Linux SCSI subsystem development
 help / color / mirror / Atom feed
* [PATCH] scsi: libsas: Handle expander discovery allocation failures
@ 2026-06-23 11:29 Haoxiang Li
  2026-06-23 11:48 ` sashiko-bot
  2026-06-26 22:11 ` Damien Le Moal
  0 siblings, 2 replies; 3+ messages in thread
From: Haoxiang Li @ 2026-06-23 11:29 UTC (permalink / raw)
  To: john.g.garry, yanaijie, James.Bottomley, martin.petersen, dlemoal,
	cassel, kees
  Cc: linux-scsi, linux-kernel, Haoxiang Li

sas_ex_discover_expander() allocates a domain device and SAS port before
allocating the expander rphy, but it does not check all allocation and
registration failures. In particular, sas_expander_alloc() can return
NULL and the returned rphy is dereferenced unconditionally.

Add error handling for sas_port_alloc(), sas_port_add(), and
sas_expander_alloc(), and unwind the resources allocated on each path.
Use sas_port_free() before a port has been added and sas_port_delete()
after it has been added.

Free the child device directly on these early failures because child->rphy
has not been initialized yet, and sas_put_device() would dereference it.

Signed-off-by: Haoxiang Li <haoxiang_li2024@163.com>
---
 drivers/scsi/libsas/sas_expander.c | 24 +++++++++++++++++++++---
 1 file changed, 21 insertions(+), 3 deletions(-)

diff --git a/drivers/scsi/libsas/sas_expander.c b/drivers/scsi/libsas/sas_expander.c
index f471ab464a78..56c04c4ae818 100644
--- a/drivers/scsi/libsas/sas_expander.c
+++ b/drivers/scsi/libsas/sas_expander.c
@@ -909,9 +909,11 @@ static struct domain_device *sas_ex_discover_expander(
 		return NULL;
 
 	phy->port = sas_port_alloc(&parent->rphy->dev, phy_id);
-	/* FIXME: better error handling */
-	BUG_ON(sas_port_add(phy->port) != 0);
-
+	if (!phy->port)
+		goto out_free_child;
+	res = sas_port_add(phy->port);
+	if (res)
+		goto out_free_port;
 
 	switch (phy->attached_dev_type) {
 	case SAS_EDGE_EXPANDER_DEVICE:
@@ -926,6 +928,9 @@ static struct domain_device *sas_ex_discover_expander(
 		rphy = NULL;	/* shut gcc up */
 		BUG();
 	}
+	if (!rphy)
+		goto out_delete_port;
+
 	port = parent->port;
 	child->rphy = rphy;
 	get_device(&rphy->dev);
@@ -963,6 +968,19 @@ static struct domain_device *sas_ex_discover_expander(
 	}
 	list_add_tail(&child->siblings, &parent->ex_dev.children);
 	return child;
+
+out_delete_port:
+	sas_port_delete(phy->port);
+	phy->port = NULL;
+	kfree(child);
+	return NULL;
+
+out_free_port:
+	sas_port_free(phy->port);
+	phy->port = NULL;
+out_free_child:
+	kfree(child);
+	return NULL;
 }
 
 static int sas_ex_discover_dev(struct domain_device *dev, int phy_id)
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-06-26 22:11 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-06-23 11:29 [PATCH] scsi: libsas: Handle expander discovery allocation failures Haoxiang Li
2026-06-23 11:48 ` sashiko-bot
2026-06-26 22:11 ` Damien Le Moal

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox