From de8e50af88d9467d9d6cfb9f3eabfd7a3257c5f9 Mon Sep 17 00:00:00 2001 From: Thorsten Blum Date: Sun, 19 Jul 2026 15:22:53 +0200 Subject: [PATCH] thermal: sysfs: Use sysfs_emit_at() in trans_table_show() Replace snprintf() with sysfs_emit_at() in trans_table_show(). sysfs_emit_at() is preferred for formatting sysfs output because it provides safer bounds checking. Convert multiple PAGE_SIZE length checks to check the number of bytes actually copied by sysfs_emit_at(), thus avoiding manual buffer size accounting. Consistently return -EFBIG when the transition table output exceeds the sysfs buffer, including the header row. Signed-off-by: Thorsten Blum Link: https://patch.msgid.link/20260719132251.31936-3-thorsten.blum@linux.dev Signed-off-by: Rafael J. Wysocki --- drivers/thermal/thermal_sysfs.c | 49 ++++++++++++++++----------------- 1 file changed, 24 insertions(+), 25 deletions(-) diff --git a/drivers/thermal/thermal_sysfs.c b/drivers/thermal/thermal_sysfs.c index b44abfc997ed..adbcb2c011e8 100644 --- a/drivers/thermal/thermal_sysfs.c +++ b/drivers/thermal/thermal_sysfs.c @@ -706,7 +706,7 @@ static ssize_t trans_table_show(struct device *dev, struct thermal_cooling_device *cdev = to_cooling_device(dev); struct cooling_dev_stats *stats; ssize_t len = 0; - int i, j; + int i, j, copied; guard(cooling_dev)(cdev); @@ -714,41 +714,40 @@ static ssize_t trans_table_show(struct device *dev, if (!stats) return -ENODATA; - len += snprintf(buf + len, PAGE_SIZE - len, " From : To\n"); - len += snprintf(buf + len, PAGE_SIZE - len, " : "); + len += sysfs_emit_at(buf, len, " From : To\n"); + len += sysfs_emit_at(buf, len, " : "); for (i = 0; i <= cdev->max_state; i++) { - if (len >= PAGE_SIZE) - break; - len += snprintf(buf + len, PAGE_SIZE - len, "state%2u ", i); + copied = sysfs_emit_at(buf, len, "state%2u ", i); + if (!copied) + goto buf_full; + len += copied; } - if (len >= PAGE_SIZE) - return PAGE_SIZE; - - len += snprintf(buf + len, PAGE_SIZE - len, "\n"); + len += sysfs_emit_at(buf, len, "\n"); for (i = 0; i <= cdev->max_state; i++) { - if (len >= PAGE_SIZE) - break; - - len += snprintf(buf + len, PAGE_SIZE - len, "state%2u:", i); + copied = sysfs_emit_at(buf, len, "state%2u:", i); + if (!copied) + goto buf_full; + len += copied; for (j = 0; j <= cdev->max_state; j++) { - if (len >= PAGE_SIZE) - break; - len += snprintf(buf + len, PAGE_SIZE - len, "%8u ", + copied = sysfs_emit_at(buf, len, "%8u ", stats->trans_table[i * (cdev->max_state + 1) + j]); + if (!copied) + goto buf_full; + len += copied; } - if (len >= PAGE_SIZE) - break; - len += snprintf(buf + len, PAGE_SIZE - len, "\n"); - } - - if (len >= PAGE_SIZE) { - pr_warn_once("Thermal transition table exceeds PAGE_SIZE. Disabling\n"); - len = -EFBIG; + copied = sysfs_emit_at(buf, len, "\n"); + if (!copied) + goto buf_full; + len += copied; } return len; + +buf_full: + pr_warn_once("Thermal transition table exceeds PAGE_SIZE. Disabling\n"); + return -EFBIG; } static DEVICE_ATTR_RO(total_trans);