Re: [PATCH 0/3] debugfs: Reserve space for string terminators
From: Ilpo Järvinen
Date: Thu Oct 08 2026 - 13:38:28 EST
On Sat, 26 Sep 2026 20:12:47 +0800, Jiale Yao wrote:
> The same boundary mistake appears in three debugfs write handlers. Each
> handler has a zero-initialized buffer and allows a user write to fill the
> entire buffer. That overwrites the only NUL terminator before the input
> is parsed with sscanf(), strsep(), or strcasecmp(), which can then read
> beyond the end of the buffer.
>
> The write paths are independent, so the fixes are split by file and can
> be applied separately. Each patch reserves one byte for the terminating
> NUL while preserving the normal input size for that handler.
>
> [...]
Thank you for your contribution, it has been applied to my local
review-ilpo-next branch. Note it will show up in the public
platform-drivers-x86/review-ilpo-next branch only once I've pushed my
local branch there, which might take a while.
FYI [if applicable to your patch], as per Linus' policy change, also
fixes are mostly routed through for-next unless the fix is for a
commit introduced in the most recent cycle or is clearly a regression
fix.
The list of commits applied:
[1/3] platform/olpc: Reserve space for a string terminator
commit: 4ef563af57cc48d5a9662d7c69aa4447c2cc1b2c
[2/3] wifi: ath12k: Reserve space for a string terminator
(no commit info)
[3/3] dmaengine: xilinx: dpdma: Reserve space for a string terminator
(no commit info)
--
i.