> When seq_buf_puts() or seq_buf_putmem() is given more than fits, it
> copies nothing and only marks the seq_buf as overflowed. If seq_buf_str()
> is used, it will terminate the buffer in its last byte, so every byte
> between the end of the data and the end of the buffer becomes part of
> the string, though the seq_buf never wrote them.
> 
> seq_buf_printf() does not have this problem, because vsnprintf() writes
> as much of the output as fits, followed by a NUL. Repeat this behavior
> in seq_buf_puts(), using strscpy(), and in seq_buf_putmem(), which also
> covers seq_buf_putmem_hex(). seq_buf_putc() needs no change, as it can
> only overflow when the buffer is already full.
> 
> Each writer now records the buffer as full once it has copied what fits,
> so that what it wrote can be told apart from bytes nothing touched.
> 
> [ ... ]
> test builds as a module (CONFIG_SEQ_BUF_KUNIT_TEST=m).
> 
> Assisted-by: LLM
> Reviewed-by: Andy Shevchenko <[email protected]>
> Signed-off-by: Kees Cook <[email protected]>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/[email protected]?part=3


Reply via email to