[PATCH 2/2] scsi: target: fix auth when CHAP_N carries a hex/b64 prefix

David Disseldorp <[email protected]> Tue, 2 Jun 2026 21:43:58 +1000
Newsgroups org.kernel.vger.target-devel,org.kernel.vger.linux-scsi
Message-ID <[email protected]>
Attempting to authenticate using a CHAP username with a '0x' or '0b'
prefix currently fails. This is due to extract_param()'s behaviour of
stripping these prefixes, and the subsequent (type == HEX) error-path.
I believe this behaviour is contrary to the RFC 3720 specification,
which states:

  5.1.  Text Format
  ...
  text-value: A string of zero or more characters that consist of
  letters, digits, dot, minus, plus, commercial at, underscore,
  slash, left bracket, right bracket, or colon.

  11.1.4.  Challenge Handshake Authentication Protocol (CHAP)
  ...
    CHAP_A=<A> CHAP_I=<I> CHAP_C=<C>

   Where A is one of A1,A2... that were proposed by the initiator.

   In the third step, the initiator MUST continue with:

      CHAP_N=<N> CHAP_R=<R>
   ...
   Where N, (A,A1,A2), I, C, and R are (correspondingly) the Name,
   Algorithm, Identifier, Challenge, and Response as defined in
   [RFC1994], N is a text string, A,A1,A2, and I are numbers, and C and
   R are large-binary-values ...

"N is a text string" implies that any hex or base64 encoding prefix
should not be interpreted or stripped. Fix this by using the new
extract_param_str() helper function to obtain the CHAP_N value as-is.

Reported-by: Sashiko (gemini/gemini-3.1-pro-preview)
Link: https://sashiko.dev/#/patchset/20260521151121.808477-1-hossu.alexandru%40gmail.com
Signed-off-by: David Disseldorp <[email protected]>
---
 drivers/target/iscsi/iscsi_target_auth.c | 8 ++------
 1 file changed, 2 insertions(+), 6 deletions(-)

diff --git a/drivers/target/iscsi/iscsi_target_auth.c b/drivers/target/iscsi/iscsi_target_auth.c
index a3ad2d244dbee..6f21075e58416 100644
--- a/drivers/target/iscsi/iscsi_target_auth.c
+++ b/drivers/target/iscsi/iscsi_target_auth.c
@@ -303,12 +303,8 @@ static int chap_server_compute_hash(
 	/*
 	 * Extract CHAP_N.
 	 */
-	if (extract_param(nr_in_ptr, "CHAP_N", MAX_CHAP_N_SIZE, chap_n,
-				&type) < 0) {
-		pr_err("Could not find CHAP_N.\n");
-		goto out;
-	}
-	if (type == HEX) {
+	ret = extract_param_str(nr_in_ptr, "CHAP_N", MAX_CHAP_N_SIZE, chap_n);
+	if (ret < 0) {
 		pr_err("Could not find CHAP_N.\n");
 		goto out;
 	}
-- 
2.51.0