summaryrefslogtreecommitdiff
path: root/drivers
diff options
context:
space:
mode:
authorLinus Torvalds <torvalds@linux-foundation.org>2026-09-25 14:41:52 -0700
committerLinus Torvalds <torvalds@linux-foundation.org>2026-09-25 14:41:52 -0700
commit049380360ca6f4cc22ac2f67fe95b98967c887f0 (patch)
tree1868b58c95de695689a2298c228d11264b0fef37 /drivers
parentf14572c203d57492e1d4e5d7851a3b143e083b82 (diff)
parent42d1221d321e55afc7bba9109a77aaf5a817c8a3 (diff)
downloadlinux-049380360ca6f4cc22ac2f67fe95b98967c887f0.tar.gz
linux-049380360ca6f4cc22ac2f67fe95b98967c887f0.zip
Merge tag 'scsi-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/jejb/scsi
Pull SCSI fixes from James Bottomley: "Mostly small driver fixes. The biggest fix is the one to the block zone handling which might trip for real or virtual hardware if the number of zones is > 2^32" * tag 'scsi-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/jejb/scsi: scsi: megaraid_sas: Protect megasas_get_ctrl_info() in megasas_resume() scsi: sd_zbc: Reject disks with too many zones scsi: block: Fix zones_cond out-of-bounds write on zone report scsi: leapraid: Avoid -Wformat-security warning scsi: devinfo: Add BLIST_SKIP_IO_HINTS for EMC Symmetrix scsi: libiscsi_tcp: Check the data direction of a Data-In PDU scsi: ufs: pltfrm: Add quirk for R-Car S4 lacking lanes-per-direction scsi: ufs: core: Keep internal commands dispatchable during error handling
Diffstat (limited to 'drivers')
-rw-r--r--drivers/scsi/leapraid/leapraid_func.h2
-rw-r--r--drivers/scsi/leapraid/leapraid_os.c8
-rw-r--r--drivers/scsi/libiscsi_tcp.c3
-rw-r--r--drivers/scsi/megaraid/megaraid_sas_base.c4
-rw-r--r--drivers/scsi/scsi_devinfo.c2
-rw-r--r--drivers/scsi/sd_zbc.c8
-rw-r--r--drivers/ufs/core/ufshcd.c6
-rw-r--r--drivers/ufs/host/ufshcd-pltfrm.c6
8 files changed, 28 insertions, 11 deletions
diff --git a/drivers/scsi/leapraid/leapraid_func.h b/drivers/scsi/leapraid/leapraid_func.h
index 4c0b9ca728d8..e8a0815bf95f 100644
--- a/drivers/scsi/leapraid/leapraid_func.h
+++ b/drivers/scsi/leapraid/leapraid_func.h
@@ -554,7 +554,6 @@ struct leapraid_fw_evt_work {
/**
* struct leapraid_fw_evt_struct - Firmware event handling structure
*
- * @fw_evt_name: Name of the firmware event.
* @fw_evt_thread: Workqueue used for processing firmware events.
* @fw_evt_lock: Spinlock protecting access to the firmware event list.
* @fw_evt_list: Linked list of pending firmware events.
@@ -565,7 +564,6 @@ struct leapraid_fw_evt_work {
*/
struct leapraid_fw_evt_struct {
u32 leapraid_evt_masks[4];
- char fw_evt_name[48];
struct workqueue_struct *fw_evt_thread;
spinlock_t fw_evt_lock; /* protects firmware event */
struct list_head fw_evt_list;
diff --git a/drivers/scsi/leapraid/leapraid_os.c b/drivers/scsi/leapraid/leapraid_os.c
index ee3242779dfd..507f11862276 100644
--- a/drivers/scsi/leapraid/leapraid_os.c
+++ b/drivers/scsi/leapraid/leapraid_os.c
@@ -2054,12 +2054,10 @@ static int leapraid_probe(struct pci_dev *pdev, const struct pci_device_id *id)
shost->transportt = leapraid_transport_template;
shost->unique_id = adapter->adapter_attr.id;
- snprintf(adapter->fw_evt_s.fw_evt_name,
- sizeof(adapter->fw_evt_s.fw_evt_name),
- "fw_event_%s%d", LEAPRAID_DRIVER_NAME,
- adapter->adapter_attr.id);
adapter->fw_evt_s.fw_evt_thread =
- alloc_ordered_workqueue(adapter->fw_evt_s.fw_evt_name, 0);
+ alloc_ordered_workqueue("fw_event_%s%d", 0,
+ LEAPRAID_DRIVER_NAME,
+ adapter->adapter_attr.id);
if (!adapter->fw_evt_s.fw_evt_thread) {
dev_err(&adapter->pdev->dev,
"%s: Failed to create fw event workqueue\n", __func__);
diff --git a/drivers/scsi/libiscsi_tcp.c b/drivers/scsi/libiscsi_tcp.c
index 7223bb18b048..d35f93451ee9 100644
--- a/drivers/scsi/libiscsi_tcp.c
+++ b/drivers/scsi/libiscsi_tcp.c
@@ -480,6 +480,9 @@ static int iscsi_tcp_data_in(struct iscsi_conn *conn, struct iscsi_task *task)
int datasn = be32_to_cpu(rhdr->datasn);
unsigned total_in_length = task->sc->sdb.length;
+ if (task->sc->sc_data_direction != DMA_FROM_DEVICE)
+ return ISCSI_ERR_PROTO;
+
/*
* lib iscsi will update this in the completion handling if there
* is status.
diff --git a/drivers/scsi/megaraid/megaraid_sas_base.c b/drivers/scsi/megaraid/megaraid_sas_base.c
index b95f187297ae..4f9a53769966 100644
--- a/drivers/scsi/megaraid/megaraid_sas_base.c
+++ b/drivers/scsi/megaraid/megaraid_sas_base.c
@@ -7886,7 +7886,9 @@ megasas_resume(struct device *dev)
goto fail_init_mfi;
}
- if (megasas_get_ctrl_info(instance) != DCMD_SUCCESS)
+ scoped_guard(mutex, &instance->reset_mutex)
+ rval = megasas_get_ctrl_info(instance);
+ if (rval != DCMD_SUCCESS)
goto fail_init_mfi;
tasklet_init(&instance->isr_tasklet, instance->instancet->tasklet,
diff --git a/drivers/scsi/scsi_devinfo.c b/drivers/scsi/scsi_devinfo.c
index 15ffbe93ac72..88a911b35c94 100644
--- a/drivers/scsi/scsi_devinfo.c
+++ b/drivers/scsi/scsi_devinfo.c
@@ -161,7 +161,7 @@ static struct {
{"DGC", "DISK", NULL, BLIST_SPARSELUN}, /* EMC CLARiiON, no storage on LUN 0 */
{"EMC", "Invista", "*", BLIST_SPARSELUN | BLIST_LARGELUN},
{"EMC", "SYMMETRIX", NULL, BLIST_SPARSELUN | BLIST_LARGELUN |
- BLIST_REPORTLUN2 | BLIST_RETRY_ITF},
+ BLIST_REPORTLUN2 | BLIST_RETRY_ITF | BLIST_SKIP_IO_HINTS},
{"EMULEX", "MD21/S2 ESDI", NULL, BLIST_SINGLELUN},
{"easyRAID", "16P", NULL, BLIST_NOREPORTLUN},
{"easyRAID", "X6P", NULL, BLIST_NOREPORTLUN},
diff --git a/drivers/scsi/sd_zbc.c b/drivers/scsi/sd_zbc.c
index 56e455fb5add..456beaf2e769 100644
--- a/drivers/scsi/sd_zbc.c
+++ b/drivers/scsi/sd_zbc.c
@@ -589,7 +589,7 @@ int sd_zbc_revalidate_zones(struct scsi_disk *sdkp)
int sd_zbc_read_zones(struct scsi_disk *sdkp, struct queue_limits *lim,
u8 buf[SD_BUF_SIZE])
{
- unsigned int nr_zones;
+ u64 nr_zones;
u32 zone_blocks = 0;
int ret;
@@ -621,6 +621,12 @@ int sd_zbc_read_zones(struct scsi_disk *sdkp, struct queue_limits *lim,
goto err;
nr_zones = round_up(sdkp->capacity, zone_blocks) >> ilog2(zone_blocks);
+ if (nr_zones > INT_MAX) {
+ sd_printk(KERN_ERR, sdkp, "Too many zones (%llu)\n",
+ nr_zones);
+ ret = -EINVAL;
+ goto err;
+ }
sdkp->early_zone_info.nr_zones = nr_zones;
sdkp->early_zone_info.zone_blocks = zone_blocks;
diff --git a/drivers/ufs/core/ufshcd.c b/drivers/ufs/core/ufshcd.c
index 2ba244cf40ac..54f4e7d7de02 100644
--- a/drivers/ufs/core/ufshcd.c
+++ b/drivers/ufs/core/ufshcd.c
@@ -6817,11 +6817,17 @@ static void ufshcd_err_handling_prepare(struct ufs_hba *hba)
}
/* Wait for ongoing ufshcd_queuecommand() calls to finish. */
blk_mq_quiesce_tagset(&hba->host->tag_set);
+ /*
+ * Internal commands are submitted on the pseudo SCSI device. Let them
+ * through so that the error handler can recover the link.
+ */
+ blk_mq_unquiesce_queue(hba->host->pseudo_sdev->request_queue);
cancel_work_sync(&hba->eeh_work);
}
static void ufshcd_err_handling_unprepare(struct ufs_hba *hba)
{
+ blk_mq_quiesce_queue_nowait(hba->host->pseudo_sdev->request_queue);
blk_mq_unquiesce_tagset(&hba->host->tag_set);
ufshcd_release(hba);
if (ufshcd_is_clkscaling_supported(hba))
diff --git a/drivers/ufs/host/ufshcd-pltfrm.c b/drivers/ufs/host/ufshcd-pltfrm.c
index 5ac7afe75934..169dbc1a75fe 100644
--- a/drivers/ufs/host/ufshcd-pltfrm.c
+++ b/drivers/ufs/host/ufshcd-pltfrm.c
@@ -206,7 +206,11 @@ static void ufshcd_init_lanes_per_dir(struct ufs_hba *hba)
dev_dbg(hba->dev,
"%s: failed to read lanes-per-direction, ret=%d\n",
__func__, ret);
- hba->lanes_per_direction = UFSHCD_DEFAULT_LANES_PER_DIRECTION;
+ /* Old R-Car S4 DTBs lack "lanes-per-direction = <1>" */
+ if (of_device_is_compatible(dev->of_node, "renesas,r8a779f0-ufs"))
+ hba->lanes_per_direction = 1;
+ else
+ hba->lanes_per_direction = UFSHCD_DEFAULT_LANES_PER_DIRECTION;
}
}