From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm2-f13.google.com (mail-wm2-f13.google.com [74.125.225.141]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 40C7C4D7D29 for ; Mon, 5 Oct 2026 18:54:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.225.141 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791226457; cv=none; b=LRngHCrddojdgloEWvoDf0OY7u1I6skToIhOCry68cUxoS9QoT3bcH66PC2WNxgdlg3wthES1u4zPy0CGMjA0jQkQMYTnOl7I9FOFgKDXSaxHRZeR+3/TF0bhoMZWEto/ICeuyTk/no6RclqhGLrCiKBJK/KzQUyKKmkJfWBI2U= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791226457; c=relaxed/simple; bh=JqbdXiNj+1x2KIBSRHaZMkJ5f/vKrl6ix5aX6QZUvBc=; h=Date:From:To:Cc:Subject:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=lwdhZ23TWOz9gyJ0Zfde5acKoZ7k81q1hFCT10qUxdQ3glMSsSOkH8yo6Z6SbhV5VFnKtT9pfeUXlrJ2PXwkH8GTV1gqjl5u+oasd/Mcz6N82kbuBIKXMzejaui3FtRc3LflsMo8aL6ncwc9ECYqTtfRYkti8fOk5EaEoV8xQq8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=GRCqqMwG; arc=none smtp.client-ip=74.125.225.141 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="GRCqqMwG" Received: by mail-wm2-f13.google.com with SMTP id 5b1f17b1804b1-4a0280d4f56so13144805e9.2 for ; Mon, 05 Oct 2026 11:54:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1791226453; x=1791831253; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=YSppTa1u/xUXXfMqFKbmpz8w8GUfT7lFF5B6YtHgZns=; b=GRCqqMwGio24omLD1gIyIBxOsvgYN8IUnuO1FSqHuH1b+fPTo4NJ8LL2zyKv+gfbii SY6OVmESQ3Wy9Iqj9eTYO/zW8cdfr6Y6jl3B2aFRdrP98nfhvOyWuslV8KUzgbZ2isPV xBqC/gYEO2FQa0pCCJfgZD1bLRoKy20S/zuwsJbSsEFLOcmp09OWAvcNIhED3arDyVXM R8/yppMjiWWtRE8oGQ6LdeQWhXy3RgM6E7MzS9cUOXXF7q4PCpSKwX8WUpJCh+TaSEuo FON4MOsF1DGKD87wNLpp4y+Ga0XKghT4uOSfeUwkSpjaYzMn49BoV8Mh8kZiTyXDo8pJ S1Aw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791226453; x=1791831253; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=YSppTa1u/xUXXfMqFKbmpz8w8GUfT7lFF5B6YtHgZns=; b=VJvTCQuhH5919GtGJwLetekC1ZOpGkZuZ0A+8wA3RkZkaXTB2Q8CfYS8tzhE0UOQM+ 8ACTl4RAwxZp8Jk3bCzBrqzweMtyX85amf2MAxIZ2DTv1VHN39oDQpVXwfOHeBNFDECl 0mGvqbHXtjhrB0d1UmCTVRFc7ugBP/s02iNtUVw4x2BTDjhYjRe5OyHN6xMTdL1dLyPM JAdULa9I6ondlryGYvnWCo/YQxF9qof/pUWwiFtJDmLPPhddrvVD8W4EV1wkmo4+24Gk al/3Wv2pnsiZAsa1kNUvP05+F9+DALMtRH+dLYkr+UDLcagPfdpkPqMiDsWisAxv1/Y5 dizA== X-Forwarded-Encrypted: i=1; AKwUvBxySWMXikYJhl8tOGc+ZYIvoXoWGF7A5hE4nr04VZORa3pSZuNpdbuu6L4V0TK5yt+VsBfDOxztG2uRK6B1qCk=@vger.kernel.org X-Gm-Message-State: AFuF++mmf63yDshniL1eKrwGHKiVVCxok2FK39f13fXo8veH8ovTpo9k 7wZA0ye7SlrO7FXZg5fHTRAGgA32qpS275wXdo/gZii5/zN7/XfSU3Bk X-Gm-Gg: AYBFou1X89VQP38xckhWyhyLipEnm26Vfywsv94Fg6oISGGPnlc8y14TfkzXZnPyUbs pZJtzMOiBnODPVQcCA5jGC23AlKVSfh3HbTsaf3wXqOvqB39JwzYsGpA3b6Gv0WICueCZVTeYQ0 62jB6UIZNC+6nlA8RSb+iXguHlV2P0rXddEGrGOTby3ak0/PCkYmj5MO4/hlgSssM7gTy6CWuVW NnIkNmECCc+Rr1W4wgiA/ULy1Di7r6YsxGbh4lHXOfdJ7gafFcSg3qy9P2yC+O+O0AHIUA6592N e6EqQzHXUYPew9igDfzSkAoD5sFNOqxHizE+otjvI7qO3yqxW3ZgMpkYKzLC633Fc6WpTM/NCDG MxoS0i2QChuwrNWdqfQExA4iD7wfckpy+T13ZJ9G3SZlUO1hCtcFsXGf2T5JiJ+2HjynnvF6v+n a8Nnzs23/qLepC1O3eczzS9JF2OyJpPoaFdxJL0z3aFZQFfEoXLSrAZenQ0rKRn/ZfW03QVeeXe AmzEqPQyoRUXM5b1pq7DxArtuNlMF1Qf14= X-Received: by 2002:a05:600c:4f8e:b0:49f:f0bd:1e40 with SMTP id 5b1f17b1804b1-4a02769cf66mr195041635e9.23.1791226453264; Mon, 05 Oct 2026 11:54:13 -0700 (PDT) Received: from pumpkin (82-69-66-36.dsl.in-addr.zen.co.uk. [82.69.66.36]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48c622affadsm5117770f8f.40.2026.10.05.11.54.12 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 05 Oct 2026 11:54:13 -0700 (PDT) Date: Mon, 5 Oct 2026 19:54:11 +0100 From: David Laight To: Kees Cook Cc: Bill Wendling , Ian Bridges , Justin Tee , Paul Ely , "James E.J. Bottomley" , "Martin K. Petersen" , linux-scsi@vger.kernel.org, linux-kernel@vger.kernel.org, linux-hardening@vger.kernel.org Subject: Re: [PATCH v5 03/12] scsi: lpfc: Print rx monitor records straight into the seq_buf Message-ID: <20261005195411.3e09bc8e@pumpkin> In-Reply-To: <20261005155708.1471260-3-kees@kernel.org> References: <20261005155653.late.426-kees@kernel.org> <20261005155708.1471260-3-kees@kernel.org> X-Mailer: Claws Mail 4.1.1 (GTK 3.24.38; arm-unknown-linux-gnueabihf) Precedence: bulk X-Mailing-List: linux-hardening@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit On Mon, 5 Oct 2026 08:56:53 -0700 Kees Cook wrote: > lpfc_rx_monitor_report() formats each record into a stack buffer, then > appends it with seq_buf_puts(), relying on seq_buf_puts() appending > nothing when a string does not fit: the debugfs output then ends at the > last whole record, and the record left out is read in full next time. > The next patch makes seq_buf_puts() copy as much as fits instead, as > seq_buf_printf() and strlcat() do. > > Print each record with seq_buf_printf(), and when it does not fit, end > the string where the record began, since the reader takes the buffer up > to its NUL. This also takes the DBG_LOG_STR_SZ buffer off the stack. > > Build tested ARCH=x86_64 with GCC 16.2.0, CONFIG_SCSI_LPFC=m and W=1. > > Assisted-by: LLM > Signed-off-by: Kees Cook > --- > drivers/scsi/lpfc/lpfc_sli.c | 45 +++++++++++++++++++++--------------- > 1 file changed, 27 insertions(+), 18 deletions(-) > > diff --git a/drivers/scsi/lpfc/lpfc_sli.c b/drivers/scsi/lpfc/lpfc_sli.c > index cfa4371169f1..a7b1ea67ed98 100644 > --- a/drivers/scsi/lpfc/lpfc_sli.c > +++ b/drivers/scsi/lpfc/lpfc_sli.c > @@ -8108,7 +8108,6 @@ u32 lpfc_rx_monitor_report(struct lpfc_hba *phba, > spinlock_t *ring_lock = &rx_monitor->lock; > u32 ring_size = rx_monitor->entries; > u32 cnt = 0; > - char tmp[DBG_LOG_STR_SZ] = {0}; > bool log_to_kmsg = (!buf || !buf_len) ? true : false; > struct seq_buf s; > > @@ -8133,27 +8132,37 @@ u32 lpfc_rx_monitor_report(struct lpfc_hba *phba, > > /* Read out this entry's data. */ > if (!log_to_kmsg) { > + unsigned int len; > + > + /* A header that did not fit leaves no room. */ > + if (seq_buf_has_overflowed(&s)) > + break; > + len = seq_buf_used(&s); > + > + seq_buf_printf(&s, > + "%03d:\t%-16llu%-16llu%-16llu%-16llu%-8llu%-8llu%-8llu%-8u%-8u%-8u%u(%u)\n", > + *head_idx, > + entry->max_bytes_per_interval, > + entry->cmf_bytes, > + entry->total_bytes, > + entry->rcv_bytes, > + entry->avg_io_latency, > + entry->avg_io_size, > + entry->max_read_cnt, > + entry->cmf_busy, entry->io_cnt, > + entry->cmf_info, > + entry->timer_utilization, > + entry->timer_interval); > + > /* > * Drop a record whole if it does not fit, without > - * consuming its ring entry. > + * consuming its ring entry: the reader takes the > + * string up to its NUL. > */ > - scnprintf(tmp, sizeof(tmp), > - "%03d:\t%-16llu%-16llu%-16llu%-16llu%-8llu%-8llu%-8llu%-8u%-8u%-8u%u(%u)\n", > - *head_idx, > - entry->max_bytes_per_interval, > - entry->cmf_bytes, > - entry->total_bytes, > - entry->rcv_bytes, > - entry->avg_io_latency, > - entry->avg_io_size, > - entry->max_read_cnt, > - entry->cmf_busy, entry->io_cnt, > - entry->cmf_info, > - entry->timer_utilization, > - entry->timer_interval); > - > - if (seq_buf_puts(&s, tmp) < 0) > + if (seq_buf_has_overflowed(&s)) { > + buf[len] = '\0'; There should probably be a seq_buf_truncate() to do that. Then a request for the length will be correct. David > break; > + } > } else { > lpfc_printf_log(phba, KERN_INFO, LOG_CGN_MGMT, > "4410 %02u: MBPI %llu Xmit %llu "