* [PATCH 1/3] platform/olpc: Reserve space for a string terminator
2026-09-26 12:12 [PATCH 0/3] debugfs: Reserve space for string terminators Jiale Yao
@ 2026-09-26 12:12 ` Jiale Yao
2026-09-26 12:12 ` [PATCH 2/3] wifi: ath12k: " Jiale Yao
` (2 subsequent siblings)
3 siblings, 0 replies; 14+ messages in thread
From: Jiale Yao @ 2026-09-26 12:12 UTC (permalink / raw)
To: Hans de Goede, Ilpo Järvinen, Andres Salomon,
Thomas Gleixner, Paul Fox, platform-driver-x86, linux-kernel
Cc: Jiale Yao
ec_dbgfs_cmd_write() copies user input into a zero-initialized stack
buffer and passes it to sscanf(). A write that fills the entire buffer
overwrites its only terminator, so the subsequent parsing can read beyond
the buffer.
Limit the copy to leave room for the trailing NUL.
Fixes: 6cca83d498bd ("Platform: OLPC: move debugfs support from x86 EC driver")
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/platform/olpc/olpc-ec.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/platform/olpc/olpc-ec.c b/drivers/platform/olpc/olpc-ec.c
index 4a2d36f7331e..063f7e55c421 100644
--- a/drivers/platform/olpc/olpc-ec.c
+++ b/drivers/platform/olpc/olpc-ec.c
@@ -269,7 +269,7 @@ static ssize_t ec_dbgfs_cmd_write(struct file *file, const char __user *buf,
mutex_lock(&ec_dbgfs_lock);
- size = simple_write_to_buffer(cmdbuf, sizeof(cmdbuf), ppos, buf, size);
+ size = simple_write_to_buffer(cmdbuf, sizeof(cmdbuf) - 1, ppos, buf, size);
m = sscanf(cmdbuf, "%x:%u %x %x %x %x %x", &ec_cmd_int[0],
&ec_dbgfs_resp_bytes, &ec_cmd_int[1], &ec_cmd_int[2],
--
2.34.1
^ permalink raw reply related [flat|nested] 14+ messages in thread* [PATCH 2/3] wifi: ath12k: Reserve space for a string terminator
2026-09-26 12:12 [PATCH 0/3] debugfs: Reserve space for string terminators Jiale Yao
2026-09-26 12:12 ` [PATCH 1/3] platform/olpc: Reserve space for a string terminator Jiale Yao
@ 2026-09-26 12:12 ` Jiale Yao
2026-09-26 12:33 ` Dan Carpenter
` (3 more replies)
2026-09-26 12:12 ` [PATCH 3/3] dmaengine: xilinx: dpdma: " Jiale Yao
2026-10-08 17:38 ` [PATCH 0/3] debugfs: Reserve space for string terminators Ilpo Järvinen
3 siblings, 4 replies; 14+ messages in thread
From: Jiale Yao @ 2026-09-26 12:12 UTC (permalink / raw)
To: Jeff Johnson, Vasanthakumar Thiagarajan, Dan Carpenter,
linux-wireless, ath12k, linux-kernel
Cc: Jiale Yao
ath12k_write_htt_stats_type() accepts count == size, which fills the
zero-initialized buffer without a terminating NUL. sscanf() then reads
beyond the buffer.
Reject input that leaves no room for the trailing NUL.
Fixes: 8c7a5031a6b0 ("wifi: ath12k: Fix buffer overflow in debugfs")
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c b/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
index b772181a496e..f84f1828275a 100644
--- a/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
+++ b/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
@@ -6190,7 +6190,7 @@ static ssize_t ath12k_write_htt_stats_type(struct file *file,
const int size = 32;
int num_args;
- if (count > size)
+ if (count >= size)
return -EINVAL;
char *buf __free(kfree) = kzalloc(size, GFP_KERNEL);
--
2.34.1
^ permalink raw reply related [flat|nested] 14+ messages in thread* Re: [PATCH 2/3] wifi: ath12k: Reserve space for a string terminator
2026-09-26 12:12 ` [PATCH 2/3] wifi: ath12k: " Jiale Yao
@ 2026-09-26 12:33 ` Dan Carpenter
2026-09-28 17:36 ` Rameshkumar Sundaram
` (2 subsequent siblings)
3 siblings, 0 replies; 14+ messages in thread
From: Dan Carpenter @ 2026-09-26 12:33 UTC (permalink / raw)
To: Jiale Yao
Cc: Jeff Johnson, Vasanthakumar Thiagarajan, linux-wireless, ath12k,
linux-kernel
On Sat, Sep 26, 2026 at 08:12:49PM +0800, Jiale Yao wrote:
> ath12k_write_htt_stats_type() accepts count == size, which fills the
> zero-initialized buffer without a terminating NUL. sscanf() then reads
> beyond the buffer.
>
> Reject input that leaves no room for the trailing NUL.
>
> Fixes: 8c7a5031a6b0 ("wifi: ath12k: Fix buffer overflow in debugfs")
> Signed-off-by: Jiale Yao <yaojiale02@163.com>
> ---
Reviewed-by: Dan Carpenter <error27@gmail.com>
regards,
dan carpenter
^ permalink raw reply [flat|nested] 14+ messages in thread* Re: [PATCH 2/3] wifi: ath12k: Reserve space for a string terminator
2026-09-26 12:12 ` [PATCH 2/3] wifi: ath12k: " Jiale Yao
2026-09-26 12:33 ` Dan Carpenter
@ 2026-09-28 17:36 ` Rameshkumar Sundaram
2026-09-29 2:35 ` Baochen Qiang
2026-10-03 23:07 ` Jeff Johnson
3 siblings, 0 replies; 14+ messages in thread
From: Rameshkumar Sundaram @ 2026-09-28 17:36 UTC (permalink / raw)
To: Jiale Yao, Jeff Johnson, Vasanthakumar Thiagarajan, Dan Carpenter,
linux-wireless, ath12k, linux-kernel
On 9/26/2026 5:42 PM, Jiale Yao wrote:
> ath12k_write_htt_stats_type() accepts count == size, which fills the
> zero-initialized buffer without a terminating NUL. sscanf() then reads
> beyond the buffer.
>
> Reject input that leaves no room for the trailing NUL.
>
> Fixes: 8c7a5031a6b0 ("wifi: ath12k: Fix buffer overflow in debugfs")
> Signed-off-by: Jiale Yao <yaojiale02@163.com>
> ---
> drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c b/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> index b772181a496e..f84f1828275a 100644
> --- a/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> +++ b/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> @@ -6190,7 +6190,7 @@ static ssize_t ath12k_write_htt_stats_type(struct file *file,
> const int size = 32;
> int num_args;
>
> - if (count > size)
> + if (count >= size)
> return -EINVAL;
>
> char *buf __free(kfree) = kzalloc(size, GFP_KERNEL);
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
^ permalink raw reply [flat|nested] 14+ messages in thread* Re: [PATCH 2/3] wifi: ath12k: Reserve space for a string terminator
2026-09-26 12:12 ` [PATCH 2/3] wifi: ath12k: " Jiale Yao
2026-09-26 12:33 ` Dan Carpenter
2026-09-28 17:36 ` Rameshkumar Sundaram
@ 2026-09-29 2:35 ` Baochen Qiang
2026-10-03 23:07 ` Jeff Johnson
3 siblings, 0 replies; 14+ messages in thread
From: Baochen Qiang @ 2026-09-29 2:35 UTC (permalink / raw)
To: Jiale Yao, Jeff Johnson, Vasanthakumar Thiagarajan, Dan Carpenter,
linux-wireless, ath12k, linux-kernel
On 9/26/2026 8:12 PM, Jiale Yao wrote:
> ath12k_write_htt_stats_type() accepts count == size, which fills the
> zero-initialized buffer without a terminating NUL. sscanf() then reads
> beyond the buffer.
>
> Reject input that leaves no room for the trailing NUL.
>
> Fixes: 8c7a5031a6b0 ("wifi: ath12k: Fix buffer overflow in debugfs")
> Signed-off-by: Jiale Yao <yaojiale02@163.com>
> ---
> drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c b/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> index b772181a496e..f84f1828275a 100644
> --- a/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> +++ b/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> @@ -6190,7 +6190,7 @@ static ssize_t ath12k_write_htt_stats_type(struct file *file,
> const int size = 32;
> int num_args;
>
> - if (count > size)
> + if (count >= size)
> return -EINVAL;
>
> char *buf __free(kfree) = kzalloc(size, GFP_KERNEL);
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
^ permalink raw reply [flat|nested] 14+ messages in thread* Re: [PATCH 2/3] wifi: ath12k: Reserve space for a string terminator
2026-09-26 12:12 ` [PATCH 2/3] wifi: ath12k: " Jiale Yao
` (2 preceding siblings ...)
2026-09-29 2:35 ` Baochen Qiang
@ 2026-10-03 23:07 ` Jeff Johnson
3 siblings, 0 replies; 14+ messages in thread
From: Jeff Johnson @ 2026-10-03 23:07 UTC (permalink / raw)
To: Jiale Yao, Jeff Johnson, Vasanthakumar Thiagarajan, Dan Carpenter,
linux-wireless, ath12k, linux-kernel
On 9/26/2026 5:12 AM, Jiale Yao wrote:
> ath12k_write_htt_stats_type() accepts count == size, which fills the
> zero-initialized buffer without a terminating NUL. sscanf() then reads
> beyond the buffer.
>
> Reject input that leaves no room for the trailing NUL.
>
> Fixes: 8c7a5031a6b0 ("wifi: ath12k: Fix buffer overflow in debugfs")
> Signed-off-by: Jiale Yao <yaojiale02@163.com>
> ---
> drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c b/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> index b772181a496e..f84f1828275a 100644
> --- a/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> +++ b/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> @@ -6190,7 +6190,7 @@ static ssize_t ath12k_write_htt_stats_type(struct file *file,
> const int size = 32;
> int num_args;
>
> - if (count > size)
> + if (count >= size)
> return -EINVAL;
>
> char *buf __free(kfree) = kzalloc(size, GFP_KERNEL);
Documenting this was reposted as a standalone patch:
https://msgid.link/20261003095913.575108-1-yaojiale02@163.com
I'm taking that patch through the ath tree.
/jeff
^ permalink raw reply [flat|nested] 14+ messages in thread
* [PATCH 3/3] dmaengine: xilinx: dpdma: Reserve space for a string terminator
2026-09-26 12:12 [PATCH 0/3] debugfs: Reserve space for string terminators Jiale Yao
2026-09-26 12:12 ` [PATCH 1/3] platform/olpc: Reserve space for a string terminator Jiale Yao
2026-09-26 12:12 ` [PATCH 2/3] wifi: ath12k: " Jiale Yao
@ 2026-09-26 12:12 ` Jiale Yao
2026-09-26 14:34 ` Laurent Pinchart
2026-10-08 17:38 ` [PATCH 0/3] debugfs: Reserve space for string terminators Ilpo Järvinen
3 siblings, 1 reply; 14+ messages in thread
From: Jiale Yao @ 2026-09-26 12:12 UTC (permalink / raw)
To: Laurent Pinchart, Vinod Koul, Frank Li, Michal Simek, Hyun Kwon,
dmaengine, linux-arm-kernel, linux-kernel
Cc: Jiale Yao
xilinx_dpdma_debugfs_write() allocates a buffer of size bytes, and
strncpy_from_user() can fill it without a terminating NUL when the input
has no NUL in the copied range. strsep() and strcasecmp() then read
beyond the buffer.
Allocate an extra byte and keep that byte zero-initialized, so the input
copied remains unchanged and the buffer is always terminated.
Fixes: 1d220435cab3 ("dmaengine: xilinx: dpdma: Add debugfs support")
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/dma/xilinx/xilinx_dpdma.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/dma/xilinx/xilinx_dpdma.c b/drivers/dma/xilinx/xilinx_dpdma.c
index d9a3542c4531..b61ef3062d84 100644
--- a/drivers/dma/xilinx/xilinx_dpdma.c
+++ b/drivers/dma/xilinx/xilinx_dpdma.c
@@ -410,7 +410,7 @@ static ssize_t xilinx_dpdma_debugfs_write(struct file *f,
if (dpdma_debugfs.testcase != DPDMA_TC_NONE)
return -EBUSY;
- kern_buff = kzalloc(size, GFP_KERNEL);
+ kern_buff = kzalloc(size + 1, GFP_KERNEL);
if (!kern_buff)
return -ENOMEM;
kern_buff_start = kern_buff;
--
2.34.1
^ permalink raw reply related [flat|nested] 14+ messages in thread* Re: [PATCH 3/3] dmaengine: xilinx: dpdma: Reserve space for a string terminator
2026-09-26 12:12 ` [PATCH 3/3] dmaengine: xilinx: dpdma: " Jiale Yao
@ 2026-09-26 14:34 ` Laurent Pinchart
2026-10-01 20:50 ` Frank Li
0 siblings, 1 reply; 14+ messages in thread
From: Laurent Pinchart @ 2026-09-26 14:34 UTC (permalink / raw)
To: Jiale Yao
Cc: Vinod Koul, Frank Li, Michal Simek, Hyun Kwon, dmaengine,
linux-arm-kernel, linux-kernel
On Sat, Sep 26, 2026 at 08:12:50PM +0800, Jiale Yao wrote:
> xilinx_dpdma_debugfs_write() allocates a buffer of size bytes, and
> strncpy_from_user() can fill it without a terminating NUL when the input
> has no NUL in the copied range. strsep() and strcasecmp() then read
> beyond the buffer.
strncpy() has long been considered unsafe, and has finally been removed
from the kernel in v7.2. A better fix would be to similarly replace
strncpy_from_user() with a safe equivalent.
> Allocate an extra byte and keep that byte zero-initialized, so the input
> copied remains unchanged and the buffer is always terminated.
>
> Fixes: 1d220435cab3 ("dmaengine: xilinx: dpdma: Add debugfs support")
> Signed-off-by: Jiale Yao <yaojiale02@163.com>
> ---
> drivers/dma/xilinx/xilinx_dpdma.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/dma/xilinx/xilinx_dpdma.c b/drivers/dma/xilinx/xilinx_dpdma.c
> index d9a3542c4531..b61ef3062d84 100644
> --- a/drivers/dma/xilinx/xilinx_dpdma.c
> +++ b/drivers/dma/xilinx/xilinx_dpdma.c
> @@ -410,7 +410,7 @@ static ssize_t xilinx_dpdma_debugfs_write(struct file *f,
> if (dpdma_debugfs.testcase != DPDMA_TC_NONE)
> return -EBUSY;
>
> - kern_buff = kzalloc(size, GFP_KERNEL);
> + kern_buff = kzalloc(size + 1, GFP_KERNEL);
> if (!kern_buff)
> return -ENOMEM;
> kern_buff_start = kern_buff;
--
Regards,
Laurent Pinchart
^ permalink raw reply [flat|nested] 14+ messages in thread* Re: [PATCH 3/3] dmaengine: xilinx: dpdma: Reserve space for a string terminator
2026-09-26 14:34 ` Laurent Pinchart
@ 2026-10-01 20:50 ` Frank Li
2026-10-01 21:00 ` Laurent Pinchart
0 siblings, 1 reply; 14+ messages in thread
From: Frank Li @ 2026-10-01 20:50 UTC (permalink / raw)
To: Laurent Pinchart
Cc: Jiale Yao, Vinod Koul, Frank Li, Michal Simek, Hyun Kwon,
dmaengine, linux-arm-kernel, linux-kernel
On Sat, Sep 26, 2026 at 05:34:15PM +0300, Laurent Pinchart wrote:
> On Sat, Sep 26, 2026 at 08:12:50PM +0800, Jiale Yao wrote:
> > xilinx_dpdma_debugfs_write() allocates a buffer of size bytes, and
> > strncpy_from_user() can fill it without a terminating NUL when the input
> > has no NUL in the copied range. strsep() and strcasecmp() then read
> > beyond the buffer.
>
> strncpy() has long been considered unsafe, and has finally been removed
> from the kernel in v7.2. A better fix would be to similarly replace
> strncpy_from_user() with a safe equivalent.
Do you means use strndup_user()?
Frank
>
> > Allocate an extra byte and keep that byte zero-initialized, so the input
> > copied remains unchanged and the buffer is always terminated.
> >
> > Fixes: 1d220435cab3 ("dmaengine: xilinx: dpdma: Add debugfs support")
> > Signed-off-by: Jiale Yao <yaojiale02@163.com>
> > ---
> > drivers/dma/xilinx/xilinx_dpdma.c | 2 +-
> > 1 file changed, 1 insertion(+), 1 deletion(-)
> >
> > diff --git a/drivers/dma/xilinx/xilinx_dpdma.c b/drivers/dma/xilinx/xilinx_dpdma.c
> > index d9a3542c4531..b61ef3062d84 100644
> > --- a/drivers/dma/xilinx/xilinx_dpdma.c
> > +++ b/drivers/dma/xilinx/xilinx_dpdma.c
> > @@ -410,7 +410,7 @@ static ssize_t xilinx_dpdma_debugfs_write(struct file *f,
> > if (dpdma_debugfs.testcase != DPDMA_TC_NONE)
> > return -EBUSY;
> >
> > - kern_buff = kzalloc(size, GFP_KERNEL);
> > + kern_buff = kzalloc(size + 1, GFP_KERNEL);
> > if (!kern_buff)
> > return -ENOMEM;
> > kern_buff_start = kern_buff;
>
> --
> Regards,
>
> Laurent Pinchart
^ permalink raw reply [flat|nested] 14+ messages in thread* Re: [PATCH 3/3] dmaengine: xilinx: dpdma: Reserve space for a string terminator
2026-10-01 20:50 ` Frank Li
@ 2026-10-01 21:00 ` Laurent Pinchart
2026-10-03 10:09 ` jiale yao
0 siblings, 1 reply; 14+ messages in thread
From: Laurent Pinchart @ 2026-10-01 21:00 UTC (permalink / raw)
To: Frank Li
Cc: Jiale Yao, Vinod Koul, Frank Li, Michal Simek, Hyun Kwon,
dmaengine, linux-arm-kernel, linux-kernel
On Thu, Oct 01, 2026 at 04:50:23PM -0400, Frank Li wrote:
> On Sat, Sep 26, 2026 at 05:34:15PM +0300, Laurent Pinchart wrote:
> > On Sat, Sep 26, 2026 at 08:12:50PM +0800, Jiale Yao wrote:
> > > xilinx_dpdma_debugfs_write() allocates a buffer of size bytes, and
> > > strncpy_from_user() can fill it without a terminating NUL when the input
> > > has no NUL in the copied range. strsep() and strcasecmp() then read
> > > beyond the buffer.
> >
> > strncpy() has long been considered unsafe, and has finally been removed
> > from the kernel in v7.2. A better fix would be to similarly replace
> > strncpy_from_user() with a safe equivalent.
>
> Do you means use strndup_user()?
I was thinking about adding a strscpy_user(), but a dup version could
possibly be interesting too if there are enough users that call
k[zm]alloc + strncpy_from_user.
> > > Allocate an extra byte and keep that byte zero-initialized, so the input
> > > copied remains unchanged and the buffer is always terminated.
> > >
> > > Fixes: 1d220435cab3 ("dmaengine: xilinx: dpdma: Add debugfs support")
> > > Signed-off-by: Jiale Yao <yaojiale02@163.com>
> > > ---
> > > drivers/dma/xilinx/xilinx_dpdma.c | 2 +-
> > > 1 file changed, 1 insertion(+), 1 deletion(-)
> > >
> > > diff --git a/drivers/dma/xilinx/xilinx_dpdma.c b/drivers/dma/xilinx/xilinx_dpdma.c
> > > index d9a3542c4531..b61ef3062d84 100644
> > > --- a/drivers/dma/xilinx/xilinx_dpdma.c
> > > +++ b/drivers/dma/xilinx/xilinx_dpdma.c
> > > @@ -410,7 +410,7 @@ static ssize_t xilinx_dpdma_debugfs_write(struct file *f,
> > > if (dpdma_debugfs.testcase != DPDMA_TC_NONE)
> > > return -EBUSY;
> > >
> > > - kern_buff = kzalloc(size, GFP_KERNEL);
> > > + kern_buff = kzalloc(size + 1, GFP_KERNEL);
> > > if (!kern_buff)
> > > return -ENOMEM;
> > > kern_buff_start = kern_buff;
--
Regards,
Laurent Pinchart
^ permalink raw reply [flat|nested] 14+ messages in thread* Re:Re: [PATCH 3/3] dmaengine: xilinx: dpdma: Reserve space for a string terminator
2026-10-01 21:00 ` Laurent Pinchart
@ 2026-10-03 10:09 ` jiale yao
2026-10-04 1:01 ` Frank Li
0 siblings, 1 reply; 14+ messages in thread
From: jiale yao @ 2026-10-03 10:09 UTC (permalink / raw)
To: Laurent Pinchart
Cc: Frank Li, Vinod Koul, Frank Li, Michal Simek, Hyun Kwon,
dmaengine, linux-arm-kernel, linux-kernel
At 2026-10-02 05:00:21, "Laurent Pinchart" <laurent.pinchart@ideasonboard.com> wrote:
>On Thu, Oct 01, 2026 at 04:50:23PM -0400, Frank Li wrote:
>> On Sat, Sep 26, 2026 at 05:34:15PM +0300, Laurent Pinchart wrote:
>> > On Sat, Sep 26, 2026 at 08:12:50PM +0800, Jiale Yao wrote:
>> > > xilinx_dpdma_debugfs_write() allocates a buffer of size bytes, and
>> > > strncpy_from_user() can fill it without a terminating NUL when the input
>> > > has no NUL in the copied range. strsep() and strcasecmp() then read
>> > > beyond the buffer.
>> >
>> > strncpy() has long been considered unsafe, and has finally been removed
>> > from the kernel in v7.2. A better fix would be to similarly replace
>> > strncpy_from_user() with a safe equivalent.
>>
>> Do you means use strndup_user()?
>
>I was thinking about adding a strscpy_user(), but a dup version could
>possibly be interesting too if there are enough users that call
>k[zm]alloc + strncpy_from_user.
Thanks for all reviews, how about this one?
https://lore.kernel.org/all/20261003095922.575350-1-yaojiale02@163.com/
>
>> > > Allocate an extra byte and keep that byte zero-initialized, so the input
>> > > copied remains unchanged and the buffer is always terminated.
>> > >
>> > > Fixes: 1d220435cab3 ("dmaengine: xilinx: dpdma: Add debugfs support")
>> > > Signed-off-by: Jiale Yao <yaojiale02@163.com>
>> > > ---
>> > > drivers/dma/xilinx/xilinx_dpdma.c | 2 +-
>> > > 1 file changed, 1 insertion(+), 1 deletion(-)
>> > >
>> > > diff --git a/drivers/dma/xilinx/xilinx_dpdma.c b/drivers/dma/xilinx/xilinx_dpdma.c
>> > > index d9a3542c4531..b61ef3062d84 100644
>> > > --- a/drivers/dma/xilinx/xilinx_dpdma.c
>> > > +++ b/drivers/dma/xilinx/xilinx_dpdma.c
>> > > @@ -410,7 +410,7 @@ static ssize_t xilinx_dpdma_debugfs_write(struct file *f,
>> > > if (dpdma_debugfs.testcase != DPDMA_TC_NONE)
>> > > return -EBUSY;
>> > >
>> > > - kern_buff = kzalloc(size, GFP_KERNEL);
>> > > + kern_buff = kzalloc(size + 1, GFP_KERNEL);
>> > > if (!kern_buff)
>> > > return -ENOMEM;
>> > > kern_buff_start = kern_buff;
>
>--
>Regards,
>
>Laurent Pinchart
^ permalink raw reply [flat|nested] 14+ messages in thread* Re: Re: [PATCH 3/3] dmaengine: xilinx: dpdma: Reserve space for a string terminator
2026-10-03 10:09 ` jiale yao
@ 2026-10-04 1:01 ` Frank Li
0 siblings, 0 replies; 14+ messages in thread
From: Frank Li @ 2026-10-04 1:01 UTC (permalink / raw)
To: jiale yao
Cc: Laurent Pinchart, Vinod Koul, Frank Li, Michal Simek, Hyun Kwon,
dmaengine, linux-arm-kernel, linux-kernel
On Sat, Oct 03, 2026 at 06:09:58PM +0800, jiale yao wrote:
> [You don't often get email from 19888972804@163.com. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ]
>
> At 2026-10-02 05:00:21, "Laurent Pinchart" <laurent.pinchart@ideasonboard.com> wrote:
> >On Thu, Oct 01, 2026 at 04:50:23PM -0400, Frank Li wrote:
> >> On Sat, Sep 26, 2026 at 05:34:15PM +0300, Laurent Pinchart wrote:
> >> > On Sat, Sep 26, 2026 at 08:12:50PM +0800, Jiale Yao wrote:
> >> > > xilinx_dpdma_debugfs_write() allocates a buffer of size bytes, and
> >> > > strncpy_from_user() can fill it without a terminating NUL when the input
> >> > > has no NUL in the copied range. strsep() and strcasecmp() then read
> >> > > beyond the buffer.
> >> >
> >> > strncpy() has long been considered unsafe, and has finally been removed
> >> > from the kernel in v7.2. A better fix would be to similarly replace
> >> > strncpy_from_user() with a safe equivalent.
> >>
> >> Do you means use strndup_user()?
> >
> >I was thinking about adding a strscpy_user(), but a dup version could
> >possibly be interesting too if there are enough users that call
> >k[zm]alloc + strncpy_from_user.
>
> Thanks for all reviews, how about this one?
> https://lore.kernel.org/all/20261003095922.575350-1-yaojiale02@163.com/
Looks good.
Frank
> >
> >> > > Allocate an extra byte and keep that byte zero-initialized, so the input
> >> > > copied remains unchanged and the buffer is always terminated.
> >> > >
> >> > > Fixes: 1d220435cab3 ("dmaengine: xilinx: dpdma: Add debugfs support")
> >> > > Signed-off-by: Jiale Yao <yaojiale02@163.com>
> >> > > ---
> >> > > drivers/dma/xilinx/xilinx_dpdma.c | 2 +-
> >> > > 1 file changed, 1 insertion(+), 1 deletion(-)
> >> > >
> >> > > diff --git a/drivers/dma/xilinx/xilinx_dpdma.c b/drivers/dma/xilinx/xilinx_dpdma.c
> >> > > index d9a3542c4531..b61ef3062d84 100644
> >> > > --- a/drivers/dma/xilinx/xilinx_dpdma.c
> >> > > +++ b/drivers/dma/xilinx/xilinx_dpdma.c
> >> > > @@ -410,7 +410,7 @@ static ssize_t xilinx_dpdma_debugfs_write(struct file *f,
> >> > > if (dpdma_debugfs.testcase != DPDMA_TC_NONE)
> >> > > return -EBUSY;
> >> > >
> >> > > - kern_buff = kzalloc(size, GFP_KERNEL);
> >> > > + kern_buff = kzalloc(size + 1, GFP_KERNEL);
> >> > > if (!kern_buff)
> >> > > return -ENOMEM;
> >> > > kern_buff_start = kern_buff;
> >
> >--
> >Regards,
> >
> >Laurent Pinchart
^ permalink raw reply [flat|nested] 14+ messages in thread
* Re: [PATCH 0/3] debugfs: Reserve space for string terminators
2026-09-26 12:12 [PATCH 0/3] debugfs: Reserve space for string terminators Jiale Yao
` (2 preceding siblings ...)
2026-09-26 12:12 ` [PATCH 3/3] dmaengine: xilinx: dpdma: " Jiale Yao
@ 2026-10-08 17:38 ` Ilpo Järvinen
3 siblings, 0 replies; 14+ messages in thread
From: Ilpo Järvinen @ 2026-10-08 17:38 UTC (permalink / raw)
To: Laurent Pinchart, Vinod Koul, Frank Li, Michal Simek,
Jeff Johnson, Hans de Goede, Andres Salomon, Thomas Gleixner,
Paul Fox, Dan Carpenter, Vasanthakumar Thiagarajan, Hyun Kwon,
dmaengine, linux-arm-kernel, linux-kernel, linux-wireless, ath12k,
platform-driver-x86, Jiale Yao
On Sat, 26 Sep 2026 20:12:47 +0800, Jiale Yao wrote:
> The same boundary mistake appears in three debugfs write handlers. Each
> handler has a zero-initialized buffer and allows a user write to fill the
> entire buffer. That overwrites the only NUL terminator before the input
> is parsed with sscanf(), strsep(), or strcasecmp(), which can then read
> beyond the end of the buffer.
>
> The write paths are independent, so the fixes are split by file and can
> be applied separately. Each patch reserves one byte for the terminating
> NUL while preserving the normal input size for that handler.
>
> [...]
Thank you for your contribution, it has been applied to my local
review-ilpo-next branch. Note it will show up in the public
platform-drivers-x86/review-ilpo-next branch only once I've pushed my
local branch there, which might take a while.
FYI [if applicable to your patch], as per Linus' policy change, also
fixes are mostly routed through for-next unless the fix is for a
commit introduced in the most recent cycle or is clearly a regression
fix.
The list of commits applied:
[1/3] platform/olpc: Reserve space for a string terminator
commit: 4ef563af57cc48d5a9662d7c69aa4447c2cc1b2c
[2/3] wifi: ath12k: Reserve space for a string terminator
(no commit info)
[3/3] dmaengine: xilinx: dpdma: Reserve space for a string terminator
(no commit info)
--
i.
^ permalink raw reply [flat|nested] 14+ messages in thread