Re: [PATCH] fs/ntfs3: reserve NUL byte when converting UTF-16 names

Konstantin Komarov <[email protected]> Thu, 23 Jul 2026 16:27:00 +0200
Newsgroups dev.linux.lists.ntfs3,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On 6/11/26 23:33, Kyle Zeng wrote:

> ntfs_utf16_to_nls() appends a trailing NUL to the converted output,
> but it passes the caller-supplied size directly to the conversion loop.
> For the UTF-8 path, utf16s_to_utf8s() can legitimately fill all
> buf_len bytes and return buf_len, after which ntfs_utf16_to_nls()
> writes the terminator one byte past the end of the destination buffer.
>
> The same contract problem exists for the NLS path when a converted
> character consumes the last available byte.
>
> Reserve one byte for the terminator before doing either conversion.
> The function continues to return the number of converted bytes,
> excluding the NUL terminator.
>
> Assisted-by: Codex:gpt-5.5
> Signed-off-by: Kyle Zeng <[email protected]>
> ---
>   fs/ntfs3/dir.c | 5 +++++
>   1 file changed, 5 insertions(+)
>
> diff --git a/fs/ntfs3/dir.c b/fs/ntfs3/dir.c
> index d99ab086ef6f..e8892cd94e04 100644
> --- a/fs/ntfs3/dir.c
> +++ b/fs/ntfs3/dir.c
> @@ -25,6 +25,11 @@ int ntfs_utf16_to_nls(struct ntfs_sb_info *sbi, const __le16 *name, u32 len,
>
>          static_assert(sizeof(wchar_t) == sizeof(__le16));
>
> +       if (buf_len <= 0)
> +               return -EINVAL;
> +
> +       buf_len -= 1;
> +
>          if (!nls) {
>                  /* UTF-16 -> UTF-8 */
>                  ret = utf16s_to_utf8s((wchar_t *)name, len, UTF16_LITTLE_ENDIAN,
> --
> 2.43.0
>
Hello,

Sorry for the delay.
Your patch was applied, thank you.

Regards,
Konstantin