format_disasm_line() strips trailing newlines from the disassembly it
stores, as diag_print_insn_context() adds its own. Since
commit 483a1bb0b6cf8 ("bpf: Do not print a newline after disassembly in
bpf_verbose_insn()"), print_bpf_insn() does not emit one, so there is
nothing left to strip.

The strnlen() resync of the seq_buf length only existed so the loop
could index the buffer safely after an overflow, and the second
termination only restored the NUL that seq_buf_pop() does not write.
Remove all of it, keeping a single seq_buf_terminate().

Build tested ARCH=x86_64 defconfig with GCC 16.2.0 and
CONFIG_BPF_SYSCALL=y.

Assisted-by: LLM
Signed-off-by: Kees Cook <[email protected]>
---
 kernel/bpf/diagnostics.c | 4 ----
 1 file changed, 4 deletions(-)

diff --git a/kernel/bpf/diagnostics.c b/kernel/bpf/diagnostics.c
index 594cf3c8b74c..8f64bfd9afee 100644
--- a/kernel/bpf/diagnostics.c
+++ b/kernel/bpf/diagnostics.c
@@ -632,10 +632,6 @@ static void format_disasm_line(struct bpf_verifier_env 
*env, int insn_idx,
 
        print_bpf_insn(&cbs, insn, env->allow_ptr_leaks);
        seq_buf_terminate(&ctx.seq);
-       ctx.seq.len = strnlen(line->text, sizeof(line->text));
-       while (ctx.seq.len && line->text[ctx.seq.len - 1] == '\n')
-               seq_buf_pop(&ctx.seq);
-       seq_buf_terminate(&ctx.seq);
 
        line->valid = true;
 }
-- 
2.34.1


Reply via email to