From: sashiko-bot@kernel.org
To: "Triet Hoang" <triet.hoang.dev@gmail.com>
Cc: linux-scsi@vger.kernel.org
Subject: Re: [PATCH] scsi: smartpqi: Handle pqi_alloc_io_request() failure
Date: Mon, 17 Aug 2026 03:46:29 +0000 [thread overview]
Message-ID: <20260817034630.62A5B1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260817033505.736519-1-triet.hoang.dev@gmail.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] The patch adds unreachable NULL pointer checks for `pqi_alloc_io_request()`. Furthermore, if the code were ever reached, it incorrectly returns a SCSI midlayer queuecommand status code (`SCSI_MLQUEUE_HOST_BUSY`) from synchronous internal management functions.
--
--- Patch [1]: [PATCH] scsi: smartpqi: Handle pqi_alloc_io_request() failure ---
commit 1b3d9355dc4c0807df6a24f973784ecb04a972d7
Author: Triet Hoang <triet.hoang.dev@gmail.com>
scsi: smartpqi: Handle pqi_alloc_io_request() failure
Check the return value of pqi_alloc_io_request() before dereferencing
the returned request in pqi_submit_raid_request_synchronous() and
pqi_lun_reset(). Returns SCSI_MLQUEUE_HOST_BUSY when allocation fails.
> diff --git a/drivers/scsi/smartpqi/smartpqi_init.c b/drivers/scsi/smartpqi/smartpqi_init.c
> index 140e8a6addbe3..5c4f9481923a7 100644
> --- a/drivers/scsi/smartpqi/smartpqi_init.c
> +++ b/drivers/scsi/smartpqi/smartpqi_init.c
> @@ -4673,6 +4673,10 @@ static int pqi_submit_raid_request_synchronous(struct pqi_ctrl_info *ctrl_info,
> }
>
> io_request = pqi_alloc_io_request(ctrl_info, NULL);
> + if (!io_request) {
> + rc = SCSI_MLQUEUE_HOST_BUSY;
[Severity: Medium]
Is this check reachable? Looking at pqi_alloc_io_request(), when the second
argument is NULL, it enters an infinite loop until it successfully claims
an I/O slot:
drivers/scsi/smartpqi/smartpqi_init.c:pqi_alloc_io_request() {
...
while (1) {
io_request = &ctrl_info->io_request_pool[ctrl_info->scsi_ml_can_queue + i];
if (atomic_inc_return(&io_request->refcount) == 1)
break;
atomic_dec(&io_request->refcount);
i = (i + 1) % PQI_RESERVED_IO_SLOTS;
}
...
}
Also, is it appropriate to return SCSI_MLQUEUE_HOST_BUSY here?
This is an internal synchronous routine which normally returns standard negative
errno values (like -ERESTARTSYS or -ENXIO). Returning a positive midlayer
queuecommand status code could lead to unhandled errors or undefined behavior
in the callers if the code were ever reached.
> + goto out;
> + }
>
> put_unaligned_le16(io_request->index,
> &(((struct pqi_raid_path_request *)request)->request_id));
[ ... ]
> @@ -6370,6 +6374,9 @@ static int pqi_lun_reset(struct pqi_ctrl_info *ctrl_info, struct pqi_scsi_dev *d
> struct pqi_task_management_request *request;
>
> io_request = pqi_alloc_io_request(ctrl_info, NULL);
> + if (!io_request)
> + return SCSI_MLQUEUE_HOST_BUSY;
[Severity: Medium]
Similarly, is it possible for pqi_alloc_io_request() to return NULL here?
Does returning SCSI_MLQUEUE_HOST_BUSY from this task management caller violate
standard error handling expectations?
> +
> io_request->io_complete_callback = pqi_lun_reset_complete;
> io_request->context = &wait;
>
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260817033505.736519-1-triet.hoang.dev@gmail.com?part=1
next prev parent reply other threads:[~2026-08-17 3:46 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-17 3:35 [PATCH] scsi: smartpqi: Handle pqi_alloc_io_request() failure Triet Hoang
2026-08-17 3:46 ` sashiko-bot [this message]
2026-08-19 6:55 ` Markus Elfring
2026-08-20 19:01 ` Don.Brace
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260817034630.62A5B1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=triet.hoang.dev@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.