All of lore.kernel.org
 help / color / mirror / Atom feed
From: Johannes Thumshirn <jthumshirn@suse.de>
To: "Dāvis Mosāns" <davispuh@gmail.com>
Cc: "James E.J. Bottomley" <JBottomley@odin.com>,
	linux-scsi@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH] SCSI: mvsas: Fix NULL pointer dereference in mvs_slot_task_free
Date: Wed, 21 Oct 2015 16:29:01 +0200	[thread overview]
Message-ID: <1445437741.16404.17.camel@suse.de> (raw)
In-Reply-To: <CAOE4rSznxS7h4vqY2THG7Mfv0QU9gRoiyMjd5B51sakYBvyT0g@mail.gmail.com>

On Wed, 2015-10-21 at 17:26 +0300, Dāvis Mosāns wrote:
> 2015-10-21 16:47 GMT+03:00 Johannes Thumshirn <jthumshirn@suse.de>:
> > On Wed, 2015-10-21 at 16:18 +0300, Dāvis Mosāns wrote:
> > > 2015-10-21 10:33 GMT+03:00 Johannes Thumshirn <jthumshirn@suse.de
> > > >:
> > > > On Tue, 2015-10-20 at 20:41 +0300, Dāvis Mosāns wrote:
> > > > > 2015-08-21 7:29 GMT+03:00 Dāvis Mosāns <davispuh@gmail.com>:
> > > > > > When pci_pool_alloc fails in mvs_task_prep then task-
> > > > > > >lldd_task
> > > > > > stays
> > > > > > NULL but it's later used in mvs_abort_task as slot which is
> > > > > > passed
> > > > > > to mvs_slot_task_free causing NULL pointer dereference.
> > > > > > 
> > > > > > Just return from mvs_slot_task_free when passed with NULL
> > > > > > slot.
> > > > > > 
> > > > > > Bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=10189
> > > > > > 1
> > > > > > Signed-off-by: Dāvis Mosāns <davispuh@gmail.com>
> > > > > > ---
> > > > > >  drivers/scsi/mvsas/mv_sas.c | 2 ++
> > > > > >  1 file changed, 2 insertions(+)
> > > > > > 
> > > > > > diff --git a/drivers/scsi/mvsas/mv_sas.c
> > > > > > b/drivers/scsi/mvsas/mv_sas.c
> > > > > > index 454536c..9c78074 100644
> > > > > > --- a/drivers/scsi/mvsas/mv_sas.c
> > > > > > +++ b/drivers/scsi/mvsas/mv_sas.c
> > > > > > @@ -887,6 +887,8 @@ static void mvs_slot_free(struct
> > > > > > mvs_info
> > > > > > *mvi,
> > > > > > u32 rx_desc)
> > > > > >  static void mvs_slot_task_free(struct mvs_info *mvi,
> > > > > > struct
> > > > > > sas_task *task,
> > > > > >                           struct mvs_slot_info *slot, u32
> > > > > > slot_idx)
> > > > > >  {
> > > > > > +       if (!slot)
> > > > > > +               return;
> > > > > >         if (!slot->task)
> > > > > >                 return;
> > > > > >         if (!sas_protocol_ata(task->task_proto))
> > > > > > --
> > > > > > 2.5.0
> > > > > > 
> > > > > 
> > > > > Can this get merged?
> > > > > So far since august it have saved me from several kernel
> > > > > crashes.
> > > > 
> > > > If it saved you from several crashes, it probably should be
> > > > tagged
> > > > for
> > > > stable, shouldn't it?
> > > > 
> > > > Reviewed-by: Johannes Thumshirn <jthumshirn@suse.de>
> > > > 
> > > > 
> > > 
> > > I don't really know how that works... this is my first patch so
> > > I'm
> > > not really concerned about in which version it gets in as long as
> > > it
> > > does.
> > > I've been compiling kernel with this patch for these months so
> > > for me
> > > it
> > > doesn't really make any difference.
> > 
> > You can add
> > Cc: stable@vger.kernel.org
> > somewhere around your Signed-off-by
> > 
> > Documentation/stable_kernel_rules.txt has all the process
> > documentation.
> 
> Should I add it together with review tags too and resend patch or
> reply to this
> thread with it edited or just leave it like it is now and whoever
> will see it
> will add it himself?

good question, but I think James can help here.

> 
> 
> also for stable requirements this line is a bit confusing
> "It or an equivalent fix must already exist in Linus' tree
> (upstream)."
> 
> but then later seems it's not requirement for Option 1

yes, if you tag it with the Cc, it will get to stable review _after_ it
is applied to Linus' tree

      reply	other threads:[~2015-10-21 14:29 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2015-08-21  4:29 [PATCH] SCSI: mvsas: Fix NULL pointer dereference in mvs_slot_task_free Dāvis Mosāns
2015-09-01 20:08 ` Dāvis Mosāns
2015-09-02 12:08 ` Tomas Henzl
2015-10-20 17:41 ` Dāvis Mosāns
2015-10-21  7:33   ` Johannes Thumshirn
2015-10-21 13:18     ` Dāvis Mosāns
2015-10-21 13:18       ` Dāvis Mosāns
2015-10-21 13:47       ` Johannes Thumshirn
2015-10-21 13:47         ` Johannes Thumshirn
2015-10-21 14:26         ` Dāvis Mosāns
2015-10-21 14:29           ` Johannes Thumshirn [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1445437741.16404.17.camel@suse.de \
    --to=jthumshirn@suse.de \
    --cc=JBottomley@odin.com \
    --cc=davispuh@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-scsi@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.