From nobody Tue Sep 29 14:00:23 2026 Received: from mailgw.kylinos.cn (mailgw.kylinos.cn [124.126.103.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 12BBF263F44 for ; Fri, 7 Aug 2026 03:31:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=124.126.103.232 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786073503; cv=none; b=H4N17cLyagCFxjZ/vH+VghB++qmUIDOi71ZlBVq7rB+KeOGBWYqcNeCatY9C8p9eW0cvSBtiQQOxJgDB0+LGqN4v67Hus/cHIujgbsaw10hw9wa77HLzTCxOCW5oYqZ7EattPMZnEOswenSwDBZPPE02mLwm/eEKnhdjgxV4/B0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786073503; c=relaxed/simple; bh=AUCj77nd839IO1AtSrGW53q3BaVZ2JW4ivhVLiYeOrg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=CiJYjJUdW+fF9UoEhCkOlUkk7VmYuKJKAMjJGPzvnRlS9fk624y9usbcv+GQ8KTdHBDpn9cjChuMBJr8ZulWI7OMkFDkbpuFn9U/b0PnaUJ5y5Q5AfbKOfsvPMrofnIJB9pv4Wxv+b27TmUmWLLaLtggM7MebX5v+BkL8F+uE5c= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn; spf=pass smtp.mailfrom=kylinos.cn; arc=none smtp.client-ip=124.126.103.232 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kylinos.cn X-UUID: 7bdf7e04921011f1aa26b74ffac11d73-20260807 X-CID-P-RULE: Release_Ham X-CID-O-INFO: VERSION:1.3.12,REQID:f61ed87a-0635-4b1b-a825-fb1b5a117086,IP:0,U RL:0,TC:0,Content:-25,EDM:0,RT:0,SF:0,FILE:0,BULK:0,RULE:Release_Ham,ACTIO N:release,TS:-25 X-CID-META: VersionHash:e7bac3a,CLOUDID:f03fcac0b6e1544fac7e5a23d12f90c7,BulkI D:nil,BulkQuantity:0,Recheck:0,SF:81|82|102|865|898,TC:nil,Content:0|15|50 ,EDM:-3,IP:nil,URL:0,File:nil,RT:nil,Bulk:nil,QS:nil,BEC:nil,COL:0,OSI:0,O SA:0,AV:0,LES:1,SPR:NO,DKR:0,DKP:0,BRR:0,BRE:0,ARC:0 X-CID-BVR: 2,SSN|SDN X-CID-BAS: 2,SSN|SDN,0,_ X-CID-FACTOR: TF_CID_SPAM_SNR X-CID-RHF: D41D8CD98F00B204E9800998ECF8427E X-UUID: 7bdf7e04921011f1aa26b74ffac11d73-20260807 X-User: liuxixin@kylinos.cn Received: from [127.0.1.1] [(10.44.16.150)] by mailgw.kylinos.cn (envelope-from ) (Generic MTA with TLSv1.3 TLS_AES_256_GCM_SHA384 256/256) with ESMTP id 132895520; Fri, 07 Aug 2026 11:31:32 +0800 From: Xixin Liu To: linuxppc-dev@lists.ozlabs.org Cc: maddy@linux.ibm.com, mpe@ellerman.id.au, npiggin@gmail.com, chleroy@kernel.org, linux-kernel@vger.kernel.org, liuxixin@kylinos.cn Subject: [PATCH v1 1/4] powerpc/perf: hv-gpci: bound sysfs hex formatting to PAGE_SIZE Date: Fri, 07 Aug 2026 11:11:14 +0800 Message-ID: In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Mailer: patches/scripts/send-local.py Content-Type: text/plain; charset="utf-8" hv-gpci sysfs show paths format hypervisor counter bytes with sprintf() into a PAGE_SIZE buffer, and only sometimes check the length afterwards. Each byte becomes two hex digits plus newlines, so the output can grow past PAGE_SIZE. Checking after sprintf() is too late: the write already overflowed the sysfs buffer. One path had no size check at all. Use sysfs_emit_at() so formatting stays within the sysfs buffer. If a field cannot fit completely, return -EFBIG rather than silently truncating. Signed-off-by: Xixin Liu --- arch/powerpc/perf/hv-gpci.c | 77 +++++++++++++++++++++++++------------ 1 file changed, 52 insertions(+), 25 deletions(-) diff --git a/arch/powerpc/perf/hv-gpci.c b/arch/powerpc/perf/hv-gpci.c index 76495744f..14a4f414b 100644 --- a/arch/powerpc/perf/hv-gpci.c +++ b/arch/powerpc/perf/hv-gpci.c @@ -136,6 +136,7 @@ static unsigned long systeminfo_gpci_request(u32 req, u= 32 starting_index, { unsigned long ret; size_t i, j; + int len; =20 arg->params.counter_request =3D cpu_to_be32(req); arg->params.starting_index =3D cpu_to_be32(starting_index); @@ -177,17 +178,23 @@ static unsigned long systeminfo_gpci_request(u32 req,= u32 starting_index, for (i =3D 0; i < be16_to_cpu(arg->params.returned_values); i++) { j =3D i * be16_to_cpu(arg->params.cv_element_size); =20 - for (; j < (i + 1) * be16_to_cpu(arg->params.cv_element_size); j++) - *n +=3D sprintf(buf + *n, "%02x", (u8)arg->bytes[j]); - *n +=3D sprintf(buf + *n, "\n"); - } - - if (*n >=3D PAGE_SIZE) { - pr_info("System information exceeds PAGE_SIZE\n"); - return -EFBIG; + for (; j < (i + 1) * be16_to_cpu(arg->params.cv_element_size); j++) { + len =3D sysfs_emit_at(buf, *n, "%02x", (u8)arg->bytes[j]); + if (len !=3D 2) + goto emit_failed; + *n +=3D len; + } + len =3D sysfs_emit_at(buf, *n, "\n"); + if (len !=3D 1) + goto emit_failed; + *n +=3D len; } =20 return ret; + +emit_failed: + pr_info("System information does not fit in sysfs buffer\n"); + return -EFBIG; } =20 static ssize_t processor_bus_topology_show(struct device *dev, struct devi= ce_attribute *attr, @@ -470,12 +477,13 @@ static ssize_t affinity_domain_via_domain_show(struct= device *dev, struct device return ret; } =20 -static void affinity_domain_via_partition_result_parse(int returned_values, +static int affinity_domain_via_partition_result_parse(int returned_values, int element_size, char *buf, size_t *last_element, size_t *n, struct hv_gpci_request_buffer *arg) { size_t i =3D 0, j =3D 0; size_t k, l, m; + int len; uint16_t total_affinity_domain_ele, size_of_each_affinity_domain_ele; =20 /* @@ -492,27 +500,44 @@ static void affinity_domain_via_partition_result_pars= e(int returned_values, */ while (i < returned_values) { k =3D j; - for (; k < j + element_size; k++) - *n +=3D sprintf(buf + *n, "%02x", (u8)arg->bytes[k]); - *n +=3D sprintf(buf + *n, "\n"); + for (; k < j + element_size; k++) { + len =3D sysfs_emit_at(buf, *n, "%02x", (u8)arg->bytes[k]); + if (len !=3D 2) + return -EFBIG; + *n +=3D len; + } + len =3D sysfs_emit_at(buf, *n, "\n"); + if (len !=3D 1) + return -EFBIG; + *n +=3D len; =20 total_affinity_domain_ele =3D (u8)arg->bytes[k - 2] << 8 | (u8)arg->byte= s[k - 3]; size_of_each_affinity_domain_ele =3D (u8)arg->bytes[k] << 8 | (u8)arg->b= ytes[k - 1]; =20 for (l =3D 0; l < total_affinity_domain_ele; l++) { for (m =3D 0; m < size_of_each_affinity_domain_ele; m++) { - *n +=3D sprintf(buf + *n, "%02x", (u8)arg->bytes[k]); + len =3D sysfs_emit_at(buf, *n, "%02x", (u8)arg->bytes[k]); + if (len !=3D 2) + return -EFBIG; + *n +=3D len; k++; } - *n +=3D sprintf(buf + *n, "\n"); + len =3D sysfs_emit_at(buf, *n, "\n"); + if (len !=3D 1) + return -EFBIG; + *n +=3D len; } =20 - *n +=3D sprintf(buf + *n, "\n"); + len =3D sysfs_emit_at(buf, *n, "\n"); + if (len !