2017-09-13 08:46:27

by Nikola Pajkovsky

[permalink] [raw]
Subject: [PATCH] scsi: aacraid: error: testing array offset 'bus' after use

Fix possible indexing array of bound for &aac->hba_map[bus][cid],
where bus and cid boundary check happens later.

Fixes: 0d643ff3c353 ("scsi: aacraid: use aac_tmf_callback for reset fib")
Signed-off-by: Nikola Pajkovsky <[email protected]>
---
drivers/scsi/aacraid/linit.c | 20 ++++++++++++--------
1 file changed, 12 insertions(+), 8 deletions(-)

diff --git a/drivers/scsi/aacraid/linit.c b/drivers/scsi/aacraid/linit.c
index 87cc4a93e637..62beb2596466 100644
--- a/drivers/scsi/aacraid/linit.c
+++ b/drivers/scsi/aacraid/linit.c
@@ -906,12 +906,14 @@ static int aac_eh_dev_reset(struct scsi_cmnd *cmd)

bus = aac_logical_to_phys(scmd_channel(cmd));
cid = scmd_id(cmd);
- info = &aac->hba_map[bus][cid];
- if (bus >= AAC_MAX_BUSES || cid >= AAC_MAX_TARGETS ||
- info->devtype != AAC_DEVTYPE_NATIVE_RAW)
+
+ if (bus >= AAC_MAX_BUSES || cid >= AAC_MAX_TARGETS)
return FAILED;

- if (info->reset_state > 0)
+ info = &aac->hba_map[bus][cid];
+
+ if (info->devtype != AAC_DEVTYPE_NATIVE_RAW &&
+ info->reset_state > 0)
return FAILED;

pr_err("%s: Host adapter reset request. SCSI hang ?\n",
@@ -962,12 +964,14 @@ static int aac_eh_target_reset(struct scsi_cmnd *cmd)

bus = aac_logical_to_phys(scmd_channel(cmd));
cid = scmd_id(cmd);
- info = &aac->hba_map[bus][cid];
- if (bus >= AAC_MAX_BUSES || cid >= AAC_MAX_TARGETS ||
- info->devtype != AAC_DEVTYPE_NATIVE_RAW)
+
+ if (bus >= AAC_MAX_BUSES || cid >= AAC_MAX_TARGETS)
return FAILED;

- if (info->reset_state > 0)
+ info = &aac->hba_map[bus][cid];
+
+ if (info->devtype != AAC_DEVTYPE_NATIVE_RAW &&
+ info->reset_state > 0)
return FAILED;

pr_err("%s: Host adapter reset request. SCSI hang ?\n",
--
2.13.5


2017-09-15 20:13:29

by Dave Carroll

[permalink] [raw]
Subject: RE: [PATCH] scsi: aacraid: error: testing array offset 'bus' after use

>
> Fix possible indexing array of bound for &aac->hba_map[bus][cid], where bus
> and cid boundary check happens later.
>
> Fixes: 0d643ff3c353 ("scsi: aacraid: use aac_tmf_callback for reset fib")
> Signed-off-by: Nikola Pajkovsky <[email protected]>
> ---
> drivers/scsi/aacraid/linit.c | 20 ++++++++++++--------
> 1 file changed, 12 insertions(+), 8 deletions(-)

Reviewed-by: Dave Carroll <[email protected]>

2017-09-16 01:46:48

by Martin K. Petersen

[permalink] [raw]
Subject: Re: [PATCH] scsi: aacraid: error: testing array offset 'bus' after use


Nikola,

> Fix possible indexing array of bound for &aac->hba_map[bus][cid],
> where bus and cid boundary check happens later.

Applied to 4.14/scsi-fixes. Thanks!

--
Martin K. Petersen Oracle Linux Engineering