[PATCH 0/8] scsi: target: keep command bytes inside the sg
From: Jia Jia
Date: Tue Oct 06 2026 - 05:34:50 EST
Eight fixes for target core reading or writing past an sg. Patches 4
through 6 and patch 8 share the DIF sg walk and apply in order. The
others stand alone. vhost-scsi keeps one sg inside one page, so those
bytes land on the next physical page. The commands reach the host
through a guest virtqueue.
Patch 1 takes the COMPARE AND WRITE write half from its own sg entries.
Adding the compare length to the first entry's offset loses the sg
boundary when the two halves are split across pages. The replacement
table is released with sg_free_table().
Patch 2 keeps each REPORT REFERRALS LBA store inside the data-in
buffer. The existing data_length checks cover one-byte fields, not the
eight-byte LBA.
Patch 3 rejects a SET TARGET PORT GROUPS list that ends on a partial
four-byte descriptor.
Patch 4 copies an 8 byte protection tuple across sg entries in
sbc_dif_generate(). A tuple that starts at the end of one entry is
written into the next entry as well.
Patch 5 does the same read in sbc_dif_verify(). A tuple that runs off
the end of the protection list fails the command. The generate change
does not cover this function.
Patch 6 limits the block CRC in both functions to the bytes each data
sg actually holds.
Patch 7 reads the pscsi MODE SENSE write-protect byte and the tape
MODE SELECT block descriptor from the whole data buffer. A short
buffer is left unchanged.
Patch 8 makes sbc_dif_verify() advance the data cursor across every sg
entry of a logical block whose application tag is 0xffff. The cursor
uses the same kmap_local_page() calls as the CRC walk.
Jia Jia (8):
scsi: target: take COMPARE AND WRITE data from the write half
scsi: target: keep REPORT REFERRALS stores inside the buffer
scsi: target: reject a short SET TARGET PORT GROUPS list
scsi: target: copy a DIF insert tuple across prot sgs
scsi: target: copy a DIF verify tuple across prot sgs
scsi: target: limit DIF block CRC to each data sg
scsi: target: keep pscsi mode bytes inside the data sgs
scsi: target: skip an escaped DIF block inside the data sg
drivers/target/target_core_alua.c | 29 +++++++---
drivers/target/target_core_pscsi.c | 98 +++++++++++++++++++++++---------
drivers/target/target_core_sbc.c | 474 ++++++++++++++++++++++++++++---------
drivers/target/target_core_transport.c | 11 +++-
4 files changed, 439 insertions(+), 173 deletions(-)
--
2.43.0