Re: [PATCH] scsi: arcmsr: fix NULL deref on dma_alloc_coherent() failure in arcmsr_alloc_xor_buffer()

Ivy Lopez <[email protected]>
Newsgroups org.kernel.vger.linux-scsi,dev.linux.lists.sashiko-reviews
Message-ID <[email protected]>
Thanks for the review.

Now that I look at it, the commit message's claim about a reachable
secondary NULL deref via arcmsr_free_ccb_pool()/arcmsr_iop_confirm()
doesn't hold up: arcmsr_alloc_ccb_pool() failing sends arcmsr_probe()
straight to unmap_pci_region, bypassing the free_ccb_pool label
entirely, so that path isn't reachable here. The acb->xor_mega = 0
line is still harmless defensively, but my stated justification for
it was wrong. My apologies for the inaccuracy!

Separately, thanks for flagging the pre-existing DMA leak of
acb->dma_coherent (and the IO queue) when arcmsr_alloc_xor_buffer()
fails inside arcmsr_alloc_ccb_pool()! I'll follow up with a separate
patch addressing that.

ivy
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.