[PATCH] scsi: smartpqi: Handle pqi_alloc_io_request() failure
From: Triet Hoang
Date: Sun Aug 16 2026 - 23:35:45 EST
Check the return value of pqi_alloc_io_request() before dereferencing
the returned request in pqi_submit_raid_request_synchronous() and
pqi_lun_reset().
Return SCSI_MLQUEUE_HOST_BUSY when a request cannot be allocated so that
the operation can be retried instead of dereferencing a NULL pointer.
Signed-off-by: Triet Hoang <triet.hoang.dev@xxxxxxxxx>
---
drivers/scsi/smartpqi/smartpqi_init.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/drivers/scsi/smartpqi/smartpqi_init.c b/drivers/scsi/smartpqi/smartpqi_init.c
index 5ec583dc2e7d..0930decef404 100644
--- a/drivers/scsi/smartpqi/smartpqi_init.c
+++ b/drivers/scsi/smartpqi/smartpqi_init.c
@@ -4667,6 +4667,10 @@ static int pqi_submit_raid_request_synchronous(struct pqi_ctrl_info *ctrl_info,
}
io_request = pqi_alloc_io_request(ctrl_info, NULL);
+ if (!io_request) {
+ rc = SCSI_MLQUEUE_HOST_BUSY;
+ goto out;
+ }
put_unaligned_le16(io_request->index,
&(((struct pqi_raid_path_request *)request)->request_id));
@@ -6353,6 +6357,9 @@ static int pqi_lun_reset(struct pqi_ctrl_info *ctrl_info, struct pqi_scsi_dev *d
struct pqi_task_management_request *request;
io_request = pqi_alloc_io_request(ctrl_info, NULL);
+ if (!io_request)
+ return SCSI_MLQUEUE_HOST_BUSY;
+
io_request->io_complete_callback = pqi_lun_reset_complete;
io_request->context = &wait;
--
2.53.0