From 01f564dfc631489d652fe1fdacb8f096e31390d6 Mon Sep 17 00:00:00 2001 From: Nishant Pandey Date: Tue, 23 Jul 2024 22:31:28 -0700 Subject: [PATCH] securemsm-kernel: Decrement the server object ref count in mutex context Decrement the smcinvoke server object refcount in mutex context so that we never get an object which is being freed. Change-Id: I1bab3d630436923c7eb60f2d46dcc3f2bd037097 Signed-off-by: Nishant Pandey --- drivers/soc/qcom/smcinvoke.c | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/drivers/soc/qcom/smcinvoke.c b/drivers/soc/qcom/smcinvoke.c index 73f17e15da9f..3f59854e8259 100644 --- a/drivers/soc/qcom/smcinvoke.c +++ b/drivers/soc/qcom/smcinvoke.c @@ -1,7 +1,7 @@ // SPDX-License-Identifier: GPL-2.0-only /* * Copyright (c) 2016-2021, The Linux Foundation. All rights reserved. - * Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2022, 2024 Qualcomm Innovation Center, Inc. All rights reserved. */ #define pr_fmt(fmt) "smcinvoke: %s: " fmt, __func__ @@ -1866,8 +1866,11 @@ static long process_accept_req(struct file *filp, unsigned int cmd, } } while (!cb_txn); out: - if (server_info) + if (server_info) { + mutex_lock(&g_smcinvoke_lock); kref_put(&server_info->ref_cnt, destroy_cb_server); + mutex_unlock(&g_smcinvoke_lock); + } if (ret && ret != -ERESTARTSYS) pr_err("accept thread returning with ret: %d\n", ret);