mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-08 04:42:04 -04:00
msm: mhi_dev: Added mutex lock in mhi_dev_write_channel
mhi_dev_write_channel is called by diag channel. While processing it, reset interrupt is received from host. During the reset sequence the work queue mhi_sm_wq is getting destroyed in mhi_dev_sm_exit API. When the mhi_dev_write_channel is resumed, queuing of work is done as part of mhi_dev_notify_sm_event. Here, as the work queue is destroyed, crash occurred with a kernel null pointer deference error. This is a race condition between reset sequence and mhi_dev_notify_sm_event. To avoid this race condition added a mutex lock mhi_lock in mhi_dev_write_channel before calling mhi_dev_notify_sm_event. Change-Id: Idaf1c33c462b6d659f3e5ddb333afe9c6a967fac Signed-off-by: Sai Chaitanya Kaveti <quic_skaveti@quicinc.com>
This commit is contained in:
parent
9ac5330952
commit
24ebbc28a2
1 changed files with 3 additions and 0 deletions
|
|
@ -3535,13 +3535,16 @@ int mhi_dev_write_channel(struct mhi_req *wreq)
|
|||
* Expected usage is when there is a write
|
||||
* to the MHI core -> notify SM.
|
||||
*/
|
||||
mutex_lock(&mhi_ctx->mhi_lock);
|
||||
mhi_log(MHI_MSG_CRITICAL, "Wakeup by chan:%d\n", ch->ch_id);
|
||||
rc = mhi_dev_notify_sm_event(MHI_DEV_EVENT_CORE_WAKEUP);
|
||||
if (rc) {
|
||||
pr_err("error sending core wakeup event\n");
|
||||
mutex_unlock(&mhi_ctx->mhi_lock);
|
||||
mutex_unlock(&mhi_ctx->mhi_write_test);
|
||||
return rc;
|
||||
}
|
||||
mutex_unlock(&mhi_ctx->mhi_lock);
|
||||
}
|
||||
|
||||
while (atomic_read(&mhi_ctx->is_suspended) &&
|
||||
|
|
|
|||
Loading…
Reference in a new issue