Linux wireless drivers development
 help / color / mirror / Atom feed
* [PATCH 0/3] debugfs: Reserve space for string terminators
@ 2026-09-26 12:12 Jiale Yao
  2026-09-26 12:12 ` [PATCH 2/3] wifi: ath12k: Reserve space for a string terminator Jiale Yao
  2026-10-08 17:38 ` [PATCH 0/3] debugfs: Reserve space for string terminators Ilpo Järvinen
  0 siblings, 2 replies; 7+ messages in thread
From: Jiale Yao @ 2026-09-26 12:12 UTC (permalink / raw)
  To: Laurent Pinchart, Vinod Koul, Frank Li, Michal Simek,
	Jeff Johnson, Hans de Goede, Ilpo Järvinen, Andres Salomon,
	Thomas Gleixner, Paul Fox, Dan Carpenter,
	Vasanthakumar Thiagarajan, Hyun Kwon, dmaengine, linux-arm-kernel,
	linux-kernel, linux-wireless, ath12k, platform-driver-x86
  Cc: Jiale Yao

The same boundary mistake appears in three debugfs write handlers. Each
handler has a zero-initialized buffer and allows a user write to fill the
entire buffer. That overwrites the only NUL terminator before the input
is parsed with sscanf(), strsep(), or strcasecmp(), which can then read
beyond the end of the buffer.

The write paths are independent, so the fixes are split by file and can
be applied separately. Each patch reserves one byte for the terminating
NUL while preserving the normal input size for that handler.

Jiale Yao (3):
  platform/olpc: Reserve space for a string terminator
  wifi: ath12k: Reserve space for a string terminator
  dmaengine: xilinx: dpdma: Reserve space for a string terminator

 drivers/dma/xilinx/xilinx_dpdma.c                   | 2 +-
 drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c | 2 +-
 drivers/platform/olpc/olpc-ec.c                     | 2 +-
 3 files changed, 3 insertions(+), 3 deletions(-)

-- 
2.34.1


^ permalink raw reply	[flat|nested] 7+ messages in thread

* [PATCH 2/3] wifi: ath12k: Reserve space for a string terminator
  2026-09-26 12:12 [PATCH 0/3] debugfs: Reserve space for string terminators Jiale Yao
@ 2026-09-26 12:12 ` Jiale Yao
  2026-09-26 12:33   ` Dan Carpenter
                     ` (3 more replies)
  2026-10-08 17:38 ` [PATCH 0/3] debugfs: Reserve space for string terminators Ilpo Järvinen
  1 sibling, 4 replies; 7+ messages in thread
From: Jiale Yao @ 2026-09-26 12:12 UTC (permalink / raw)
  To: Jeff Johnson, Vasanthakumar Thiagarajan, Dan Carpenter,
	linux-wireless, ath12k, linux-kernel
  Cc: Jiale Yao

ath12k_write_htt_stats_type() accepts count == size, which fills the
zero-initialized buffer without a terminating NUL. sscanf() then reads
beyond the buffer.

Reject input that leaves no room for the trailing NUL.

Fixes: 8c7a5031a6b0 ("wifi: ath12k: Fix buffer overflow in debugfs")
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c b/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
index b772181a496e..f84f1828275a 100644
--- a/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
+++ b/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
@@ -6190,7 +6190,7 @@ static ssize_t ath12k_write_htt_stats_type(struct file *file,
 	const int size = 32;
 	int num_args;
 
-	if (count > size)
+	if (count >= size)
 		return -EINVAL;
 
 	char *buf __free(kfree) = kzalloc(size, GFP_KERNEL);
-- 
2.34.1


^ permalink raw reply related	[flat|nested] 7+ messages in thread

* Re: [PATCH 2/3] wifi: ath12k: Reserve space for a string terminator
  2026-09-26 12:12 ` [PATCH 2/3] wifi: ath12k: Reserve space for a string terminator Jiale Yao
@ 2026-09-26 12:33   ` Dan Carpenter
  2026-09-28 17:36   ` Rameshkumar Sundaram
                     ` (2 subsequent siblings)
  3 siblings, 0 replies; 7+ messages in thread
From: Dan Carpenter @ 2026-09-26 12:33 UTC (permalink / raw)
  To: Jiale Yao
  Cc: Jeff Johnson, Vasanthakumar Thiagarajan, linux-wireless, ath12k,
	linux-kernel

On Sat, Sep 26, 2026 at 08:12:49PM +0800, Jiale Yao wrote:
> ath12k_write_htt_stats_type() accepts count == size, which fills the
> zero-initialized buffer without a terminating NUL. sscanf() then reads
> beyond the buffer.
> 
> Reject input that leaves no room for the trailing NUL.
> 
> Fixes: 8c7a5031a6b0 ("wifi: ath12k: Fix buffer overflow in debugfs")
> Signed-off-by: Jiale Yao <yaojiale02@163.com>
> ---

Reviewed-by: Dan Carpenter <error27@gmail.com>

regards,
dan carpenter


^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: [PATCH 2/3] wifi: ath12k: Reserve space for a string terminator
  2026-09-26 12:12 ` [PATCH 2/3] wifi: ath12k: Reserve space for a string terminator Jiale Yao
  2026-09-26 12:33   ` Dan Carpenter
@ 2026-09-28 17:36   ` Rameshkumar Sundaram
  2026-09-29  2:35   ` Baochen Qiang
  2026-10-03 23:07   ` Jeff Johnson
  3 siblings, 0 replies; 7+ messages in thread
From: Rameshkumar Sundaram @ 2026-09-28 17:36 UTC (permalink / raw)
  To: Jiale Yao, Jeff Johnson, Vasanthakumar Thiagarajan, Dan Carpenter,
	linux-wireless, ath12k, linux-kernel

On 9/26/2026 5:42 PM, Jiale Yao wrote:
> ath12k_write_htt_stats_type() accepts count == size, which fills the
> zero-initialized buffer without a terminating NUL. sscanf() then reads
> beyond the buffer.
> 
> Reject input that leaves no room for the trailing NUL.
> 
> Fixes: 8c7a5031a6b0 ("wifi: ath12k: Fix buffer overflow in debugfs")
> Signed-off-by: Jiale Yao <yaojiale02@163.com>
> ---
>   drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c | 2 +-
>   1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c b/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> index b772181a496e..f84f1828275a 100644
> --- a/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> +++ b/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> @@ -6190,7 +6190,7 @@ static ssize_t ath12k_write_htt_stats_type(struct file *file,
>   	const int size = 32;
>   	int num_args;
>   
> -	if (count > size)
> +	if (count >= size)
>   		return -EINVAL;
>   
>   	char *buf __free(kfree) = kzalloc(size, GFP_KERNEL);


Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: [PATCH 2/3] wifi: ath12k: Reserve space for a string terminator
  2026-09-26 12:12 ` [PATCH 2/3] wifi: ath12k: Reserve space for a string terminator Jiale Yao
  2026-09-26 12:33   ` Dan Carpenter
  2026-09-28 17:36   ` Rameshkumar Sundaram
@ 2026-09-29  2:35   ` Baochen Qiang
  2026-10-03 23:07   ` Jeff Johnson
  3 siblings, 0 replies; 7+ messages in thread
From: Baochen Qiang @ 2026-09-29  2:35 UTC (permalink / raw)
  To: Jiale Yao, Jeff Johnson, Vasanthakumar Thiagarajan, Dan Carpenter,
	linux-wireless, ath12k, linux-kernel



On 9/26/2026 8:12 PM, Jiale Yao wrote:
> ath12k_write_htt_stats_type() accepts count == size, which fills the
> zero-initialized buffer without a terminating NUL. sscanf() then reads
> beyond the buffer.
> 
> Reject input that leaves no room for the trailing NUL.
> 
> Fixes: 8c7a5031a6b0 ("wifi: ath12k: Fix buffer overflow in debugfs")
> Signed-off-by: Jiale Yao <yaojiale02@163.com>
> ---
>  drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c b/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> index b772181a496e..f84f1828275a 100644
> --- a/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> +++ b/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> @@ -6190,7 +6190,7 @@ static ssize_t ath12k_write_htt_stats_type(struct file *file,
>  	const int size = 32;
>  	int num_args;
>  
> -	if (count > size)
> +	if (count >= size)
>  		return -EINVAL;
>  
>  	char *buf __free(kfree) = kzalloc(size, GFP_KERNEL);

Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>


^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: [PATCH 2/3] wifi: ath12k: Reserve space for a string terminator
  2026-09-26 12:12 ` [PATCH 2/3] wifi: ath12k: Reserve space for a string terminator Jiale Yao
                     ` (2 preceding siblings ...)
  2026-09-29  2:35   ` Baochen Qiang
@ 2026-10-03 23:07   ` Jeff Johnson
  3 siblings, 0 replies; 7+ messages in thread
From: Jeff Johnson @ 2026-10-03 23:07 UTC (permalink / raw)
  To: Jiale Yao, Jeff Johnson, Vasanthakumar Thiagarajan, Dan Carpenter,
	linux-wireless, ath12k, linux-kernel

On 9/26/2026 5:12 AM, Jiale Yao wrote:
> ath12k_write_htt_stats_type() accepts count == size, which fills the
> zero-initialized buffer without a terminating NUL. sscanf() then reads
> beyond the buffer.
> 
> Reject input that leaves no room for the trailing NUL.
> 
> Fixes: 8c7a5031a6b0 ("wifi: ath12k: Fix buffer overflow in debugfs")
> Signed-off-by: Jiale Yao <yaojiale02@163.com>
> ---
>  drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c b/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> index b772181a496e..f84f1828275a 100644
> --- a/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> +++ b/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> @@ -6190,7 +6190,7 @@ static ssize_t ath12k_write_htt_stats_type(struct file *file,
>  	const int size = 32;
>  	int num_args;
>  
> -	if (count > size)
> +	if (count >= size)
>  		return -EINVAL;
>  
>  	char *buf __free(kfree) = kzalloc(size, GFP_KERNEL);

Documenting this was reposted as a standalone patch:
https://msgid.link/20261003095913.575108-1-yaojiale02@163.com

I'm taking that patch through the ath tree.

/jeff

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: [PATCH 0/3] debugfs: Reserve space for string terminators
  2026-09-26 12:12 [PATCH 0/3] debugfs: Reserve space for string terminators Jiale Yao
  2026-09-26 12:12 ` [PATCH 2/3] wifi: ath12k: Reserve space for a string terminator Jiale Yao
@ 2026-10-08 17:38 ` Ilpo Järvinen
  1 sibling, 0 replies; 7+ messages in thread
From: Ilpo Järvinen @ 2026-10-08 17:38 UTC (permalink / raw)
  To: Laurent Pinchart, Vinod Koul, Frank Li, Michal Simek,
	Jeff Johnson, Hans de Goede, Andres Salomon, Thomas Gleixner,
	Paul Fox, Dan Carpenter, Vasanthakumar Thiagarajan, Hyun Kwon,
	dmaengine, linux-arm-kernel, linux-kernel, linux-wireless, ath12k,
	platform-driver-x86, Jiale Yao

On Sat, 26 Sep 2026 20:12:47 +0800, Jiale Yao wrote:

> The same boundary mistake appears in three debugfs write handlers. Each
> handler has a zero-initialized buffer and allows a user write to fill the
> entire buffer. That overwrites the only NUL terminator before the input
> is parsed with sscanf(), strsep(), or strcasecmp(), which can then read
> beyond the end of the buffer.
> 
> The write paths are independent, so the fixes are split by file and can
> be applied separately. Each patch reserves one byte for the terminating
> NUL while preserving the normal input size for that handler.
> 
> [...]

Thank you for your contribution, it has been applied to my local
review-ilpo-next branch. Note it will show up in the public
platform-drivers-x86/review-ilpo-next branch only once I've pushed my
local branch there, which might take a while.

FYI [if applicable to your patch], as per Linus' policy change, also
fixes are mostly routed through for-next unless the fix is for a
commit introduced in the most recent cycle or is clearly a regression
fix.

The list of commits applied:
[1/3] platform/olpc: Reserve space for a string terminator
      commit: 4ef563af57cc48d5a9662d7c69aa4447c2cc1b2c
[2/3] wifi: ath12k: Reserve space for a string terminator
      (no commit info)
[3/3] dmaengine: xilinx: dpdma: Reserve space for a string terminator
      (no commit info)

--
 i.


^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2026-10-08 17:38 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-26 12:12 [PATCH 0/3] debugfs: Reserve space for string terminators Jiale Yao
2026-09-26 12:12 ` [PATCH 2/3] wifi: ath12k: Reserve space for a string terminator Jiale Yao
2026-09-26 12:33   ` Dan Carpenter
2026-09-28 17:36   ` Rameshkumar Sundaram
2026-09-29  2:35   ` Baochen Qiang
2026-10-03 23:07   ` Jeff Johnson
2026-10-08 17:38 ` [PATCH 0/3] debugfs: Reserve space for string terminators Ilpo Järvinen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox