From: Paolo Bonzini <[email protected]> When documenting the invariant that mode pages need to fit the smallest output buffer of all callers (which is SCSI_MAX_MODE_LEN), the expression used by the assertion was incorrect.
Even though SCSI_MAX_MODE_LEN is indeed 256, using "length < 256" had two issues: 1) it used the wrong operator, since "length < ..." is more related to having room for extra data; 2) it missed the extra two bytes for page number and length. Reviewed-by: Philippe Mathieu-Daudé <[email protected]> Signed-off-by: Paolo Bonzini <[email protected]> (cherry picked from commit e2da3d92744d12b0c2e554ed533a4c9011dbd975) Signed-off-by: Michael Tokarev <[email protected]> diff --git a/hw/scsi/scsi-disk.c b/hw/scsi/scsi-disk.c index 755e0960ba2..831598688d1 100644 --- a/hw/scsi/scsi-disk.c +++ b/hw/scsi/scsi-disk.c @@ -1343,7 +1343,7 @@ static int mode_sense_page(SCSIDiskState *s, int page, uint8_t **p_outbuf, return -1; } - assert(length < 256); + assert(length + 2 <= SCSI_MAX_MODE_LEN); (*p_outbuf)[0] = page; (*p_outbuf)[1] = length; *p_outbuf += length + 2; -- 2.47.3
