From: Stefan Richter <stefanr@s5r6.in-berlin.de>
To: Chris Boot <bootc@bootc.net>
Cc: linux1394-devel@lists.sourceforge.net,
linux-kernel@vger.kernel.org, linux-scsi@vger.kernel.org
Subject: Re: [PATCH 1/3] firewire-sbp2: Take into account Unit_Unique_ID
Date: Sat, 11 Feb 2012 14:06:05 +0100 [thread overview]
Message-ID: <20120211140605.0501e039@stein> (raw)
In-Reply-To: <4F365E75.2030302@bootc.net>
On Feb 11 Chris Boot wrote:
> On 11/02/2012 11:12, Stefan Richter wrote:
> > On Feb 10 Chris Boot wrote:
> >> + if ((leaf[0]& 0xffff0000) != 0x00020000)
> >> + return -EINVAL;
> >
> > This could be relaxed to "if (leaf[0]< 0x00020000)", but the stricter
> > check is fine too.
>
> Well the standard does say the length must be exactly 2 rather than just
> defining it a leaf node that contains an EUI-64. But I did not realise
> various firmware gets things quite so wrong sometimes...
I expect firmware writers to get length == 2 right, but we need to
protect ourselves against very dumb mistakes or malicious input of course.
Whether the length field is 2 or not could be totally ignored by
firewire-sbp2 just like we ignore the block CRC, except that we need to
catch the corner case of a bogus Config ROM where the descriptor leaf
overlaps the 1 kB ROM size limit, or that it is placed right at the end of
the ROM but is shorter than 2 quadlets.
core-device.c::read_config_rom() already catches the cases of blocks
overlapping the end of the ROM but merely handles them by overwriting the
block length by 0. Higher-level code which reads a descriptor block or
directory block in the Config ROM cache is required to respect the length
field of the block. We could simplify this for upper layer code by
overwriting the pointer to the block instead of the header of the block,
like it is done already with pointers to blocks outside of the ROM.
Anyway; if the length of an alleged EUI-64 descriptor leaf is greater than
2, I agree that there is little reason to look at the rest of the
descriptor; it would likely contain garbage too.
--
Stefan Richter
-=====-===-- --=- -=-==
http://arcgraph.de/sr/
next prev parent reply other threads:[~2012-02-11 13:06 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <EE1CAC85-DF0C-4C21-B2BD-446C481C938F@bootc.net>
2012-02-10 13:41 ` [PATCH 0/3] firewire-sbp2: Various fixes Chris Boot
2012-02-10 13:41 ` [PATCH 1/3] firewire-sbp2: Take into account Unit_Unique_ID Chris Boot
2012-02-11 11:12 ` Stefan Richter
2012-02-11 12:26 ` Chris Boot
2012-02-11 13:06 ` Stefan Richter [this message]
2012-02-10 13:41 ` [PATCH 2/3] firewire-sbp2: Ignore SBP-2 targets on the local node Chris Boot
2012-02-11 11:28 ` Stefan Richter
2012-02-11 12:16 ` Clemens Ladisch
2012-02-11 12:31 ` Chris Boot
2012-02-11 15:46 ` Clemens Ladisch
2012-02-11 15:49 ` Chris Boot
2012-02-11 11:56 ` Stefan Richter
2012-02-11 12:32 ` Chris Boot
2012-02-10 13:41 ` [PATCH 3/3] firewire-sbp2: Fix SCSI sense data mangling Chris Boot
2012-02-15 14:59 ` [PATCH v2 0/3] firewire-sbp2: Various fixes Chris Boot
2012-02-15 14:59 ` [PATCH v2 1/3] firewire-sbp2: Take into account Unit_Unique_ID Chris Boot
2012-02-15 14:59 ` [PATCH v2 2/3] firewire-sbp2: Ignore SBP-2 targets on the local node Chris Boot
2012-02-15 14:59 ` [PATCH v2 3/3] firewire-sbp2: Fix SCSI sense data mangling Chris Boot
2012-02-22 22:17 ` [PATCH v2 0/3] firewire-sbp2: Various fixes Stefan Richter
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20120211140605.0501e039@stein \
--to=stefanr@s5r6.in-berlin.de \
--cc=bootc@bootc.net \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=linux1394-devel@lists.sourceforge.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox