Re: [PATCH] scsi: arcmsr: fix NULL deref on dma_alloc_coherent() failure in arcmsr_alloc_xor_buffer()
Ivy Lopez <[email protected]>
| Newsgroups | org.kernel.vger.linux-scsi,dev.linux.lists.sashiko-reviews |
|---|---|
| Message-ID | <[email protected]> |
Thanks for the review. Now that I look at it, the commit message's claim about a reachable secondary NULL deref via arcmsr_free_ccb_pool()/arcmsr_iop_confirm() doesn't hold up: arcmsr_alloc_ccb_pool() failing sends arcmsr_probe() straight to unmap_pci_region, bypassing the free_ccb_pool label entirely, so that path isn't reachable here. The acb->xor_mega = 0 line is still harmless defensively, but my stated justification for it was wrong. My apologies for the inaccuracy! Separately, thanks for flagging the pre-existing DMA leak of acb->dma_coherent (and the IO queue) when arcmsr_alloc_xor_buffer() fails inside arcmsr_alloc_ccb_pool()! I'll follow up with a separate patch addressing that. ivy