msm: adsprpc: prevent use-after-free from fastrpc ctx

Avoid using fastrpc ctx after sending rpmsg since it may get
free during async session. During async fastrpc session there
is race condition where after sending rpmsg the ctx could be
free from async query thread.

Change-Id: I5738163096e429f19bd9b495699a1897083737b3
Signed-off-by: Edgar Flores <edgarf@codeaurora.org>
This commit is contained in:
Edgar Flores 2020-08-05 10:56:20 -07:00 • committed by Gerrit - the friendly Code Review server
commit 0739405b7b

View file

@ -2589,7 +2589,8 @@ static int fastrpc_invoke_send(struct smq_invoke_ctx *ctx,
}
err = rpmsg_send(channel_ctx->rpdev->ept, (void *)msg, sizeof(*msg));
trace_fastrpc_rpmsg_send(fl->cid, (uint64_t)ctx, msg->invoke.header.ctx,
handle, ctx->sc, msg->invoke.page.addr, msg->invoke.page.size);
handle, msg->invoke.header.sc, msg->invoke.page.addr,
msg->invoke.page.size);
mutex_unlock(&channel_ctx->rpmsg_mutex);
bail:
return err;