From: sashiko-bot@kernel.org
To: "Ajaykumar Rajappa" <ajaykr@linux.ibm.com>
Cc: linux-s390@vger.kernel.org,
"Alexander Gordeev" <agordeev@linux.ibm.com>,
"Christian Borntraeger" <borntraeger@linux.ibm.com>,
"Heiko Carstens" <hca@linux.ibm.com>,
"Vasily Gorbik" <gor@linux.ibm.com>
Subject: Re: [PATCH v5] zfcp: Fix integer underflow in status read buffer payload length
Date: Thu, 08 Oct 2026 10:08:03 +0000 [thread overview]
Message-ID: <sashiko-outbox-163996@kernel.org> (raw)
In-Reply-To: <20261008095757.1813357-1-ajaykr@linux.ibm.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Low] zfcp: Build failure due to missing 'level' argument in zfcp_dbf_pl_write() call
--
commit cd0f8c110960ca9697ab6d9c8ecf78b8b828c640
Author: Ajaykumar Rajappa <ajaykr@linux.ibm.com>
zfcp: Fix integer underflow in status read buffer payload length
This commit fixes an integer underflow in status read buffer length
calculations by validating the payload access against the payload offset.
It prevents payload reads when the buffer length does not reach the payload
area, while maintaining existing tracing formatting.
> diff --git a/drivers/s390/scsi/zfcp_dbf.c b/drivers/s390/scsi/zfcp_dbf.c
> index 81fb8af408e9c..c5501eae99772 100644
> --- a/drivers/s390/scsi/zfcp_dbf.c
> +++ b/drivers/s390/scsi/zfcp_dbf.c
[ ... ]
> @@ -253,13 +254,17 @@ void zfcp_dbf_hba_fsf_uss(char *tag, struct zfcp_fsf_req *req)
> rec->u.uss.s_id = ntoh24(srb->s_id);
> memcpy(&rec->u.uss.res4, &srb->res4, sizeof(rec->u.uss.res4));
>
> - /* status read buffer payload length */
> - rec->pl_len = (!srb->length) ? 0 : srb->length -
> - offsetof(struct fsf_status_read_buffer, payload);
> + /* Unconditionally store value-shifted SRB length: pl_len is a bijective
> + * map of srb->length (pl_len + pay_offset == srb->length). A bogus
> + * srb->length < pay_offset wraps to a large non-zero pl_len, which is
> + * unambiguously distinguishable from pl_len == 0(genuine empty payload)
> + */
> + rec->pl_len = (u16)(srb->length - pay_offset);
>
> - if (rec->pl_len)
> + /* Only access payload bytes when srb->length actually covers them. */
> + if (srb->length > pay_offset)
> zfcp_dbf_pl_write(dbf, srb->payload.data, rec->pl_len,
> - "fsf_uss", req->req_id, ZFCP_DBF_PAY_LEVEL);
> + "fsf_uss", req->req_id);
[Severity: Low]
Does this change break the build? The function zfcp_dbf_pl_write() is
defined as requiring 6 arguments:
static inline
void zfcp_dbf_pl_write(struct zfcp_dbf *dbf, void *data, u16 length,
char *area, u64 req_id, int level)
However, the modified call above drops the 6th argument
(ZFCP_DBF_PAY_LEVEL), which will result in a 'too few arguments to function'
compilation error.
> log:
> debug_event(dbf->hba, level, rec, sizeof(*rec));
> spin_unlock_irqrestore(&dbf->hba_lock, flags);
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261008095757.1813357-1-ajaykr@linux.ibm.com?part=1
next prev parent reply other threads:[~2026-10-08 10:08 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 9:57 [PATCH v5] zfcp: Fix integer underflow in status read buffer payload length Ajaykumar Rajappa
2026-10-08 10:08 ` sashiko-bot [this message]
-- strict thread matches above, loose matches on Subject: below --
2026-10-08 10:17 Ajaykumar Rajappa
2026-10-08 10:28 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=sashiko-outbox-163996@kernel.org \
--to=sashiko-bot@kernel.org \
--cc=agordeev@linux.ibm.com \
--cc=ajaykr@linux.ibm.com \
--cc=borntraeger@linux.ibm.com \
--cc=gor@linux.ibm.com \
--cc=hca@linux.ibm.com \
--cc=linux-s390@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox