mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Jia Jia <physicalmtea@gmail.com>
To: "Martin K . Petersen" <mkp@kernel.org>
Cc: Jan Engelhardt <jengelh@inai.de>, Hannes Reinecke <hare@suse.de>,
	Paolo Bonzini <pbonzini@redhat.com>,
	Akinobu Mita <akinobu.mita@gmail.com>,
	James Bottomley <James.Bottomley@suse.de>,
	linux-scsi@vger.kernel.org, target-devel@vger.kernel.org,
	linux-kernel@vger.kernel.org, Jia Jia <physicalmtea@gmail.com>
Subject: [PATCH 0/8] scsi: target: keep command bytes inside the sg
Date: Tue,  6 Oct 2026 17:33:30 +0800	[thread overview]
Message-ID: <20261006093338.27342-1-physicalmtea@gmail.com> (raw)

Eight fixes for target core reading or writing past an sg.  Patches 4
through 6 and patch 8 share the DIF sg walk and apply in order.  The
others stand alone.  vhost-scsi keeps one sg inside one page, so those
bytes land on the next physical page.  The commands reach the host
through a guest virtqueue.

Patch 1 takes the COMPARE AND WRITE write half from its own sg entries.
Adding the compare length to the first entry's offset loses the sg
boundary when the two halves are split across pages.  The replacement
table is released with sg_free_table().

Patch 2 keeps each REPORT REFERRALS LBA store inside the data-in
buffer.  The existing data_length checks cover one-byte fields, not the
eight-byte LBA.

Patch 3 rejects a SET TARGET PORT GROUPS list that ends on a partial
four-byte descriptor.

Patch 4 copies an 8 byte protection tuple across sg entries in
sbc_dif_generate().  A tuple that starts at the end of one entry is
written into the next entry as well.

Patch 5 does the same read in sbc_dif_verify().  A tuple that runs off
the end of the protection list fails the command.  The generate change
does not cover this function.

Patch 6 limits the block CRC in both functions to the bytes each data
sg actually holds.

Patch 7 reads the pscsi MODE SENSE write-protect byte and the tape
MODE SELECT block descriptor from the whole data buffer.  A short
buffer is left unchanged.

Patch 8 makes sbc_dif_verify() advance the data cursor across every sg
entry of a logical block whose application tag is 0xffff.  The cursor
uses the same kmap_local_page() calls as the CRC walk.

Jia Jia (8):
  scsi: target: take COMPARE AND WRITE data from the write half
  scsi: target: keep REPORT REFERRALS stores inside the buffer
  scsi: target: reject a short SET TARGET PORT GROUPS list
  scsi: target: copy a DIF insert tuple across prot sgs
  scsi: target: copy a DIF verify tuple across prot sgs
  scsi: target: limit DIF block CRC to each data sg
  scsi: target: keep pscsi mode bytes inside the data sgs
  scsi: target: skip an escaped DIF block inside the data sg

 drivers/target/target_core_alua.c      |  29 +++++++---
 drivers/target/target_core_pscsi.c     |  98 +++++++++++++++++++++++---------
 drivers/target/target_core_sbc.c       | 474 ++++++++++++++++++++++++++++---------
 drivers/target/target_core_transport.c |  11 +++-
 4 files changed, 439 insertions(+), 173 deletions(-)

-- 
2.43.0

             reply	other threads:[~2026-10-06  9:34 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-06  9:33 Jia Jia [this message]
2026-10-06  9:33 ` [PATCH 1/8] scsi: target: take COMPARE AND WRITE data from the write half Jia Jia
2026-10-06  9:33 ` [PATCH 2/8] scsi: target: keep REPORT REFERRALS stores inside the buffer Jia Jia
2026-10-06  9:33 ` [PATCH 3/8] scsi: target: reject a short SET TARGET PORT GROUPS list Jia Jia
2026-10-06  9:33 ` [PATCH 4/8] scsi: target: copy a DIF insert tuple across prot sgs Jia Jia
2026-10-06  9:33 ` [PATCH 5/8] scsi: target: copy a DIF verify " Jia Jia
2026-10-06  9:33 ` [PATCH 6/8] scsi: target: limit DIF block CRC to each data sg Jia Jia
2026-10-06  9:33 ` [PATCH 7/8] scsi: target: keep pscsi mode bytes inside the data sgs Jia Jia
2026-10-06  9:33 ` [PATCH 8/8] scsi: target: skip an escaped DIF block inside the data sg Jia Jia

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261006093338.27342-1-physicalmtea@gmail.com \
    --to=physicalmtea@gmail.com \
    --cc=James.Bottomley@suse.de \
    --cc=akinobu.mita@gmail.com \
    --cc=hare@suse.de \
    --cc=jengelh@inai.de \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-scsi@vger.kernel.org \
    --cc=mkp@kernel.org \
    --cc=pbonzini@redhat.com \
    --cc=target-devel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®