From: sashiko-bot@kernel.org
To: "Damien Le Moal" <dlemoal@kernel.org>
Cc: linux-ide@vger.kernel.org, linux-s390@vger.kernel.org,
linux-scsi@vger.kernel.org, cassel@kernel.org,
"Alexander Gordeev" <agordeev@linux.ibm.com>,
dlemoal@kernel.org,
"Christian Borntraeger" <borntraeger@linux.ibm.com>,
"Heiko Carstens" <hca@linux.ibm.com>,
"Vasily Gorbik" <gor@linux.ibm.com>
Subject: Re: [PATCH v2 34/40] target: use 16-bits defined sense codes
Date: Thu, 03 Sep 2026 04:02:02 +0000 [thread overview]
Message-ID: <20260903040203.42A091F00A3E@smtp.kernel.org> (raw)
In-Reply-To: <20260903034201.112211-35-dlemoal@kernel.org>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
New issues:
- [Medium] Uninitialized stack variable read in debug log due to concurrent list modification
Pre-existing issues:
- [High] Logic error causes Unit Attention Interlock to fail and incorrectly return SAM_STAT_BUSY
--
commit 95a802c45c6965b17dd9cccbc6b6421dcf571862
Author: Damien Le Moal <dlemoal@kernel.org>
target: use 16-bits defined sense codes
Refactor the target core code to use the 16-bits sense codes for building
sense and replace all hard-coded additional sense codes and additional
sense code qualifiers with the enum values defined in
include/scsi/scsi_sense.h. This helps with code clarity as the sense codes
being processed are easier to test and self-documented.
No functional change intended.
> diff --git a/drivers/target/target_core_spc.c b/drivers/target/target_core_spc.c
> index f964a531e053a..f11766dfb5428 100644
> --- a/drivers/target/target_core_spc.c
> +++ b/drivers/target/target_core_spc.c
> @@ -1226,9 +1226,9 @@ static sense_reason_t spc_emulate_request_sense(struct se_cmd *cmd)
> {
> unsigned char *cdb = cmd->t_task_cdb;
> unsigned char *rbuf;
> - u8 ua_asc = 0, ua_ascq = 0;
> unsigned char buf[SE_SENSE_BUF];
> bool desc_format = target_sense_desc_format(cmd->se_dev);
> + u16 sense_code;
[Severity: Medium]
Could this uninitialized variable cause an issue?
The previous code initialized ua_asc and ua_ascq to 0, but sense_code is
left uninitialized here.
[ ... ]
> diff --git a/drivers/target/target_core_ua.c b/drivers/target/target_core_ua.c
> index 4276690fb6cbd..ea97b05d47ab7 100644
> --- a/drivers/target/target_core_ua.c
> +++ b/drivers/target/target_core_ua.c
[ ... ]
> @@ -232,8 +230,7 @@ bool core_scsi3_ua_for_check_condition(struct se_cmd *cmd, u8 *key, u8 *asc,
> * clearing it.
> */
> if (!dev_ua_intlck_clear) {
> - *asc = ua->ua_asc;
> - *ascq = ua->ua_ascq;
> + *code = scsi_sense_code(ua->ua_asc, ua->ua_ascq);
> break;
> }
[Severity: High]
This is a pre-existing issue, but if dev_ua_intlck_clear is false, the loop
breaks early without updating the head variable to 0.
Since head remains 1, core_scsi3_ua_for_check_condition() later returns
head == 0, which evaluates to false.
Does this incorrect return value mislead the target core into aborting the
sense processing in translate_sense_reason() and returning a SAM_STAT_BUSY
status instead of a CHECK CONDITION?
[ ... ]
> @@ -317,7 +310,8 @@ int core_scsi3_ua_clear_for_request_sense(
> pr_debug("[%s]: Released UNIT ATTENTION condition, mapped"
> " LUN: %llu, got REQUEST_SENSE reported ASC: 0x%02x,"
> " ASCQ: 0x%02x\n", nacl->se_tpg->se_tpg_tfo->fabric_name,
> - cmd->orig_fe_lun, *asc, *ascq);
> + cmd->orig_fe_lun, scsi_sense_code_asc(*code),
> + scsi_sense_code_ascq(*code));
>
> return (head) ? -EPERM : 0;
> }
[Severity: Medium]
Is it possible for this debug log to read the uninitialized stack variable
from spc_emulate_request_sense()?
If the list is cleared concurrently between the lockless list_empty_careful()
check and acquiring the ua_lock, the loop is skipped and *code is never
assigned.
Will this unconditionally pass uninitialized memory to pr_debug() and
potentially trigger a KMSAN warning?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260903034201.112211-1-dlemoal@kernel.org?part=34
next prev parent reply other threads:[~2026-09-03 4:02 UTC|newest]
Thread overview: 130+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-03 3:41 [PATCH v2 00/40] Use defined 16-bits ASC/ASCQ combinations Damien Le Moal
2026-09-03 3:41 ` [PATCH v2 01/40] scsi: define all additional sense codes and their qualifiers Damien Le Moal
2026-09-03 3:55 ` sashiko-bot
2026-09-03 11:54 ` Johannes Thumshirn
2026-09-07 12:01 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 02/40] scsi: constants: use defined sense codes Damien Le Moal
2026-09-03 3:53 ` sashiko-bot
2026-09-03 12:35 ` Johannes Thumshirn
2026-09-07 12:02 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 03/40] scsi: constants: rename internal struct field names Damien Le Moal
2026-09-03 3:50 ` sashiko-bot
2026-09-03 12:37 ` Johannes Thumshirn
2026-09-07 12:04 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 04/40] scsi: rename sense field of struct scsi_failure Damien Le Moal
2026-09-03 3:53 ` sashiko-bot
2026-09-07 12:10 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 05/40] scsi: prepare for using 16-bits defined sense codes Damien Le Moal
2026-09-03 3:53 ` sashiko-bot
2026-09-03 12:39 ` Johannes Thumshirn
2026-09-07 12:16 ` Hannes Reinecke
2026-09-08 0:22 ` Damien Le Moal
2026-09-08 14:29 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 06/40] scsi: use struct scsi_sense_hdr to log sense keys and codes Damien Le Moal
2026-09-03 3:51 ` sashiko-bot
2026-09-07 12:18 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 07/40] scsi: core: use 16-bits defined sense codes Damien Le Moal
2026-09-03 3:56 ` sashiko-bot
2026-09-07 12:21 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 08/40] scsi: sd: " Damien Le Moal
2026-09-03 4:00 ` sashiko-bot
2026-09-07 12:25 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 09/40] scsi: sr: " Damien Le Moal
2026-09-03 3:54 ` sashiko-bot
2026-09-07 13:56 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 10/40] scsi: ses: " Damien Le Moal
2026-09-03 3:51 ` sashiko-bot
2026-09-07 12:27 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 11/40] scsi: ch: " Damien Le Moal
2026-09-03 3:50 ` sashiko-bot
2026-09-07 13:48 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 12/40] scsi: st: " Damien Le Moal
2026-09-03 3:49 ` sashiko-bot
2026-09-07 13:47 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 13/40] scsi: device_handlers: hp_sw: " Damien Le Moal
2026-09-03 3:49 ` sashiko-bot
2026-09-07 12:28 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 14/40] scsi: device_handlers: rdac: " Damien Le Moal
2026-09-03 3:51 ` sashiko-bot
2026-09-07 13:49 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 15/40] scsi: device_handlers: emc: " Damien Le Moal
2026-09-03 3:50 ` sashiko-bot
2026-09-07 13:48 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 16/40] scsi: device_handlers: alua: " Damien Le Moal
2026-09-03 3:52 ` sashiko-bot
2026-09-07 12:29 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 17/40] scsi: mpt3sas: " Damien Le Moal
2026-09-03 3:51 ` sashiko-bot
2026-09-07 12:29 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 18/40] scsi: mpi3mr: " Damien Le Moal
2026-09-03 3:51 ` sashiko-bot
2026-09-07 12:30 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 19/40] scsi: 3w-xxxx: " Damien Le Moal
2026-09-03 3:52 ` sashiko-bot
2026-09-07 13:51 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 20/40] scsi: leapraid: " Damien Le Moal
2026-09-03 3:52 ` sashiko-bot
2026-09-07 13:52 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 21/40] scsi: megaraid: " Damien Le Moal
2026-09-03 3:54 ` sashiko-bot
2026-09-07 12:33 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 22/40] scsi: myrX: " Damien Le Moal
2026-09-03 4:01 ` sashiko-bot
2026-09-07 12:34 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 23/40] scsi: smartpqi: " Damien Le Moal
2026-09-03 3:54 ` sashiko-bot
2026-09-07 12:35 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 24/40] scsi: qla2xxx: " Damien Le Moal
2026-09-03 4:00 ` sashiko-bot
2026-09-07 12:36 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 25/40] scsi: ps3rom: " Damien Le Moal
2026-09-03 4:01 ` sashiko-bot
2026-09-07 12:36 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 26/40] scsi: lpfc: " Damien Le Moal
2026-09-03 3:54 ` sashiko-bot
2026-09-07 12:37 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 27/40] scsi: stex: " Damien Le Moal
2026-09-03 3:59 ` sashiko-bot
2026-09-07 12:38 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 28/40] scsi: mvumi: " Damien Le Moal
2026-09-03 4:02 ` sashiko-bot
2026-09-07 12:38 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 29/40] scsi: libiscsi: " Damien Le Moal
2026-09-03 3:55 ` sashiko-bot
2026-09-07 12:40 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 30/40] scsi: ibmvscsi_tgt: " Damien Le Moal
2026-09-03 4:04 ` sashiko-bot
2026-09-07 12:40 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 31/40] scsi: scsi_debug: " Damien Le Moal
2026-09-03 4:01 ` sashiko-bot
2026-09-07 12:47 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 32/40] scsi: hpsa: " Damien Le Moal
2026-09-03 3:57 ` sashiko-bot
2026-09-07 12:52 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 33/40] scsi: storvsc: " Damien Le Moal
2026-09-03 3:58 ` sashiko-bot
2026-09-07 12:53 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 34/40] target: " Damien Le Moal
2026-09-03 4:02 ` sashiko-bot [this message]
2026-09-07 12:55 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 35/40] usb: storage: " Damien Le Moal
2026-09-03 4:01 ` sashiko-bot
2026-09-07 12:56 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 36/40] cdrom: " Damien Le Moal
2026-09-03 3:57 ` sashiko-bot
2026-09-07 13:17 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 37/40] ata: libata: " Damien Le Moal
2026-09-03 4:06 ` sashiko-bot
2026-09-03 9:10 ` Niklas Cassel
2026-09-07 13:19 ` Hannes Reinecke
2026-09-03 3:41 ` [PATCH v2 38/40] s390: scsi: " Damien Le Moal
2026-09-03 4:01 ` sashiko-bot
2026-09-07 13:20 ` Hannes Reinecke
2026-09-08 0:24 ` Damien Le Moal
2026-09-03 3:42 ` [PATCH v2 39/40] scsi: cleanup scsi_proto.h Damien Le Moal
2026-09-03 4:00 ` sashiko-bot
2026-09-07 13:41 ` Hannes Reinecke
2026-09-03 3:42 ` [PATCH v2 40/40] scsi: remove scsi_build_sense() and scsi_build_sense_buffer() Damien Le Moal
2026-09-03 3:58 ` sashiko-bot
2026-09-03 9:15 ` Niklas Cassel
2026-09-07 13:43 ` Hannes Reinecke
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260903040203.42A091F00A3E@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=agordeev@linux.ibm.com \
--cc=borntraeger@linux.ibm.com \
--cc=cassel@kernel.org \
--cc=dlemoal@kernel.org \
--cc=gor@linux.ibm.com \
--cc=hca@linux.ibm.com \
--cc=linux-ide@vger.kernel.org \
--cc=linux-s390@vger.kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.