[PATCH v4 03/11] seq_buf: Copy what fits when seq_buf_puts() and seq_buf_putmem() overflow
sashiko-bot at kernel.org
sashiko-bot at kernel.org
Sat Oct 3 04:07:57 UTC 2026
> When seq_buf_puts() or seq_buf_putmem() is given more than fits, it
> copies nothing and only marks the seq_buf as overflowed. If seq_buf_str()
> is used, it will terminate the buffer in its last byte, so every byte
> between the end of the data and the end of the buffer becomes part of
> the string, though the seq_buf never wrote them.
>
> seq_buf_printf() does not have this problem, because vsnprintf() writes
> as much of the output as fits, followed by a NUL. Repeat this behavior
> in seq_buf_puts(), using strscpy(), and in seq_buf_putmem(), which also
> covers seq_buf_putmem_hex(). seq_buf_putc() needs no change, as it can
> only overflow when the buffer is already full.
>
> Each writer now records the buffer as full once it has copied what fits,
> so that what it wrote can be told apart from bytes nothing touched.
>
> [ ... ]
> test builds as a module (CONFIG_SEQ_BUF_KUNIT_TEST=m).
>
> Assisted-by: LLM
> Reviewed-by: Andy Shevchenko <andriy.shevchenko at linux.intel.com>
> Signed-off-by: Kees Cook <kees at kernel.org>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261003035906.too.263-kees@kernel.org?part=3
More information about the Linux-security-module-archive
mailing list