[PATCH 08/12] vhost-scsi: improve CDB size validation and remove TODO comment

Weimin Xiong <[email protected]>
Newsgroups dev.linux.lists.virtualization
Message-ID <[email protected]>
From: xiongweimin <[email protected]>

Improve the CDB size validation by adding a zero-length check for
additional safety. Also remove the misleading TODO comment since
scsi_command_size() already correctly handles both fixed and
variable-length CDBs.

Signed-off-by: Weimin Xiong <[email protected]>
Co-authored-by: Cursor <[email protected]>
---
 drivers/vhost/scsi.c | 13 ++++++++-----
 1 file changed, 8 insertions(+), 5 deletions(-)

diff --git a/drivers/vhost/scsi.c b/drivers/vhost/scsi.c
index 219d9d881..2fbc328c9 100644
--- a/drivers/vhost/scsi.c
+++ b/drivers/vhost/scsi.c
@@ -1432,12 +1432,15 @@ vhost_scsi_handle_vq(struct vhost_scsi *vs, struct vhost_virtqueue *vq)
 			lun = vhost_buf_to_lun(v_req.lun);
 		}
 		/*
-		 * Check that the received CDB size does not exceeded our
-		 * hardcoded max for vhost-scsi, then get a pre-allocated
-		 * cmd descriptor for the new virtio-scsi tag.
-		 *
-		 * TODO what if cdb was too small for varlen cdb header?
+		 * Check that the received CDB size is valid and does not
+		 * exceed our hardcoded max for vhost-scsi, then get a
+		 * pre-allocated cmd descriptor for the new virtio-scsi tag.
+		 * scsi_command_size() handles both fixed and variable-length CDBs.
 		 */
+		if (unlikely(scsi_command_size(cdb) == 0)) {
+			vq_err(vq, "Received SCSI CDB with zero length\n");
+			goto err;
+		}
 		if (unlikely(scsi_command_size(cdb) > VHOST_SCSI_MAX_CDB_SIZE)) {
 			vq_err(vq, "Received SCSI CDB with command_size: %d that"
 				" exceeds SCSI_MAX_VARLEN_CDB_SIZE: %d\n",
-- 
2.43.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.