Linux-ARM-Kernel Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 0/3] debugfs: Reserve space for string terminators
@ 2026-09-26 12:12 Jiale Yao
  2026-09-26 12:12 ` [PATCH 3/3] dmaengine: xilinx: dpdma: Reserve space for a string terminator Jiale Yao
  2026-10-08 17:38 ` [PATCH 0/3] debugfs: Reserve space for string terminators Ilpo Järvinen
  0 siblings, 2 replies; 8+ messages in thread
From: Jiale Yao @ 2026-09-26 12:12 UTC (permalink / raw)
  To: Laurent Pinchart, Vinod Koul, Frank Li, Michal Simek,
	Jeff Johnson, Hans de Goede, Ilpo Järvinen, Andres Salomon,
	Thomas Gleixner, Paul Fox, Dan Carpenter,
	Vasanthakumar Thiagarajan, Hyun Kwon, dmaengine, linux-arm-kernel,
	linux-kernel, linux-wireless, ath12k, platform-driver-x86
  Cc: Jiale Yao

The same boundary mistake appears in three debugfs write handlers. Each
handler has a zero-initialized buffer and allows a user write to fill the
entire buffer. That overwrites the only NUL terminator before the input
is parsed with sscanf(), strsep(), or strcasecmp(), which can then read
beyond the end of the buffer.

The write paths are independent, so the fixes are split by file and can
be applied separately. Each patch reserves one byte for the terminating
NUL while preserving the normal input size for that handler.

Jiale Yao (3):
  platform/olpc: Reserve space for a string terminator
  wifi: ath12k: Reserve space for a string terminator
  dmaengine: xilinx: dpdma: Reserve space for a string terminator

 drivers/dma/xilinx/xilinx_dpdma.c                   | 2 +-
 drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c | 2 +-
 drivers/platform/olpc/olpc-ec.c                     | 2 +-
 3 files changed, 3 insertions(+), 3 deletions(-)

-- 
2.34.1



^ permalink raw reply	[flat|nested] 8+ messages in thread

* [PATCH 3/3] dmaengine: xilinx: dpdma: Reserve space for a string terminator
  2026-09-26 12:12 [PATCH 0/3] debugfs: Reserve space for string terminators Jiale Yao
@ 2026-09-26 12:12 ` Jiale Yao
  2026-09-26 14:34   ` Laurent Pinchart
  2026-10-08 17:38 ` [PATCH 0/3] debugfs: Reserve space for string terminators Ilpo Järvinen
  1 sibling, 1 reply; 8+ messages in thread
From: Jiale Yao @ 2026-09-26 12:12 UTC (permalink / raw)
  To: Laurent Pinchart, Vinod Koul, Frank Li, Michal Simek, Hyun Kwon,
	dmaengine, linux-arm-kernel, linux-kernel
  Cc: Jiale Yao

xilinx_dpdma_debugfs_write() allocates a buffer of size bytes, and
strncpy_from_user() can fill it without a terminating NUL when the input
has no NUL in the copied range. strsep() and strcasecmp() then read
beyond the buffer.

Allocate an extra byte and keep that byte zero-initialized, so the input
copied remains unchanged and the buffer is always terminated.

Fixes: 1d220435cab3 ("dmaengine: xilinx: dpdma: Add debugfs support")
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/dma/xilinx/xilinx_dpdma.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/dma/xilinx/xilinx_dpdma.c b/drivers/dma/xilinx/xilinx_dpdma.c
index d9a3542c4531..b61ef3062d84 100644
--- a/drivers/dma/xilinx/xilinx_dpdma.c
+++ b/drivers/dma/xilinx/xilinx_dpdma.c
@@ -410,7 +410,7 @@ static ssize_t xilinx_dpdma_debugfs_write(struct file *f,
 	if (dpdma_debugfs.testcase != DPDMA_TC_NONE)
 		return -EBUSY;
 
-	kern_buff = kzalloc(size, GFP_KERNEL);
+	kern_buff = kzalloc(size + 1, GFP_KERNEL);
 	if (!kern_buff)
 		return -ENOMEM;
 	kern_buff_start = kern_buff;
-- 
2.34.1



^ permalink raw reply related	[flat|nested] 8+ messages in thread

* Re: [PATCH 3/3] dmaengine: xilinx: dpdma: Reserve space for a string terminator
  2026-09-26 12:12 ` [PATCH 3/3] dmaengine: xilinx: dpdma: Reserve space for a string terminator Jiale Yao
@ 2026-09-26 14:34   ` Laurent Pinchart
  2026-10-01 20:50     ` Frank Li
  0 siblings, 1 reply; 8+ messages in thread
From: Laurent Pinchart @ 2026-09-26 14:34 UTC (permalink / raw)
  To: Jiale Yao
  Cc: Vinod Koul, Frank Li, Michal Simek, Hyun Kwon, dmaengine,
	linux-arm-kernel, linux-kernel

On Sat, Sep 26, 2026 at 08:12:50PM +0800, Jiale Yao wrote:
> xilinx_dpdma_debugfs_write() allocates a buffer of size bytes, and
> strncpy_from_user() can fill it without a terminating NUL when the input
> has no NUL in the copied range. strsep() and strcasecmp() then read
> beyond the buffer.

strncpy() has long been considered unsafe, and has finally been removed
from the kernel in v7.2. A better fix would be to similarly replace
strncpy_from_user() with a safe equivalent.

> Allocate an extra byte and keep that byte zero-initialized, so the input
> copied remains unchanged and the buffer is always terminated.
> 
> Fixes: 1d220435cab3 ("dmaengine: xilinx: dpdma: Add debugfs support")
> Signed-off-by: Jiale Yao <yaojiale02@163.com>
> ---
>  drivers/dma/xilinx/xilinx_dpdma.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/dma/xilinx/xilinx_dpdma.c b/drivers/dma/xilinx/xilinx_dpdma.c
> index d9a3542c4531..b61ef3062d84 100644
> --- a/drivers/dma/xilinx/xilinx_dpdma.c
> +++ b/drivers/dma/xilinx/xilinx_dpdma.c
> @@ -410,7 +410,7 @@ static ssize_t xilinx_dpdma_debugfs_write(struct file *f,
>  	if (dpdma_debugfs.testcase != DPDMA_TC_NONE)
>  		return -EBUSY;
>  
> -	kern_buff = kzalloc(size, GFP_KERNEL);
> +	kern_buff = kzalloc(size + 1, GFP_KERNEL);
>  	if (!kern_buff)
>  		return -ENOMEM;
>  	kern_buff_start = kern_buff;

-- 
Regards,

Laurent Pinchart


^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: [PATCH 3/3] dmaengine: xilinx: dpdma: Reserve space for a string terminator
  2026-09-26 14:34   ` Laurent Pinchart
@ 2026-10-01 20:50     ` Frank Li
  2026-10-01 21:00       ` Laurent Pinchart
  0 siblings, 1 reply; 8+ messages in thread
From: Frank Li @ 2026-10-01 20:50 UTC (permalink / raw)
  To: Laurent Pinchart
  Cc: Jiale Yao, Vinod Koul, Frank Li, Michal Simek, Hyun Kwon,
	dmaengine, linux-arm-kernel, linux-kernel

On Sat, Sep 26, 2026 at 05:34:15PM +0300, Laurent Pinchart wrote:
> On Sat, Sep 26, 2026 at 08:12:50PM +0800, Jiale Yao wrote:
> > xilinx_dpdma_debugfs_write() allocates a buffer of size bytes, and
> > strncpy_from_user() can fill it without a terminating NUL when the input
> > has no NUL in the copied range. strsep() and strcasecmp() then read
> > beyond the buffer.
>
> strncpy() has long been considered unsafe, and has finally been removed
> from the kernel in v7.2. A better fix would be to similarly replace
> strncpy_from_user() with a safe equivalent.

Do you means use strndup_user()?

Frank

>
> > Allocate an extra byte and keep that byte zero-initialized, so the input
> > copied remains unchanged and the buffer is always terminated.
> >
> > Fixes: 1d220435cab3 ("dmaengine: xilinx: dpdma: Add debugfs support")
> > Signed-off-by: Jiale Yao <yaojiale02@163.com>
> > ---
> >  drivers/dma/xilinx/xilinx_dpdma.c | 2 +-
> >  1 file changed, 1 insertion(+), 1 deletion(-)
> >
> > diff --git a/drivers/dma/xilinx/xilinx_dpdma.c b/drivers/dma/xilinx/xilinx_dpdma.c
> > index d9a3542c4531..b61ef3062d84 100644
> > --- a/drivers/dma/xilinx/xilinx_dpdma.c
> > +++ b/drivers/dma/xilinx/xilinx_dpdma.c
> > @@ -410,7 +410,7 @@ static ssize_t xilinx_dpdma_debugfs_write(struct file *f,
> >  	if (dpdma_debugfs.testcase != DPDMA_TC_NONE)
> >  		return -EBUSY;
> >
> > -	kern_buff = kzalloc(size, GFP_KERNEL);
> > +	kern_buff = kzalloc(size + 1, GFP_KERNEL);
> >  	if (!kern_buff)
> >  		return -ENOMEM;
> >  	kern_buff_start = kern_buff;
>
> --
> Regards,
>
> Laurent Pinchart


^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: [PATCH 3/3] dmaengine: xilinx: dpdma: Reserve space for a string terminator
  2026-10-01 20:50     ` Frank Li
@ 2026-10-01 21:00       ` Laurent Pinchart
  2026-10-03 10:09         ` jiale yao
  0 siblings, 1 reply; 8+ messages in thread
From: Laurent Pinchart @ 2026-10-01 21:00 UTC (permalink / raw)
  To: Frank Li
  Cc: Jiale Yao, Vinod Koul, Frank Li, Michal Simek, Hyun Kwon,
	dmaengine, linux-arm-kernel, linux-kernel

On Thu, Oct 01, 2026 at 04:50:23PM -0400, Frank Li wrote:
> On Sat, Sep 26, 2026 at 05:34:15PM +0300, Laurent Pinchart wrote:
> > On Sat, Sep 26, 2026 at 08:12:50PM +0800, Jiale Yao wrote:
> > > xilinx_dpdma_debugfs_write() allocates a buffer of size bytes, and
> > > strncpy_from_user() can fill it without a terminating NUL when the input
> > > has no NUL in the copied range. strsep() and strcasecmp() then read
> > > beyond the buffer.
> >
> > strncpy() has long been considered unsafe, and has finally been removed
> > from the kernel in v7.2. A better fix would be to similarly replace
> > strncpy_from_user() with a safe equivalent.
> 
> Do you means use strndup_user()?

I was thinking about adding a strscpy_user(), but a dup version could
possibly be interesting too if there are enough users that call
k[zm]alloc + strncpy_from_user.

> > > Allocate an extra byte and keep that byte zero-initialized, so the input
> > > copied remains unchanged and the buffer is always terminated.
> > >
> > > Fixes: 1d220435cab3 ("dmaengine: xilinx: dpdma: Add debugfs support")
> > > Signed-off-by: Jiale Yao <yaojiale02@163.com>
> > > ---
> > >  drivers/dma/xilinx/xilinx_dpdma.c | 2 +-
> > >  1 file changed, 1 insertion(+), 1 deletion(-)
> > >
> > > diff --git a/drivers/dma/xilinx/xilinx_dpdma.c b/drivers/dma/xilinx/xilinx_dpdma.c
> > > index d9a3542c4531..b61ef3062d84 100644
> > > --- a/drivers/dma/xilinx/xilinx_dpdma.c
> > > +++ b/drivers/dma/xilinx/xilinx_dpdma.c
> > > @@ -410,7 +410,7 @@ static ssize_t xilinx_dpdma_debugfs_write(struct file *f,
> > >  	if (dpdma_debugfs.testcase != DPDMA_TC_NONE)
> > >  		return -EBUSY;
> > >
> > > -	kern_buff = kzalloc(size, GFP_KERNEL);
> > > +	kern_buff = kzalloc(size + 1, GFP_KERNEL);
> > >  	if (!kern_buff)
> > >  		return -ENOMEM;
> > >  	kern_buff_start = kern_buff;

-- 
Regards,

Laurent Pinchart


^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re:Re: [PATCH 3/3] dmaengine: xilinx: dpdma: Reserve space for a string terminator
  2026-10-01 21:00       ` Laurent Pinchart
@ 2026-10-03 10:09         ` jiale yao
  2026-10-04  1:01           ` Frank Li
  0 siblings, 1 reply; 8+ messages in thread
From: jiale yao @ 2026-10-03 10:09 UTC (permalink / raw)
  To: Laurent Pinchart
  Cc: Frank Li, Vinod Koul, Frank Li, Michal Simek, Hyun Kwon,
	dmaengine, linux-arm-kernel, linux-kernel

At 2026-10-02 05:00:21, "Laurent Pinchart" <laurent.pinchart@ideasonboard.com> wrote:
>On Thu, Oct 01, 2026 at 04:50:23PM -0400, Frank Li wrote:
>> On Sat, Sep 26, 2026 at 05:34:15PM +0300, Laurent Pinchart wrote:
>> > On Sat, Sep 26, 2026 at 08:12:50PM +0800, Jiale Yao wrote:
>> > > xilinx_dpdma_debugfs_write() allocates a buffer of size bytes, and
>> > > strncpy_from_user() can fill it without a terminating NUL when the input
>> > > has no NUL in the copied range. strsep() and strcasecmp() then read
>> > > beyond the buffer.
>> >
>> > strncpy() has long been considered unsafe, and has finally been removed
>> > from the kernel in v7.2. A better fix would be to similarly replace
>> > strncpy_from_user() with a safe equivalent.
>> 
>> Do you means use strndup_user()?
>
>I was thinking about adding a strscpy_user(), but a dup version could
>possibly be interesting too if there are enough users that call
>k[zm]alloc + strncpy_from_user.

Thanks for all reviews, how about this one?
https://lore.kernel.org/all/20261003095922.575350-1-yaojiale02@163.com/
>
>> > > Allocate an extra byte and keep that byte zero-initialized, so the input
>> > > copied remains unchanged and the buffer is always terminated.
>> > >
>> > > Fixes: 1d220435cab3 ("dmaengine: xilinx: dpdma: Add debugfs support")
>> > > Signed-off-by: Jiale Yao <yaojiale02@163.com>
>> > > ---
>> > >  drivers/dma/xilinx/xilinx_dpdma.c | 2 +-
>> > >  1 file changed, 1 insertion(+), 1 deletion(-)
>> > >
>> > > diff --git a/drivers/dma/xilinx/xilinx_dpdma.c b/drivers/dma/xilinx/xilinx_dpdma.c
>> > > index d9a3542c4531..b61ef3062d84 100644
>> > > --- a/drivers/dma/xilinx/xilinx_dpdma.c
>> > > +++ b/drivers/dma/xilinx/xilinx_dpdma.c
>> > > @@ -410,7 +410,7 @@ static ssize_t xilinx_dpdma_debugfs_write(struct file *f,
>> > >  	if (dpdma_debugfs.testcase != DPDMA_TC_NONE)
>> > >  		return -EBUSY;
>> > >
>> > > -	kern_buff = kzalloc(size, GFP_KERNEL);
>> > > +	kern_buff = kzalloc(size + 1, GFP_KERNEL);
>> > >  	if (!kern_buff)
>> > >  		return -ENOMEM;
>> > >  	kern_buff_start = kern_buff;
>
>-- 
>Regards,
>
>Laurent Pinchart

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: Re: [PATCH 3/3] dmaengine: xilinx: dpdma: Reserve space for a string terminator
  2026-10-03 10:09         ` jiale yao
@ 2026-10-04  1:01           ` Frank Li
  0 siblings, 0 replies; 8+ messages in thread
From: Frank Li @ 2026-10-04  1:01 UTC (permalink / raw)
  To: jiale yao
  Cc: Laurent Pinchart, Vinod Koul, Frank Li, Michal Simek, Hyun Kwon,
	dmaengine, linux-arm-kernel, linux-kernel

On Sat, Oct 03, 2026 at 06:09:58PM +0800, jiale yao wrote:
> [You don't often get email from 19888972804@163.com. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ]
>
> At 2026-10-02 05:00:21, "Laurent Pinchart" <laurent.pinchart@ideasonboard.com> wrote:
> >On Thu, Oct 01, 2026 at 04:50:23PM -0400, Frank Li wrote:
> >> On Sat, Sep 26, 2026 at 05:34:15PM +0300, Laurent Pinchart wrote:
> >> > On Sat, Sep 26, 2026 at 08:12:50PM +0800, Jiale Yao wrote:
> >> > > xilinx_dpdma_debugfs_write() allocates a buffer of size bytes, and
> >> > > strncpy_from_user() can fill it without a terminating NUL when the input
> >> > > has no NUL in the copied range. strsep() and strcasecmp() then read
> >> > > beyond the buffer.
> >> >
> >> > strncpy() has long been considered unsafe, and has finally been removed
> >> > from the kernel in v7.2. A better fix would be to similarly replace
> >> > strncpy_from_user() with a safe equivalent.
> >>
> >> Do you means use strndup_user()?
> >
> >I was thinking about adding a strscpy_user(), but a dup version could
> >possibly be interesting too if there are enough users that call
> >k[zm]alloc + strncpy_from_user.
>
> Thanks for all reviews, how about this one?
> https://lore.kernel.org/all/20261003095922.575350-1-yaojiale02@163.com/

Looks good.

