git: d2018cedb414 - main - xdr: Fix xdr_string

From: Dag-Erling Smørgrav <des_at_FreeBSD.org>
Date: Tue, 29 Sep 2026 12:13:31 UTC
The branch main has been updated by des:

URL: https://cgit.FreeBSD.org/src/commit/?id=d2018cedb414ef17e77b7fc2fa19fd81328da46b

commit d2018cedb414ef17e77b7fc2fa19fd81328da46b
Author:     Dag-Erling Smørgrav <des@FreeBSD.org>
AuthorDate: 2026-09-29 12:12:59 +0000
Commit:     Dag-Erling Smørgrav <des@FreeBSD.org>
CommitDate: 2026-09-29 12:12:59 +0000

    xdr: Fix xdr_string
    
    Forcing maxsize to RPC_MAXDATASIZE breaks code that deliberately uses
    XDR with longer strings than permitted by SunRPC.
    
    MFC after:      1 week
    Fixes:          6448ec89e739 (" * limit size of buffers to RPC_MAXDATASIZE")
    Fixes:          e17d7ab869bb ("xdr_string: don't leak strings with xdr_free")
    Sponsored by:   Klara, Inc.
    Sponsored by:   NetApp, Inc.
    Reviewed by:    kevans, brooks
    Differential Revision:  https://reviews.freebsd.org/D59994
---
 lib/libc/xdr/xdr.c | 6 ++----
 sys/xdr/xdr.c      | 6 ++----
 2 files changed, 4 insertions(+), 8 deletions(-)

diff --git a/lib/libc/xdr/xdr.c b/lib/libc/xdr/xdr.c
index 47aafea4bc30..f8cc5267d350 100644
--- a/lib/libc/xdr/xdr.c
+++ b/lib/libc/xdr/xdr.c
@@ -47,8 +47,6 @@
 #include <stdlib.h>
 #include <string.h>
 
-#include <rpc/rpc.h>
-#include <rpc/rpc_com.h>
 #include <rpc/types.h>
 #include <rpc/xdr.h>
 #include "un-namespace.h"
@@ -702,7 +700,7 @@ xdr_string(XDR *xdrs, char **cpp, u_int maxsize)
 		 * be invalid.  Otherwise, if it's very small, we might
 		 * fail to free the string.
 		 */
-		maxsize = RPC_MAXDATASIZE;
+		maxsize = ~0U;
 		/* FALLTHROUGH */
 	case XDR_ENCODE:
 		size = strlen(sp);
@@ -764,7 +762,7 @@ xdr_string(XDR *xdrs, char **cpp, u_int maxsize)
 bool_t
 xdr_wrapstring(XDR *xdrs, char **cpp)
 {
-	return xdr_string(xdrs, cpp, RPC_MAXDATASIZE);
+	return (xdr_string(xdrs, cpp, ~0U));
 }
 
 /*
diff --git a/sys/xdr/xdr.c b/sys/xdr/xdr.c
index f983a474abdd..e012c83104d4 100644
--- a/sys/xdr/xdr.c
+++ b/sys/xdr/xdr.c
@@ -46,8 +46,6 @@
 #include <sys/malloc.h>
 #include <sys/module.h>
 
-#include <rpc/rpc.h>
-#include <rpc/rpc_com.h>
 #include <rpc/types.h>
 #include <rpc/xdr.h>
 
@@ -626,7 +624,7 @@ xdr_string(XDR *xdrs, char **cpp, u_int maxsize)
 		 * be invalid.  Otherwise, if it's very small, we might
 		 * fail to free the string.
 		 */
-		maxsize = RPC_MAXDATASIZE;
+		maxsize = ~0U;
 		/* FALLTHROUGH */
 	case XDR_ENCODE:
 		size = strlen(sp);
@@ -687,7 +685,7 @@ xdr_string(XDR *xdrs, char **cpp, u_int maxsize)
 bool_t
 xdr_wrapstring(XDR *xdrs, char **cpp)
 {
-	return xdr_string(xdrs, cpp, RPC_MAXDATASIZE);
+	return (xdr_string(xdrs, cpp, ~0U));
 }
 
 /*