[PATCH 4/4] nvmet: reject out-of-range mdts values in configfs store
Guixin Liu
kanie at linux.alibaba.com
Wed Jul 29 04:02:31 PDT 2026
nvmet_param_mdts_store() accepts any integer that kstrtoint() can parse
and stores it directly into port->mdts. The value is only range-checked
later, when the port is enabled: nvmet_enable_port() silently resets
port->mdts to 0 if it is negative or greater than NVMET_MAX_MDTS.
As a result, writing e.g. "mdts=1000" succeeds and reading the attribute
back returns 1000, yet enabling the port quietly turns it into 0. This
is confusing and hides the invalid input from the user.
Validate the value against [0, NVMET_MAX_MDTS] in the store handler and
reject anything out of range with -EINVAL, so the error is reported at
write time and port->mdts never holds a value the port cannot use.
Fixes: 0a5a94648627 ("nvmet: introduce new mdts configuration entry")
Signed-off-by: Guixin Liu <kanie at linux.alibaba.com>
---
drivers/nvme/target/configfs.c | 10 ++++++----
1 file changed, 6 insertions(+), 4 deletions(-)
diff --git a/drivers/nvme/target/configfs.c b/drivers/nvme/target/configfs.c
index 2b69ffcfc8df..413ee2d16d29 100644
--- a/drivers/nvme/target/configfs.c
+++ b/drivers/nvme/target/configfs.c
@@ -312,15 +312,17 @@ static ssize_t nvmet_param_mdts_store(struct config_item *item,
const char *page, size_t count)
{
struct nvmet_port *port = to_nvmet_port(item);
- int ret;
+ int ret, mdts;
if (nvmet_is_port_enabled(port, __func__))
return -EACCES;
- ret = kstrtoint(page, 0, &port->mdts);
- if (ret) {
- pr_err("Invalid value '%s' for mdts\n", page);
+ ret = kstrtoint(page, 0, &mdts);
+ if (ret || mdts < 0 || mdts > NVMET_MAX_MDTS) {
+ pr_err("Invalid value '%s' for mdts, should be 0-%d\n",
+ page, NVMET_MAX_MDTS);
return -EINVAL;
}
+ port->mdts = mdts;
return count;
}
--
2.43.7
More information about the Linux-nvme
mailing list