From: Niklas Cassel <cassel@kernel.org>
To: "James E.J. Bottomley" <James.Bottomley@HansenPartnership.com>,
"Martin K. Petersen" <mkp@kernel.org>
Cc: linux-scsi@vger.kernel.org, Damien Le Moal <dlemoal@kernel.org>,
John Garry <john.garry@linux.dev>,
Niklas Cassel <cassel@kernel.org>
Subject: [PATCH v8 11/11] scsi: scsi_debug: Validate the access parameters of WRITE ATOMIC (16)
Date: Sat, 26 Sep 2026 20:17:14 +0200 [thread overview]
Message-ID: <20260926181702.508975-24-cassel@kernel.org> (raw)
In-Reply-To: <20260926181702.508975-13-cassel@kernel.org>
resp_atomic_write() validates the fields that are specific to an atomic
write, but never the range that the command addresses. Every other
command that writes user data calls check_device_access_params() first,
which rejects a transfer that ends beyond the capacity of the device,
one whose length exceeds the size of the store, and any write to a write
protected device.
Call check_device_access_params(). The zone checks that it ends with are
unreachable, as atomic writes and ZBC emulation are mutually exclusive.
Assisted-by: LLM
Fixes: 84f3a3c01d70 ("scsi: scsi_debug: Atomic write support")
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Reviewed-by: John Garry <john.garry@linux.dev>
Signed-off-by: Niklas Cassel <cassel@kernel.org>
---
Tested with:
modprobe scsi_debug sector_size=512 physblk_exp=3 dev_size_mb=128 \
atomic_wr=1
The device has a capacity of 262144 logical blocks. A WRITE ATOMIC (16)
of eight blocks at LBA 262140 is now terminated with ILLEGAL REQUEST /
LOGICAL BLOCK ADDRESS OUT OF RANGE; before this patch it completed with
GOOD status, having written eight blocks at LBA 0 instead.
With the wp module parameter set to 1, a WRITE ATOMIC (16) is now
terminated with DATA PROTECT / LOGICAL UNIT SOFTWARE WRITE PROTECTED,
which is what an ordinary WRITE(16) has always returned; before this
patch it completed with GOOD status and wrote the data.
---
drivers/scsi/scsi_debug.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/scsi/scsi_debug.c b/drivers/scsi/scsi_debug.c
index 0ae0a6ac3baa..ef2daef1b599 100644
--- a/drivers/scsi/scsi_debug.c
+++ b/drivers/scsi/scsi_debug.c
@@ -6253,6 +6253,10 @@ static int resp_atomic_write(struct scsi_cmnd *scp,
}
}
+ ret = check_device_access_params(scp, lba, len, true);
+ if (ret)
+ return ret;
+
/* Short atomic writes are not allowed. */
if (scsi_bufflen(scp) < len * sdebug_sector_size)
return DID_ERROR << 16;
--
2.55.0
prev parent reply other threads:[~2026-09-26 18:17 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-26 18:17 [PATCH v8 00/11] scsi: scsi_debug: fix zoned write validation Niklas Cassel
2026-09-26 18:17 ` [PATCH v8 01/11] scsi: scsi_debug: Refuse a zoned device with a non-zero lowest aligned LBA Niklas Cassel
2026-09-26 18:17 ` [PATCH v8 02/11] scsi: scsi_debug: Make atomic writes and ZBC emulation mutually exclusive Niklas Cassel
2026-09-26 18:17 ` [PATCH v8 03/11] scsi: scsi_debug: Take the zone metadata lock before the data lock Niklas Cassel
2026-09-26 18:17 ` [PATCH v8 04/11] scsi: scsi_debug: Evaluate scsi_debug_lbp() only once Niklas Cassel
2026-09-26 18:17 ` [PATCH v8 05/11] scsi: scsi_debug: Report the residual of a write Niklas Cassel
2026-09-26 18:29 ` sashiko-bot
2026-09-26 18:17 ` [PATCH v8 06/11] scsi: scsi_debug: Enforce physical block alignment of zoned writes Niklas Cassel
2026-09-26 18:17 ` [PATCH v8 07/11] scsi: scsi_debug: Do not write a partial physical block to a zoned device Niklas Cassel
2026-09-26 18:17 ` [PATCH v8 08/11] scsi: scsi_debug: Advance the write pointer over the data written Niklas Cassel
2026-09-26 18:17 ` [PATCH v8 09/11] scsi: scsi_debug: Refuse a short WRITE ATOMIC (16) before writing it Niklas Cassel
2026-09-26 18:17 ` [PATCH v8 10/11] scsi: scsi_debug: Map the region written by WRITE ATOMIC (16) Niklas Cassel
2026-09-26 18:17 ` Niklas Cassel [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260926181702.508975-24-cassel@kernel.org \
--to=cassel@kernel.org \
--cc=James.Bottomley@HansenPartnership.com \
--cc=dlemoal@kernel.org \
--cc=john.garry@linux.dev \
--cc=linux-scsi@vger.kernel.org \
--cc=mkp@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox