Bootconfig fixes for v7.2-rc1:

- bootconfig: Fix NULL-pointer arithmetic
   Fix undefined pointer arithmetic in xbc_snprint_cmdline() when probing
   the buffer length with NULL and size 0. Track the written length as a
   size_t instead to prevent build-time UBSan/FORTIFY_SOURCE failures.
 -----BEGIN PGP SIGNATURE-----
 
 iQFPBAABCgA5FiEEh7BulGwFlgAOi5DV2/sHvwUrPxsFAmpEY1sbHG1hc2FtaS5o
 aXJhbWF0c3VAZ21haWwuY29tAAoJENv7B78FKz8bxAgH/A+wNARuaA8k3qHdRrzm
 eoKNfwPNc2C+QwPMsYVgk0aa1HaZWwuJ7FJQn0P0z3uXO6uvDg5S3q2LTyyLyoTy
 3DFcyrAQ1eIk5tj88LTmLHq5a6Jntsl+OZMXy3gU8fVJV8sQFYt1fovHctn0oaY3
 Yw5iwGkVzwFMh4BwZn9RfH73zECeUticJeO4qQadRApMsrWgNDz7f+P8YzcUxbBx
 BLBE4hnfKA5awRoYaOqGQ5jHsPoyj5GwwDEt+KU412M/E85rQAfGDyw5RXwqnb91
 rs7w6EJ8nfEGWDpqJTpZQxZbpvNc88cnh08lnxyFKGWiOBvV7G/qRNXG4AmI2e//
 oh4=
 =t5+P
 -----END PGP SIGNATURE-----

Merge tag 'bootconfig-fixes-v7.2-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace

Pull bootconfig fix from Masami Hiramatsu:

 - bootconfig: Fix NULL-pointer arithmetic

   Fix undefined pointer arithmetic in xbc_snprint_cmdline() when
   probing the buffer length with NULL and size 0. Track the written
   length as a size_t instead to prevent build-time UBSan/FORTIFY_SOURCE
   failures.

* tag 'bootconfig-fixes-v7.2-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace:
  bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline()
This commit is contained in:
Linus Torvalds 2026-07-01 14:21:03 -10:00
commit 4a50a141f0

View File

@ -427,10 +427,18 @@ static char xbc_namebuf[XBC_KEYLEN_MAX] __initdata;
int __init xbc_snprint_cmdline(char *buf, size_t size, struct xbc_node *root)
{
struct xbc_node *knode, *vnode;
char *end = buf + size;
const char *val, *q;
size_t len = 0;
int ret;
/*
* Track the running written length rather than advancing @buf, so we
* never form "buf + size" or "buf += ret" while @buf is NULL (the
* size-probe call passes buf=NULL, size=0). NULL pointer arithmetic
* is undefined behavior and trips host UBSan / FORTIFY_SOURCE when
* this renderer runs at kernel build time. snprintf(NULL, 0, ...)
* itself is well defined and returns the would-be length.
*/
xbc_node_for_each_key_value(root, knode, val) {
ret = xbc_node_compose_key_after(root, knode,
xbc_namebuf, XBC_KEYLEN_MAX);
@ -439,10 +447,11 @@ int __init xbc_snprint_cmdline(char *buf, size_t size, struct xbc_node *root)
vnode = xbc_node_get_child(knode);
if (!vnode) {
ret = snprintf(buf, rest(buf, end), "%s ", xbc_namebuf);
ret = snprintf(buf ? buf + len : NULL, rest(len, size),
"%s ", xbc_namebuf);
if (ret < 0)
return ret;
buf += ret;
len += ret;
continue;
}
xbc_array_for_each_value(vnode, val) {
@ -452,15 +461,15 @@ int __init xbc_snprint_cmdline(char *buf, size_t size, struct xbc_node *root)
* whitespace.
*/
q = strpbrk(val, " \t\r\n") ? "\"" : "";
ret = snprintf(buf, rest(buf, end), "%s=%s%s%s ",
xbc_namebuf, q, val, q);
ret = snprintf(buf ? buf + len : NULL, rest(len, size),
"%s=%s%s%s ", xbc_namebuf, q, val, q);
if (ret < 0)
return ret;
buf += ret;
len += ret;
}
}
return buf - (end - size);
return len;
}
#undef rest