> Using seq_buf_set_overflow() would leave the bytes between "len" > and "size" untouched, so if seq_buf_str() is used on an overflowed > seq_buf, those bytes may be exposed. For any paths that don't claim > partially written bytes, by setting "len = size" before calling > seq_buf_set_overflow(), wipe the unclaimed bytes. The seq_buf_puts() > and related APIs already claim those bytes now, so only the unclaimed > cases remain. A specific example of this was seq_buf_path() which uses > d_path() and would write to the tail before discovering it was out > of space, and would correctly mark a seq_buf as overflowed, but the > path fragment would be left over. > > Clear from len to the end of the buffer in seq_buf_set_overflow(), which > every overflow goes through, including seq_buf_commit() with a negative > count. > > Add a test that fills a seq_buf, leaves it too little room for a path, and > checks that nothing of the path is left in the buffer. The tests run before > anything writable is mounted, so it takes its file from shmem. > > seq_buf_path() was never exported, unlike the other writers, so the > test failed to link as a module. Export it. > > Tests passed under qemu on ARCH=x86_64 with GCC 16.2.0 and CONFIG_KASAN=y, > and on big-endian ARCH=s390 with GCC s390x-linux-gnu 16.2.0, and the > test builds as a module (CONFIG_SEQ_BUF_KUNIT_TEST=m). > > Assisted-by: LLM > Reviewed-by: Andy Shevchenko <[email protected]> > Signed-off-by: Kees Cook <[email protected]>
Sashiko has reviewed this patch and found no issues. It looks great! -- Sashiko AI review ยท https://sashiko.dev/#/patchset/[email protected]?part=4
