]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
scsi: elx: efct: Fix refcount leak in efct_hw_io_abort()
authorWenTao Liang <vulab@iscas.ac.cn>
Thu, 11 Jun 2026 05:30:37 +0000 (13:30 +0800)
committerMartin K. Petersen <martin.petersen@oracle.com>
Mon, 13 Jul 2026 02:21:22 +0000 (22:21 -0400)
When efct_hw_reqtag_alloc() fails in efct_hw_io_abort(), the error path
returns -ENOSPC without releasing the reference obtained via
kref_get_unless_zero() earlier in the function. All other error paths
correctly drop the reference. This causes a permanent reference leak on the
io_to_abort object.

Additionally, the abort_in_progress flag is left set to true on this path,
which means future abort attempts for the same I/O will immediately return
-EINPROGRESS even though the abort was never submitted, effectively
blocking recovery.

Fix this by adding the missing kref_put() call and reset abort_in_progress
to false, matching the cleanup done in the efct_hw_wq_write() failure path
below.

Cc: stable@vger.kernel.org
Fixes: 63de51327a64 ("scsi: elx: efct: Hardware I/O and SGL initialization")
Signed-off-by: WenTao Liang <vulab@iscas.ac.cn>
Reviewed-by: Daniel Wagner <dwagner@suse.de>
Link: https://patch.msgid.link/20260611053037.63756-1-vulab@iscas.ac.cn
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
drivers/scsi/elx/efct/efct_hw.c

index 1838032f648621a9e95d4b9595c09fb7e3275136..b79c6a7ea79122a413568a36268ad7e0f84719ce 100644 (file)
@@ -1997,6 +1997,8 @@ efct_hw_io_abort(struct efct_hw *hw, struct efct_hw_io *io_to_abort,
        wqcb = efct_hw_reqtag_alloc(hw, efct_hw_wq_process_abort, io_to_abort);
        if (!wqcb) {
                efc_log_err(hw->os, "can't allocate request tag\n");
+               io_to_abort->abort_in_progress = false;
+               kref_put(&io_to_abort->ref, io_to_abort->release);
                return -ENOSPC;
        }