From: Niklas Cassel <cassel@kernel.org>
To: "James E.J. Bottomley" <James.Bottomley@HansenPartnership.com>,
"Martin K. Petersen" <mkp@kernel.org>
Cc: linux-scsi@vger.kernel.org, Damien Le Moal <dlemoal@kernel.org>,
John Garry <john.garry@linux.dev>,
Niklas Cassel <cassel@kernel.org>
Subject: [PATCH v11 03/13] scsi: scsi_debug: Refuse a negative physblk_exp
Date: Tue, 29 Sep 2026 10:25:00 +0200 [thread overview]
Message-ID: <20260929082456.857423-18-cassel@kernel.org> (raw)
In-Reply-To: <20260929082456.857423-15-cassel@kernel.org>
sdebug_init() refuses a physblk_exp above 15, but the parameter is a
signed int, so a negative value is accepted. The driver then shifts by
it when it builds the Block Limits VPD page, which is undefined
behaviour, and READ CAPACITY (16) reports an exponent of 15 for -1.
Refuse a negative value as well, and print it as a signed value.
Assisted-by: LLM
Fixes: ea61fca58c13 ("scsi_debug: Add support for physical block exponent and alignment")
Signed-off-by: Niklas Cassel <cassel@kernel.org>
---
Tested by loading the module with physblk_exp=-1. Before this patch it
loads, and READ CAPACITY (16) reports a logical blocks per physical
block exponent of 15. After it the module is refused with -EINVAL and
"invalid physblk_exp -1".
---
drivers/scsi/scsi_debug.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/scsi/scsi_debug.c b/drivers/scsi/scsi_debug.c
index 8e45a57ae406..f7c71fcc53fd 100644
--- a/drivers/scsi/scsi_debug.c
+++ b/drivers/scsi/scsi_debug.c
@@ -8656,8 +8656,8 @@ static int __init scsi_debug_init(void)
return -EINVAL;
}
- if (sdebug_physblk_exp > 15) {
- pr_err("invalid physblk_exp %u\n", sdebug_physblk_exp);
+ if (sdebug_physblk_exp < 0 || sdebug_physblk_exp > 15) {
+ pr_err("invalid physblk_exp %d\n", sdebug_physblk_exp);
return -EINVAL;
}
--
2.55.0
next prev parent reply other threads:[~2026-09-29 8:26 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 8:24 [PATCH v11 00/13] scsi: scsi_debug: fix zoned write validation Niklas Cassel
2026-09-29 8:24 ` [PATCH v11 01/13] scsi: scsi_debug: Refuse a zoned device with a non-zero lowest aligned LBA Niklas Cassel
2026-09-29 8:24 ` [PATCH v11 02/13] scsi: scsi_debug: Make atomic writes and ZBC emulation mutually exclusive Niklas Cassel
2026-09-29 8:25 ` Niklas Cassel [this message]
2026-09-29 13:34 ` [PATCH v11 03/13] scsi: scsi_debug: Refuse a negative physblk_exp Damien Le Moal
2026-09-29 8:25 ` [PATCH v11 04/13] scsi: scsi_debug: Take the zone metadata lock before the data lock Niklas Cassel
2026-09-29 8:25 ` [PATCH v11 05/13] scsi: scsi_debug: Evaluate scsi_debug_lbp() only once Niklas Cassel
2026-09-29 8:25 ` [PATCH v11 06/13] scsi: scsi_debug: Avoid 32-bit overflow in WRITE SCATTERED offsets Niklas Cassel
2026-09-29 13:39 ` Damien Le Moal
2026-09-29 8:25 ` [PATCH v11 07/13] scsi: scsi_debug: Report the residual of a write Niklas Cassel
2026-09-29 8:25 ` [PATCH v11 08/13] scsi: scsi_debug: Enforce physical block alignment of zoned writes Niklas Cassel
2026-09-29 8:25 ` [PATCH v11 09/13] scsi: scsi_debug: Do not write a partial physical block to a zoned device Niklas Cassel
2026-09-29 8:25 ` [PATCH v11 10/13] scsi: scsi_debug: Advance the write pointer over the data written Niklas Cassel
2026-09-29 8:25 ` [PATCH v11 11/13] scsi: scsi_debug: Refuse a short WRITE ATOMIC (16) before writing it Niklas Cassel
2026-09-29 8:25 ` [PATCH v11 12/13] scsi: scsi_debug: Map the region written by WRITE ATOMIC (16) Niklas Cassel
2026-09-29 8:25 ` [PATCH v11 13/13] scsi: scsi_debug: Validate the access parameters of " Niklas Cassel
2026-10-03 14:23 ` [PATCH v11 00/13] scsi: scsi_debug: fix zoned write validation Martin K. Petersen (Oracle)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929082456.857423-18-cassel@kernel.org \
--to=cassel@kernel.org \
--cc=James.Bottomley@HansenPartnership.com \
--cc=dlemoal@kernel.org \
--cc=john.garry@linux.dev \
--cc=linux-scsi@vger.kernel.org \
--cc=mkp@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox