From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from gabe.freedesktop.org (gabe.freedesktop.org [131.252.210.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 1F026CD5BC9 for ; Mon, 25 May 2026 17:10:09 +0000 (UTC) Received: from gabe.freedesktop.org (localhost [127.0.0.1]) by gabe.freedesktop.org (Postfix) with ESMTP id 970DC8920D; Mon, 25 May 2026 17:10:08 +0000 (UTC) Authentication-Results: gabe.freedesktop.org; dkim=pass (2048-bit key; unprotected) header.d=suse.com header.i=@suse.com header.b="KSNrwM1o"; dkim-atps=neutral Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) by gabe.freedesktop.org (Postfix) with ESMTPS id 5B0F28920D for ; Mon, 25 May 2026 17:10:08 +0000 (UTC) Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-4891d7164ddso47086535e9.3 for ; Mon, 25 May 2026 10:10:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.com; s=google; t=1779729007; x=1780333807; darn=lists.freedesktop.org; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=izugkSqOYsBmSyQ8jfD9m1SVj73YG14U78pRBc6Lai0=; b=KSNrwM1opFvcKIzJVlHhT45lTCORBhOIxIdcNPgk2NSwhhIWYtUc0r3WCpX/4qMKCZ UEDFOTQmakUYaZa97Cm7l9nR3UdSKujemsD43qx6X3wvDrqUny7th0rfzAINdhl3bvIQ QzDqCLgM+5hDD0FCRx7ydzhZLiYJEqIAJ12sjdY7RFTEuEXM5DH2xluXoaLYOZNlyPNI 6XuzR8QH4m6bLjKCTv+s/gdDzeljBHHujPodvbvGTrY2Y27jvuKaop+lDwaBOhCAgMWy 1NBgQOcZ7/EVYLQAw/6pJqE6w8pjLV0MM+/cld/NZ9i2B9udmCm9mqgAGr1KthgDzFqE Xwrg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779729007; x=1780333807; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=izugkSqOYsBmSyQ8jfD9m1SVj73YG14U78pRBc6Lai0=; b=qMxzSwoNFsR6TY1LmxQicQs8EANNPcKs2+4VqVnKbvzamVx4EknpkVHF8QzoxxrNdF jZ36mkbMq3FHrYigWd7BL3QYvwF4ULBptR9PIMK6vPIvebpg+sSWk7BkFWgvx8M+AmVt GJF6/FL6o5gZJGH1ZkzbvKqiQU1div8mJ4C47HlTUkUflP7rv/cKO/DgSPNFeb0vsevd 9sAnG5PWQXgd0Df0rAoPZDivhjGPSIJfCSIF9od/Pt3Q+0kAj9RrCAkML7q+8VrrFJVt 4BL3Xo+Vu2i7ZFRljwfJtRvlddaFG2yL+vS30Yc3HsQFcPGdv4NpE8S56cgAveQQfC4v KCbg== X-Forwarded-Encrypted: i=1; AFNElJ9le733IIX5qkmv/PsQHe+vPcsCTKr39PDjHu4bjFQKX225iU2mdp843bnPA4wtUebJHtSG5OlloK0=@lists.freedesktop.org X-Gm-Message-State: AOJu0YzQYTzZSZSywp7oEf/E0QZ6ERnEqCeTbyZWR9dEhubo4qPSuoyE rolsmH7UUFygixQQQ3uEjYHBlNJCBHWEJzgfzPl9TKAYNtVOFMTKKJdvnPU0FyY1VmM= X-Gm-Gg: Acq92OGOe1jW4VxUGy3tyPRWiGmHI4jPaPI3aG3X02jL4fhPBYBdFkTfQr7ztqkdgKw h0w5qullcIfth5dzpB99I5qfPe1LYLq3bGorr/Zz/6b3cGjlmdHVDjiwdzjxQr/FTf/+G9pF3cw ILzTrp2YoQWklB2NxOTi3u6QUSH7bhFt05782Aj9DDeaHb6kKCSc/pYgrFeqhmvCw/5wGMIDgfS Raak6EGNNYGyoVzsbdTPBRC4PjyPOBdPWnvU+vFcgLKCkQVkayIudO2VEArIQ7ZdFu+P2wB/q4F b/FrjxWaQD4MBp/f+U5AcvdFYthXG873Xq0lRCZcpdlgKsrmeoPHY0TTBWmi3gdhgdLR51WqtLz CMSdxwQ9yWAZLk0mMN2tnFCTYUj6Al7ixauXBy9X50E0+E039V3uaHT4qlGBkBNsgjdTOGIwFFe OExS97TymU61wTwwL46tWrpcnQcbYmQzdh0keNsfbrZkhvMIByaxMVQSONIh4fSiqUuznZ7PTNw 1NeyBkNDgBPlUkU4BT8+qUPHt4NeseVKnu1Q8PLyy9X+Rofjzay8srM0K5GMOyIJQmUGlwz9uR+ 1tt8uHWirPbaFPI= X-Received: by 2002:a05:600c:35cf:b0:490:44eb:c1e5 with SMTP id 5b1f17b1804b1-49044ebc257mr277307095e9.31.1779729006482; Mon, 25 May 2026 10:10:06 -0700 (PDT) Received: from ?IPV6:2a00:1028:838d:271e:8e3b:4aff:fe4c:a100? (dynamic-2a00-1028-838d-271e-8e3b-4aff-fe4c-a100.ipv6.o2.cz. [2a00:1028:838d:271e:8e3b:4aff:fe4c:a100]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4904526c926sm456877405e9.1.2026.05.25.10.10.03 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 25 May 2026 10:10:06 -0700 (PDT) Message-ID: Date: Mon, 25 May 2026 19:10:03 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH 08/11] params: Convert generic kernel_param_ops .get helpers to seq_buf To: Kees Cook Cc: Luis Chamberlain , Pengpeng Hou , Richard Weinberger , Anton Ivanov , Johannes Berg , "Rafael J. Wysocki" , Len Brown , Corey Minyard , Gabriel Somlo , "Michael S. Tsirkin" , Jani Nikula , Joonas Lahtinen , Rodrigo Vivi , Tvrtko Ursulin , David Airlie , Simona Vetter , Bart Van Assche , Jason Gunthorpe , Leon Romanovsky , Laurent Pinchart , Hans de Goede , Mauro Carvalho Chehab , Bjorn Helgaas , Hannes Reinecke , "James E.J. Bottomley" , "Martin K. Petersen" , Daniel Lezcano , Zhang Rui , Lukasz Luba , Greg Kroah-Hartman , Jiri Slaby , Alan Stern , Jason Wang , Xuan Zhuo , =?UTF-8?Q?Eugenio_P=C3=A9rez?= , Jason Baron , Jim Cromie , Tiwei Bie , Benjamin Berg , =?UTF-8?Q?Ilpo_J=C3=A4rvinen?= , "David E. Box" , "Maciej W. Rozycki" , Srinivas Pandruvada , Peter Zijlstra , Heiko Carstens , Vasily Gorbik , Sean Christopherson , Paolo Bonzini , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, "H. Peter Anvin" , Vinod Koul , Frank Li , Daniel Gomez , Sami Tolvanen , Aaron Tomlin , Alexander Potapenko , Marco Elver , Dmitry Vyukov , Andrew Morton , John Johansen , Paul Moore , James Morris , "Serge E. Hallyn" , Andy Shevchenko , Georgia Garcia , kvm@vger.kernel.org, dmaengine@vger.kernel.org, linux-modules@vger.kernel.org, kasan-dev@googlegroups.com, linux-mm@kvack.org, apparmor@lists.ubuntu.com, linux-security-module@vger.kernel.org, linux-um@lists.infradead.org, linux-acpi@vger.kernel.org, openipmi-developer@lists.sourceforge.net, qemu-devel@nongnu.org, intel-gfx@lists.freedesktop.org, dri-devel@lists.freedesktop.org, linux-rdma@vger.kernel.org, linux-media@vger.kernel.org, linux-pci@vger.kernel.org, linux-scsi@vger.kernel.org, linux-pm@vger.kernel.org, linuxppc-dev@lists.ozlabs.org, linux-serial@vger.kernel.org, linux-usb@vger.kernel.org, usb-storage@lists.one-eyed-alien.net, virtualization@lists.linux.dev, linux-kernel@vger.kernel.org, linux-arch@vger.kernel.org, netdev@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-hardening@vger.kernel.org References: <20260521133315.work.845-kees@kernel.org> <20260521133326.2465264-8-kees@kernel.org> Content-Language: en-US From: Petr Pavlu In-Reply-To: <20260521133326.2465264-8-kees@kernel.org> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: intel-gfx@lists.freedesktop.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Intel graphics driver community testing & development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: intel-gfx-bounces@lists.freedesktop.org Sender: "Intel-gfx" On 5/21/26 3:33 PM, Kees Cook wrote: > Convert the generic struct kernel_param_ops .get helpers in > kernel/params.c directly to the seq_buf signature, drop their legacy > "char *" form, and refresh prototypes in : > > param_get_byte/short/ushort/int/uint/long/ulong/ullong/hexint > param_get_charp/bool/invbool/string > param_array_get > > The STANDARD_PARAM_DEF() macro expands to a seq_buf body for every > numeric helper. param_array_get() now writes element output directly > into the parent seq_buf when the element ops provide .get; it only > allocates the per-call PAGE_SIZE bounce buffer when the element ops > still use the legacy .get_str path. The common "rewrite the prior > element's trailing newline as a comma" step lives outside both > branches so the two paths share it. > > The non-core changes in this commit (arch/x86/kvm, mm/kfence, > drivers/dma/dmatest, security/apparmor) are the small set of callers that > directly invoke one of the converted generic helpers from their own .get > callback (e.g. an apparmor wrapper that adds a capability check and then > delegates to param_get_bool()). Because the helpers' signature changes > here, these wrappers must move in lockstep. Each of them is updated > to take "struct seq_buf *" and pass it through; param_get_debug() in > apparmor also pulls aa_print_debug_params() (and its val_mask_to_str() > helper, in security/apparmor/lib.c) over to seq_buf, since that is the > only consumer. No other behavioural change is intended. > > Custom .get callbacks that do not delegate to a generic helper (and > therefore still match the .get_str signature) are routed automatically > to the .get_str field by the DEFINE_KERNEL_PARAM_OPS _Generic dispatcher > and are deliberately left alone here, to be changed separately within > their respective subsystems. > > Signed-off-by: Kees Cook > --- > [...] > @@ -453,36 +457,46 @@ static int param_array_set(const char *val, const struct kernel_param *kp) > arr->num ?: &temp_num); > } > > -static int param_array_get(char *buffer, const struct kernel_param *kp) > +static int param_array_get(struct seq_buf *s, const struct kernel_param *kp) > { > - int i, off, ret; > - char *elem_buf; > const struct kparam_array *arr = kp->arr; > struct kernel_param p = *kp; > + char *elem_buf = NULL; > + int i, ret = 0; > > - elem_buf = kmalloc(PAGE_SIZE, GFP_KERNEL); > - if (!elem_buf) > - return -ENOMEM; > + for (i = 0; i < (arr->num ? *arr->num : arr->max); i++) { > + size_t before = s->len; > > - for (i = off = 0; i < (arr->num ? *arr->num : arr->max); i++) { > p.arg = arr->elem + arr->elemsize * i; > check_kparam_locked(p.mod); > - ret = arr->ops->get_str(elem_buf, &p); > - if (ret < 0) > - goto out; > - ret = min(ret, (int)(PAGE_SIZE - 1 - off)); > - if (!ret) > + > + if (arr->ops->get) { > + ret = arr->ops->get(s, &p); > + if (ret < 0) > + goto out; > + } else { > + if (!elem_buf) { > + elem_buf = kmalloc(PAGE_SIZE, GFP_KERNEL); > + if (!elem_buf) { > + ret = -ENOMEM; > + goto out; > + } > + } > + ret = arr->ops->get_str(elem_buf, &p); > + if (ret < 0) > + goto out; > + seq_buf_putmem(s, elem_buf, ret); > + } > + > + /* Nothing got written (e.g. overflow) — stop. */ > + if (s->len == before) > break; > + > /* Replace the previous element's trailing newline with a comma. */ > - if (i) > - buffer[off - 1] = ','; > - memcpy(buffer + off, elem_buf, ret); > - off += ret; > - if (off == PAGE_SIZE - 1) > - break; > + if (i && s->buffer[before - 1] == '\n') > + s->buffer[before - 1] = ','; > } > - buffer[off] = '\0'; > - ret = off; > + ret = 0; > out: > kfree(elem_buf); > return ret; Since you're almost completely rewriting the logic in param_array_get(), I suggest tightening it up a bit. The function could warn or return an error when a kernel_param_ops::get/get_str() call adds a string that doesn't terminate with '\n', specifically, when the call adds either a zero-length string or a non-zero-length string that ends with a different character (unless an overflow occurred). The updated code silently stops the loop when a get call returns a zero-length string. Similarly, handling of a string not terminated by '\n' is halfway there because of the added check "s->buffer[before - 1] == '\n'". -- Thanks, Petr