=3D 1) + return -EFBIG; + *n +=3D len; i++; j =3D k; } =20 *last_element =3D k; + return 0; } =20 static ssize_t affinity_domain_via_partition_show(struct device *dev, stru= ct device_attribute *attr, @@ -555,12 +580,10 @@ static ssize_t affinity_domain_via_partition_show(str= uct device *dev, struct dev * to buffer util we get all the information. */ while (ret =3D=3D H_PARAMETER) { - affinity_domain_via_partition_result_parse( - be16_to_cpu(arg->params.returned_values) - 1, - be16_to_cpu(arg->params.cv_element_size), buf, - &last_element, &n, arg); - - if (n >=3D PAGE_SIZE) { + if (affinity_domain_via_partition_result_parse( + be16_to_cpu(arg->params.returned_values) - 1, + be16_to_cpu(arg->params.cv_element_size), buf, + &last_element, &n, arg)) { put_cpu_var(hv_gpci_reqb); pr_debug("System information does not fit in sysfs buffer\n"); return -EFBIG; @@ -587,10 +610,14 @@ static ssize_t affinity_domain_via_partition_show(str= uct device *dev, struct dev } =20 parse_result: - affinity_domain_via_partition_result_parse( - be16_to_cpu(arg->params.returned_values), - be16_to_cpu(arg->params.cv_element_size), - buf, &last_element, &n, arg); + if (affinity_domain_via_partition_result_parse( + be16_to_cpu(arg->params.returned_values), + be16_to_cpu(arg->params.cv_element_size), + buf, &last_element, &n, arg)) { + put_cpu_var(hv_gpci_reqb); + pr_debug("System information does not fit in sysfs buffer\n"); + return -EFBIG; + } =20 put_cpu_var(hv_gpci_reqb); return n; --=20 2.43.0 From nobody Tue Sep 29 14:00:23 2026 Received: from mailgw.kylinos.cn (mailgw.kylinos.cn [124.126.103.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8465525F99F for ; Fri, 7 Aug 2026 03:31:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=124.126.103.232 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786073504; cv=none; b=K7hhbHq1NkTjO5oUiDYv8+13hyK+lJGrKDi9HrOjw7iTLUNg1tAnMcxygasACj+oJCjAnPKq4iMbsnM7zDLH3zc7RzquwQprpsdY4HUIUtAYxDgTsBopkEmysoOVnRiMM4kDR3sgfkZaqiYFjuI26LrB9CXl0ZE3GRHdi3A0qx0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786073504; c=relaxed/simple; bh=aa8Shcj9Lpe0MML1tB1dRx4Ch963woePc0Eh6xGZu4w=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=lPm/iK3FTXxfY/R1R3de6/lZKaP0ewK+h/4+qvJ0+iOTsMvad3iQJ0kHjVuuwpeL2+j+W0cNmyHlN3ixu+pGcHCReBFZ1HGX4+Ftch5e29CmR9jtV32MEqC89XmTkE8Dft3DzPkKeksSYrpGVWaMkI3lXfEIgPuy5jpwmOwgasE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn; spf=pass smtp.mailfrom=kylinos.cn; arc=none smtp.client-ip=124.126.103.232 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kylinos.cn X-UUID: 7d35d3b6921011f1aa26b74ffac11d73-20260807 X-CID-P-RULE: Release_Ham X-CID-O-INFO: VERSION:1.3.12,REQID:239a4416-a78f-4cde-8a7a-971fdd4509ab,IP:0,U RL:0,TC:0,Content:0,EDM:0,RT:0,SF:0,FILE:0,BULK:0,RULE:Release_Ham,ACTION: release,TS:0 X-CID-META: VersionHash:e7bac3a,CLOUDID:58481a91c5a73d8ca54b7e90130cdc05,BulkI D:nil,BulkQuantity:0,Recheck:0,SF:81|82|102|865|898,TC:nil,Content:0|15|50 ,EDM:-3,IP:nil,URL:0,File:nil,RT:nil,Bulk:nil,QS:nil,BEC:nil,COL:0,OSI:0,O SA:0,AV:0,LES:1,SPR:NO,DKR:0,DKP:0,BRR:0,BRE:0,ARC:0 X-CID-BVR: 2,SSN|SDN X-CID-BAS: 2,SSN|SDN,0,_ X-CID-FACTOR: TF_CID_SPAM_SNR X-CID-RHF: D41D8CD98F00B204E9800998ECF8427E X-UUID: 7d35d3b6921011f1aa26b74ffac11d73-20260807 X-User: liuxixin@kylinos.cn Received: from [127.0.1.1] [(10.44.16.150)] by mailgw.kylinos.cn (envelope-from ) (Generic MTA with TLSv1.3 TLS_AES_256_GCM_SHA384 256/256) with ESMTP id 2051555578; Fri, 07 Aug 2026 11:31:34 +0800 From: Xixin Liu To: linuxppc-dev@lists.ozlabs.org Cc: maddy@linux.ibm.com, mpe@ellerman.id.au, npiggin@gmail.com, chleroy@kernel.org, linux-kernel@vger.kernel.org, liuxixin@kylinos.cn Subject: [PATCH v1 2/4] powerpc/powernv: opal-imc: fix debugfs name buffer size Date: Fri, 07 Aug 2026 11:11:14 +0800 Message-ID: In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Mailer: patches/scripts/send-local.py Content-Type: text/plain; charset="utf-8" char mode[16]/cmd[16] are too small for sprintf("imc_mode_%d") / sprintf("imc_cmd_%d") when id is a full u32 (up to 20 bytes including NUL). id comes from DT "chip-id" as u32. Enlarge the buffers and use snprintf. Signed-off-by: Xixin Liu --- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/arch/powerpc/platforms/powernv/opal-imc.c b/arch/powerpc/platf= orms/powernv/opal-imc.c index b3fd5c648dea..77de53d47cb6 100644 --- a/arch/powerpc/platforms/powernv/opal-imc.c +++ b/arch/powerpc/platforms/powernv/opal-imc.c @@ -51,7 +51,8 @@ struct imc_pmu *pmu_ptr) { static u64 loc, *imc_mode_addr, *imc_cmd_addr; - char mode[16], cmd[16]; + /* "imc_mode_" / "imc_cmd_" + max u32 decimal + NUL */ + char mode[20], cmd[20]; u32 cb_offset; struct imc_mem_info *ptr =3D pmu_ptr->mem_info; =20 @@ -63,12 +64,12 @@ while (ptr->vbase !=3D NULL) { loc =3D (u64)(ptr->vbase) + cb_offset; imc_mode_addr =3D (u64 *)(loc + IMC_CNTL_BLK_MODE_OFFSET); - sprintf(mode, "imc_mode_%d", (u32)(ptr->id)); + snprintf(mode, sizeof(mode), "imc_mode_%u", ptr->id); imc_debugfs_create_x64(mode, 0600, imc_debugfs_parent, imc_mode_addr); =20 imc_cmd_addr =3D (u64 *)(loc + IMC_CNTL_BLK_CMD_OFFSET); - sprintf(cmd, "imc_cmd_%d", (u32)(ptr->id)); + snprintf(cmd, sizeof(cmd), "imc_cmd_%u", ptr->id); imc_debugfs_create_x64(cmd, 0600, imc_debugfs_parent, imc_cmd_addr); ptr++; --=20 2.43.0 From nobody Tue Sep 29 14:00:23 2026 Received: from mailgw.kylinos.cn (mailgw.kylinos.cn [124.126.103.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 01538305688 for ; Fri, 7 Aug 2026 03:31:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=124.126.103.232 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786073506; cv=none; b=fnzIq0+ghHEMRpkHqvHVJKj6FAXQDiR0Zc/4/N+DrL9yKDPwHd9qbhFyGWgPX9YoZpyE+uB/hCTXsYSQoE+etwmMQZQVc9qsgukk55rKYGd/daO/L+ufDrtliAOr/hkMjHGAFegoYD6lZUR5OHXqlfre8xFm1/Dcy/dEQe3Q3gw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786073506; c=relaxed/simple; bh=uftTTtmCtTyPGczJJxoLHYfY8QhRqsceiesrkwVpR+g=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=VaUWo4STc3xZqNx2bMssDCe89K5R6QZTsLubbuJt2e3N0GVAX3n4IkCdUMDP1NiTHWOGoTPt67UPNvxmLKn3wNtpzh8+Hslzb55KYeLcuq8B0aez3QRdRKEETWOahEPASyoPHPBgPnDhvVW1A2U3uV9zPht2+wvnb5rpyiyWikA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn; spf=pass smtp.mailfrom=kylinos.cn; arc=none smtp.client-ip=124.126.103.232 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kylinos.cn X-UUID: 7e894400921011f1aa26b74ffac11d73-20260807 X-CID-P-RULE: Release_Ham X-CID-O-INFO: VERSION:1.3.12,REQID:33ea77ee-d0f3-4b6e-9568-4b9186e6dcaa,IP:0,U RL:0,TC:0,Content:0,EDM:0,RT:0,SF:0,FILE:0,BULK:0,RULE:Release_Ham,ACTION: release,TS:0 X-CID-META: VersionHash:e7bac3a,CLOUDID:30d4aacd81b1023fa7802ba724ca08a9,BulkI D:nil,BulkQuantity:0,Recheck:0,SF:81|82|102|865|898,TC:nil,Content:0|15|50 ,EDM:-3,IP:nil,URL:0,File:nil,RT:nil,Bulk:nil,QS:nil,BEC:nil,COL:0,OSI:0,O SA:0,AV:0,LES:1,SPR:NO,DKR:0,DKP:0,BRR:0,BRE:0,ARC:0 X-CID-BVR: 2,SSN|SDN X-CID-BAS: 2,SSN|SDN,0,_ X-CID-FACTOR: TF_CID_SPAM_SNR X-CID-RHF: D41D8CD98F00B204E9800998ECF8427E X-UUID: 7e894400921011f1aa26b74ffac11d73-20260807 X-User: liuxixin@kylinos.cn Received: from [127.0.1.1] [(10.44.16.150)] by mailgw.kylinos.cn (envelope-from ) (Generic MTA with TLSv1.3 TLS_AES_256_GCM_SHA384 256/256) with ESMTP id 1171004808; Fri, 07 Aug 2026 11:31:36 +0800 From: Xixin Liu To: linuxppc-dev@lists.ozlabs.org Cc: maddy@linux.ibm.com, mpe@ellerman.id.au, npiggin@gmail.com, chleroy@kernel.org, linux-kernel@vger.kernel.org, liuxixin@kylinos.cn Subject: [PATCH v1 3/4] powerpc/pseries: energy: bound H_BEST_ENERGY cnt and sysfs output Date: Fri, 07 Aug 2026 11:11:14 +0800 Message-ID: In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Mailer: patches/scripts/send-local.py Content-Type: text/plain; charset="utf-8" The H_BEST_ENERGY sysfs path takes cnt from the hypercall return buffer and walks buf_page[2*i+1] without checking that cnt fits in the single page allocated for the hcall, and sprintf()s into the PAGE_SIZE sysfs buffer without remaining-space checks. Clamp cnt to the number of u32 pairs that fit in the page, and stop formatting before overflowing the sysfs page. Signed-off-by: Xixin Liu --- 1 file changed, 14 insertions(+), 2 deletions(-) diff --git a/arch/powerpc/platforms/pseries/pseries_energy.c b/arch/powerpc= /platforms/pseries/pseries_energy.c index fdaf85ecd39b..8344f00656e5 100644 --- a/arch/powerpc/platforms/pseries/pseries_energy.c +++ b/arch/powerpc/platforms/pseries/pseries_energy.c @@ -209,16 +209,28 @@ return -EINVAL; } =20 + /* + * Each entry occupies two u32s in buf_page. Never walk past the + * page, and never sprintf past the PAGE_SIZE sysfs buffer. + */ cnt =3D retbuf[0]; + if (cnt > (PAGE_SIZE / sizeof(u32)) / 2) + cnt =3D (PAGE_SIZE / sizeof(u32)) / 2; + for (i =3D 0; i < cnt; i++) { cpu =3D drc_index_to_cpu(buf_page[2*i+1]); if ((cpu_online(cpu) && !activate) || - (!cpu_online(cpu) && activate)) + (!cpu_online(cpu) && activate)) { + if (s - page >=3D PAGE_SIZE - 16) + break; s +=3D sprintf(s, "%d,", cpu); + } } if (s > page) { /* Something to show */ s--; /* Suppress last comma */ - s +=3D sprintf(s, "\n"); + /* sprintf needs room for '\n' and trailing NUL. */ + if (s - page < PAGE_SIZE - 1) + s +=3D sprintf(s, "\n"); } =20 free_page((unsigned long) buf_page); --=20 2.43.0 From nobody Tue Sep 29 14:00:23 2026 Received: from mailgw.kylinos.cn (mailgw.kylinos.cn [124.126.103.