Skip to content

Commit 3417c1b

Browse files
committed
ses: Fix problems with simple enclosures
Simple enclosure implementations (mostly USB) are allowed to return only page 8 to every diagnostic query. That really confuses our implementation because we assume the return is the page we asked for and end up doing incorrect offsets based on bogus information leading to accesses outside of allocated ranges. Fix that by checking the page code of the return and giving an error if it isn't the one we asked for. This should fix reported bugs with USB storage by simply refusing to attach to enclosures that behave like this. It's also good defensive practise now that we're starting to see more USB enclosures. Reported-by: Andrea Gelmini <andrea.gelmini@gelma.net> Cc: stable@vger.kernel.org Reviewed-by: Ewan D. Milne <emilne@redhat.com> Reviewed-by: Tomas Henzl <thenzl@redhat.com> Signed-off-by: James Bottomley <James.Bottomley@HansenPartnership.com>
1 parent 527e931 commit 3417c1b

1 file changed

Lines changed: 19 additions & 1 deletion

File tree

drivers/scsi/ses.c

Lines changed: 19 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -84,6 +84,7 @@ static void init_device_slot_control(unsigned char *dest_desc,
8484
static int ses_recv_diag(struct scsi_device *sdev, int page_code,
8585
void *buf, int bufflen)
8686
{
87+
int ret;
8788
unsigned char cmd[] = {
8889
RECEIVE_DIAGNOSTIC,
8990
1, /* Set PCV bit */
@@ -92,9 +93,26 @@ static int ses_recv_diag(struct scsi_device *sdev, int page_code,
9293
bufflen & 0xff,
9394
0
9495
};
96+
unsigned char recv_page_code;
9597

96-
return scsi_execute_req(sdev, cmd, DMA_FROM_DEVICE, buf, bufflen,
98+
ret = scsi_execute_req(sdev, cmd, DMA_FROM_DEVICE, buf, bufflen,
9799
NULL, SES_TIMEOUT, SES_RETRIES, NULL);
100+
if (unlikely(!ret))
101+
return ret;
102+
103+
recv_page_code = ((unsigned char *)buf)[0];
104+
105+
if (likely(recv_page_code == page_code))
106+
return ret;
107+
108+
/* successful diagnostic but wrong page code. This happens to some
109+
* USB devices, just print a message and pretend there was an error */
110+
111+
sdev_printk(KERN_ERR, sdev,
112+
"Wrong diagnostic page; asked for %d got %u\n",
113+
page_code, recv_page_code);
114+
115+
return -EINVAL;
98116
}
99117

100118
static int ses_send_diag(struct scsi_device *sdev, int page_code,

0 commit comments

Comments
 (0)