From 24ebbc28a20e73312534a8ea2144288db3f457dc Mon Sep 17 00:00:00 2001 From: Sai Chaitanya Kaveti Date: Tue, 9 Nov 2021 12:01:29 +0530 Subject: [PATCH] msm: mhi_dev: Added mutex lock in mhi_dev_write_channel mhi_dev_write_channel is called by diag channel. While processing it, reset interrupt is received from host. During the reset sequence the work queue mhi_sm_wq is getting destroyed in mhi_dev_sm_exit API. When the mhi_dev_write_channel is resumed, queuing of work is done as part of mhi_dev_notify_sm_event. Here, as the work queue is destroyed, crash occurred with a kernel null pointer deference error. This is a race condition between reset sequence and mhi_dev_notify_sm_event. To avoid this race condition added a mutex lock mhi_lock in mhi_dev_write_channel before calling mhi_dev_notify_sm_event. Change-Id: Idaf1c33c462b6d659f3e5ddb333afe9c6a967fac Signed-off-by: Sai Chaitanya Kaveti --- drivers/platform/msm/mhi_dev/mhi.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/drivers/platform/msm/mhi_dev/mhi.c b/drivers/platform/msm/mhi_dev/mhi.c index a6e5f1c52797..187e0c31c0cd 100644 --- a/drivers/platform/msm/mhi_dev/mhi.c +++ b/drivers/platform/msm/mhi_dev/mhi.c @@ -3535,13 +3535,16 @@ int mhi_dev_write_channel(struct mhi_req *wreq) * Expected usage is when there is a write * to the MHI core -> notify SM. */ + mutex_lock(&mhi_ctx->mhi_lock); mhi_log(MHI_MSG_CRITICAL, "Wakeup by chan:%d\n", ch->ch_id); rc = mhi_dev_notify_sm_event(MHI_DEV_EVENT_CORE_WAKEUP); if (rc) { pr_err("error sending core wakeup event\n"); + mutex_unlock(&mhi_ctx->mhi_lock); mutex_unlock(&mhi_ctx->mhi_write_test); return rc; } + mutex_unlock(&mhi_ctx->mhi_lock); } while (atomic_read(&mhi_ctx->is_suspended) &&