thermal: testing: reject missing command arguments

The thermal testing debugfs command parser splits commands at ':' and
passes the right-hand side to the command implementation. Commands such
as deltz, tzaddtrip, tzreg, and tzunreg require a zone id, but writing
one of those command names without ':' leaves the argument pointer NULL.

The command implementations parse the id with sscanf(arg, "%d", ...), so
the missing-argument form dereferences a NULL pointer from the debugfs
write path.

Reject missing arguments in tt_command_exec() before calling handlers
that require an id.

Fixes: f6a034f2df ("thermal: Introduce a debugfs-based testing facility")
Assisted-by: Codex:gpt-5.5-cyber-preview
Signed-off-by: Samuel Moelius <sam.moelius@trailofbits.com>
Link: https://patch.msgid.link/20260605185212.2491144-1-sam.moelius@trailofbits.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
This commit is contained in:
Samuel Moelius 2026-06-05 18:52:06 +00:00 committed by Rafael J. Wysocki
parent bdbca04e7e
commit ef3e98b0aa

View File

@ -116,18 +116,30 @@ static int tt_command_exec(int index, const char *arg)
break;
case TT_CMD_DELTZ:
if (!arg || !*arg)
return -EINVAL;
ret = tt_del_tz(arg);
break;
case TT_CMD_TZADDTRIP:
if (!arg || !*arg)
return -EINVAL;
ret = tt_zone_add_trip(arg);
break;
case TT_CMD_TZREG:
if (!arg || !*arg)
return -EINVAL;
ret = tt_zone_reg(arg);
break;
case TT_CMD_TZUNREG:
if (!arg || !*arg)
return -EINVAL;
ret = tt_zone_unreg(arg);
break;