mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Kees Cook <kees@kernel.org>
To: David Laight <david.laight.linux@gmail.com>
Cc: Bill Wendling <morbo@google.com>, Ian Bridges <icb@fastmail.org>,
	Justin Tee <justin.tee@broadcom.com>,
	Paul Ely <paul.ely@broadcom.com>,
	"James E.J. Bottomley" <James.Bottomley@hansenpartnership.com>,
	"Martin K. Petersen" <mkp@kernel.org>,
	linux-scsi@vger.kernel.org, linux-kernel@vger.kernel.org,
	linux-hardening@vger.kernel.org
Subject: Re: [PATCH v5 03/12] scsi: lpfc: Print rx monitor records straight into the seq_buf
Date: Tue, 6 Oct 2026 06:26:00 -0700	[thread overview]
Message-ID: <202610060624.88739E8B@keescook> (raw)
In-Reply-To: <20261005195411.3e09bc8e@pumpkin>

On Mon, Oct 05, 2026 at 07:54:11PM +0100, David Laight wrote:
> On Mon,  5 Oct 2026 08:56:53 -0700
> Kees Cook <kees@kernel.org> wrote:
> 
> > lpfc_rx_monitor_report() formats each record into a stack buffer, then
> > appends it with seq_buf_puts(), relying on seq_buf_puts() appending
> > nothing when a string does not fit: the debugfs output then ends at the
> > last whole record, and the record left out is read in full next time.
> > The next patch makes seq_buf_puts() copy as much as fits instead, as
> > seq_buf_printf() and strlcat() do.
> > 
> > Print each record with seq_buf_printf(), and when it does not fit, end
> > the string where the record began, since the reader takes the buffer up
> > to its NUL. This also takes the DBG_LOG_STR_SZ buffer off the stack.
> > 
> > Build tested ARCH=x86_64 with GCC 16.2.0, CONFIG_SCSI_LPFC=m and W=1.
> > 
> > Assisted-by: LLM
> > Signed-off-by: Kees Cook <kees@kernel.org>
> > ---
> >  drivers/scsi/lpfc/lpfc_sli.c | 45 +++++++++++++++++++++---------------
> >  1 file changed, 27 insertions(+), 18 deletions(-)
> > 
> > diff --git a/drivers/scsi/lpfc/lpfc_sli.c b/drivers/scsi/lpfc/lpfc_sli.c
> > index cfa4371169f1..a7b1ea67ed98 100644
> > --- a/drivers/scsi/lpfc/lpfc_sli.c
> > +++ b/drivers/scsi/lpfc/lpfc_sli.c
> > @@ -8108,7 +8108,6 @@ u32 lpfc_rx_monitor_report(struct lpfc_hba *phba,
> >  	spinlock_t *ring_lock = &rx_monitor->lock;
> >  	u32 ring_size = rx_monitor->entries;
> >  	u32 cnt = 0;
> > -	char tmp[DBG_LOG_STR_SZ] = {0};
> >  	bool log_to_kmsg = (!buf || !buf_len) ? true : false;
> >  	struct seq_buf s;
> >  
> > @@ -8133,27 +8132,37 @@ u32 lpfc_rx_monitor_report(struct lpfc_hba *phba,
> >  
> >  		/* Read out this entry's data. */
> >  		if (!log_to_kmsg) {
> > +			unsigned int len;
> > +
> > +			/* A header that did not fit leaves no room. */
> > +			if (seq_buf_has_overflowed(&s))
> > +				break;
> > +			len = seq_buf_used(&s);
> > +
> > +			seq_buf_printf(&s,
> > +				       "%03d:\t%-16llu%-16llu%-16llu%-16llu%-8llu%-8llu%-8llu%-8u%-8u%-8u%u(%u)\n",
> > +				       *head_idx,
> > +				       entry->max_bytes_per_interval,
> > +				       entry->cmf_bytes,
> > +				       entry->total_bytes,
> > +				       entry->rcv_bytes,
> > +				       entry->avg_io_latency,
> > +				       entry->avg_io_size,
> > +				       entry->max_read_cnt,
> > +				       entry->cmf_busy, entry->io_cnt,
> > +				       entry->cmf_info,
> > +				       entry->timer_utilization,
> > +				       entry->timer_interval);
> > +
> >  			/*
> >  			 * Drop a record whole if it does not fit, without
> > -			 * consuming its ring entry.
> > +			 * consuming its ring entry: the reader takes the
> > +			 * string up to its NUL.
> >  			 */
> > -			scnprintf(tmp, sizeof(tmp),
> > -				  "%03d:\t%-16llu%-16llu%-16llu%-16llu%-8llu%-8llu%-8llu%-8u%-8u%-8u%u(%u)\n",
> > -				  *head_idx,
> > -				  entry->max_bytes_per_interval,
> > -				  entry->cmf_bytes,
> > -				  entry->total_bytes,
> > -				  entry->rcv_bytes,
> > -				  entry->avg_io_latency,
> > -				  entry->avg_io_size,
> > -				  entry->max_read_cnt,
> > -				  entry->cmf_busy, entry->io_cnt,
> > -				  entry->cmf_info,
> > -				  entry->timer_utilization,
> > -				  entry->timer_interval);
> > -
> > -			if (seq_buf_puts(&s, tmp) < 0)
> > +			if (seq_buf_has_overflowed(&s)) {
> > +				buf[len] = '\0';
> 
> There should probably be a seq_buf_truncate() to do that.
> Then a request for the length will be correct.

We don't really have a "rewind" API. (Oh please don't make me add
another API ... I'm at 3 already in this series...)


-- 
Kees Cook

  reply	other threads:[~2026-10-06 13:26 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-05 15:56 [PATCH v5 00/12] seq_buf: Add seq_buf_strlen() Kees Cook
2026-10-05 15:56 ` [PATCH v5 01/12] seq_buf: Do not print an empty line from an overflowed seq_buf_do_printk() Kees Cook
2026-10-05 15:56 ` [PATCH v5 02/12] seq_buf: Do not pop from an overflowed seq_buf Kees Cook
2026-10-05 15:56 ` [PATCH v5 03/12] scsi: lpfc: Print rx monitor records straight into the seq_buf Kees Cook
2026-10-05 18:54   ` David Laight
2026-10-06 13:26     ` Kees Cook [this message]
2026-10-05 15:56 ` [PATCH v5 04/12] seq_buf: Copy what fits when seq_buf_puts() and seq_buf_putmem() overflow Kees Cook
2026-10-05 15:56 ` [PATCH v5 05/12] seq_buf: Clear what a writer did not claim when a seq_buf overflows Kees Cook
2026-10-05 18:59   ` David Laight
2026-10-06 21:26     ` Kees Cook
2026-10-05 15:56 ` [PATCH v5 06/12] seq_buf: Add seq_buf_strlen() Kees Cook
2026-10-05 15:56 ` [PATCH v5 07/12] seq_buf: Add seq_buf_terminate() Kees Cook
2026-10-05 15:56 ` [PATCH v5 08/12] bpf: Remove dead newline stripping from format_disasm_line() Kees Cook
2026-10-05 15:56 ` [PATCH v5 09/12] seq_buf: Add seq_buf_init_append() Kees Cook
2026-10-05 15:57 ` [PATCH v5 10/12] powerpc/papr_scm: Return the string length from the sysfs show functions Kees Cook
2026-10-05 15:57 ` [PATCH v5 11/12] nvdimm: ndtest: Return the string length from flags_show() Kees Cook
2026-10-05 15:57 ` [PATCH v5 12/12] docs: core-api: Document the seq_buf API Kees Cook

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=202610060624.88739E8B@keescook \
    --to=kees@kernel.org \
    --cc=James.Bottomley@hansenpartnership.com \
    --cc=david.laight.linux@gmail.com \
    --cc=icb@fastmail.org \
    --cc=justin.tee@broadcom.com \
    --cc=linux-hardening@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-scsi@vger.kernel.org \
    --cc=mkp@kernel.org \
    --cc=morbo@google.com \
    --cc=paul.ely@broadcom.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®