Commit fa2aaddc authored by Andy Lutomirski's avatar Andy Lutomirski Committed by Kleber Sacilotto de Souza

nvme: Fix nvme_get/set_features() with a NULL result pointer

BugLink: https://bugs.launchpad.net/bugs/1664602

nvme_set_features() callers seem to expect that passing NULL as the
result pointer is acceptable.  Teach nvme_set_features() not to try to
write to the NULL address.

For symmetry, make the same change to nvme_get_features(), despite the
fact that all current callers pass a valid result pointer.

I assume that this bug hasn't been reported in practice because
the callers that pass NULL are all in the SCSI translation layer
and no one uses the relevant operations.

Cc: stable@vger.kernel.org
Signed-off-by: default avatarAndy Lutomirski <luto@kernel.org>
Reviewed-by: default avatarSagi Grimberg <sagi@grimberg.me>
Signed-off-by: default avatarJens Axboe <axboe@fb.com>
(cherry picked from commit 9b47f77a)
Signed-off-by: default avatarKai-Heng Feng <kai.heng.feng@canonical.com>
Acked-By: default avatarAceLan Kao <acelan.kao@canonical.com>
Acked-By: default avatarShrirang Bagul <shrirang.bagul@canonical.com>
Signed-off-by: default avatarKhalid Elmously <khalid.elmously@canonical.com>
parent e8f85779
...@@ -320,7 +320,7 @@ int nvme_get_features(struct nvme_ctrl *dev, unsigned fid, unsigned nsid, ...@@ -320,7 +320,7 @@ int nvme_get_features(struct nvme_ctrl *dev, unsigned fid, unsigned nsid,
ret = __nvme_submit_sync_cmd(dev->admin_q, &c, &cqe, NULL, 0, 0, ret = __nvme_submit_sync_cmd(dev->admin_q, &c, &cqe, NULL, 0, 0,
NVME_QID_ANY, 0, 0); NVME_QID_ANY, 0, 0);
if (ret >= 0) if (ret >= 0 && result)
*result = le32_to_cpu(cqe.result); *result = le32_to_cpu(cqe.result);
return ret; return ret;
} }
...@@ -340,7 +340,7 @@ int nvme_set_features(struct nvme_ctrl *dev, unsigned fid, unsigned dword11, ...@@ -340,7 +340,7 @@ int nvme_set_features(struct nvme_ctrl *dev, unsigned fid, unsigned dword11,
ret = __nvme_submit_sync_cmd(dev->admin_q, &c, &cqe, NULL, 0, 0, ret = __nvme_submit_sync_cmd(dev->admin_q, &c, &cqe, NULL, 0, 0,
NVME_QID_ANY, 0, 0); NVME_QID_ANY, 0, 0);
if (ret >= 0) if (ret >= 0 && result)
*result = le32_to_cpu(cqe.result); *result = le32_to_cpu(cqe.result);
return ret; return ret;
} }
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment