提交 9b80cb4b 编写于 作者: M Mike Christie 提交者: James Bottomley

[SCSI] libiscsi: fix senselen calculation

Yanling Qi, noted that when the sense data length of
a check-condition is greater than 0x7f (127), senselen = (data[0] << 8)
| data[1] will become negative. It causes different kinds of panics from
GPF, spin_lock deadlock to spin_lock recursion.

We were also swapping this value on big endien machines.

This patch fixes both issues by using be16_to_cpu().
Signed-off-by: NMike Christie <michaelc@cs.wisc.edu>
Signed-off-by: NJames Bottomley <James.Bottomley@SteelEye.com>
上级 94cb3f82
...@@ -260,7 +260,7 @@ static int iscsi_scsi_cmd_rsp(struct iscsi_conn *conn, struct iscsi_hdr *hdr, ...@@ -260,7 +260,7 @@ static int iscsi_scsi_cmd_rsp(struct iscsi_conn *conn, struct iscsi_hdr *hdr,
} }
if (rhdr->cmd_status == SAM_STAT_CHECK_CONDITION) { if (rhdr->cmd_status == SAM_STAT_CHECK_CONDITION) {
int senselen; uint16_t senselen;
if (datalen < 2) { if (datalen < 2) {
invalid_datalen: invalid_datalen:
...@@ -270,12 +270,12 @@ static int iscsi_scsi_cmd_rsp(struct iscsi_conn *conn, struct iscsi_hdr *hdr, ...@@ -270,12 +270,12 @@ static int iscsi_scsi_cmd_rsp(struct iscsi_conn *conn, struct iscsi_hdr *hdr,
goto out; goto out;
} }
senselen = (data[0] << 8) | data[1]; senselen = be16_to_cpu(*(uint16_t *)data);
if (datalen < senselen) if (datalen < senselen)
goto invalid_datalen; goto invalid_datalen;
memcpy(sc->sense_buffer, data + 2, memcpy(sc->sense_buffer, data + 2,
min(senselen, SCSI_SENSE_BUFFERSIZE)); min_t(uint16_t, senselen, SCSI_SENSE_BUFFERSIZE));
debug_scsi("copied %d bytes of sense\n", debug_scsi("copied %d bytes of sense\n",
min(senselen, SCSI_SENSE_BUFFERSIZE)); min(senselen, SCSI_SENSE_BUFFERSIZE));
} }
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册