[PATCH v2] scsi: hpsa: validate active path before indexing enclosure arrays

Pengpeng Hou posted 1 patch 1 month, 2 weeks ago
drivers/scsi/hpsa.c | 8 ++++++++
1 file changed, 8 insertions(+)
[PATCH v2] scsi: hpsa: validate active path before indexing enclosure arrays
Posted by Pengpeng Hou 1 month, 2 weeks ago
hpsa_get_enclosure_info() uses the firmware-provided active path
number as an index into the eight-entry box and phys_connector arrays.
The index is not checked before the array write and connector copy.

Reject enclosure information with an out-of-range active path before
updating those per-path arrays.

Fixes: cca8f13b4fda ("hpsa: Add box and bay information for enclosure devices")
Assisted-by: Codex:gpt-5
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
---
Changes since v1: https://lore.kernel.org/all/20260704010943.16707-1-pengpeng@iscas.ac.cn/
- rebase on current hpsa sources
- validate the firmware path number against the destination arrays before
  either access

This revision was not built or tested on Smart Array hardware.

 drivers/scsi/hpsa.c | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/drivers/scsi/hpsa.c b/drivers/scsi/hpsa.c
index 8edad1830abe..5725fd9a6aaa 100644
--- a/drivers/scsi/hpsa.c
+++ b/drivers/scsi/hpsa.c
@@ -3505,6 +3505,14 @@ static void hpsa_get_enclosure_info(struct ctlr_info *h,
 		goto out;
 	}
 
+	if (id_phys->active_path_number >= ARRAY_SIZE(encl_dev->box)) {
+		dev_warn(&h->pdev->dev,
+			 "%s: invalid active path %u for bdi[0x%x]\n",
+			 __func__, id_phys->active_path_number, bmic_device_index);
+		rc = -1;
+		goto out;
+	}
+
 	encl_dev->box[id_phys->active_path_number] = bssbp->phys_box_on_port;
 	memcpy(&encl_dev->phys_connector[id_phys->active_path_number],
 		bssbp->phys_connector, sizeof(bssbp->phys_connector));
-- 
2.50.1 (Apple Git-155)