[Unstable,Artful,SRU,Zesty] scsi: hisi_sas: add null check before indirect pointer dereference

Message ID 20170804184058.syhwjji6vkltccal@xps13.dannf
State New
Headers show

Commit Message

dann frazier Aug. 4, 2017, 6:40 p.m.
From: "Gustavo A. R. Silva" <garsilva@embeddedor.com>

BugLink: https://bugs.launchpad.net/bugs/1708714

Add null check before indirectly dereferencing pointer task->lldd_task
in statement u32 tag = slot->idx;

Addresses-Coverity-ID: 1373843
Signed-off-by: Gustavo A. R. Silva <garsilva@embeddedor.com>
Reviewed-by: John Garry <john.garry@huawei.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
(cherry picked from commit eb045e046d5b2aab7710f82c2e5fb1403c69332b)
Signed-off-by: dann frazier <dann.frazier@canonical.com>
---
 drivers/scsi/hisi_sas/hisi_sas_main.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

Comments

Seth Forshee Aug. 7, 2017, 2 p.m. | #1
On Fri, Aug 04, 2017 at 12:40:58PM -0600, dann frazier wrote:
> From: "Gustavo A. R. Silva" <garsilva@embeddedor.com>
> 
> BugLink: https://bugs.launchpad.net/bugs/1708714
> 
> Add null check before indirectly dereferencing pointer task->lldd_task
> in statement u32 tag = slot->idx;
> 
> Addresses-Coverity-ID: 1373843
> Signed-off-by: Gustavo A. R. Silva <garsilva@embeddedor.com>
> Reviewed-by: John Garry <john.garry@huawei.com>
> Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
> (cherry picked from commit eb045e046d5b2aab7710f82c2e5fb1403c69332b)
> Signed-off-by: dann frazier <dann.frazier@canonical.com>

Clean cherry pick, scope limited to platform-specific drive.

Acked-by: Seth Forshee <seth.forshee@canonical.com>

Applied to artful/master-next, and unstable/master, thanks.
Stefan Bader Aug. 8, 2017, 9:46 a.m. | #2
On 04.08.2017 20:40, dann frazier wrote:
> From: "Gustavo A. R. Silva" <garsilva@embeddedor.com>
> 
> BugLink: https://bugs.launchpad.net/bugs/1708714
> 
> Add null check before indirectly dereferencing pointer task->lldd_task
> in statement u32 tag = slot->idx;
> 
> Addresses-Coverity-ID: 1373843
> Signed-off-by: Gustavo A. R. Silva <garsilva@embeddedor.com>
> Reviewed-by: John Garry <john.garry@huawei.com>
> Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
> (cherry picked from commit eb045e046d5b2aab7710f82c2e5fb1403c69332b)
> Signed-off-by: dann frazier <dann.frazier@canonical.com>
Acked-by: Stefan Bader <stefan.bader@canonical.com>

> ---
>  drivers/scsi/hisi_sas/hisi_sas_main.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/scsi/hisi_sas/hisi_sas_main.c b/drivers/scsi/hisi_sas/hisi_sas_main.c
> index 7e6e8823a5c7..938a22f12868 100644
> --- a/drivers/scsi/hisi_sas/hisi_sas_main.c
> +++ b/drivers/scsi/hisi_sas/hisi_sas_main.c
> @@ -963,7 +963,7 @@ static int hisi_sas_abort_task(struct sas_task *task)
>  						     HISI_SAS_INT_ABT_DEV, 0);
>  			rc = hisi_sas_softreset_ata_disk(device);
>  		}
> -	} else if (task->task_proto & SAS_PROTOCOL_SMP) {
> +	} else if (task->lldd_task && task->task_proto & SAS_PROTOCOL_SMP) {
>  		/* SMP */
>  		struct hisi_sas_slot *slot = task->lldd_task;
>  		u32 tag = slot->idx;
>
Kleber Souza Aug. 8, 2017, 9:50 a.m. | #3
Applied on zesty/master-next branch. Thanks.

Patch

diff --git a/drivers/scsi/hisi_sas/hisi_sas_main.c b/drivers/scsi/hisi_sas/hisi_sas_main.c
index 7e6e8823a5c7..938a22f12868 100644
--- a/drivers/scsi/hisi_sas/hisi_sas_main.c
+++ b/drivers/scsi/hisi_sas/hisi_sas_main.c
@@ -963,7 +963,7 @@  static int hisi_sas_abort_task(struct sas_task *task)
 						     HISI_SAS_INT_ABT_DEV, 0);
 			rc = hisi_sas_softreset_ata_disk(device);
 		}
-	} else if (task->task_proto & SAS_PROTOCOL_SMP) {
+	} else if (task->lldd_task && task->task_proto & SAS_PROTOCOL_SMP) {
 		/* SMP */
 		struct hisi_sas_slot *slot = task->lldd_task;
 		u32 tag = slot->idx;