From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mgamail.intel.com (mgamail.intel.com [192.198.163.12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B21EB3BD645 for ; Thu, 26 Mar 2026 09:54:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=192.198.163.12 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1774518874; cv=none; b=JEQNH4e0KnCD9571fSeKWibo46UoM42ndQKe9eV2bvA9jAuqDTjCcA/fW77Lp49/odo88Lc1LsbPkUV/ElC0A8tOD5wID3chEfJdvw5x7x6pDJQIU6kwqzENhU6fy+PXGklHbsR+Zt7b/f4NXUvhL22JPeyDk+/rK51N7201PsE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1774518874; c=relaxed/simple; bh=KyhSZtZH3wwvWeMNEuSFJ2fpWxTjx+38RmhVvsiSg+c=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=Qz0OH52QzaVtguHPX/dCu+kMII2cfhkE7ZZNHN6TO1q0hm2oUdokNMWF1kX4fw8t56S1eTPnObsAC1Ewq2O5A2B365IWHHZL5qa2Bf5k2dRwEPPX7fuWVdhOW4mVgCbiN+K7aVn8nNiQ1olk5p/ks97tG8fww/bvbM2vUJWrQB0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.intel.com; spf=pass smtp.mailfrom=linux.intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=kMYO/x9U; arc=none smtp.client-ip=192.198.163.12 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="kMYO/x9U" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1774518873; x=1806054873; h=date:from:to:cc:subject:message-id:references: mime-version:in-reply-to; bh=KyhSZtZH3wwvWeMNEuSFJ2fpWxTjx+38RmhVvsiSg+c=; b=kMYO/x9UAlO2iUfIbiTDoR+aDo2z3W3lOw/wHeDniZ9s4z74SpkeZ29+ u4sLH5TyR/Y5iv+wCPjeicBcH0PHOpTxAEHD88k/aKmnbRMQPKLX75bmn ya112uAE5Nt9Yu5HbzQziq90SHQmIKbQtGdxQNfisGj1ymMSpRREpIRox G0Qwr+VqOFbTW17du3yKBbdQRayw64H/0mWmtbvhsEufIg/mubILf4d8+ LeAC09mSJXkepZ6DhN5eaoVnoUk699rMLEXPa3acPNoTNaPoSkJOK1xXZ rmWK0fQzjlq2t/zPg+f9biJYwQKbfcNNzLHrMmkOnCh+g7WYSLuNsyFIo A==; X-CSE-ConnectionGUID: j7Lhbtn8TMqKfUfsjM6iwg== X-CSE-MsgGUID: ZERTjiLcTG2G3d12pUAZzg== X-IronPort-AV: E=McAfee;i="6800,10657,11740"; a="79476416" X-IronPort-AV: E=Sophos;i="6.23,141,1770624000"; d="scan'208";a="79476416" Received: from orviesa007.jf.intel.com ([10.64.159.147]) by fmvoesa106.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 26 Mar 2026 02:54:32 -0700 X-CSE-ConnectionGUID: qSW+kmeSSmuwoZ15mNwjpQ== X-CSE-MsgGUID: x3VXS9efScqYQEZOHgNwQA== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.23,141,1770624000"; d="scan'208";a="225215383" Received: from smoticic-mobl1.ger.corp.intel.com (HELO localhost) ([10.245.245.216]) by orviesa007-auth.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 26 Mar 2026 02:54:29 -0700 Date: Thu, 26 Mar 2026 11:54:27 +0200 From: Andy Shevchenko To: Masami Hiramatsu Cc: Petr Mladek , Steven Rostedt , Rasmus Villemoes , Sergey Senozhatsky , Andrew Morton , David Laight , linux-kernel@vger.kernel.org Subject: Re: [PATCH v5 0/2] lib/vsprintf: Fixes size check Message-ID: References: <177444525139.185641.12184379647176430297.stgit@devnote2> <20260325224158.d5366b99fd0a1eb54ce5e19b@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20260325224158.d5366b99fd0a1eb54ce5e19b@kernel.org> Organization: Intel Finland Oy - BIC 0357606-4 - c/o Alberga Business Park, 6 krs, Bertel Jungin Aukio 5, 02600 Espoo On Wed, Mar 25, 2026 at 10:41:58PM +0900, Masami Hiramatsu wrote: > On Wed, 25 Mar 2026 22:27:31 +0900 > "Masami Hiramatsu (Google)" wrote: > > > Hi, > > > > Here is the 5th version of patches to fix vsnprintf(). > > > > - Fix to limit the size of width and precision. > > - Warn if the return size is over INT_MAX. > > > > Previous version is here; > > > > https://lore.kernel.org/all/177440550682.147866.1854734911195480940.stgit@devnote2/ > > > > In this version, negative precision is treated as zero to match the > > previous behavior and check the field/precision passed as string > > literals too[1/2]. Also, update bstr_printf() not to return negative > > value[2/2]. > BTW, skip_atoi() is used for converting precision and width, > but this does not check the overflow. This is expected to be > checked by compiler (-Wformat-overflow) but it checks the > width <= INT_MAX, but precision <= LONG_MAX (why?) and clang > does not check precision. > > To avoid this issue, below fix is needed, but I'm not sure > this is meaningful check, because with [1/2] change, the > return value is limited anyway, and it's easy to check > during the review process if an obviously abnormal > precision value is passed in the format string. > diff --git a/lib/vsprintf.c b/lib/vsprintf.c I you event want to do that, it should use macros from overflow.h, also see how kstrto*() and memparse() perform such checks. Also this may slow down the conversion. -- With Best Regards, Andy Shevchenko