From: Bill Wendling <[email protected]> Several strlcat() call sites being converted to seq_buf need behavior seq_buf doesn't currently provide. The normal seq_buf_init() always sets the new buffer size to 0 via seq_buf_clear(). Code migrating from strlcat(buf, ...), which appends to whatever buf already contains, can't use seq_buf_init() without discarding that existing content. Add seq_buf_init_append(), which preserves the existing contents and positions the seq_buf to append after it. Add KUnit tests for behavior coverage.
Tests passed under qemu on ARCH=x86_64 with GCC 16.2.0 and CONFIG_KASAN=y, and on big-endian ARCH=s390 with GCC s390x-linux-gnu 16.1.0. Assisted-by: LLM Signed-off-by: Bill Wendling <[email protected]> Co-developed-by: Kees Cook <[email protected]> Signed-off-by: Kees Cook <[email protected]> --- Cc: "Matthew Wilcox (Oracle)" <[email protected]> Cc: Andrew Morton <[email protected]> Cc: Andy Shevchenko <[email protected]> Cc: David Gow <[email protected]> Cc: Petr Mladek <[email protected]> Cc: Shuvam Pandey <[email protected]> Cc: Steven Rostedt <[email protected]> --- include/linux/seq_buf.h | 20 +++++++++++++++ lib/tests/seq_buf_kunit.c | 53 +++++++++++++++++++++++++++++++++++++++ 2 files changed, 73 insertions(+) diff --git a/include/linux/seq_buf.h b/include/linux/seq_buf.h index 7f025c7a68be..89d847d40626 100644 --- a/include/linux/seq_buf.h +++ b/include/linux/seq_buf.h @@ -46,6 +46,26 @@ seq_buf_init(struct seq_buf *s, char *buf, unsigned int size) seq_buf_clear(s); } +/** + * seq_buf_init_append - initialize a seq_buf over a buffer that may + * already hold NUL-terminated content + * @s: the seq_buf handle + * @buf: pointer to the (possibly non-empty) buffer + * @size: total size of @buf + * + * Unlike seq_buf_init(), which always starts @buf at len=0, this + * preserves whatever NUL-terminated content @buf already holds and + * positions @s to append after it. Useful for converting code that used + * to append to an existing buffer with strlcat()/scnprintf() and friends. + */ +static inline void +seq_buf_init_append(struct seq_buf *s, char *buf, unsigned int size) +{ + s->buffer = buf; + s->size = size; + s->len = strnlen(buf, size); +} + /* * seq_buf have a buffer that might overflow. When this happens * len is set to be greater than size. diff --git a/lib/tests/seq_buf_kunit.c b/lib/tests/seq_buf_kunit.c index 0259c8506b89..f3058771d96c 100644 --- a/lib/tests/seq_buf_kunit.c +++ b/lib/tests/seq_buf_kunit.c @@ -29,6 +29,58 @@ static void seq_buf_init_test(struct kunit *test) KUNIT_EXPECT_EQ(test, seq_buf_strlen(&s), 0); } +static void seq_buf_init_append_test(struct kunit *test) +{ + char buf[32] = "hello"; + struct seq_buf s; + + /* Initial string contents match. */ + seq_buf_init_append(&s, buf, sizeof(buf)); + KUNIT_EXPECT_EQ(test, s.size, 32); + KUNIT_EXPECT_EQ(test, s.len, 5); + KUNIT_EXPECT_FALSE(test, seq_buf_has_overflowed(&s)); + KUNIT_EXPECT_EQ(test, seq_buf_buffer_left(&s), 32 - 5); + KUNIT_EXPECT_EQ(test, seq_buf_used(&s), 5); + KUNIT_EXPECT_STREQ(test, seq_buf_str(&s), "hello"); + KUNIT_EXPECT_EQ(test, seq_buf_strlen(&s), 5); + + /* Appending with space works. */ + seq_buf_puts(&s, " world"); + KUNIT_EXPECT_FALSE(test, seq_buf_has_overflowed(&s)); + KUNIT_EXPECT_EQ(test, seq_buf_used(&s), 11); + KUNIT_EXPECT_STREQ(test, seq_buf_str(&s), "hello world"); + KUNIT_EXPECT_EQ(test, seq_buf_strlen(&s), 11); + + /* No truncation when space for NUL is present. */ + seq_buf_init_append(&s, buf, 12); + KUNIT_EXPECT_EQ(test, s.size, 12); + KUNIT_EXPECT_EQ(test, s.len, 11); + KUNIT_EXPECT_FALSE(test, seq_buf_has_overflowed(&s)); + KUNIT_EXPECT_EQ(test, seq_buf_used(&s), 11); + KUNIT_EXPECT_STREQ(test, seq_buf_str(&s), "hello world"); + KUNIT_EXPECT_EQ(test, seq_buf_strlen(&s), 11); + + /* Check for required truncation when full. */ + seq_buf_init_append(&s, buf, 11); + KUNIT_EXPECT_EQ(test, s.size, 11); + KUNIT_EXPECT_EQ(test, s.len, 11); + KUNIT_EXPECT_FALSE(test, seq_buf_has_overflowed(&s)); + KUNIT_EXPECT_EQ(test, seq_buf_buffer_left(&s), 0); + KUNIT_EXPECT_EQ(test, seq_buf_used(&s), 11); + KUNIT_EXPECT_STREQ(test, seq_buf_str(&s), "hello worl"); + KUNIT_EXPECT_EQ(test, seq_buf_strlen(&s), 10); + + /* + * The size bounds the scan: the string reaches past it, so an + * unbounded strlen() would report 10 here and leave @s overflowed. + */ + seq_buf_init_append(&s, buf, 5); + KUNIT_EXPECT_EQ(test, s.size, 5); + KUNIT_EXPECT_EQ(test, s.len, 5); + KUNIT_EXPECT_FALSE(test, seq_buf_has_overflowed(&s)); + KUNIT_EXPECT_EQ(test, seq_buf_buffer_left(&s), 0); + KUNIT_EXPECT_STREQ(test, seq_buf_str(&s), "hell"); +} static void seq_buf_declare_test(struct kunit *test) { @@ -621,6 +673,7 @@ static void seq_buf_strlen_embedded_nul_test(struct kunit *test) static struct kunit_case seq_buf_test_cases[] = { KUNIT_CASE(seq_buf_init_test), + KUNIT_CASE(seq_buf_init_append_test), KUNIT_CASE(seq_buf_declare_test), KUNIT_CASE(seq_buf_clear_test), KUNIT_CASE(seq_buf_puts_test), -- 2.34.1

