mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Daniel Thompson <daniel.thompson@linaro.org>
To: Doug Anderson <dianders@chromium.org>
Cc: Jason Wessel <jason.wessel@windriver.com>,
	kgdb-bugreport@lists.sourceforge.net,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH v2 7/7] kdb: Simplify management of tmpbuffer in kdb_read()
Date: Tue, 23 Apr 2024 12:02:12 +0100	[thread overview]
Message-ID: <20240423110212.GC1567803@aspen.lan> (raw)
In-Reply-To: <CAD=FV=XqSmD4WGyBp7Cv1i8X9yjk2gH1y2j_5qzkxtDL+GKv3g@mail.gmail.com>

On Mon, Apr 22, 2024 at 04:52:52PM -0700, Doug Anderson wrote:
> On Mon, Apr 22, 2024 at 9:38 AM Daniel Thompson
> <daniel.thompson@linaro.org> wrote:
> > diff --git a/kernel/debug/kdb/kdb_io.c b/kernel/debug/kdb/kdb_io.c
> > index 94a638a9d52fa..640208675c9a8 100644
> > --- a/kernel/debug/kdb/kdb_io.c
> > +++ b/kernel/debug/kdb/kdb_io.c
> > @@ -310,21 +309,16 @@ static char *kdb_read(char *buffer, size_t bufsize)
> >         case 9: /* Tab */
> >                 if (tab < 2)
> >                         ++tab;
> > -               p_tmp = buffer;
> > -               while (*p_tmp == ' ')
> > -                       p_tmp++;
> > -               if (p_tmp > cp)
> > -                       break;
> > -               memcpy(tmpbuffer, p_tmp, cp-p_tmp);
> > -               *(tmpbuffer + (cp-p_tmp)) = '\0';
> > -               p_tmp = strrchr(tmpbuffer, ' ');
> > -               if (p_tmp)
> > -                       ++p_tmp;
> > -               else
> > -                       p_tmp = tmpbuffer;
> > -               len = strlen(p_tmp);
> > -               buf_size = sizeof(tmpbuffer) - (p_tmp - tmpbuffer);
> > -               count = kallsyms_symbol_complete(p_tmp, buf_size);
> > +
> > +               tmp = *cp;
> > +               *cp = '\0';
> > +               p_tmp = strrchr(buffer, ' ');
> > +               p_tmp = (p_tmp ? p_tmp + 1 : buffer);
> > +               strscpy(tmpbuffer, p_tmp, sizeof(tmpbuffer));
>
> You're now using strscpy() here. Is that actually important, or are
> you just following good practices and being extra paranoid? If it's
> actually important, this probably also needs to be CCed to stable,
> right? The old code just assumed that it  could copy the whole buffer
> into tmpbuffer. I assume that was OK, but it wasn't documented in the
> function comments that there was a maximum size that buffer could
> be...

This is pretty much it.

I used strscpy() because the function does not document any upper limit
on the length of the supplied buffer. Thus using strscpy() means we are
resilient in the face of future refactoring.

I chose not to Cc: stable@... since it's only a theoretic overflow.
With the code as it currently is kdb_read() should never be passed a
buffer long enough to cause problems.


Daniel.

  reply	other threads:[~2024-04-23 11:02 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-04-22 16:35 [PATCH v2 0/7] kdb: Refactor and fix bugs " Daniel Thompson
2024-04-22 16:35 ` [PATCH v2 1/7] kdb: Fix buffer overflow during tab-complete Daniel Thompson
2024-04-22 21:39   ` Justin Stitt
2024-04-22 23:51   ` Doug Anderson
2024-04-23 10:17     ` Daniel Thompson
2024-04-22 16:35 ` [PATCH v2 2/7] kdb: Use format-strings rather than '\0' injection in kdb_read() Daniel Thompson
2024-04-22 23:52   ` Doug Anderson
2024-04-23 10:37     ` Daniel Thompson
2024-04-22 16:35 ` [PATCH v2 3/7] kdb: Fix console handling when editing and tab-completing commands Daniel Thompson
2024-04-22 23:52   ` Doug Anderson
2024-04-22 16:35 ` [PATCH v2 4/7] kdb: Merge identical case statements in kdb_read() Daniel Thompson
2024-04-22 23:52   ` Doug Anderson
2024-04-22 16:35 ` [PATCH v2 5/7] kdb: Use format-specifiers rather than memset() for padding " Daniel Thompson
2024-04-22 23:52   ` Doug Anderson
2024-04-22 16:35 ` [PATCH v2 6/7] kdb: Replace double memcpy() with memmove() " Daniel Thompson
2024-04-22 23:52   ` Doug Anderson
2024-04-22 16:36 ` [PATCH v2 7/7] kdb: Simplify management of tmpbuffer " Daniel Thompson
2024-04-22 23:52   ` Doug Anderson
2024-04-23 11:02     ` Daniel Thompson [this message]
2024-04-22 22:49 ` [PATCH v2 0/7] kdb: Refactor and fix bugs " Justin Stitt
2024-04-23 11:19   ` Daniel Thompson

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20240423110212.GC1567803@aspen.lan \
    --to=daniel.thompson@linaro.org \
    --cc=dianders@chromium.org \
    --cc=jason.wessel@windriver.com \
    --cc=kgdb-bugreport@lists.sourceforge.net \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®