From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id DBBB4C433FE for ; Wed, 3 Nov 2021 17:20:41 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by mail.kernel.org (Postfix) with ESMTP id BBDA861073 for ; Wed, 3 Nov 2021 17:20:41 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S230132AbhKCRXQ (ORCPT ); Wed, 3 Nov 2021 13:23:16 -0400 Received: from verein.lst.de ([213.95.11.211]:60452 "EHLO verein.lst.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229885AbhKCRXH (ORCPT ); Wed, 3 Nov 2021 13:23:07 -0400 Received: by verein.lst.de (Postfix, from userid 2407) id F39F968AA6; Wed, 3 Nov 2021 18:20:28 +0100 (CET) Date: Wed, 3 Nov 2021 18:20:28 +0100 From: Christoph Hellwig To: Tadeusz Struk Cc: Christoph Hellwig , Bart Van Assche , linux-scsi@vger.kernel.org, "James E . J . Bottomley" , "Martin K . Petersen" , linux-kernel@vger.kernel.org, stable@vger.kernel.org, Douglas Gilbert Subject: Re: [PATCH v2 1/2] scsi: scsi_ioctl: Validate command size Message-ID: <20211103172028.GA5881@lst.de> References: <20211103170659.22151-1-tadeusz.struk@linaro.org> <20211103170951.GA4896@lst.de> <62249975-7bcc-f23d-808e-8a0da1131570@linaro.org> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <62249975-7bcc-f23d-808e-8a0da1131570@linaro.org> User-Agent: Mutt/1.5.17 (2007-11-01) Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Wed, Nov 03, 2021 at 10:19:21AM -0700, Tadeusz Struk wrote: > On 11/3/21 10:09, Christoph Hellwig wrote: >>> + if (hdr->cmd_len < 6) >>> + return -EMSGSIZE; >> The checks looks good, but I'd be tempted to place it next to the >> other check on hdr->cmd_len in the caller. > > Do you mean in sg_io()? > I don't mind changing it, but putting the check here in > scsi_fill_sghdr_rq() was suggested by Douglas (cc'ed now). Ok, let's keep it that way for now.