On Tue, Jul 21, 2026 at 04:20:42PM +0530, Mallesh Koujalagi wrote:
> event_string[] has a fixed size of WEDGE_STR_LEN (32) bytes. Since
> scnprintf() reserves space for the terminating null byte, it can write
> at most 31 characters.
>
> When len reaches WEDGE_STR_LEN - 1, only the null terminator fits in the
> remaining space. Any further scnprintf() calls return 0 and additional
> recovery method names are silently dropped, making the truncation hard
> to detect.
>
> Add a drm_WARN_ON() check for len >= WEDGE_STR_LEN - 1 before attempting
> another write. If the buffer is already full, emit a warning and stop
> processing further entries. This makes buffer truncation visible and
> allows the loop to exit cleanly instead of silently ignoring recovery
> methods.
>
> Fixes: b7cf9f4ac1b8 ("drm: Introduce device wedged event")
> Signed-off-by: Mallesh Koujalagi <[email protected]>
> ---
> drivers/gpu/drm/drm_drv.c | 3 +++
> 1 file changed, 3 insertions(+)
>
> diff --git a/drivers/gpu/drm/drm_drv.c b/drivers/gpu/drm/drm_drv.c
> index 1ff0bf7cba6a..63eef0a19e99 100644
> --- a/drivers/gpu/drm/drm_drv.c
> +++ b/drivers/gpu/drm/drm_drv.c
> @@ -578,6 +578,9 @@ int drm_dev_wedged_event(struct drm_device *dev, unsigned
> long method,
> if (drm_WARN_ONCE(dev, !recovery, "invalid recovery method
> %u\n", opt))
> break;
>
> + if (drm_WARN_ON(dev, len >= WEDGE_STR_LEN - 1))
len is the starting offset for current method, so the string can still
be truncated. And we also have to account for the trailing comma which
we later drop, so I think the correct logic would be something like
if (drm_WARN_ON(dev, len + strlen(recovery) + 1 >=
WEDGE_STR_LEN - 1))
which looks worth an explanation here.
Raag
> + break;
> +
> len += scnprintf(event_string + len, sizeof(event_string) -
> len, "%s,", recovery);
> }
>
> --
> 2.48.1
>