Replace sprintf() with sysfs_emit() in sysfs show functions. The sprintf() function is unaware of the PAGE_SIZE limit of the sysfs buffer, which can potentially lead to buffer overruns. sysfs_emit() is strictly designed for sysfs attributes and inherently protects against buffer boundaries.
Signed-off-by: Mohammad Davoudi MDavoudi2011@gmail.com --- drivers/staging/greybus/gbphy.c | 2 +- drivers/staging/greybus/light.c | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/staging/greybus/gbphy.c b/drivers/staging/greybus/gbphy.c index bdb0f5164..bb9a5b538 100644 --- a/drivers/staging/greybus/gbphy.c +++ b/drivers/staging/greybus/gbphy.c @@ -31,7 +31,7 @@ static ssize_t protocol_id_show(struct device *dev, { struct gbphy_device *gbphy_dev = to_gbphy_dev(dev);
- return sprintf(buf, "0x%02x\n", gbphy_dev->cport_desc->protocol_id); + return sysfs_emit(buf, "0x%02x\n", gbphy_dev->cport_desc->protocol_id); } static DEVICE_ATTR_RO(protocol_id);
diff --git a/drivers/staging/greybus/light.c b/drivers/staging/greybus/light.c index cab02b5da..2689f9a75 100644 --- a/drivers/staging/greybus/light.c +++ b/drivers/staging/greybus/light.c @@ -173,7 +173,7 @@ static ssize_t fade_##__dir##_show(struct device *dev, \ struct led_classdev *cdev = dev_get_drvdata(dev); \ struct gb_channel *channel = get_channel_from_cdev(cdev); \ \ - return sprintf(buf, "%u\n", channel->fade_##__dir); \ + return sysfs_emit(buf, "%u\n", channel->fade_##__dir); \ } \ \ static ssize_t fade_##__dir##_store(struct device *dev, \ @@ -220,7 +220,7 @@ static ssize_t color_show(struct device *dev, struct device_attribute *attr, struct led_classdev *cdev = dev_get_drvdata(dev); struct gb_channel *channel = get_channel_from_cdev(cdev);
- return sprintf(buf, "0x%08x\n", channel->color); + return sysfs_emit(buf, "0x%08x\n", channel->color); }
static ssize_t color_store(struct device *dev, struct device_attribute *attr,
On Wed, Jul 15, 2026 at 05:28:58PM +0000, Mohammad Davoudi wrote:
Replace sprintf() with sysfs_emit() in sysfs show functions. The sprintf() function is unaware of the PAGE_SIZE limit of the sysfs buffer, which can potentially lead to buffer overruns. sysfs_emit() is strictly designed for sysfs attributes and inherently protects against buffer boundaries.
Signed-off-by: Mohammad Davoudi MDavoudi2011@gmail.com
We're not applying this kind of patch in cases where sprintf is fine.
Really, I never like commit messages which talk about "potential buffer overruns". Is it a buffer overrun or not? If it's really hard to figure out then say that "This code is really hard to figure out and I suspect its fine but let's be safe."
In this case the code is really simple and we can all see the original code is fine just from reading the diff...
regards, dan carpenter
On Thu, 16 Jul 2026 00:31:35 +0300 Dan Carpenter error27@gmail.com wrote:
On Wed, Jul 15, 2026 at 05:28:58PM +0000, Mohammad Davoudi wrote:
Replace sprintf() with sysfs_emit() in sysfs show functions. The sprintf() function is unaware of the PAGE_SIZE limit of the sysfs buffer, which can potentially lead to buffer overruns. sysfs_emit() is strictly designed for sysfs attributes and inherently protects against buffer boundaries.
Signed-off-by: Mohammad Davoudi MDavoudi2011@gmail.com
We're not applying this kind of patch in cases where sprintf is fine.
Really, I never like commit messages which talk about "potential buffer overruns". Is it a buffer overrun or not? If it's really hard to figure out then say that "This code is really hard to figure out and I suspect its fine but let's be safe."
In this case the code is really simple and we can all see the original code is fine just from reading the diff...
And you also have to double-check that it is valid to call sysfs_emit() in that context. The call sequences aren't all that obvious and are difficult to verify.
David
regards, dan carpenter