From 55836f1ebf42e94f2b19df3f1b8fdbbadfbe6f81 Mon Sep 17 00:00:00 2001 From: Bapiraju Alla Date: Wed, 16 Dec 2020 10:54:11 +0530 Subject: [PATCH] qcacmn: Flush Rx diag event work during idle shutdown Currently, Rx diag event work is not being flushed during idle shutdown. This may result in use after free access if the scheduled diag event work gets the chance to execute after driver modules are closed. To address this, flush diag events work during idle shutdown. Change-Id: I348e80d2c86a5e070f0fb67d66b758529fede76c CRs-Fixed: 2838020 --- wmi/src/wmi_unified.c | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/wmi/src/wmi_unified.c b/wmi/src/wmi_unified.c index ed0a40f1beac..f2513e553dc3 100644 --- a/wmi/src/wmi_unified.c +++ b/wmi/src/wmi_unified.c @@ -3160,6 +3160,7 @@ void wmi_unified_detach(struct wmi_unified *wmi_handle) &soc->wmi_pdev[i]->event_queue); } + qdf_flush_work(&soc->wmi_pdev[i]->rx_diag_event_work); buf = qdf_nbuf_queue_remove( &soc->wmi_pdev[i]->diag_event_queue); while (buf) { @@ -3231,6 +3232,16 @@ wmi_unified_remove_work(struct wmi_unified *wmi_handle) buf = qdf_nbuf_queue_remove(&wmi_handle->event_queue); } qdf_spin_unlock_bh(&wmi_handle->eventq_lock); + + /* Remove diag events work */ + qdf_flush_work(&wmi_handle->rx_diag_event_work); + qdf_spin_lock_bh(&wmi_handle->diag_eventq_lock); + buf = qdf_nbuf_queue_remove(&wmi_handle->diag_event_queue); + while (buf) { + qdf_nbuf_free(buf); + buf = qdf_nbuf_queue_remove(&wmi_handle->diag_event_queue); + } + qdf_spin_unlock_bh(&wmi_handle->diag_eventq_lock); } /**