From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qk2-f12.google.com (mail-qk2-f12.google.com [74.125.230.204]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 784374AB1A6 for ; Thu, 10 Sep 2026 15:39:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.230.204 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789054777; cv=none; b=fT4d4J6FOzMwSZbtVROm98piDNmkSvdeY0FIieXhOnQn046RudLZNHCrbhaRl8mdE18HVCd/Nw8Jc6iRGDFPNNJwplnDjK6daoweMnKyhgpA+QRUX/vnmnvmCBmbWy9VjDmC82EmSS0pKqXPDh5t5LKPYPpusmtBYMbzSbCyA5w= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789054777; c=relaxed/simple; bh=yWG+hoDEtLJ/6H3nP82927cNZvMVB+giKJZJxO/9hwY=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=NXGoeja69psxrJV81EuZpON/rkaIfoO2KX4wUI1h5B2FyU/mqCDOIi786bKlyhyjUSwP2T1bs8lIOQUr4y7uVWll3M4QhIW9kPJozuAnVL3PJkn3GAsVQomY5pvSFnXWBPL9i+YZ1TtBWPVBZLF0btIu1FlviYLnL65Kcm9AvXY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=rn6XOEe5; arc=none smtp.client-ip=74.125.230.204 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="rn6XOEe5" Received: by mail-qk2-f12.google.com with SMTP id d75a77b69052e-5308fc4b67cso14493971cf.1 for ; Thu, 10 Sep 2026 08:39:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789054774; x=1789659574; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=LVg0q1Ig+XeCRC/Adf+hBiNx1miS6vJUHYevs12aWqM=; b=rn6XOEe5eR3CvGtusW2Y5oWYJ861I5S8DHjNeP4uo+jnGfHopfHnA6OjxpzYXScrNU vVfbp/0NQ0JyEFs1vVX3tb4Ee+vKJ5ghkZesChZoQZnYFOx/8YM+bh9T9b+O9zDS22aZ jxxks++bcrge+TR6WBtRlJjuBksCT4vnJBLB6isM3wSigWQw0j1bCMCgjg4gahzwa+3j jI90g9ThbT9cJARel5CRBBbii3LJzj8gbvBCiqRq6CDzzNV3Lb40iCVP65eh3LfjbKdG 1pD0NP/U7dQbdJPT3Dq05g98sogLNOSvZmMr2tdvcIH+cre14K1JO6O78PSokjVBV0Ad SXow== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789054774; x=1789659574; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=LVg0q1Ig+XeCRC/Adf+hBiNx1miS6vJUHYevs12aWqM=; b=ZQ0+UP6uAiNxZSDBaFytpacZS4OuEimT49vcvgLDYGOtpTkEQrgXtUm6zlHE5JN/Mj 7C1zry+9yj9TY/S9FBBTk0UpEeOm0H7C6tnmwzk0NvWVdk6hcIADs+O2t4yP5+GgOE0M L+t8P5MYLY4CcbfWczVdE5o2D9ORdn0L+myc0gOJZReo9xo8sNMBZxcDENl7ikHjlA8H rg/8ahmjaoqQ/zOXbnNBC91tqxlJecIqjFB0BSi3lrER2lZGTTfS0tMiONnxdXR4X64E jV+tqQAmV6pgwKwFfTSZNfmGl5CdPpJJF2VTIUeVwOt3o6tY2acr9GYZFWCr6EvPIgCO 6I7Q== X-Forwarded-Encrypted: i=1; AKwUvBzcDnSG1mTZNvavwCJTOS8mxFPMsAiyLrLeG9fk8c4MEDx0uBbFyMdC0c/XN+hVd3zAMBanwSHrd6lMAzE=@vger.kernel.org X-Gm-Message-State: AFuF++kCpc0Sxu6Uu2nknUzEeYwW2HMVl57zPpJET6C5EAJ/kU1ZJ7Hj 1bpb4B1x9nw5J4bDKwbTgZlG8cMcjf1XQWB0rykrBx8qesT/HMyPDBGp X-Gm-Gg: AYBFou3x7QDG0ZFdpA7MkJUqX13IGKEs9faj8kVUY/iCkhiuSuioPsYTlkFkJ9nQ7SM BUnuJr4CYHaQvjV7rQdtXxi/iOANUATy10QlG14kTXh35+ISRNYQRfYQV3UIDEi3ZpZVsZjrwEX OdxHZhohbnQKV4WR1TNUiufN+dYuj3VcM+IXE1w85PmDeCLHazKAfu2A0tCBshgXYF+xUkR3hkQ 7FQEF7AJeMBg0/Txbg3pRBbzWnpQZi3lnX94Fmyeh5TBJoxmdSBPgS37zkSITIxHdyQTM/FUiul xtDDGF35UIHpuF6T3gj/1Uv1RZnkbqI9R2N5d+lL2qizOMS4G/1lDbPLPNBRjJF+RENBkljxGWe NK7DoSqTzVeEqBDuLxuS2pCu0lsqI5liz4m7XMFT3nwrOtXaX6zT/EiDG3KYBC/d+GnAVWtwcPq TZhiWYctzoXgP0tnsUwqvUPlky076XJHEHc7JVij8LmBSmd+pveJi/gh24E0QaAiIjK06vQCTAy 54PuI1I X-Received: by 2002:ac8:5a8d:0:b0:530:6ffd:1ce8 with SMTP id d75a77b69052e-530aedb7cbbmr100110721cf.41.1789054773862; Thu, 10 Sep 2026 08:39:33 -0700 (PDT) Received: from tofu.. ([128.210.0.165]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-5305413ce9dsm170860171cf.11.2026.09.10.08.39.32 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 08:39:33 -0700 (PDT) From: Georgios Androutsopoulos To: Greg Kroah-Hartman , "Rafael J . Wysocki" , Danilo Krummrich , Miguel Ojeda Cc: Dave Ertman , Ira Weiny , Leon Romanovsky , Boqun Feng , Gary Guo , =?UTF-8?q?Bj=C3=B6rn=20Roy=20Baron?= , Benno Lossin , Andreas Hindborg , Alice Ryhl , Trevor Gross , Daniel Almeida , Tamir Duberstein , Alexandre Courbot , =?UTF-8?q?Onur=20=C3=96zkan?= , driver-core@lists.linux.dev, rust-for-linux@vger.kernel.org, linux-kernel@vger.kernel.org, Georgios Androutsopoulos Subject: [PATCH v2] rust: auxiliary: validate DeviceId name length Date: Thu, 10 Sep 2026 11:38:44 -0400 Message-ID: <20260910153844.3987791-1-georgeandrout13@gmail.com> X-Mailer: git-send-email 2.47.3 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit `DeviceId::new()` copies `modname` and `name` into the fixed 40-byte `auxiliary_device_id::name` array without checking that they fit. An oversized name is caught by the array bounds check, but the error reports an out-of-bounds index in the copy loop rather than the constraint the caller violated. Check the invariant explicitly instead, so the failure states the length limit rather than an array index. This should only be reached when constructing a device ID table, so the failure is a compile time error. Document that intent. Signed-off-by: Georgios Androutsopoulos --- Changes in v2: - Drop Fixes: following feedback from Danilo Krummrich and Alexandre Courbot. - Replace the `# Panics` section with a note that this is for device ID table construction, following feedback from Danilo Krummrich and Gary Guo. - Reword the commit message so it does not suggest runtime evaluation, following feedback from Alexandre Courbot. - Link to v1: https://lore.kernel.org/rust-for-linux/20260909033246.2779303-1-georgeandrout13@gmail.com/ --- rust/kernel/auxiliary.rs | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/rust/kernel/auxiliary.rs b/rust/kernel/auxiliary.rs index 60dfbec8f330..2ace0428e45e 100644 --- a/rust/kernel/auxiliary.rs +++ b/rust/kernel/auxiliary.rs @@ -137,10 +137,18 @@ macro_rules! module_auxiliary_driver { impl DeviceId { /// Create a new [`DeviceId`] from name. + /// + /// This is only intended to be called in const context, when constructing a + /// device ID table, where exceeding `AUXILIARY_NAME_SIZE` is a compile time error. pub const fn new(modname: &'static CStr, name: &'static CStr) -> Self { let name = name.to_bytes_with_nul(); let modname = modname.to_bytes_with_nul(); + assert!( + modname.len().saturating_add(name.len()) <= bindings::AUXILIARY_NAME_SIZE as usize, + "auxiliary device ID is too long" + ); + let mut id: bindings::auxiliary_device_id = pin_init::zeroed(); let mut i = 0; while i < modname.len() { base-commit: 28924df2a08f440c73991b83028032c901de2ae4 -- 2.47.3