* [PATCH] scsi_transport_sas: fix BSG ioctl memory corruption
@ 2017-02-21 18:03 Omar Sandoval
2017-02-21 18:31 ` Christoph Hellwig
2017-02-21 21:19 ` Jens Axboe
0 siblings, 2 replies; 3+ messages in thread
From: Omar Sandoval @ 2017-02-21 18:03 UTC (permalink / raw)
To: Jens Axboe, linux-block; +Cc: Christoph Hellwig, kernel-team
From: Omar Sandoval <osandov@fb.com>
The end_device and sas_host devices support BSG ioctls, but the
request_queue allocated for them isn't set up to allocate the struct
scsi_request payload. This leads to memory corruption in the call to
scsi_req_init() in bsg_map_hdr(), since it will memset past the end of
the allocated request. Fix it by setting ->cmd_size on the allocated
request_queue.
Fixes: 82ed4db499b8 ("block: split scsi_request out of struct request")
Signed-off-by: Omar Sandoval <osandov@fb.com>
---
I don't know what sg ioctls these devices actually support, but I tested
this with sg_inq, which previously caused KASAN splats.
drivers/scsi/scsi_transport_sas.c | 24 ++++++++++++++++--------
1 file changed, 16 insertions(+), 8 deletions(-)
diff --git a/drivers/scsi/scsi_transport_sas.c b/drivers/scsi/scsi_transport_sas.c
index 126a5ee00987..f94535130a34 100644
--- a/drivers/scsi/scsi_transport_sas.c
+++ b/drivers/scsi/scsi_transport_sas.c
@@ -227,27 +227,31 @@ static int sas_bsg_initialize(struct Scsi_Host *shost, struct sas_rphy *rphy)
return 0;
}
+ q = blk_alloc_queue(GFP_KERNEL);
+ if (!q)
+ return -ENOMEM;
+ q->cmd_size = sizeof(struct scsi_request);
+
if (rphy) {
- q = blk_init_queue(sas_non_host_smp_request, NULL);
+ q->request_fn = sas_non_host_smp_request;
dev = &rphy->dev;
name = dev_name(dev);
release = NULL;
} else {
- q = blk_init_queue(sas_host_smp_request, NULL);
+ q->request_fn = sas_host_smp_request;
dev = &shost->shost_gendev;
snprintf(namebuf, sizeof(namebuf),
"sas_host%d", shost->host_no);
name = namebuf;
release = sas_host_release;
}
- if (!q)
- return -ENOMEM;
+ error = blk_init_allocated_queue(q);
+ if (error)
+ goto out_cleanup_queue;
error = bsg_register_queue(q, dev, name, release);
- if (error) {
- blk_cleanup_queue(q);
- return -ENOMEM;
- }
+ if (error)
+ goto out_cleanup_queue;
if (rphy)
rphy->q = q;
@@ -261,6 +265,10 @@ static int sas_bsg_initialize(struct Scsi_Host *shost, struct sas_rphy *rphy)
queue_flag_set_unlocked(QUEUE_FLAG_BIDI, q);
return 0;
+
+out_cleanup_queue:
+ blk_cleanup_queue(q);
+ return error;
}
static void sas_bsg_remove(struct Scsi_Host *shost, struct sas_rphy *rphy)
--
2.11.1
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH] scsi_transport_sas: fix BSG ioctl memory corruption
2017-02-21 18:03 [PATCH] scsi_transport_sas: fix BSG ioctl memory corruption Omar Sandoval
@ 2017-02-21 18:31 ` Christoph Hellwig
2017-02-21 21:19 ` Jens Axboe
1 sibling, 0 replies; 3+ messages in thread
From: Christoph Hellwig @ 2017-02-21 18:31 UTC (permalink / raw)
To: Omar Sandoval; +Cc: Jens Axboe, linux-block, Christoph Hellwig, kernel-team
On Tue, Feb 21, 2017 at 10:03:50AM -0800, Omar Sandoval wrote:
> From: Omar Sandoval <osandov@fb.com>
>
> The end_device and sas_host devices support BSG ioctls, but the
> request_queue allocated for them isn't set up to allocate the struct
> scsi_request payload. This leads to memory corruption in the call to
> scsi_req_init() in bsg_map_hdr(), since it will memset past the end of
> the allocated request. Fix it by setting ->cmd_size on the allocated
> request_queue.
Oh, I missed that SAS still opencodes it's queue allocations.
Acked-by: Christoph Hellwig <hch@lst.de>
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] scsi_transport_sas: fix BSG ioctl memory corruption
2017-02-21 18:03 [PATCH] scsi_transport_sas: fix BSG ioctl memory corruption Omar Sandoval
2017-02-21 18:31 ` Christoph Hellwig
@ 2017-02-21 21:19 ` Jens Axboe
1 sibling, 0 replies; 3+ messages in thread
From: Jens Axboe @ 2017-02-21 21:19 UTC (permalink / raw)
To: Omar Sandoval, linux-block; +Cc: Christoph Hellwig, kernel-team
On 02/21/2017 11:03 AM, Omar Sandoval wrote:
> From: Omar Sandoval <osandov@fb.com>
>
> The end_device and sas_host devices support BSG ioctls, but the
> request_queue allocated for them isn't set up to allocate the struct
> scsi_request payload. This leads to memory corruption in the call to
> scsi_req_init() in bsg_map_hdr(), since it will memset past the end of
> the allocated request. Fix it by setting ->cmd_size on the allocated
> request_queue.
Good catch, thanks Omar. Applied.
--
Jens Axboe
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2017-02-21 21:19 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-02-21 18:03 [PATCH] scsi_transport_sas: fix BSG ioctl memory corruption Omar Sandoval
2017-02-21 18:31 ` Christoph Hellwig
2017-02-21 21:19 ` Jens Axboe
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.