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9386A3806CD for ; Fri, 7 Aug 2026 03:31:44 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=124.126.103.232 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786073507; cv=none; b=Jd58jY6Y/qoRqtsF+OKDaFJHLUnqaJ6GP67XXe0M5Ro9jyzbBRhiZWYKlBcmzlfkov+XtwMYiNzHUV31L9uK4NfDU+jKOFrzvspf3L6BVc1fWZgH/QB5VzkZJBXGEv37BbZXp1nZ5BVBXw9D6jgDV5lRcRMD0ObXb66UBzV8KHE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786073507; c=relaxed/simple; bh=ZHMk6GGhLrW8MwM2HasObIG/LWJM80jkxom/AN/DLmA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=GYWRjlr9k6QBjyCwpwWjsOLBSXJJCMIBRqilzVO6lRT8C1yt5OLjYX96muXqSPJbhHmNe9VpEDaTfqO8nRXMGPd8uE8Sj2DdN5lNbZ4vNMNg57hK7NS836o4KhdLq9A//ps/2CpvtkD06urJhgHMoYLdYPcTPVQrLr1Md0Cxczw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn; spf=pass smtp.mailfrom=kylinos.cn; arc=none smtp.client-ip=124.126.103.232 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kylinos.cn X-UUID: 7fe54e8e921011f1aa26b74ffac11d73-20260807 X-CID-P-RULE: Release_Ham X-CID-O-INFO: VERSION:1.3.12,REQID:17bc8f88-179b-4294-825c-f8e819814ab2,IP:0,U RL:0,TC:0,Content:0,EDM:0,RT:0,SF:0,FILE:0,BULK:0,RULE:Release_Ham,ACTION: release,TS:0 X-CID-META: VersionHash:e7bac3a,CLOUDID:931868f0700bd6dfc3791efc2f9cf001,BulkI D:nil,BulkQuantity:0,Recheck:0,SF:81|82|102|865|898,TC:nil,Content:0|15|50 ,EDM:-3,IP:nil,URL:0,File:nil,RT:nil,Bulk:nil,QS:nil,BEC:nil,COL:0,OSI:0,O SA:0,AV:0,LES:1,SPR:NO,DKR:0,DKP:0,BRR:0,BRE:0,ARC:0 X-CID-BVR: 2,SSN|SDN X-CID-BAS: 2,SSN|SDN,0,_ X-CID-FACTOR: TF_CID_SPAM_SNR X-CID-RHF: D41D8CD98F00B204E9800998ECF8427E X-UUID: 7fe54e8e921011f1aa26b74ffac11d73-20260807 X-User: liuxixin@kylinos.cn Received: from [127.0.1.1] [(10.44.16.150)] by mailgw.kylinos.cn (envelope-from ) (Generic MTA with TLSv1.3 TLS_AES_256_GCM_SHA384 256/256) with ESMTP id 1943659936; Fri, 07 Aug 2026 11:31:38 +0800 From: Xixin Liu To: linuxppc-dev@lists.ozlabs.org Cc: maddy@linux.ibm.com, mpe@ellerman.id.au, npiggin@gmail.com, chleroy@kernel.org, linux-kernel@vger.kernel.org, liuxixin@kylinos.cn Subject: [PATCH v1 4/4] powerpc/iommu: fix debugfs name buffer for 64-bit it_index Date: Fri, 07 Aug 2026 11:11:14 +0800 Message-ID: In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Mailer: patches/scripts/send-local.py Content-Type: text/plain; charset="utf-8" iommu debugfs names sprintf() "%08lx" into char name[10]. The "8" in %08lx is a minimum width, so a 64-bit it_index can need up to 16 hex digits plus NUL. Size the buffer for an unsigned long and use snprintf. Signed-off-by: Xixin Liu --- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/arch/powerpc/kernel/iommu.c b/arch/powerpc/kernel/iommu.c index ee1b5cb557c9..e8f48aef7832 100644 --- a/arch/powerpc/kernel/iommu.c +++ b/arch/powerpc/kernel/iommu.c @@ -53,10 +53,11 @@ =20 static void iommu_debugfs_add(struct iommu_table *tbl) { - char name[10]; + /* unsigned long hex + NUL; %08lx is a minimum width only */ + char name[2 * sizeof(unsigned long) + 1]; struct dentry *liobn_entry; =20 - sprintf(name, "%08lx", tbl->it_index); + snprintf(name, sizeof(name), "%08lx", tbl->it_index); liobn_entry =3D debugfs_create_dir(name, iommu_debugfs_dir); =20 debugfs_create_file_unsafe("weight", 0400, liobn_entry, tbl, &iommu_debug= fs_fops_weight); @@ -70,9 +71,9 @@ =20 static void iommu_debugfs_del(struct iommu_table *tbl) { - char name[10]; + char name[2 * sizeof(unsigned long) + 1]; =20 - sprintf(name, "%08lx", tbl->it_index); + snprintf(name, sizeof(name), "%08lx", tbl->it_index); debugfs_lookup_and_remove(name, iommu_debugfs_dir); } #else --=20 2.43.0