mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-08 04:42:04 -04:00
msm: kgsl: Fix possible use-after-free while adding context to active list
Consider a scenario where a context is valid when the check is made in adreno_dispatcher_queue_cmds(), but by the time we reach _track_context(), context has been detached. We would try to delete the entry from the active context list as part of detaching the context though the entry is not added yet. Now in _track_context() the context is actually added. When the context is finally destroyed, we would be left with invalid entry in the list. Next time when a context is added, an attempt would be made to use a freed entry. Fix this by moving the entry deletion part under drawctxt lock. Change-Id: Idab7cbf10987598b3e6395b2d50c20d1990d1f02 Signed-off-by: Puranam V G Tejaswi <pvgtejas@codeaurora.org> Signed-off-by: Neeraja P <neerp@codeaurora.org>
This commit is contained in:
parent
4707ea1d4a
commit
45f301e539
1 changed files with 3 additions and 1 deletions
|
|
@ -444,11 +444,13 @@ void adreno_drawctxt_detach(struct kgsl_context *context)
|
|||
drawctxt = ADRENO_CONTEXT(context);
|
||||
rb = drawctxt->rb;
|
||||
|
||||
spin_lock(&drawctxt->lock);
|
||||
|
||||
spin_lock(&adreno_dev->active_list_lock);
|
||||
list_del_init(&drawctxt->active_node);
|
||||
spin_unlock(&adreno_dev->active_list_lock);
|
||||
|
||||
spin_lock(&drawctxt->lock);
|
||||
|
||||
count = drawctxt_detach_drawobjs(drawctxt, list);
|
||||
spin_unlock(&drawctxt->lock);
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue