Re: [PATCH] smb: client: avoid NULL resp_iov dereference
From: zihan xi
Date: Sun Sep 27 2026 - 00:23:03 EST
On Sun, Sep 27, 2026 at 10:23 AM Namjae Jeon <linkinjeon@xxxxxxxxxx> wrote:
>
> > @@ -1111,7 +1111,7 @@ compound_send_recv(const unsigned int xid, struct cifs_ses *ses,
> > /*
> > * Compounding is never used during session establish.
> > */
> > - if (num_processed == num_rqst) {
> > + if (num_processed == num_rqst && resp_iov) {
> Could you please explain how this code path can be reached? Earlier in
> the function, if ses->ses_status == SES_NEW or optype contains
> CIFS_NEG_OP or CIFS_SESS_OP, the code checks !resp_iov and returns
> -EINVAL.
Hi Namjae,
Thanks for checking.
You are right. I could not find a reachable path to the
resp_iov[0] dereference with resp_iov == NULL.
Before waiting for responses, the session-establishment branch
returns -EINVAL when resp_iov is NULL. For ordinary requests that
may use a NULL resp_iov, optype is fixed and does not contain
CIFS_NEG_OP or CIFS_SESS_OP. In addition, SES_NEW is only the
initial session state and is not re-entered during this operation.
Therefore, the condition surrounding the resp_iov[0] dereference
cannot become true with resp_iov == NULL. The smatch warning does not
account for this control-flow and state invariant.
The added guard is redundant, so I will withdraw this follow-up
patch.
Thanks,
Zihan