* [PATCH] scsi: lpfc: sanity check hrq is null before dereferencing it
@ 2017-02-24 13:56 Colin King
2017-03-04 17:42 ` James Smart
0 siblings, 1 reply; 2+ messages in thread
From: Colin King @ 2017-02-24 13:56 UTC (permalink / raw)
To: James Smart, Dick Kennedy, James E . J . Bottomley,
Martin K . Petersen, linux-scsi
Cc: kernel-janitors, linux-kernel
From: Colin Ian King <colin.king@canonical.com>
The sanity check for hrq should be moved to before the deference
of hrq to ensure we don't perform a null pointer deference.
Detected by CoverityScan, CID#1411650 ("Dereference before null check")
Signed-off-by: Colin Ian King <colin.king@canonical.com>
---
drivers/scsi/lpfc/lpfc_sli.c | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
diff --git a/drivers/scsi/lpfc/lpfc_sli.c b/drivers/scsi/lpfc/lpfc_sli.c
index e43e5e2..1fba5dc 100644
--- a/drivers/scsi/lpfc/lpfc_sli.c
+++ b/drivers/scsi/lpfc/lpfc_sli.c
@@ -15185,17 +15185,17 @@ lpfc_mrq_create(struct lpfc_hba *phba, struct lpfc_queue **hrqp,
drq = drqp[idx];
cq = cqp[idx];
- if (hrq->entry_count != drq->entry_count) {
- status = -EINVAL;
- goto out;
- }
-
/* sanity check on queue memory */
if (!hrq || !drq || !cq) {
status = -ENODEV;
goto out;
}
+ if (hrq->entry_count != drq->entry_count) {
+ status = -EINVAL;
+ goto out;
+ }
+
if (idx == 0) {
bf_set(lpfc_mbx_rq_create_num_pages,
&rq_create->u.request,
--
2.10.2
^ permalink raw reply [flat|nested] 2+ messages in thread* Re: [PATCH] scsi: lpfc: sanity check hrq is null before dereferencing it
2017-02-24 13:56 [PATCH] scsi: lpfc: sanity check hrq is null before dereferencing it Colin King
@ 2017-03-04 17:42 ` James Smart
0 siblings, 0 replies; 2+ messages in thread
From: James Smart @ 2017-03-04 17:42 UTC (permalink / raw)
To: Colin King, Dick Kennedy, James E . J . Bottomley,
Martin K . Petersen, linux-scsi
Cc: kernel-janitors, linux-kernel
Looks good. I included it in the lpfc patch set just posted.
-- james
On 2/24/2017 5:56 AM, Colin King wrote:
> From: Colin Ian King <colin.king@canonical.com>
>
> The sanity check for hrq should be moved to before the deference
> of hrq to ensure we don't perform a null pointer deference.
>
> Detected by CoverityScan, CID#1411650 ("Dereference before null check")
>
> Signed-off-by: Colin Ian King <colin.king@canonical.com>
> ---
> drivers/scsi/lpfc/lpfc_sli.c | 10 +++++-----
> 1 file changed, 5 insertions(+), 5 deletions(-)
>
> diff --git a/drivers/scsi/lpfc/lpfc_sli.c b/drivers/scsi/lpfc/lpfc_sli.c
> index e43e5e2..1fba5dc 100644
> --- a/drivers/scsi/lpfc/lpfc_sli.c
> +++ b/drivers/scsi/lpfc/lpfc_sli.c
> @@ -15185,17 +15185,17 @@ lpfc_mrq_create(struct lpfc_hba *phba, struct lpfc_queue **hrqp,
> drq = drqp[idx];
> cq = cqp[idx];
>
> - if (hrq->entry_count != drq->entry_count) {
> - status = -EINVAL;
> - goto out;
> - }
> -
> /* sanity check on queue memory */
> if (!hrq || !drq || !cq) {
> status = -ENODEV;
> goto out;
> }
>
> + if (hrq->entry_count != drq->entry_count) {
> + status = -EINVAL;
> + goto out;
> + }
> +
> if (idx == 0) {
> bf_set(lpfc_mbx_rq_create_num_pages,
> &rq_create->u.request,
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2017-03-04 17:42 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2017-02-24 13:56 [PATCH] scsi: lpfc: sanity check hrq is null before dereferencing it Colin King
2017-03-04 17:42 ` James Smart
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®