From: Jia Jia <physicalmtea@gmail.com>
To: "Martin K . Petersen" <mkp@kernel.org>
Cc: Jan Engelhardt <jengelh@inai.de>, Hannes Reinecke <hare@suse.de>,
Paolo Bonzini <pbonzini@redhat.com>,
Akinobu Mita <akinobu.mita@gmail.com>,
James Bottomley <James.Bottomley@suse.de>,
linux-scsi@vger.kernel.org, target-devel@vger.kernel.org,
linux-kernel@vger.kernel.org, Jia Jia <physicalmtea@gmail.com>
Subject: [PATCH 1/8] scsi: target: take COMPARE AND WRITE data from the write half
Date: Tue, 6 Oct 2026 17:33:31 +0800 [thread overview]
Message-ID: <20261006093338.27342-2-physicalmtea@gmail.com> (raw)
In-Reply-To: <20261006093338.27342-1-physicalmtea@gmail.com>
compare_and_write_callback() builds the write sgl as
sg->offset + block_size on the first data sg. That offset is the end
of the compare buffer, not the write buffer.
vhost-scsi keeps each descriptor inside one page. A 512-byte compare
buffer placed at the end of a page makes offset + block_size equal to
PAGE_SIZE, and the write then uses the next physical page. The kernel
subsequently reads 512 bytes from that page. If the adjacent memory
region happens to be a freed slab object, KASAN reports:
BUG: KASAN: slab-use-after-free in copy_folio_from_iter_atomic
Read of size 512
compare_and_write_callback
__target_execute_cmd
sbc_execute_rw
fd_execute_rw
fd_do_rw
vfs_iter_write
copy_folio_from_iter_atomic
Skip the compare bytes and describe only the sg entries that hold the
write half. A write that crosses an sg boundary stays in those entries
instead of being forced into one slot.
Free that table with sg_free_table(). sg_alloc_table() chains once
the write half has more entries than fit in one page, and kfree() of
cmd->t_data_sg would drop only the first allocation.
Fixes: d94e5a61357a ("target: fix COMPARE_AND_WRITE non zero SGL offset data corruption")
Signed-off-by: Jia Jia <physicalmtea@gmail.com>
---
drivers/target/target_core_sbc.c | 100 +++++++++++++++++--------
drivers/target/target_core_transport.c | 11 ++-
2 files changed, 80 insertions(+), 31 deletions(-)
diff --git a/drivers/target/target_core_sbc.c b/drivers/target/target_core_sbc.c
index 21f5cb86d70c..adef903652ac 100644
--- a/drivers/target/target_core_sbc.c
+++ b/drivers/target/target_core_sbc.c
@@ -433,19 +433,74 @@ compare_and_write_do_cmp(struct scatterlist *read_sgl, unsigned int read_nents,
return ret;
}
+/*
+ * Data-out is compare bytes followed by write bytes. Take the write
+ * half from whatever sg entries hold it. Do not add block_size onto
+ * the first sg offset: that page may end before the write half.
+ */
+static int sbc_caw_build_write_sg(struct sg_table *tbl,
+ struct scatterlist *data_sg,
+ unsigned int data_nents, unsigned int skip,
+ unsigned int len)
+{
+ struct scatterlist *sg, *out;
+ unsigned int nents = 0, left = len, left_skip = skip;
+ unsigned int avail, chunk;
+ int i;
+
+ for_each_sg(data_sg, sg, data_nents, i) {
+ if (!sg->length)
+ continue;
+ if (!left)
+ break;
+ if (left_skip >= sg->length) {
+ left_skip -= sg->length;
+ continue;
+ }
+ avail = sg->length - left_skip;
+ chunk = min(left, avail);
+ nents++;
+ left -= chunk;
+ left_skip = 0;
+ }
+ if (!nents || left)
+ return -EINVAL;
+
+ if (sg_alloc_table(tbl, nents, GFP_KERNEL))
+ return -ENOMEM;
+
+ left = len;
+ left_skip = skip;
+ out = tbl->sgl;
+ for_each_sg(data_sg, sg, data_nents, i) {
+ if (!sg->length)
+ continue;
+ if (!left)
+ break;
+ if (left_skip >= sg->length) {
+ left_skip -= sg->length;
+ continue;
+ }
+ avail = sg->length - left_skip;
+ chunk = min(left, avail);
+ sg_set_page(out, sg_page(sg), chunk, sg->offset + left_skip);
+ left -= chunk;
+ left_skip = 0;
+ out = sg_next(out);
+ }
+ return 0;
+}
+
static sense_reason_t compare_and_write_callback(struct se_cmd *cmd, bool success,
int *post_ret)
{
struct se_device *dev = cmd->se_dev;
struct sg_table write_tbl = { };
struct scatterlist *write_sg;
- struct sg_mapping_iter m;
- unsigned int len;
- unsigned int block_size = dev->dev_attrib.block_size;
- unsigned int compare_len = (cmd->t_task_nolb * block_size);
+ unsigned int compare_len = (cmd->t_task_nolb * dev->dev_attrib.block_size);
unsigned int miscmp_off = 0;
sense_reason_t ret = TCM_NO_SENSE;
- int i;
+ int rc;
if (!success) {
/*
@@ -499,34 +554,19 @@ static sense_reason_t compare_and_write_callback(struct se_cmd *cmd, bool succes
} else if (ret)
goto out;
- if (sg_alloc_table(&write_tbl, cmd->t_data_nents, GFP_KERNEL) < 0) {
- pr_err("Unable to allocate compare_and_write sg\n");
- ret = TCM_OUT_OF_RESOURCES;
+ rc = sbc_caw_build_write_sg(&write_tbl, cmd->t_data_sg,
+ cmd->t_data_nents, compare_len,
+ compare_len);
+ if (rc) {
+ pr_err("Unable to build compare_and_write sg\n");
+ if (rc == -ENOMEM)
+ ret = TCM_OUT_OF_RESOURCES;
+ else
+ ret = TCM_LOGICAL_UNIT_COMMUNICATION_FAILURE;
goto out;
}
write_sg = write_tbl.sgl;
- i = 0;
- len = compare_len;
- sg_miter_start(&m, cmd->t_data_sg, cmd->t_data_nents, SG_MITER_TO_SG);
- /*
- * Currently assumes NoLB=1 and SGLs are PAGE_SIZE..
- */
- while (len) {
- sg_miter_next(&m);
-
- if (block_size < PAGE_SIZE) {
- sg_set_page(&write_sg[i], m.page, block_size,
- m.piter.sg->offset + block_size);
- } else {
- sg_miter_next(&m);
- sg_set_page(&write_sg[i], m.page, block_size,
- m.piter.sg->offset);
- }
- len -= block_size;
- i++;
- }
- sg_miter_stop(&m);
/*
* Save the original SGL + nents values before updating to new
* assignments, to be released in transport_free_pages() ->
@@ -535,7 +575,7 @@ static sense_reason_t compare_and_write_callback(struct se_cmd *cmd, bool succes
cmd->t_data_sg_orig = cmd->t_data_sg;
cmd->t_data_sg = write_sg;
cmd->t_data_nents_orig = cmd->t_data_nents;
- cmd->t_data_nents = 1;
+ cmd->t_data_nents = write_tbl.nents;
cmd->sam_task_attr = TCM_HEAD_TAG;
cmd->transport_complete_callback = compare_and_write_post;
diff --git a/drivers/target/target_core_transport.c b/drivers/target/target_core_transport.c
index dcfe94594916..3cae5ed67d41 100644
--- a/drivers/target/target_core_transport.c
+++ b/drivers/target/target_core_transport.c
@@ -22,6 +22,7 @@
#include <linux/module.h>
#include <linux/ratelimit.h>
#include <linux/vmalloc.h>
+#include <linux/scatterlist.h>
#include <linux/unaligned.h>
#include <net/sock.h>
#include <net/tcp.h>
@@ -2724,10 +2725,18 @@ static inline void transport_reset_sgl_orig(struct se_cmd *cmd)
* Check for saved t_data_sg that may be used for COMPARE_AND_WRITE
* emulation, and free + reset pointers if necessary..
*/
+ struct sg_table table = { };
+
if (!cmd->t_data_sg_orig)
return;
- kfree(cmd->t_data_sg);
+ /*
+ * compare_and_write_callback() built this with sg_alloc_table().
+ * Above SG_MAX_SINGLE_ALLOC the tail is a separate allocation.
+ */
+ table.sgl = cmd->t_data_sg;
+ table.orig_nents = cmd->t_data_nents;
+ sg_free_table(&table);
cmd->t_data_sg = cmd->t_data_sg_orig;
cmd->t_data_sg_orig = NULL;
cmd->t_data_nents = cmd->t_data_nents_orig;
--
2.34.1
next prev parent reply other threads:[~2026-10-06 9:34 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-06 9:33 [PATCH 0/8] scsi: target: keep command bytes inside the sg Jia Jia
2026-10-06 9:33 ` Jia Jia [this message]
2026-10-06 9:33 ` [PATCH 2/8] scsi: target: keep REPORT REFERRALS stores inside the buffer Jia Jia
2026-10-06 9:33 ` [PATCH 3/8] scsi: target: reject a short SET TARGET PORT GROUPS list Jia Jia
2026-10-06 9:33 ` [PATCH 4/8] scsi: target: copy a DIF insert tuple across prot sgs Jia Jia
2026-10-06 9:33 ` [PATCH 5/8] scsi: target: copy a DIF verify " Jia Jia
2026-10-06 9:33 ` [PATCH 6/8] scsi: target: limit DIF block CRC to each data sg Jia Jia
2026-10-06 9:33 ` [PATCH 7/8] scsi: target: keep pscsi mode bytes inside the data sgs Jia Jia
2026-10-06 9:33 ` [PATCH 8/8] scsi: target: skip an escaped DIF block inside the data sg Jia Jia
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261006093338.27342-2-physicalmtea@gmail.com \
--to=physicalmtea@gmail.com \
--cc=James.Bottomley@suse.de \
--cc=akinobu.mita@gmail.com \
--cc=hare@suse.de \
--cc=jengelh@inai.de \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=mkp@kernel.org \
--cc=pbonzini@redhat.com \
--cc=target-devel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®