From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wr1-f54.google.com (mail-wr1-f54.google.com [209.85.221.54]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9CD2517A2EA for ; Wed, 25 Feb 2026 23:12:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.54 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772061145; cv=none; b=gEWw1JBCL2teRLLlltXHoLFiZkBvK6aITTqVe4n5OyIlq3Awlyb6HNBLh0j+yDbKemBtT3eif1/29uz4gEjQBoZDGC2OkMJ8zxv6yMDK20ukDSZvKJNnJUhsvMTJiz6vFdPrmHLTTYtY8gScOgR6VNiW3U13EoqXEDgYjxWM4IM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772061145; c=relaxed/simple; bh=mktAuhFvOegNecDNPnjU/yatWa3GQ6+habt1MpR67bA=; h=Date:From:To:Cc:Subject:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=AEbu9zeQWOipNvyIhr4XT+MR5VXrwtNRg/ftv2U4D8a+1PHG4snj1HJLZkuKRnwpKvI4QGzRbiNfDdLrM+dvjzavZGbUk2ELbI3oFDSn6ZXtVf2jxPahFyEcD9oTGX57hEWT8B5PCYafMVaDQx9zosNO2W0RbpuOWsDaCtNoMIw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=b6+wRqhI; arc=none smtp.client-ip=209.85.221.54 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="b6+wRqhI" Received: by mail-wr1-f54.google.com with SMTP id ffacd0b85a97d-43767807da6so147846f8f.2 for ; Wed, 25 Feb 2026 15:12:24 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1772061143; x=1772665943; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:subject:cc:to:from:date:from:to:cc:subject:date :message-id:reply-to; bh=gS8py3u+cEzTgux8bkBur54jjtLsYVQ5f5l5cYoXnEM=; b=b6+wRqhIKv6L++ieq7J5UTnGWmPaJBSPJpok1gR3qrjE/tjj7FTZNlhpIhsJuJyT7W a9Gz9SG7uXC4iSO8sRaBgiY4yIOJai821fLCj9LcNQ+fGBQMcBEgUJWF8xnn6c8Uo/7r Jf2lIXFWUDKLtPfOC/hQE2i8AFglxvUcsb/Dofk2ae6FRssVII6bsL4nVFBBogQD8R4J EPC0Ev830Tw1QYd5nGn2wW1J2mOCqHa1NV3N8TZ0rqUbtn4w4kSl2tOwa/M+KToCbLzI cSKIe+ITSsV2uhI4cmN3Smwc2oTHQ9Eqag6tdkIG51r7g9b4ZMBdcCBNUOwZivfX7NHY xb4g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1772061143; x=1772665943; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:subject:cc:to:from:date:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=gS8py3u+cEzTgux8bkBur54jjtLsYVQ5f5l5cYoXnEM=; b=roMAJn9FfZaGx0wEy4Bgdl0vjtpymHqi7npncGSgFwC6fQiKyKsVE0j1UKQDNpABfS 4jLG/Qq5ucc5ZjiIVwDPApoK2bEfHA/lFh6gaP0Jcy9c5VdR4XGXgckikjbc5BOSY6t5 9/LaMJKq7QnpTANNXuaxnx4JhAKiSc+4MZof883GJkxD3ImqY2zZUgCMnXUlSqvGZbVe sI9iHh4AVMVUzM+VUZ0U9krCCKAeOIBtS32NjLj90miVFnNNZzHW66JWP2VuqHkqwChL WipkMkt1FbNnVc/ZbEjfTMKCepO4OBHE/nPSd6gLCWkfzfhkNhxQxemjA/OjJftvTVoI 7KUQ== X-Forwarded-Encrypted: i=1; AJvYcCXFHCqaoGwONLNEqUOqNt9elN6sJbsk3L6T8PMFxbdO6vh6hUh3YgH3l4hlZveanwfu2Yt/sRqJeJjaJig=@vger.kernel.org X-Gm-Message-State: AOJu0YxLqZ+UYcd+LY/hpMDhIzRbiYqvyq9/Wf+oHrUK5Eixf0+ksdV3 xe2T0G+n70yJVXC1aSn7x2JzHRg3RwY+emxx1rkwc7f18BMbzw2s+Pre X-Gm-Gg: ATEYQzxmfzXar66ZmyKn4rM+/TbCLRbW46MHKedFXsTdshGsAaC6Oe0tZJY3E9ZvpUS vIZXLpjHFI2J0YS0EsY3+5kwgGh/16iWTaxt0w9IrR41Kjlu27eyYdgUcIRKAgBdLOck9kg9+Fw 5cDrDchLvmjPfjrX58vtmZDu6eKieHgtnBY+L5iQArDePsstS5UGhCGNm6wdr36/qzAtZuOppaE 6cpSIMhotMRkUb9DuH0hfAgDtpoIHeBg444z9fk/9VI5EGg28D5QPhAPTey0OQZUQSjB+0pqPCG TwbPRUyJEh6waGe2/hRNa8lNGFFbvZjyqhnUrZW6WkeMlYUe+SJagkLu/s5u7L/tILCiACxqGbj J+WnlpQVcCcUzcBqxEV7etdSVADRJ3DttNso2CZYeo93IJD/uk+VVCaOsrT8d3TIjZ9W/bshq9d OQgTVn4T2TwPfouf2EBgPkNSfjXhnhAgDhQBPS75rtLkPEwzx63c3Ce3EjrkHOX7wA X-Received: by 2002:a05:6000:1a8f:b0:437:6ca8:3ede with SMTP id ffacd0b85a97d-43997ee2a6dmr578869f8f.15.1772061142902; Wed, 25 Feb 2026 15:12:22 -0800 (PST) Received: from pumpkin (82-69-66-36.dsl.in-addr.zen.co.uk. [82.69.66.36]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-43970d5463dsm33766391f8f.34.2026.02.25.15.12.22 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 25 Feb 2026 15:12:22 -0800 (PST) Date: Wed, 25 Feb 2026 23:12:21 +0000 From: David Laight To: Thomas =?UTF-8?B?V2Vpw59zY2h1aA==?= Cc: Willy Tarreau , linux-kernel@vger.kernel.org, Cheng Li Subject: Re: [PATCH v3 next 07/17] tools/nolibc/printf: Move snprintf length check to callback Message-ID: <20260225231221.70b0531f@pumpkin> In-Reply-To: References: <20260223101735.2922-1-david.laight.linux@gmail.com> <20260223101735.2922-8-david.laight.linux@gmail.com> X-Mailer: Claws Mail 4.1.1 (GTK 3.24.38; arm-unknown-linux-gnueabihf) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable On Wed, 25 Feb 2026 23:37:42 +0100 Thomas Wei=C3=9Fschuh wrote: > On 2026-02-23 10:17:25+0000, david.laight.linux@gmail.com wrote: >=20 > (...) >=20 > > @@ -425,18 +430,25 @@ int __nolibc_printf(__nolibc_printf_cb cb, intptr= _t state, size_t n, const char > > =20 > > /* literal char, just queue it */ > > } > > + > > + /* Request a final '\0' be added to the snprintf() output. > > + * This may be the only call of the cb() function. > > + */ > > + if (cb(state, NULL, 0) !=3D 0) > > + return -1; > > + > > return written; > > } =20 >=20 > (...) >=20 > > +static int __nolibc_sprintf_cb(void *v_state, const char *buf, size_t = size) > > { > > - char **state =3D (char **)_state; > > + struct __nolibc_sprintf_cb_state *state =3D v_state; > > + size_t space =3D state->space; > > + char *tgt; > > + > > + /* Truncate the request to fit in the output buffer space. > > + * The last byte is reserved for the terminating '\0'. > > + * state->space can only be zero for snprintf(NULL, 0, fmt, args) > > + * so this normally lets through calls with 'size =3D=3D 0'. > > + */ > > + if (size >=3D space) { > > + if (space <=3D 1) > > + return 0; > > + size =3D space - 1; > > + } > > + tgt =3D state->buf; > > + > > + /* __nolibc_printf() ends with cb(state, NULL, 0) to request the outp= ut > > + * buffer be '\0' terminated. > > + * That will be the only cb() call for, eg, snprintf(buf, sz, ""). > > + * Zero lengths can occur at other times (eg "%s" for an empty string= ). > > + * Unconditionally write the '\0' byte to reduce code size, it is > > + * normally overwritten by the data being output. > > + * There is no point adding a '\0' after copied data - there is always > > + * another call. > > + */ > > + *tgt =3D '\0'; > > + state->space =3D space - size; > > + state->buf =3D tgt + size; > > + memcpy(tgt, buf, size); =20 >=20 > This trips UBSAN for me when 'buf =3D=3D NULL'. >=20 > if (cb(state, NULL, 0) !=3D 0) > return -1; >=20 > It can be fixed by adding a NULL check around memcpy(), > but I'd rather not do this as a random fixup. Blame Willy, he made me remove the 'if (size)' check to reduce the code size. The '*tgt =3D 0' line is (only) needed when size is zero, the other lines are clearly pointless. So the 'random fixup' is adding 'if (size)' rather than a NULL pointer check printf("%s", "") will give a zero size with non-NULL buf. IIRC the C standard make memcpy(tgt, NULL, 0) UB because some old system no one has used for 40+ years would trap when NULL was loaded into an 'address register' and they wanted it to be compliant. David >=20 > > =20 > > - memcpy(*state, buf, size); > > - *state +=3D size; > > return 0; > > } =20 >=20 > (...)