Linux SCSI subsystem development
 help / color / mirror / Atom feed
From: Finn Thain <fthain@telegraphics.com.au>
To: Petros Koutoupis <petros@petroskoutoupis.com>
Cc: kashyap.desai@avagotech.com, sumit.saxena@avagotech.com,
	uday.lingala@avagotech.com, megaraidlinux.pdl@avagotech.com,
	linux-scsi@vger.kernel.org,
	Dan Carpenter <dan.carpenter@oracle.com>
Subject: Re: [PATCH] megaraid: add scsi_cmnd NULL check before use
Date: Sun, 8 May 2016 13:32:42 +1000 (AEST)	[thread overview]
Message-ID: <alpine.LNX.2.00.1605081235490.19865@nippy.intranet> (raw)
In-Reply-To: <1462668011.32105.7.camel@petros-ultrathin>


On Sat, 7 May 2016, Petros Koutoupis wrote:

> The current state of the code checks to see if the reference to 
> scsi_cmnd is not null, but it never checks to see if it is null and 
> always assumes it is valid before its use in below switch statement. 
> This patch addresses that.
> 

There is no sign-off here.

> --- linux/drivers/scsi/megaraid/megaraid_sas_fusion.c.orig	2016-05-07 09:12:56.748969851 -0500
> +++ linux/drivers/scsi/megaraid/megaraid_sas_fusion.c	2016-05-07 09:15:29.612967113 -0500
> @@ -2277,6 +2277,10 @@ complete_cmd_fusion(struct megasas_insta
>  
>  		if (cmd_fusion->scmd)
>  			cmd_fusion->scmd->SCp.ptr = NULL;
> +		else if ((!cmd_fusion->scmd) &&
> +			 ((scsi_io_req->Function == MPI2_FUNCTION_SCSI_IO_REQUEST) ||
> +			 (scsi_io_req->Function == MEGASAS_MPI2_FUNCTION_LD_IO_REQUEST)))
> +			goto next;

That contains a tautology.

>  
>  		scmd_local = cmd_fusion->scmd;
>  		status = scsi_io_req->RaidContext.status;
> @@ -2336,7 +2340,7 @@ complete_cmd_fusion(struct megasas_insta
>  				megasas_complete_cmd(instance, cmd_mfi, DID_OK);
>  			break;
>  		}
> -
> +next:
>  		fusion->last_reply_idx[MSIxIndex]++;
>  		if (fusion->last_reply_idx[MSIxIndex] >=
>  		    fusion->reply_q_depth)
> 
> 

Your patch is equivalent to this one:

@@ -2294,6 +2294,8 @@
 			complete(&cmd_fusion->done);
 			break;
 		case MPI2_FUNCTION_SCSI_IO_REQUEST:  /*Fast Path IO.*/
+			if (unlikely(!scmd_local))
+				break;
 			/* Update load balancing info */
 			device_id = MEGASAS_DEV_INDEX(scmd_local);
 			lbinfo = &fusion->load_balance_info[device_id];
@@ -2311,6 +2313,8 @@
 			}
 			/* Fall thru and complete IO */
 		case MEGASAS_MPI2_FUNCTION_LD_IO_REQUEST: /* LD-IO Path */
+			if (unlikely(!scmd_local))
+				break;
 			/* Map the FW Cmd Status */
 			map_cmd_status(cmd_fusion, status, extStatus);
 			scsi_io_req->RaidContext.status = 0;


I don't know anything about this driver or hardware so I'm not actually 
advocating any of these changes, just pointing out that your patch has 
issues.

I would have expected the 'smatch' checker to detect either the potential 
NULL pointer derefs or alternatively the redundant test for a non-NULL 
pointer. Maybe it has detected this already (?) or maybe the NULL pointer 
deref can be shown to be impossible?

-- 

  reply	other threads:[~2016-05-08  3:33 UTC|newest]

Thread overview: 20+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2016-05-08  0:40 [PATCH] megaraid: add scsi_cmnd NULL check before use Petros Koutoupis
2016-05-08  3:32 ` Finn Thain [this message]
2016-05-08 12:08   ` Petros Koutoupis
2016-05-08 12:22     ` Finn Thain
2016-05-08 16:34       ` Petros Koutoupis
2016-05-09  1:35         ` Julian Calaby
2016-05-09  2:59           ` Petros Koutoupis
2016-05-09  8:05   ` Dan Carpenter
2016-05-09  9:43     ` Dan Carpenter
2016-05-09  9:48     ` Sumit Saxena
2016-05-09 19:29       ` Dan Carpenter
2016-05-09 21:28       ` Petros Koutoupis
2016-05-11  9:41         ` Sumit Saxena
2016-05-12  1:49           ` Petros Koutoupis
2016-05-12  6:35             ` Dan Carpenter
2016-05-12 12:35               ` Sumit Saxena
2016-05-13  7:43                 ` Finn Thain
2016-05-13  7:43                   ` Sumit Saxena
2016-05-13  9:25                     ` Finn Thain
2016-05-13 23:34               ` Petros Koutoupis

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=alpine.LNX.2.00.1605081235490.19865@nippy.intranet \
    --to=fthain@telegraphics.com.au \
    --cc=dan.carpenter@oracle.com \
    --cc=kashyap.desai@avagotech.com \
    --cc=linux-scsi@vger.kernel.org \
    --cc=megaraidlinux.pdl@avagotech.com \
    --cc=petros@petroskoutoupis.com \
    --cc=sumit.saxena@avagotech.com \
    --cc=uday.lingala@avagotech.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox