Re: [PATCH nvmet-v1 1/1] nvmet: zns: reject full zone report when buffer is too small

Christoph Hellwig <[email protected]>
Newsgroups org.infradead.lists.linux-nvme
Message-ID <[email protected]>
On Thu, Jul 09, 2026 at 02:51:39PM +0800, Xixin Liu wrote:
> Zone Management Receive uses the Partial Report (PR) bit in dword 13.  On a
> partial report (PR bit set), the host accepts an incomplete listing and
> Number of Zones must not exceed the zone descriptors copied to the host
> buffer.  On a full report (PR bit clear), Number of Zones is the total
> number of matching zones and every descriptor must fit in the buffer (ZNS
> Command Set Specification Rev 1.2, section 3.4.2).
> 
> nvmet_bdev_zone_zmgmt_recv_work() already caps Number of Zones for partial
> reports, but on a full report it may still succeed when the buffer only
> holds part of the matching descriptors.  Reject the command in that case.
> 
> Signed-off-by: Xixin Liu <[email protected]>
> ---
>  drivers/nvme/target/zns.c | 15 ++++++++++++---
>  1 file changed, 12 insertions(+), 3 deletions(-)
> 
> diff --git a/drivers/nvme/target/zns.c b/drivers/nvme/target/zns.c
> index f00921931eb6..a53986fcc04a 100644
> --- a/drivers/nvme/target/zns.c
> +++ b/drivers/nvme/target/zns.c
> @@ -295,11 +295,20 @@ static void nvmet_bdev_zone_zmgmt_recv_work(struct work_struct *w)
>  	}
>  
>  	/*
> -	 * When partial bit is set nr_zones must indicate the number of zone
> -	 * descriptors actually transferred.
> +	 * Partial report (PR bit set): the host accepts an incomplete listing,
> +	 * so cap Number of Zones to the descriptors that fit in the buffer.
> +	 * Full report (PR bit clear): Number of Zones is the match count; fail
> +	 * if the buffer cannot hold every matching zone descriptor.
>  	 */
> -	if (req->cmd->zmr.pr)
> +	if (req->cmd->zmr.pr) {
>  		rz_data.nr_zones = min(rz_data.nr_zones, rz_data.out_nr_zones);
> +	} else {
> +		if (rz_data.nr_zones > rz_data.out_nr_zones) {
> +			req->error_loc = offsetof(struct nvme_zone_mgmt_recv_cmd, numd);

Overly line here.  Easily fixed by using and else if above.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.