Thread (11 messages) 11 messages, 2 authors, 27d ago

Re: [PATCH v6 1/6] treewide: Get rid of get_task_comm()

flat view

From: sashiko-bot@kernel.org
Date: 2026-09-10 16:58:45

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Passing a pointer to `struct task_struct` instead of its `comm` field to `strscpy_pad()` leads to an incompatible pointer cast and a kernel memory info leak.
--

commit 90523a0d5e26d2bcb762f02d00c73857b4ad6c5d
Author: André Almeida [off-list ref]

treewide: Get rid of get_task_comm()

This commit replaces calls to get_task_comm() with strscpy_pad() across the
tree. It aims to properly handle buffer padding and truncation depending on
buffer sizes.

Link: https://lore.kernel.org/lkml/CAHk-=wi5c=_-FBGo_88CowJd_F-Gi6Ud9d=TALm65ReN7YjrMw@mail.gmail.com/ (local)

[ ... ]
quoted hunk ↗ jump to hunk
diff --git a/security/smack/smack_lsm.c b/security/smack/smack_lsm.c
index 8e88ac65fd7fc..0e1aa2bb4a7ca 100644
--- a/security/smack/smack_lsm.c
+++ b/security/smack/smack_lsm.c
@@ -138,6 +138,8 @@ smk_bu_tsk_to_obj(struct task_struct *tsk, const struct task_smack *tsp,
 	char acc[SMK_NUM_ACCESS_TYPE + 1];
 	char comm[TASK_COMM_LEN];
 
+	strscpy_pad(comm, tsk);
[Severity: High]
Could this lead to a kernel memory info leak by passing the task_struct
pointer instead of the process name string?

strscpy_pad() expects a const char * as its second argument, but it receives
a struct task_struct * here instead of tsk->comm.

If this compiles (e.g., without -Werror), this copies up to 16 bytes starting
at the base of the task_struct into the comm buffer. When this buffer is
later printed via pr_info() during a Smack Bringup log, it dumps raw kernel
memory to dmesg, which could be leveraged to bypass KASLR or read sensitive
struct fields.
quoted hunk ↗ jump to hunk
+
 	if (rc <= 0)
 		return rc;
 	if (rc > SMACK_UNCONFINED_OBJECT)
@@ -147,7 +149,7 @@ smk_bu_tsk_to_obj(struct task_struct *tsk, const struct task_smack *tsp,
 
 	pr_info("Smack %s: (%s %s %s) %s %s\n", smk_bu_mess[rc],
 		smk_of_task(tsp)->smk_known, oskp->smk_known,
-		acc, get_task_comm(comm, tsk), note);
+		acc, comm, note);
 	return 0;
 #else
 	return rc;
-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260910-tonyk-long_name-v6-0-d70afbf194c5@igalia.com?part=1
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help