Re: [PATCH v3 07/20] tracing: Add __print_untrusted_str()

Mickaël Salaün <[email protected]> Thu, 6 Aug 2026 19:21:52 +0200
Newsgroups org.kernel.vger.linux-trace-kernel,org.kernel.vger.linux-security-module
Message-ID <[email protected]>
Hi Steven,

I addressed your previous review for this helper, is this patch ok with
you now?

I also addressed your other review about the tracepoints.  They are well
tested, including with a dedicated tool I wrote (not public yet).  Could
you get a quick look for me to push this series to -next before the
merge window?

Thanks

On Wed, Jul 22, 2026 at 07:11:39PM +0200, Mickaël Salaün wrote:
> Landlock tracepoints expose filesystem paths and process names that may
> contain spaces, equal signs, or other characters that break ftrace field
> parsing.
> 
> Add a __print_untrusted_str() TP_printk helper that escapes separators
> (space, equal sign), quotes, backslashes, and non-printable bytes via
> string_escape_mem(), so an untrusted string cannot inject field
> separators or control characters into the ftrace output and can be
> unambiguously recovered.
> 
> This guarantee applies to the in-kernel ftrace text output (trace,
> trace_pipe).  Userspace libtraceevent (perf, trace-cmd) does not yet
> parse this helper, so a companion libtraceevent change is needed for
> those consumers to pretty-print the field.
> 
> Cc: Günther Noack <[email protected]>
> Cc: Masami Hiramatsu <[email protected]>
> Cc: Mathieu Desnoyers <[email protected]>
> Cc: Steven Rostedt <[email protected]>
> Cc: Tingmao Wang <[email protected]>
> Signed-off-by: Mickaël Salaün <[email protected]>
> ---
> 
> Changes since v2:
> https://patch.msgid.link/[email protected]
> - Add a Return: kdoc for trace_print_untrusted_str_seq() and rename its
>   declaration parameter to src.
> 
> Changes since v1:
> https://patch.msgid.link/[email protected]
> - Remove WARN_ON() (pointed out by Steven Rostedt).
> ---
>  include/linux/trace_events.h               |  2 +
>  include/trace/stages/stage3_trace_output.h |  4 ++
>  include/trace/stages/stage7_class_define.h |  1 +
>  kernel/trace/trace_output.c                | 44 ++++++++++++++++++++++
>  4 files changed, 51 insertions(+)
> 
> diff --git a/include/linux/trace_events.h b/include/linux/trace_events.h
> index 308c76b57d13..4ece9b8d9d6b 100644
> --- a/include/linux/trace_events.h
> +++ b/include/linux/trace_events.h
> @@ -60,6 +60,8 @@ trace_print_hex_dump_seq(struct trace_seq *p, const char *prefix_str,
>  			 int prefix_type, int rowsize, int groupsize,
>  			 const void *buf, size_t len, bool ascii);
>  
> +const char *trace_print_untrusted_str_seq(struct trace_seq *s, const char *src);
> +
>  int trace_raw_output_prep(struct trace_iterator *iter,
>  			  struct trace_event *event);
>  extern __printf(2, 3)
> diff --git a/include/trace/stages/stage3_trace_output.h b/include/trace/stages/stage3_trace_output.h
> index 181b81335781..0235dbd11b52 100644
> --- a/include/trace/stages/stage3_trace_output.h
> +++ b/include/trace/stages/stage3_trace_output.h
> @@ -133,6 +133,10 @@
>  	trace_print_hex_dump_seq(p, prefix_str, prefix_type,		\
>  				 rowsize, groupsize, buf, len, ascii)
>  
> +#undef __print_untrusted_str
> +#define __print_untrusted_str(str)					\
> +		trace_print_untrusted_str_seq(p, __get_str(str))
> +
>  #undef __print_ns_to_secs
>  #define __print_ns_to_secs(value)			\
>  	({						\
> diff --git a/include/trace/stages/stage7_class_define.h b/include/trace/stages/stage7_class_define.h
> index 47008897a795..f29a82e7a4c4 100644
> --- a/include/trace/stages/stage7_class_define.h
> +++ b/include/trace/stages/stage7_class_define.h
> @@ -24,6 +24,7 @@
>  #undef __print_array
>  #undef __print_dynamic_array
>  #undef __print_hex_dump
> +#undef __print_untrusted_str
>  #undef __get_buf
>  
>  #undef __event_in_hardirq
> diff --git a/kernel/trace/trace_output.c b/kernel/trace/trace_output.c
> index a5ad76175d10..f0a9b29b3e36 100644
> --- a/kernel/trace/trace_output.c
> +++ b/kernel/trace/trace_output.c
> @@ -16,6 +16,7 @@
>  #include <linux/btf.h>
>  #include <linux/bpf.h>
>  #include <linux/hashtable.h>
> +#include <linux/string_helpers.h>
>  
>  #include "trace_output.h"
>  #include "trace_btf.h"
> @@ -325,6 +326,49 @@ trace_print_hex_dump_seq(struct trace_seq *p, const char *prefix_str,
>  }
>  EXPORT_SYMBOL(trace_print_hex_dump_seq);
>  
> +/**
> + * trace_print_untrusted_str_seq - print a string after escaping characters
> + * @s: trace seq struct to write to
> + * @src: The string to print
> + *
> + * Prints a string to a trace seq after escaping all special characters,
> + * including common separators (space, equal sign), quotes, and backslashes.
> + * This transforms a string from an untrusted source (e.g. user space) to make
> + * it:
> + * - safe to parse,
> + * - easy to read (for simple strings),
> + * - easy to get back the original.
> + *
> + * Return: A pointer to the escaped string within the trace seq buffer, or
> + * %NULL if @src is %NULL or the buffer is exhausted.
> + */
> +const char *trace_print_untrusted_str_seq(struct trace_seq *s,
> +					   const char *src)
> +{
> +	int escaped_size;
> +	char *buf;
> +	size_t buf_size = seq_buf_get_buf(&s->seq, &buf);
> +	const char *ret = trace_seq_buffer_ptr(s);
> +
> +	/* Buffer exhaustion is normal when the trace buffer is full. */
> +	if (!src || buf_size == 0)
> +		return NULL;
> +
> +	escaped_size = string_escape_mem(src, strlen(src), buf, buf_size,
> +		ESCAPE_SPACE | ESCAPE_SPECIAL | ESCAPE_NAP | ESCAPE_APPEND |
> +		ESCAPE_OCTAL, " ='\"\\");
> +	if (unlikely(escaped_size >= buf_size)) {
> +		/* We need some room for the final '\0'. */
> +		seq_buf_set_overflow(&s->seq);
> +		s->full = 1;
> +		return NULL;
> +	}
> +	seq_buf_commit(&s->seq, escaped_size);
> +	trace_seq_putc(s, 0);
> +	return ret;
> +}
> +EXPORT_SYMBOL(trace_print_untrusted_str_seq);
> +
>  int trace_raw_output_prep(struct trace_iterator *iter,
>  			  struct trace_event *trace_event)
>  {
> -- 
> 2.54.0
> 
>