From: John Garry <john.garry@linux.dev>
To: Niklas Cassel <cassel@kernel.org>,
"James E.J. Bottomley" <James.Bottomley@HansenPartnership.com>,
"Martin K. Petersen" <mkp@kernel.org>
Cc: linux-scsi@vger.kernel.org, Damien Le Moal <dlemoal@kernel.org>
Subject: Re: [PATCH v4 10/10] scsi: scsi_debug: Validate the access parameters of WRITE ATOMIC (16)
Date: Fri, 18 Sep 2026 08:33:07 +0100 [thread overview]
Message-ID: <d9971f1c-6e8c-4e6b-889e-bb8d6449b451@linux.dev> (raw)
In-Reply-To: <20260918062910.1709791-22-cassel@kernel.org>
On 9/18/26 07:29, Niklas Cassel wrote:
> resp_atomic_write() validates the fields that are specific to an atomic
> write, the alignment and granularity of the transfer, the atomic
> boundary and the maximum transfer length, but it never validates the
> range that the command addresses. Every other command that writes user
> data calls check_device_access_params() first, which rejects a transfer
> that ends beyond the capacity of the device, one whose length exceeds
> the size of the store, and any write to a write protected device.
>
> As a consequence a WRITE ATOMIC (16) past the end of the device is not
> terminated with LOGICAL BLOCK ADDRESS OUT OF RANGE. do_device_access()
> reduces the LBA modulo the size of the store, so the command writes
> somewhere else on the medium instead. A WRITE ATOMIC (16) also writes to
> a device whose wp module parameter is set, which every other write
> refuses with DATA PROTECT.
>
> Call check_device_access_params(). The zone checks that it ends with are
> unreachable, as atomic writes and ZBC emulation are mutually exclusive.
These are quite verbose commit messages ... LLM-generated, by chance?
>
> Assisted-by: LLM
> Fixes: 84f3a3c01d70 ("scsi: scsi_debug: Atomic write support")
> Signed-off-by: Niklas Cassel <cassel@kernel.org>
Reviewed-by: John Garry <john.garry@linux.dev>
> ---
> Tested with:
>
> modprobe scsi_debug sector_size=512 physblk_exp=3 dev_size_mb=128 \
> atomic_wr=1
>
> The device has a capacity of 262144 logical blocks. A WRITE ATOMIC (16)
> of eight blocks at LBA 262140 is now terminated with ILLEGAL REQUEST /
> LOGICAL BLOCK ADDRESS OUT OF RANGE; before this patch it completed with
> GOOD status, having written eight blocks at LBA 0 instead.
>
> With the wp module parameter set to 1, a WRITE ATOMIC (16) is now
> terminated with DATA PROTECT / LOGICAL UNIT SOFTWARE WRITE PROTECTED,
> which is what an ordinary WRITE(16) has always returned; before this
> patch it completed with GOOD status and wrote the data.
> ---
> drivers/scsi/scsi_debug.c | 4 ++++
> 1 file changed, 4 insertions(+)
>
> diff --git a/drivers/scsi/scsi_debug.c b/drivers/scsi/scsi_debug.c
> index 5243401701f9..5ae1241e4d8b 100644
> --- a/drivers/scsi/scsi_debug.c
> +++ b/drivers/scsi/scsi_debug.c
> @@ -6246,6 +6246,10 @@ static int resp_atomic_write(struct scsi_cmnd *scp,
> }
> }
>
> + ret = check_device_access_params(scp, lba, len, true);
> + if (ret)
> + return ret;
> +
> if (lbp) {
> sdeb_meta_write_lock(sip);
> meta_data_locked = true;
next prev parent reply other threads:[~2026-09-18 7:33 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-18 6:29 [PATCH v4 00/10] scsi: scsi_debug: fix zoned write validation Niklas Cassel
2026-09-18 6:29 ` [PATCH v4 01/10] scsi: scsi_debug: Refuse a zoned device with a non-zero lowest aligned LBA Niklas Cassel
2026-09-18 9:26 ` Damien Le Moal
2026-09-18 6:29 ` [PATCH v4 02/10] scsi: scsi_debug: Make atomic writes and ZBC emulation mutually exclusive Niklas Cassel
2026-09-18 7:21 ` John Garry
2026-09-18 9:26 ` Damien Le Moal
2026-09-18 6:29 ` [PATCH v4 03/10] scsi: scsi_debug: Take the zone metadata lock before the data lock Niklas Cassel
2026-09-18 9:28 ` Damien Le Moal
2026-09-18 6:29 ` [PATCH v4 04/10] scsi: scsi_debug: Evaluate scsi_debug_lbp() only once Niklas Cassel
2026-09-18 9:29 ` Damien Le Moal
2026-09-18 6:29 ` [PATCH v4 05/10] scsi: scsi_debug: Report the residual of a write Niklas Cassel
2026-09-18 6:29 ` [PATCH v4 06/10] scsi: scsi_debug: Enforce physical block alignment of zoned writes Niklas Cassel
2026-09-18 6:29 ` [PATCH v4 07/10] scsi: scsi_debug: Do not write a partial physical block to a zoned device Niklas Cassel
2026-09-18 9:31 ` Damien Le Moal
2026-09-18 10:25 ` Niklas Cassel
2026-09-18 6:29 ` [PATCH v4 08/10] scsi: scsi_debug: Advance the write pointer over the data written Niklas Cassel
2026-09-18 6:29 ` [PATCH v4 09/10] scsi: scsi_debug: Map the region written by WRITE ATOMIC (16) Niklas Cassel
2026-09-18 7:29 ` John Garry
2026-09-18 8:09 ` Niklas Cassel
2026-09-18 6:29 ` [PATCH v4 10/10] scsi: scsi_debug: Validate the access parameters of " Niklas Cassel
2026-09-18 7:33 ` John Garry [this message]
2026-09-18 7:53 ` Niklas Cassel
2026-09-18 8:19 ` John Garry
2026-09-18 8:55 ` Niklas Cassel
2026-09-18 9:32 ` Damien Le Moal
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=d9971f1c-6e8c-4e6b-889e-bb8d6449b451@linux.dev \
--to=john.garry@linux.dev \
--cc=James.Bottomley@HansenPartnership.com \
--cc=cassel@kernel.org \
--cc=dlemoal@kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=mkp@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox