From: sashiko-bot@kernel.org
To: "Nihar Panda" <niharp@linux.ibm.com>
Cc: linux-s390@vger.kernel.org, linux-scsi@vger.kernel.org,
"Alexander Gordeev" <agordeev@linux.ibm.com>,
"Vasily Gorbik" <gor@linux.ibm.com>,
"Heiko Carstens" <hca@linux.ibm.com>
Subject: Re: [PATCH 3/4] zfcp: trace return values of sysfs unit add store
Date: Fri, 24 Jul 2026 06:09:24 +0000 [thread overview]
Message-ID: <20260724060925.128ED1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260724053934.2781087-4-niharp@linux.ibm.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] Uninitialized kernel stack memory (`fcp_lun`) is written to a debug trace buffer when `kstrtoull` parsing fails, causing an information leak to userspace.
--
--- Patch [3]: [PATCH 3/4] zfcp: trace return values of sysfs unit add store ---
commit 2f001159c00d2d39b83745c171b53d3cb2468df3
Author: Chinmaya Kajagar <chinmayk@linux.ibm.com>
zfcp: trace return values of sysfs unit add store
This commit adds tracing for unit_add sysfs attribute failures to help
debug issues where the kernel cannot add a LUN. It adds a new trace record
ZFCP_DBF_HBA_UAS and updates zfcp_sysfs_unit_add_store() to log these events.
> diff --git a/drivers/s390/scsi/zfcp_sysfs.c b/drivers/s390/scsi/zfcp_sysfs.c
> index 42423549e511d..729c9664a48f8 100644
> --- a/drivers/s390/scsi/zfcp_sysfs.c
> +++ b/drivers/s390/scsi/zfcp_sysfs.c
[ ... ]
> @@ -442,17 +442,24 @@ static ssize_t zfcp_sysfs_unit_add_store(struct device *dev,
> const char *buf, size_t count)
> {
> struct zfcp_port *port = container_of(dev, struct zfcp_port, dev);
> + struct zfcp_adapter *adapter = port->adapter;
> u64 fcp_lun;
> - int retval;
> + int retval = -EINVAL;
>
> - if (kstrtoull(buf, 0, (unsigned long long *) &fcp_lun))
> - return -EINVAL;
> + if (kstrtoull(buf, 0, (unsigned long long *)&fcp_lun)) {
> + zfcp_dbf_hba_uas("syuast1", 3, adapter, port->wwpn,
> + fcp_lun, retval);
[Severity: Medium]
Does this code leak uninitialized kernel stack memory into the trace buffer?
If kstrtoull() fails to parse the input, it returns an error and may not
write to fcp_lun. The uninitialized fcp_lun variable is then immediately
passed to zfcp_dbf_hba_uas(), which records it in the trace buffer that
can be read from userspace.
> + return retval;
> + }
>
> flush_work(&port->rport_work);
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260724053934.2781087-1-niharp@linux.ibm.com?part=3
next prev parent reply other threads:[~2026-07-24 6:09 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-24 5:39 [PATCH 0/4] Request to queue zfcp enhancements for upstream v7.3 merge window Nihar Panda
2026-07-24 5:39 ` [PATCH 1/4] zfcp: Enhance fsf status read buffer tracing Nihar Panda
2026-07-24 6:18 ` sashiko-bot
2026-07-24 5:39 ` [PATCH 2/4] zfcp: Trace plogi and prli within open port response as payload Nihar Panda
2026-07-24 6:11 ` sashiko-bot
2026-07-24 5:39 ` [PATCH 3/4] zfcp: trace return values of sysfs unit add store Nihar Panda
2026-07-24 6:09 ` sashiko-bot [this message]
2026-07-24 5:39 ` [PATCH 4/4] fixup! " Nihar Panda
2026-07-24 6:13 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260724060925.128ED1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=agordeev@linux.ibm.com \
--cc=gor@linux.ibm.com \
--cc=hca@linux.ibm.com \
--cc=linux-s390@vger.kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=niharp@linux.ibm.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.