Commit e2da3d9274 for qemu.org

commit e2da3d92744d12b0c2e554ed533a4c9011dbd975
Author: Paolo Bonzini <pbonzini@redhat.com>
Date:   Tue Jul 21 17:56:42 2026 +0200

    scsi-disk: fix off by one in assertion

    When documenting the invariant that mode pages need to fit the smallest
    output buffer of all callers (which is SCSI_MAX_MODE_LEN), the expression
    used by the assertion was incorrect.

    Even though SCSI_MAX_MODE_LEN is indeed 256, using "length < 256" had
    two issues: 1) it used the wrong operator, since "length < ..." is more
    related to having room for extra data; 2) it missed the extra two bytes
    for page number and length.

    Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
    Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>

diff --git a/hw/scsi/scsi-disk.c b/hw/scsi/scsi-disk.c
index 85d0bd0b81..1b0cce128c 100644
--- a/hw/scsi/scsi-disk.c
+++ b/hw/scsi/scsi-disk.c
@@ -1321,7 +1321,7 @@ static int mode_sense_page(SCSIDiskState *s, int page, uint8_t **p_outbuf,
         return -1;
     }

-    assert(length < 256);
+    assert(length + 2 <= SCSI_MAX_MODE_LEN);
     (*p_outbuf)[0] = page;
     (*p_outbuf)[1] = length;
     *p_outbuf += length + 2;