mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-07 20:33:58 -04:00
msm: adsprpc: prevent use-after-free from fastrpc ctx
Avoid using fastrpc ctx after sending rpmsg since it may get free during async session. During async fastrpc session there is race condition where after sending rpmsg the ctx could be free from async query thread. Change-Id: I5738163096e429f19bd9b495699a1897083737b3 Signed-off-by: Edgar Flores <edgarf@codeaurora.org>
This commit is contained in:
parent
adbbbc5659
commit
0739405b7b
1 changed files with 2 additions and 1 deletions
|
|
@ -2589,7 +2589,8 @@ static int fastrpc_invoke_send(struct smq_invoke_ctx *ctx,
|
|||
}
|
||||
err = rpmsg_send(channel_ctx->rpdev->ept, (void *)msg, sizeof(*msg));
|
||||
trace_fastrpc_rpmsg_send(fl->cid, (uint64_t)ctx, msg->invoke.header.ctx,
|
||||
handle, ctx->sc, msg->invoke.page.addr, msg->invoke.page.size);
|
||||
handle, msg->invoke.header.sc, msg->invoke.page.addr,
|
||||
msg->invoke.page.size);
|
||||
mutex_unlock(&channel_ctx->rpmsg_mutex);
|
||||
bail:
|
||||
return err;
|
||||
|
|
|
|||
Loading…
Reference in a new issue