Frank

> >
> >> > > Allocate an extra byte and keep that byte zero-initialized, so the input
> >> > > copied remains unchanged and the buffer is always terminated.
> >> > >
> >> > > Fixes: 1d220435cab3 ("dmaengine: xilinx: dpdma: Add debugfs support")
> >> > > Signed-off-by: Jiale Yao <yaojiale02@163.com>
> >> > > ---
> >> > >  drivers/dma/xilinx/xilinx_dpdma.c | 2 +-
> >> > >  1 file changed, 1 insertion(+), 1 deletion(-)
> >> > >
> >> > > diff --git a/drivers/dma/xilinx/xilinx_dpdma.c b/drivers/dma/xilinx/xilinx_dpdma.c
> >> > > index d9a3542c4531..b61ef3062d84 100644
> >> > > --- a/drivers/dma/xilinx/xilinx_dpdma.c
> >> > > +++ b/drivers/dma/xilinx/xilinx_dpdma.c
> >> > > @@ -410,7 +410,7 @@ static ssize_t xilinx_dpdma_debugfs_write(struct file *f,
> >> > >          if (dpdma_debugfs.testcase != DPDMA_TC_NONE)
> >> > >                  return -EBUSY;
> >> > >
> >> > > -        kern_buff = kzalloc(size, GFP_KERNEL);
> >> > > +        kern_buff = kzalloc(size + 1, GFP_KERNEL);
> >> > >          if (!kern_buff)
> >> > >                  return -ENOMEM;
> >> > >          kern_buff_start = kern_buff;
> >
> >--
> >Regards,
> >
> >Laurent Pinchart


^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: [PATCH 0/3] debugfs: Reserve space for string terminators
  2026-09-26 12:12 [PATCH 0/3] debugfs: Reserve space for string terminators Jiale Yao
  2026-09-26 12:12 ` [PATCH 3/3] dmaengine: xilinx: dpdma: Reserve space for a string terminator Jiale Yao
@ 2026-10-08 17:38 ` Ilpo Järvinen
  1 sibling, 0 replies; 8+ messages in thread
From: Ilpo Järvinen @ 2026-10-08 17:38 UTC (permalink / raw)
  To: Laurent Pinchart, Vinod Koul, Frank Li, Michal Simek,
	Jeff Johnson, Hans de Goede, Andres Salomon, Thomas Gleixner,
	Paul Fox, Dan Carpenter, Vasanthakumar Thiagarajan, Hyun Kwon,
	dmaengine, linux-arm-kernel, linux-kernel, linux-wireless, ath12k,
	platform-driver-x86, Jiale Yao

On Sat, 26 Sep 2026 20:12:47 +0800, Jiale Yao wrote:

> The same boundary mistake appears in three debugfs write handlers. Each
> handler has a zero-initialized buffer and allows a user write to fill the
> entire buffer. That overwrites the only NUL terminator before the input
> is parsed with sscanf(), strsep(), or strcasecmp(), which can then read
> beyond the end of the buffer.
> 
> The write paths are independent, so the fixes are split by file and can
> be applied separately. Each patch reserves one byte for the terminating
> NUL while preserving the normal input size for that handler.
> 
> [...]

Thank you for your contribution, it has been applied to my local
review-ilpo-next branch. Note it will show up in the public
platform-drivers-x86/review-ilpo-next branch only once I've pushed my
local branch there, which might take a while.

FYI [if applicable to your patch], as per Linus' policy change, also
fixes are mostly routed through for-next unless the fix is for a
commit introduced in the most recent cycle or is clearly a regression
fix.

The list of commits applied:
[1/3] platform/olpc: Reserve space for a string terminator
      commit: 4ef563af57cc48d5a9662d7c69aa4447c2cc1b2c
[2/3] wifi: ath12k: Reserve space for a string terminator
      (no commit info)
[3/3] dmaengine: xilinx: dpdma: Reserve space for a string terminator
      (no commit info)

--
 i.



^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2026-10-08 17:38 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-26 12:12 [PATCH 0/3] debugfs: Reserve space for string terminators Jiale Yao
2026-09-26 12:12 ` [PATCH 3/3] dmaengine: xilinx: dpdma: Reserve space for a string terminator Jiale Yao
2026-09-26 14:34   ` Laurent Pinchart
2026-10-01 20:50     ` Frank Li
2026-10-01 21:00       ` Laurent Pinchart
2026-10-03 10:09         ` jiale yao
2026-10-04  1:01           ` Frank Li
2026-10-08 17:38 ` [PATCH 0/3] debugfs: Reserve space for string terminators Ilpo Järvinen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox