kernel/trace/trace_functions_graph.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)
The comment above buffer mentions sign, 10 bytes width for number and null
terminator, but buffer itself isn't large enough to hold that much data.
This is a cosmetic change, since PID cannot be negative, other than -1.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Signed-off-by: Artem Sadovnikov <a.sadovnikov@ispras.ru>
---
kernel/trace/trace_functions_graph.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/kernel/trace/trace_functions_graph.c b/kernel/trace/trace_functions_graph.c
index a8c1f56340680..d789d308ab1de 100644
--- a/kernel/trace/trace_functions_graph.c
+++ b/kernel/trace/trace_functions_graph.c
@@ -344,7 +344,7 @@ static void print_graph_proc(struct trace_seq *s, pid_t pid)
{
char comm[TASK_COMM_LEN];
/* sign + log10(MAX_INT) + '\0' */
- char pid_str[11];
+ char pid_str[12];
int spaces = 0;
int len;
int i;
--
2.43.0
On Tue, 17 Jun 2025 11:19:06 +0000 Artem Sadovnikov <a.sadovnikov@ispras.ru> wrote: > The comment above buffer mentions sign, 10 bytes width for number and null > terminator, but buffer itself isn't large enough to hold that much data. > > This is a cosmetic change, since PID cannot be negative, other than -1. Right, where I'll change the subject as that makes it look like this is a real bug. And it is likely that "pid_str" will be allocated as 12 anyway, just for alignment reasons. But I'll take your patch. -- Steve > > Found by Linux Verification Center (linuxtesting.org) with SVACE. > > Signed-off-by: Artem Sadovnikov <a.sadovnikov@ispras.ru> > --- > kernel/trace/trace_functions_graph.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/kernel/trace/trace_functions_graph.c b/kernel/trace/trace_functions_graph.c > index a8c1f56340680..d789d308ab1de 100644 > --- a/kernel/trace/trace_functions_graph.c > +++ b/kernel/trace/trace_functions_graph.c > @@ -344,7 +344,7 @@ static void print_graph_proc(struct trace_seq *s, pid_t pid) > { > char comm[TASK_COMM_LEN]; > /* sign + log10(MAX_INT) + '\0' */ > - char pid_str[11]; > + char pid_str[12]; > int spaces = 0; > int len; > int i;
On Tue, 17 Jun 2025 11:00:17 -0400 Steven Rostedt <rostedt@goodmis.org> wrote: > On Tue, 17 Jun 2025 11:19:06 +0000 > Artem Sadovnikov <a.sadovnikov@ispras.ru> wrote: > > > The comment above buffer mentions sign, 10 bytes width for number and null > > terminator, but buffer itself isn't large enough to hold that much data. > > > > This is a cosmetic change, since PID cannot be negative, other than -1. > > Right, where I'll change the subject as that makes it look like this is a > real bug. Can your resend and Cc linux-trace-kernel@vger.kernel.org otherwise it will not get into the patchwork queue. Rename the Subject to: fgraph: Make pid_str size match the comment Thanks! -- Steve
© 2016 - 2025 Red Hat, Inc.