public inbox for drm-ai-reviews@public-inbox.freedesktop.org
 help / color / mirror / Atom feed
From: Claude Code Review Bot <claude-review@example.com>
To: dri-devel-reviews@example.com
Subject: Claude review: lib/fonts: Store font data for user space with font_data_export()
Date: Tue, 03 Mar 2026 13:19:16 +1000	[thread overview]
Message-ID: <review-patch12-20260302141255.518657-13-tzimmermann@suse.de> (raw)
In-Reply-To: <20260302141255.518657-13-tzimmermann@suse.de>

Patch Review

This patch has the most significant functional change in the series.

**Issue 1 (potential underflow)**: `font_data_export()` computes:
```c
memset(data + glyphsize, 0, pitch * vpitch - glyphsize);
```
If `vpitch < font->height`, then `pitch * vpitch < glyphsize` and this unsigned subtraction wraps to a huge value, causing a buffer overflow. The caller (`fbcon_get_font`) checks `font->height > vpitch` beforehand, but `font_data_export()` is `EXPORT_SYMBOL_GPL` and could be called by other code without that check. Adding a defensive `if (vpitch < font->height) return -ENOSPC;` in `font_data_export()` would be prudent.

**Issue 2 (behavioral change for width 17-24)**: The old code handled fonts with width 17-24 using a special 4-byte internal pitch with 3-byte export:
```c
for (j = 0; j < vc->vc_font.height; j++) {
    *data++ = fontdata[0];
    *data++ = fontdata[1];
    *data++ = fontdata[2];
    fontdata += sizeof(u32);
}
```
The new code uses a straight 3-byte pitch (DIV_ROUND_UP(24, 8) = 3) without the 4-byte stride on the source side. The commit message argues this is correct and cites the setfont utility. However, this changes the interpretation of stored font data for 17-24px wide fonts. If any existing internal font data uses a 4-byte internal pitch, this would read incorrect glyph data. There don't appear to be any built-in fonts with width 17-24, so this may be safe in practice, but the change should be tested with user-space 17-24px fonts loaded via setfont.

**Issue 3**: The overflow check `font->charcount * glyphsize > font_data_size(fd)` doesn't use `check_mul_overflow`, unlike `font_data_import()`. While realistic values won't overflow, consistency with the import path would be better.

---
Generated by Claude Code Patch Reviewer

  reply	other threads:[~2026-03-03  3:19 UTC|newest]

Thread overview: 29+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-03-02 14:08 [PATCH v2 00/13] vc,fbcon,fonts: Proper handling of font data Thomas Zimmermann
2026-03-02 14:08 ` [PATCH v2 01/13] fbdev: Declare src parameter of fb_pad_ helpers as constant Thomas Zimmermann
2026-03-03  3:19   ` Claude review: " Claude Code Review Bot
2026-03-02 14:08 ` [PATCH v2 02/13] vt: Remove trailing whitespaces Thomas Zimmermann
2026-03-03  3:19   ` Claude review: " Claude Code Review Bot
2026-03-02 14:08 ` [PATCH v2 03/13] vt: Store font in struct vc_font Thomas Zimmermann
2026-03-03  3:19   ` Claude review: " Claude Code Review Bot
2026-03-02 14:08 ` [PATCH v2 04/13] vt: Calculate font-buffer size with vc_font_size() Thomas Zimmermann
2026-03-03  3:19   ` Claude review: " Claude Code Review Bot
2026-03-02 14:08 ` [PATCH v2 05/13] lib/fonts: Remove trailing whitespaces Thomas Zimmermann
2026-03-03  3:19   ` Claude review: " Claude Code Review Bot
2026-03-02 14:08 ` [PATCH v2 06/13] lib/fonts: Remove FNTCHARCNT() Thomas Zimmermann
2026-03-03  3:19   ` Claude review: " Claude Code Review Bot
2026-03-02 14:08 ` [PATCH v2 07/13] lib/fonts: Store font data as font_data_t; update consoles Thomas Zimmermann
2026-03-03  3:19   ` Claude review: " Claude Code Review Bot
2026-03-02 14:08 ` [PATCH v2 08/13] lib/fonts: Read font size with font_data_size() Thomas Zimmermann
2026-03-03  3:19   ` Claude review: " Claude Code Review Bot
2026-03-02 14:08 ` [PATCH v2 09/13] lib/fonts: Compare font data for equality with font_data_is_equal() Thomas Zimmermann
2026-03-03  3:19   ` Claude review: " Claude Code Review Bot
2026-03-02 14:08 ` [PATCH v2 10/13] lib/fonts: Manage font-data lifetime with font_data_get/_put() Thomas Zimmermann
2026-03-03  3:19   ` Claude review: " Claude Code Review Bot
2026-03-02 14:08 ` [PATCH v2 11/13] lib/fonts: Create font_data_t from struct console_font with font_data_import() Thomas Zimmermann
2026-03-03  3:19   ` Claude review: " Claude Code Review Bot
2026-03-02 14:08 ` [PATCH v2 12/13] lib/fonts: Store font data for user space with font_data_export() Thomas Zimmermann
2026-03-03  3:19   ` Claude Code Review Bot [this message]
2026-03-02 14:08 ` [PATCH v2 13/13] lib/fonts: Remove internal symbols and macros from public header file Thomas Zimmermann
2026-03-03  3:19   ` Claude review: " Claude Code Review Bot
2026-03-03  3:19 ` Claude review: vc,fbcon,fonts: Proper handling of font data Claude Code Review Bot
  -- strict thread matches above, loose matches on Subject: below --
2026-03-09 14:14 [PATCH v3 00/13] " Thomas Zimmermann
2026-03-09 14:14 ` [PATCH v3 12/13] lib/fonts: Store font data for user space with font_data_export() Thomas Zimmermann
2026-03-10  2:19   ` Claude review: " Claude Code Review Bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=review-patch12-20260302141255.518657-13-tzimmermann@suse.de \
    --to=claude-review@example.com \
    --cc=dri-devel-reviews@example.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox