mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Alejandro Colomar <alx@kernel.org>
To: Kees Cook <kees@kernel.org>
Cc: "Alejandro Colomar" <alx+linux-hardening@kernel.org>,
	"Andy Shevchenko" <andriy.shevchenko@linux.intel.com>,
	"Bill Wendling" <morbo@google.com>,
	"Matthew Wilcox (Oracle)" <willy@infradead.org>,
	"Andrew Morton" <akpm@linux-foundation.org>,
	"David Gow" <david@davidgow.net>,
	"Petr Mladek" <pmladek@suse.com>,
	"Shuvam Pandey" <shuvampandey1@gmail.com>,
	"Steven Rostedt" <rostedt@goodmis.org>,
	"Jonathan Corbet" <corbet@lwn.net>,
	"Sergey Senozhatsky" <senozhatsky@chromium.org>,
	"Günther Noack" <gnoack@google.com>,
	"Mickaël Salaün" <mic@digikod.net>,
	"Masami Hiramatsu" <mhiramat@kernel.org>,
	"Mathieu Desnoyers" <mathieu.desnoyers@efficios.com>,
	"Jiri Kosina" <jikos@kernel.org>,
	"Alexei Starovoitov" <ast@kernel.org>,
	"Daniel Borkmann" <daniel@iogearbox.net>,
	"Andrii Nakryiko" <andrii@kernel.org>,
	"Eduard Zingerman" <eddyz87@gmail.com>,
	"Kumar Kartikeya Dwivedi" <memxor@gmail.com>,
	"Martin KaFai Lau" <martin.lau@linux.dev>,
	"Song Liu" <song@kernel.org>,
	"Yonghong Song" <yonghong.song@linux.dev>,
	"Jiri Olsa" <jolsa@kernel.org>,
	"Emil Tsalapatis" <emil@etsalapatis.com>,
	"Ihor Solodrai" <ihor.solodrai@linux.dev>,
	"Christophe Leroy (CS GROUP)" <chleroy@kernel.org>,
	"Uwe Kleine-König" <u.kleine-koenig@baylibre.com>,
	"Madhavan Srinivasan" <maddy@linux.ibm.com>,
	"Michael Ellerman" <mpe@ellerman.id.au>,
	"Nicholas Piggin" <npiggin@gmail.com>,
	"Shivaprasad G Bhat" <sbhat@linux.ibm.com>,
	"Thorsten Blum" <blum@kernel.org>,
	"Alison Schofield" <alison.schofield@intel.com>,
	"Dave Jiang" <dave.jiang@intel.com>,
	"Greg Kroah-Hartman" <gregkh@linuxfoundation.org>,
	"Guangshuo Li" <lgs201920130244@gmail.com>,
	"Ira Weiny" <iweiny@kernel.org>,
	"Uwe Kleine-König" <u.kleine-koenig@pengutronix.de>,
	"Vishal Verma" <vishal.l.verma@intel.com>,
	"Randy Dunlap" <rdunlap@infradead.org>,
	"Shuah Khan" <skhan@linuxfoundation.org>,
	linux-kernel@vger.kernel.org, bpf@vger.kernel.org,
	linux-security-module@vger.kernel.org,
	linux-trace-kernel@vger.kernel.org,
	linuxppc-dev@lists.ozlabs.org, nvdimm@lists.linux.dev,
	linux-doc@vger.kernel.org, linux-hardening@vger.kernel.org
Subject: Re: [PATCH v4 05/11] seq_buf: Add seq_buf_strlen()
Date: Mon, 5 Oct 2026 18:43:23 +0200	[thread overview]
Message-ID: <asPSYn7sLqiH39Fu@debian> (raw)
In-Reply-To: <20261005155839.d5d200-kees@kernel.org>

[-- Attachment #1: Type: text/plain, Size: 2123 bytes --]

Hi Kees,

> Date: 2026-10-05 08:58:45-0700
> From: Kees Cook <kees@kernel.org>
>
> On Mon, Oct 05, 2026 at 01:34:10PM +0200, Alejandro Colomar wrote:
> > > Yeah, reasonable. :) For v5 I've added this to seq_buf_str()'s kernel-doc:
> > >
> > >  * A zero-sized seq_buf has nowhere to put a NUL, so the empty string
> > >  * is returned instead of writing to @s->buffer. Any other seq_buf
> > >  * returns @s->buffer, even when it holds an empty string, so callers
> > >  * always get their own buffer back.
> >
> > Are such buffers actually used on purpose anywhere?  Why not keep the
> > WARN_ON?
> 
> Yes, though not often: the sched_ext debug dump builds a nested per-CPU
> seq_buf from seq_buf_get_buf(), which returns a size of 0 once the dump
> buffer has overflowed, and it handles that case on purpose (see the
> "$s may already have overflowed" comment in kernel/sched/ext/ext.c).

Hmmmm, so IIUC, it is a sentinel value, and not really a buffer size?

Did you consider not holding the size of the buffer, but rather an end
pointer?  It also allows you to find how much you can write to the
buffer, but has slightly better semantics: the end doesn't change if you
advance the position.  'end' can only change through reallocations
(which I don't know if you do in the kernel).

It's fundamentally the same issue as was discussed with ARRAY_END() vs
ARRAY_SIZE(), where ARRAY_END() is more robust.  Also, using NULL as a
sentinel value is more readable; otherwise, you wonder why a buffer can
have 0 bytes.

I think it'd simplify the implementation of the buffer.

> Greg asked about the WARN_ON() in v2[1]: a size that comes from a device
> or from userspace would have to be checked before every seq_buf_init(),
> or it becomes a crash under panic_on_warn, and an empty buffer can just
> hold the empty string. So the accessors do that instead.

Makes sense.  Thanks for clarifying!


Have a lovely night!
Alex

> 
> [1] https://lore.kernel.org/all/2026091953-cherub-empty-ef35@gregkh/
> 
> -Kees
> 
> -- 
> Kees Cook

-- 
<https://www.alejandro-colomar.es>

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 833 bytes --]

  reply	other threads:[~2026-10-05 16:43 UTC|newest]

Thread overview: 27+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-03  3:59 [PATCH v4 00/11] " Kees Cook
2026-10-03  3:59 ` [PATCH v4 01/11] seq_buf: Do not print an empty line from an overflowed seq_buf_do_printk() Kees Cook
2026-10-03  4:50   ` bot+bpf-ci
2026-10-05 10:05     ` Kees Cook
2026-10-03  3:59 ` [PATCH v4 02/11] seq_buf: Do not pop from an overflowed seq_buf Kees Cook
2026-10-03  3:59 ` [PATCH v4 03/11] seq_buf: Copy what fits when seq_buf_puts() and seq_buf_putmem() overflow Kees Cook
2026-10-03  4:50   ` bot+bpf-ci
2026-10-05 10:06     ` Kees Cook
2026-10-03  3:59 ` [PATCH v4 04/11] seq_buf: Clear what a writer did not claim when a seq_buf overflows Kees Cook
2026-10-03  4:50   ` bot+bpf-ci
2026-10-03  3:59 ` [PATCH v4 05/11] seq_buf: Add seq_buf_strlen() Kees Cook
2026-10-03 15:36   ` Andy Shevchenko
2026-10-04  7:26     ` Kees Cook
2026-10-04  8:34       ` Andy Shevchenko
2026-10-05 11:22         ` Kees Cook
2026-10-05 11:34           ` Alejandro Colomar
2026-10-05 15:58             ` Kees Cook
2026-10-05 16:43               ` Alejandro Colomar [this message]
2026-10-03  3:59 ` [PATCH v4 06/11] seq_buf: Add seq_buf_terminate() Kees Cook
2026-10-03  3:59 ` [PATCH v4 07/11] bpf: Remove dead newline stripping from format_disasm_line() Kees Cook
2026-10-03  3:59 ` [PATCH v4 08/11] seq_buf: Add seq_buf_init_append() Kees Cook
2026-10-03  4:33   ` bot+bpf-ci
2026-10-03 10:31     ` Kees Cook
2026-10-03  3:59 ` [PATCH v4 09/11] powerpc/papr_scm: Return the string length from the sysfs show functions Kees Cook
2026-10-03  3:59 ` [PATCH v4 10/11] nvdimm: ndtest: Return the string length from flags_show() Kees Cook
2026-10-03  3:59 ` [PATCH v4 11/11] docs: core-api: Document the seq_buf API Kees Cook
2026-10-03  6:32 ` [PATCH v4 00/11] seq_buf: Add seq_buf_strlen() Alexei Starovoitov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=asPSYn7sLqiH39Fu@debian \
    --to=alx@kernel.org \
    --cc=akpm@linux-foundation.org \
    --cc=alison.schofield@intel.com \
    --cc=alx+linux-hardening@kernel.org \
    --cc=andrii@kernel.org \
    --cc=andriy.shevchenko@linux.intel.com \
    --cc=ast@kernel.org \
    --cc=blum@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=chleroy@kernel.org \
    --cc=corbet@lwn.net \
    --cc=daniel@iogearbox.net \
    --cc=dave.jiang@intel.com \
    --cc=david@davidgow.net \
    --cc=eddyz87@gmail.com \
    --cc=emil@etsalapatis.com \
    --cc=gnoack@google.com \
    --cc=gregkh@linuxfoundation.org \
    --cc=ihor.solodrai@linux.dev \
    --cc=iweiny@kernel.org \
    --cc=jikos@kernel.org \
    --cc=jolsa@kernel.org \
    --cc=kees@kernel.org \
    --cc=lgs201920130244@gmail.com \
    --cc=linux-doc@vger.kernel.org \
    --cc=linux-hardening@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=linux-trace-kernel@vger.kernel.org \
    --cc=linuxppc-dev@lists.ozlabs.org \
    --cc=maddy@linux.ibm.com \
    --cc=martin.lau@linux.dev \
    --cc=mathieu.desnoyers@efficios.com \
    --cc=memxor@gmail.com \
    --cc=mhiramat@kernel.org \
    --cc=mic@digikod.net \
    --cc=morbo@google.com \
    --cc=mpe@ellerman.id.au \
    --cc=npiggin@gmail.com \
    --cc=nvdimm@lists.linux.dev \
    --cc=pmladek@suse.com \
    --cc=rdunlap@infradead.org \
    --cc=rostedt@goodmis.org \
    --cc=sbhat@linux.ibm.com \
    --cc=senozhatsky@chromium.org \
    --cc=shuvampandey1@gmail.com \
    --cc=skhan@linuxfoundation.org \
    --cc=song@kernel.org \
    --cc=u.kleine-koenig@baylibre.com \
    --cc=u.kleine-koenig@pengutronix.de \
    --cc=vishal.l.verma@intel.com \
    --cc=willy@infradead.org \
    --cc=yonghong.song@linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®