep = ehead; ep != NULL((void *)0); ep = ep->next) {
42
Assuming 'ep' is not equal to NULL
297 p = *ep->utmp.ut_host ? ep->utmp.ut_host : "-";
43
Loop condition is true. Entering loop body
44
Assuming the condition is false
45
'?' condition is false
298 for (x = NULL((void *)0), i = 0; p[i] != '\0' && i < UT_HOSTSIZE256; i++)
46
Loop condition is true. Entering loop body
299 if (p[i] == ':') {
47
Taking false branch
300 x = &p[i];
301 *x++ = '\0';
302 break;
303 }
304 if (!nflag
47.1
'nflag' is not equal to 0
&& inet_aton(p, &addr) &&
305 (hp = gethostbyaddr((char *)&addr, sizeof(addr), AF_INET2))) {
306 if (domain[0] != '\0') {
307 p = hp->h_name;
308 p += strlen(hp->h_name);
309 p -= strlen(domain);
310 if (p > hp->h_name &&
311 strcasecmp(p, domain) == 0)
312 *p = '\0';
313 }
314 p = hp->h_name;
315 }
316 if (x
47.2
'x' is null
) {
48
Taking false branch
317 (void)snprintf(buf, sizeof(buf), "%s:%.*s", p,
318 (int)(ep->utmp.ut_host + UT_HOSTSIZE256 - x), x);
319 p = buf;
320 }
321 (void)printf("%-*.*s %-2.2s %-*.*s ",
322 NAME_WIDTH8, UT_NAMESIZE32, ep->utmp.ut_name,
323 strncmp(ep->utmp.ut_line, "tty", 3) ?
49
Assuming the condition is false
50
'?' condition is false
324 ep->utmp.ut_line : ep->utmp.ut_line + 3,
325 HOST_WIDTH16, HOST_WIDTH16, *p ? p : "-");
51
'?' condition is true
326 pr_attime(&ep->utmp.ut_time, &now);
327 pr_idle(ep->idle);
328 pr_args(ep->kp);
52
Calling 'pr_args'
329 printf("\n");
330 }
331 exit(0);
332}
333
334static void
335fmt_putc(int c, int *leftp)
336{
337
338 if (*leftp == 0)
339 return;
340 if (*leftp != -1)
341 *leftp -= 1;
342 putchar(c)(!__isthreaded ? __sputc(c, (&__sF[1])) : (putc)(c, (&
__sF[1])))
;
343}
344
345static void
346fmt_puts(const char *s, int *leftp)
347{
348 static char *v = NULL((void *)0);
63
'v' initialized to a null pointer value
349 static size_t maxlen = 0;
350 size_t len;
351
352 if (*leftp == 0)
64
Assuming the condition is false
65
Taking false branch
353 return;
354 len = strlen(s) * 4 + 1;
355 if (len > maxlen) {
66
Assuming 'len' is <= 'maxlen'
67
Taking false branch
356 free(v);
357 maxlen = 0;
358 if (len < getpagesize())
359 len = getpagesize();
360 v = malloc(len);
361 if (v == NULL((void *)0))
362 return;
363 maxlen = len;
364 }
365 strvis(v, s, VIS_TAB0x08 | VIS_NL0x10 | VIS_CSTYLE0x02);
366 if (*leftp != -1) {
68
Assuming the condition is true
69
Taking true branch
367 len = strlen(v);
70
Null pointer passed as 1st argument to string length function
368 if (len > *leftp) {
369 v[*leftp] = '\0';
370 *leftp = 0;
371 } else
372 *leftp -= len;
373 }
374 printf("%s", v);
375}
376
377
378static void
379pr_args(struct kinfo_proc *kp)
380{
381 char **argv, *str;
382 int left;
383
384 if (kp == NULL((void *)0))
53
Assuming 'kp' is not equal to NULL
54
Taking false branch
385 goto nothing; /* no matching process found */
386 left = argwidth;
387 argv = kvm_getargv(kd, kp, argwidth+60); /* +60 for ftpd snip */
388 if (argv == NULL((void *)0))
55
Assuming 'argv' is not equal to NULL
389 goto nothing;
390
391 if (*argv == NULL((void *)0) || **argv == '\0') {
56
Assuming the condition is false
57
Assuming the condition is false
58
Taking false branch
392 /* Process has zeroed argv[0], display executable name. */
393 fmt_putc('(', &left);
394 fmt_puts(kp->p_comm, &left);
395 fmt_putc(')', &left);
396 }
397 while (*argv) {
59
Loop condition is true. Entering loop body
398 /*
399 * ftp argv[0] is in the following format:
400 * ftpd: HOSTNAME: [USER/PASS: ]CMD args (ftpd)
401 */
402 if (strncmp(*argv, "ftpd:", 5) == 0) {
60
Assuming the condition is false
61
Taking false branch
403 if ((str = strchr(*argv + 5, ':')) != NULL((void *)0))
404 str = strchr(str + 1, ':');
405 if (str != NULL((void *)0)) {
406 if ((str[0] == ':') &&
407 isspace((unsigned char)str[1]))
408 str += 2;
409 fmt_puts(str, &left);
410 } else
411 fmt_puts(*argv, &left);
412 } else
413 fmt_puts(*argv, &left);
62
Calling 'fmt_puts'
414 argv++;
415 fmt_putc(' ', &left);
416 }
417 return;
418nothing:
419 putchar('-')(!__isthreaded ? __sputc('-', (&__sF[1])) : (putc)('-', (
&__sF[1])))
;
420}
421
422static void
423pr_header(time_t *nowp, int nusers)
424{
425 double avenrun[3];
426 struct timespec boottime;
427 time_t uptime;
428 int days, hrs, i, mins;
429 char buf[256];
430
431 /*
432 * Print time of day.
433 */
434 (void)strftime(buf, sizeof(buf) - 1, "%l:%M%p", localtime(nowp));
435 buf[sizeof(buf) - 1] = '\0';
436 (void)printf("%s ", buf);
437
438 /*
439 * Print how long system has been up.
440 */
441 if (clock_gettime(CLOCK_BOOTTIME6, &boottime) != -1) {
442 uptime = boottime.tv_sec;
443 if (uptime > 59) {
444 uptime += 30;
445 days = uptime / SECSPERDAY(24 * 60 * 60);
446 uptime %= SECSPERDAY(24 * 60 * 60);
447 hrs = uptime / SECSPERHOUR(60 * 60);
448 uptime %= SECSPERHOUR(60 * 60);
449 mins = uptime / 60;
450 (void)printf(" up");
451 if (days > 0)
452 (void)printf(" %d day%s,", days,
453 days > 1 ? "s" : "");
454 if (hrs > 0 && mins > 0)
455 (void)printf(" %2d:%02d,", hrs, mins);
456 else {
457 if (hrs > 0)
458 (void)printf(" %d hr%s,",
459 hrs, hrs > 1 ? "s" : "");
460 if (mins > 0 || (days == 0 && hrs == 0))
461 (void)printf(" %d min%s,",
462 mins, mins != 1 ? "s" : "");
463 }
464 } else
465 printf(" %d secs,", (int)uptime);
466 }
467
468 /* Print number of users logged in to system */
469 (void)printf(" %d user%s", nusers, nusers != 1 ? "s" : "");
470
471 /*
472 * Print 1, 5, and 15 minute load averages.
473 */
474 if (getloadavg(avenrun, sizeof(avenrun) / sizeof(avenrun[0])) == -1)
475 (void)printf(", no load average information available\n");
476 else {
477 (void)printf(", load averages:");
478 for (i = 0; i < (sizeof(avenrun) / sizeof(avenrun[0])); i++) {
479 if (i > 0)
480 (void)printf(",");
481 (void)printf(" %.2f", avenrun[i]);
482 }
483 (void)printf("\n");
484 }
485}
486
487static struct stat *
488ttystat(char *line)
489{
490 static struct stat sb;
491 char ttybuf[sizeof(_PATH_DEV"/dev/") + UT_LINESIZE8];
492
493 /* Note, line may not be NUL-terminated */
494 (void)strlcpy(ttybuf, _PATH_DEV"/dev/", sizeof(ttybuf));
495 (void)strncat(ttybuf, line, sizeof(ttybuf) - 1 - strlen(ttybuf));
496 if (stat(ttybuf, &sb))
497 return (NULL((void *)0));
498 return (&sb);
499}
500
501static void
502usage(int wcmd)
503{
504 if (wcmd)
505 (void)fprintf(stderr(&__sF[2]),
506 "usage: w [-ahi] [-M core] [-N system] [user]\n");
507 else
508 (void)fprintf(stderr(&__sF[2]),
509 "usage: uptime\n");
510 exit (1);
511}