event_string[] has a fixed size of WEDGE_STR_LEN (32) bytes. Since
scnprintf() reserves space for the terminating null byte, it can write
at most 31 characters.

When len reaches WEDGE_STR_LEN - 1, only the null terminator fits in the
remaining space. Any further scnprintf() calls return 0 and additional
recovery method names are silently dropped, making the truncation hard
to detect.

Add a drm_WARN_ON() check for len >= WEDGE_STR_LEN - 1 before attempting
another write. If the buffer is already full, emit a warning and stop
processing further entries. This makes buffer truncation visible and
allows the loop to exit cleanly instead of silently ignoring recovery
methods.

Fixes: b7cf9f4ac1b8 ("drm: Introduce device wedged event")
Signed-off-by: Mallesh Koujalagi <[email protected]>
---
 drivers/gpu/drm/drm_drv.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/gpu/drm/drm_drv.c b/drivers/gpu/drm/drm_drv.c
index 1ff0bf7cba6a..63eef0a19e99 100644
--- a/drivers/gpu/drm/drm_drv.c
+++ b/drivers/gpu/drm/drm_drv.c
@@ -578,6 +578,9 @@ int drm_dev_wedged_event(struct drm_device *dev, unsigned 
long method,
                if (drm_WARN_ONCE(dev, !recovery, "invalid recovery method 
%u\n", opt))
                        break;
 
+               if (drm_WARN_ON(dev, len >= WEDGE_STR_LEN - 1))
+                       break;
+
                len += scnprintf(event_string + len, sizeof(event_string) - 
len, "%s,", recovery);
        }
 
-- 
2.48.1

Reply via email to