mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Bradley Morgan <brads@mainlining.org>
To: akpm@linux-foundation.org
Cc: blum@kernel.org, tglx@linutronix.de, dianders@chromium.org,
	linux-kernel@vger.kernel.org, brads@mainlining.org
Subject: [PATCH v2] watchdog/perf: fix off by one in the raw event config copy
Date: Sat, 3 Oct 2026 00:08:00 +0000	[thread overview]
Message-ID: <20261003000800.2-brads@mainlining.org> (raw)
In-Reply-To: <CAD=FV=U-uH7iTA8Gs_vTqzbKjpk9uwCiSRGbPchmJc7DAWR43w@mail.gmail.com>

You were right, the truncation was the bigger half of the bug and my
v1 only closed the corner. Fixed both with your len + 1 shape.

Commit 6164be01f179 ("watchdog/perf: optimize bytes copied and remove
manual NUL-termination") replaced strscpy(buf, str, sizeof(buf)) plus a
manual buf[len] = 0 with strscpy(buf, str, len). That count is one less
than the code needs, strscpy() always reserves the last byte of the
destination for the NUL, so the config loses its final digit.
nmi_watchdog=r300,panic for example ends up with buf = "30" and arms
the raw event with the wrong config.

The same count also drops the empty case on the floor, strscpy() with
a zero count writes nothing at all, so nmi_watchdog=r,1 leaves buf
uninitialized and kstrtoull() reads stack garbage.

The old code was safe on both counts by accident, strscpy() filled the
whole buffer before buf[len] = 0 overwrote the comma position, so the
worst outcome was a truncated parse failure.

Pass len + 1 so the copy includes the character the NUL replaces, and
reject len >= sizeof(buf) like the code did before the optimization,
which also makes an empty config a clean parse failure again.

Suggested-by: Doug Anderson <dianders@chromium.org>
Fixes: 6164be01f179 ("watchdog/perf: optimize bytes copied and remove manual NUL-termination")
Signed-off-by: Bradley Morgan <brads@mainlining.org>
---
 kernel/watchdog_perf.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/kernel/watchdog_perf.c b/kernel/watchdog_perf.c
index cca0485ba28c..a4f677c16b20 100644
--- a/kernel/watchdog_perf.c
+++ b/kernel/watchdog_perf.c
@@ -301,10 +301,10 @@ void __init hardlockup_config_perf_event(const char *str)
 	} else {
 		unsigned int len = comma - str;
 
-		if (!len || len > sizeof(buf))
+		if (len >= sizeof(buf))
 			return;
 
-		strscpy(buf, str, len);
+		strscpy(buf, str, len + 1);
 		if (kstrtoull(buf, 16, &config))
 			return;
 	}
-- 
2.53.0


  reply	other threads:[~2026-10-03  0:07 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-02 17:50 [PATCH] watchdog/perf: reject empty config before the raw event parse Bradley Morgan
2026-10-02 22:12 ` Doug Anderson
2026-10-02 22:17   ` Bradley Morgan
2026-10-02 22:19     ` Doug Anderson
2026-10-03  0:08       ` Bradley Morgan [this message]
2026-10-03  0:30         ` [PATCH v2] watchdog/perf: fix off by one in the raw event config copy Doug Anderson
2026-10-03 10:28           ` Bradley Morgan

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261003000800.2-brads@mainlining.org \
    --to=brads@mainlining.org \
    --cc=akpm@linux-foundation.org \
    --cc=blum@kernel.org \
    --cc=dianders@chromium.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=tglx@linutronix.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®