If the NULL test on dev->i2o_dev or i2o_dev is needed, then the dereference
should be after the NULL test.
A simplified version of the semantic match that detects this problem is as
follows (http://coccinelle.lip6.fr/):
// <smpl>
@match exists@
expression x, E;
identifier fld;
@@
* x->fld
  ... when != \(x = E\|&x\)
* x == NULL
// </smpl>
Signed-off-by: Julia Lawall <julia@diku.dk>
Cc: James Bottomley <James.Bottomley@suse.de>
Cc: Kashyap Desai <kashyap.desai@lsi.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
 {
        struct i2o_block_device *dev = req->rq_disk->private_data;
        struct i2o_controller *c;
-       u32 tid = dev->i2o_dev->lct_data.tid;
+       u32 tid;
        struct i2o_message *msg;
        u32 *mptr;
        struct i2o_block_request *ireq = req->special;
                goto exit;
        }
 
+       tid = dev->i2o_dev->lct_data.tid;
        c = dev->i2o_dev->iop;
 
        msg = i2o_msg_get(c);
 
         *      Do the incoming paperwork
         */
        i2o_dev = SCpnt->device->hostdata;
-       c = i2o_dev->iop;
 
        SCpnt->scsi_done = done;
 
                done(SCpnt);
                goto exit;
        }
-
+       c = i2o_dev->iop;
        tid = i2o_dev->lct_data.tid;
 
        osm_debug("qcmd: Tid = %03x\n", tid);