From: sashiko-bot@kernel.org
To: "Ranjan Kumar" <ranjan.kumar@broadcom.com>
Cc: linux-scsi@vger.kernel.org
Subject: Re: [PATCH v4 08/10] mpi3mr: Fix SAS port allocation and registration error handling
Date: Wed, 05 Aug 2026 11:40:28 +0000 [thread overview]
Message-ID: <20260805114029.A25AD1F00A3E@smtp.kernel.org> (raw)
In-Reply-To: <20260805110634.346670-9-ranjan.kumar@broadcom.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] Skipping `sas_port_delete` and `sas_port_delete_phy` during a controller reset causes permanent memory leaks of SAS transport objects and triggers a kernel `BUG()` on subsequent device discovery.
--
--- Patch [8]: [PATCH v4 08/10] mpi3mr: Fix SAS port allocation and registration error handling ---
commit 2a61369a5f802bef404aa18e7c7a2583f37c4fc7
Author: Ranjan Kumar <ranjan.kumar@broadcom.com>
mpi3mr: Fix SAS port allocation and registration error handling
This commit adds NULL checks after SAS port and rphy allocations to prevent
NULL pointer dereferences. It cleans up memory and state if registration
fails, resolving memory leaks and dangling pointers. Finally, it prevents
deadlocks in the SCSI mid-layer by checking for resets or driver stops.
> diff --git a/drivers/scsi/mpi3mr/mpi3mr_transport.c b/drivers/scsi/mpi3mr/mpi3mr_transport.c
> index b309cfdf66873..db9cb0b03b9ff 100644
> --- a/drivers/scsi/mpi3mr/mpi3mr_transport.c
> +++ b/drivers/scsi/mpi3mr/mpi3mr_transport.c
[ ... ]
> @@ -1600,12 +1644,12 @@ static void mpi3mr_sas_port_remove(struct mpi3mr_ioc *mrioc, u64 sas_address,
> mr_sas_port->remote_identify.sas_address,
> mr_sas_phy->phy_id);
> mr_sas_phy->phy_belongs_to_port = 0;
> - if (!mrioc->stop_drv_processing)
> + if (!mrioc->stop_drv_processing && !mrioc->reset_in_progress)
> sas_port_delete_phy(mr_sas_port->port,
> mr_sas_phy->phy);
> list_del(&mr_sas_phy->port_siblings);
> }
> - if (!mrioc->stop_drv_processing)
> + if (!mrioc->stop_drv_processing && !mrioc->reset_in_progress)
> sas_port_delete(mr_sas_port->port);
[Severity: Critical]
Does skipping sas_port_delete() and sas_port_delete_phy() during a reset cause
a memory leak and a kernel BUG() during rediscovery?
Because mr_sas_port is unconditionally freed at the end of
mpi3mr_sas_port_remove(), the transport objects (sas_port and sas_rphy) are
leaked when their delete functions are bypassed.
Additionally, the sas_phy remains linked to the leaked port's phy_list. When
the reset completes and the device comes back online, mpi3mr_sas_port_add()
will create a new port and call sas_port_add_phy() on the same sas_phy.
The SAS transport layer detects the phy is already linked to another port and
intentionally triggers a BUG().
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260805110634.346670-1-ranjan.kumar@broadcom.com?part=8
next prev parent reply other threads:[~2026-08-05 11:40 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-05 11:06 [PATCH v4 00/10] mpi3mr: Few Enhancements and minor fixes Ranjan Kumar
2026-08-05 11:06 ` [PATCH v4 01/10] mpi3mr: Skip device shutdown during unload per controller configuration Ranjan Kumar
2026-08-05 11:33 ` sashiko-bot
2026-08-05 11:06 ` [PATCH v4 02/10] mpi3mr: Update MPI Headers to revision 41 Ranjan Kumar
2026-08-05 11:33 ` sashiko-bot
2026-08-05 11:06 ` [PATCH v4 03/10] mpi3mr: Add early timestamp synchronization after driver load Ranjan Kumar
2026-08-05 11:06 ` [PATCH v4 04/10] mpi3mr: Fix NVMe page size caching for non-operational devices Ranjan Kumar
2026-08-05 11:40 ` sashiko-bot
2026-08-05 11:06 ` [PATCH v4 05/10] mpi3mr: Fix performance regression caused by extended IRQ poll sleep Ranjan Kumar
2026-08-05 11:32 ` sashiko-bot
2026-08-05 11:06 ` [PATCH v4 06/10] mpi3mr: Fix memory leak on operational queue creation failure Ranjan Kumar
2026-08-05 11:40 ` sashiko-bot
2026-08-05 11:06 ` [PATCH v4 07/10] mpi3mr: Fix firmware event reference leak during cleanup Ranjan Kumar
2026-08-05 11:38 ` sashiko-bot
2026-08-05 11:06 ` [PATCH v4 08/10] mpi3mr: Fix SAS port allocation and registration error handling Ranjan Kumar
2026-08-05 11:40 ` sashiko-bot [this message]
2026-08-05 11:06 ` [PATCH v4 09/10] mpi3mr: Fix SAS PHY cleanup in host addition error paths Ranjan Kumar
2026-08-05 11:06 ` [PATCH v4 10/10] mpi3mr: Driver version update to 8.18.0.8.50 Ranjan Kumar
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260805114029.A25AD1F00A3E@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=ranjan.kumar@broadcom.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox