From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qk1-f182.google.com (mail-qk1-f182.google.com [209.85.222.182]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C177C32861E for ; Thu, 11 Jun 2026 21:33:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.182 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781213618; cv=none; b=TCVbHhmsdjXy1qZjFOrdmAwLs2g09hUBNYq9YCvAasb2Y/m1ZEMuP0h3UXoc50Ayg0QIMUBYX1MbZWbkuzDG7dTmeSAGDtUJts0ZE8RZTbMMiQ7W7u45g1F0D/ZocjGGlvebM+2Wyy+nGAESECjHrDoaVln/UPzk9c/mOBnXhkM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781213618; c=relaxed/simple; bh=mT8kNUEDIcc/xJe/GoAWK7HRYZZ5fog7EKo6wCAye9s=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=mmMwNQiEHGmig161nkNRCixbKJEkxT6agVWdjcVhsLEq0y/XSBNU52FQE2ZKK0m4ACGuzHLpVUsjn/1/rQFIlzKFIxW9FkYgNu1OY+2CHgWkPWLxVpVPFj8oP8suyNsFZaVyxb7LFVKnmvuNEwKdNkotBpp1weJ7gwaj3O7Z30c= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=openai.com; spf=pass smtp.mailfrom=openai.com; dkim=pass (1024-bit key) header.d=openai.com header.i=@openai.com header.b=KFNE9ufp; arc=none smtp.client-ip=209.85.222.182 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=openai.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=openai.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=openai.com header.i=@openai.com header.b="KFNE9ufp" Received: by mail-qk1-f182.google.com with SMTP id af79cd13be357-91587626a3eso39543185a.2 for ; Thu, 11 Jun 2026 14:33:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=openai.com; s=google; t=1781213616; x=1781818416; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=mKga1ggz6sdNzSSWK/KwEajXdsMF2aeCFFV+bSkqv7s=; b=KFNE9ufpR4GETbFMm0LVyuObEqLbqBX6EGsQhYjlDr39dpN/g5uZtR1EhfbXLzjqXs 55mgrRMwpb9QyHNvuAx0/CZFiA7IF/EI9TQmIjIT4jfrcTVhMbtFwp9H/4h32pAH0g2x GtZvT+QRNj0zkgFYUFzCJOmeABTsUcx6ZMFh8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781213616; x=1781818416; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=mKga1ggz6sdNzSSWK/KwEajXdsMF2aeCFFV+bSkqv7s=; b=ojOUShF3RW0e4IQ/PF4lD8j+O7axUqDN45vl4S5zGfBQleOrBRL+RmhYBxkyFqEPT3 3itPbdPUtp54aawUHXn7TvA5849xNsAcmdKVw6p5uyuvN3wi9QQmcQ9f70Ep5o6ivRIR qAao/t+bK+bEB8jBI+scW0Xx7kRbCAV3RnySKxjoROwg8H9OR80gJ/lJnIUqFx5L68ox 51RlTJmyevvdx8e90DCHn/PlxQtB4cBknUNv20A8WoD8b7u+GV73RH0zVAKHkB4KeqlQ dO0BWS2Neiz/tDOL+Mv/n0BeMo/PCmDvtFjZfU+d5Uq0fFt+dMuUJfgfWCLU0leRYZwD eu2A== X-Gm-Message-State: AOJu0YyNm1F+E1AffYYaTTKySd+KJstMoU8jCC7jEdx7tlCdtEcjhEGO 9avpl04XK0SO2uMFiBq4khfKOtouxKL9ZVzOta6paPVoBIebNNT4omwrM192pDolpEk= X-Gm-Gg: Acq92OEYTtF7vAsIFm/jkQsv6FMjQt7BLz8cW/284/cuVg0xfFZlWYFK4VHa5sSRSSr QaJWO6T83xB+vq1TTb0rYOIDrbC16/9+drivwdoUbLhJ6xXoTrziEwo6dQjFS+vqVyIhuiDrtyn kAywhCi6hQ+0t/VvUhHfJ0l70MFRogH0JBz9M+qarrKGMAX+VDapkV+8BVb//xVseD6V/nPpjYK QaBUuhdEFLy5gcjcGYYjHLJFJ5vZ9OKqqJg8ATpdHMOWBJODttXK76/z/aaaoWuso81usYXyDkt fWIF0vp+hSm2aNQPwnori3s3GFyxMF+seWSVv7xhinTB6vnybvrAURiWLw0bnKfBZdjrnOthfyw E76flxA1I1P87ezR3ha/++5VvKwZ/uoUn30FziTnuqTEA1PGsxl5etoKPtsRey0a7Esw20R3C/j 2QDYAGqU/yPZWJu2exepW2VF6M5KFL6GkA/JwF2wMz3QxbSkRWb0IDY96ZCjBubRdcGmdW/NPtg vqLFJqfV/JvdsYrqvMRh3xipAlrZzHnKmg= X-Received: by 2002:a05:620a:c4b:b0:915:e12d:19ce with SMTP id af79cd13be357-9160b030a68mr742279285a.47.1781213615629; Thu, 11 Jun 2026 14:33:35 -0700 (PDT) Received: from com-75606.node.ndb.openai.org ([209.249.37.146]) by smtp.gmail.com with ESMTPSA id af79cd13be357-9161a006e50sm26861285a.29.2026.06.11.14.33.34 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Thu, 11 Jun 2026 14:33:35 -0700 (PDT) From: Kyle Zeng To: ntfs3@lists.linux.dev Cc: linux-kernel@vger.kernel.org, Konstantin Komarov , outbounddisclosures@openai.com, Kyle Zeng Subject: [PATCH] fs/ntfs3: reserve NUL byte when converting UTF-16 names Date: Thu, 11 Jun 2026 14:33:31 -0700 Message-ID: <20260611213331.16763-1-kylebot@openai.com> X-Mailer: git-send-email 2.54.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit ntfs_utf16_to_nls() appends a trailing NUL to the converted output, but it passes the caller-supplied size directly to the conversion loop. For the UTF-8 path, utf16s_to_utf8s() can legitimately fill all buf_len bytes and return buf_len, after which ntfs_utf16_to_nls() writes the terminator one byte past the end of the destination buffer. The same contract problem exists for the NLS path when a converted character consumes the last available byte. Reserve one byte for the terminator before doing either conversion. The function continues to return the number of converted bytes, excluding the NUL terminator. Assisted-by: Codex:gpt-5.5 Signed-off-by: Kyle Zeng --- fs/ntfs3/dir.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/fs/ntfs3/dir.c b/fs/ntfs3/dir.c index d99ab086ef6f..e8892cd94e04 100644 --- a/fs/ntfs3/dir.c +++ b/fs/ntfs3/dir.c @@ -25,6 +25,11 @@ int ntfs_utf16_to_nls(struct ntfs_sb_info *sbi, const __le16 *name, u32 len, static_assert(sizeof(wchar_t) == sizeof(__le16)); + if (buf_len <= 0) + return -EINVAL; + + buf_len -= 1; + if (!nls) { /* UTF-16 -> UTF-8 */ ret = utf16s_to_utf8s((wchar_t *)name, len, UTF16_LITTLE_ENDIAN, -- 2.43.0