On Fri, 18 Sep 2026 17:27:03 -0700
Kees Cook <[email protected]> wrote:

> Several strlcat() call sites being converted to seq_buf need behavior
> seq_buf doesn't currently provide. The return from seq_buf_used() is
> not the length of the string in a seq_buf. Once the buffer is full or
> has overflowed it returns the buffer size, which counts the byte that
> seq_buf_str() replaces with the NUL, so a caller that needs the string
> and its length has to call seq_buf_str() and then walk the string with
> strlen().
> 
> Move the termination out of seq_buf_str() into a helper that returns
> where it put the NUL, and add seq_buf_strlen(), which terminates the
> buffer in the same way and returns that offset.
> 

Let's make a appropriate function to terminate the string in the
seq_buf and not have it be an internal helper function (This has been
on my todo list for some time).


> Add tests comparing seq_buf_strlen() against strlen() of seq_buf_str()
> for empty, appended, truncated, exactly full, and overflowed buffers,
> and checking that seq_buf_strlen() alone terminates a full buffer.
> 
> Tests passed under qemu on ARCH=x86_64 with GCC 16.2.0 and CONFIG_KASAN=y,
> and on big-endian ARCH=s390 with GCC s390x-linux-gnu 16.1.0.
> 
> Assisted-by: LLM
> Reviewed-by: Andy Shevchenko <[email protected]>
> Signed-off-by: Kees Cook <[email protected]>
> ---
> Cc: "Matthew Wilcox (Oracle)" <[email protected]>
> Cc: Andrew Morton <[email protected]>
> Cc: Andy Shevchenko <[email protected]>
> Cc: David Gow <[email protected]>
> Cc: Petr Mladek <[email protected]>
> Cc: Shuvam Pandey <[email protected]>
> Cc: Steven Rostedt <[email protected]>
> ---
>  include/linux/seq_buf.h   |  57 +++++++++++++++++--
>  lib/tests/seq_buf_kunit.c | 114 ++++++++++++++++++++++++++++++++++++++
>  2 files changed, 166 insertions(+), 5 deletions(-)
> 
> diff --git a/include/linux/seq_buf.h b/include/linux/seq_buf.h
> index 0c0a0db04b09..7f025c7a68be 100644
> --- a/include/linux/seq_buf.h
> +++ b/include/linux/seq_buf.h
> @@ -89,6 +89,27 @@ static inline unsigned int seq_buf_used(struct seq_buf *s)
>       return min(s->len, s->size);
>  }
>  
> +/*
> + * NUL-terminate the buffer in @s: directly after the data when there is
> + * room for it, otherwise in the last byte of the buffer. @s->size must not
> + * be zero.
> + *
> + * Returns: the offset of the NUL.
> + */
> +static inline size_t __seq_buf_terminate(struct seq_buf *s)
> +{
> +     size_t end;
> +
> +     if (seq_buf_buffer_left(s))
> +             end = s->len;
> +     else
> +             end = s->size - 1;
> +
> +     s->buffer[end] = 0;
> +
> +     return end;
> +}

That is, make this a separate patch to introduce a
"seq_buf_terminate()" function as there's several places in the kernel
that could replace seq_buf_str() with it.

Thanks,

-- Steve

Reply via email to