From 780b9bb5d5f59774f95c2e8d243a7630a8a83f21 Mon Sep 17 00:00:00 2001 From: Deepak Kumar Singh Date: Mon, 14 Jan 2019 17:23:12 +0530 Subject: [PATCH] soc: qcom: qmi: Remove txn idr entry in qmi handle release txn idr entry contains local pointer, which can go out of context if the calling function exits. Qmi handle can be released from other thread context(SSR), where iterating over pending transactions list if txn idr entry is not removed it results in crash in next iteration as the previous txn idr entry is not valid. CR-Fixed: 2373541 Change-Id: I0c96a575fb198115532de9977095f2c056742b33 Signed-off-by: Deepak Kumar Singh --- drivers/soc/qcom/qmi_interface.c | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/drivers/soc/qcom/qmi_interface.c b/drivers/soc/qcom/qmi_interface.c index 676cf6bd1ed4..5fffadd60c93 100644 --- a/drivers/soc/qcom/qmi_interface.c +++ b/drivers/soc/qcom/qmi_interface.c @@ -347,8 +347,12 @@ int qmi_txn_wait(struct qmi_txn *txn, unsigned long timeout) ret = wait_for_completion_timeout(&txn->completion, timeout); - if (txn->result == -ENETRESET) + mutex_lock(&txn->lock); + if (txn->result == -ENETRESET) { + mutex_unlock(&txn->lock); return txn->result; + } + mutex_unlock(&txn->lock); mutex_lock(&qmi->txn_lock); mutex_lock(&txn->lock); @@ -712,8 +716,11 @@ void qmi_handle_release(struct qmi_handle *qmi) mutex_lock(&qmi->txn_lock); idr_for_each_entry(&qmi->txns, txn, txn_id) { + mutex_lock(&txn->lock); + idr_remove(&qmi->txns, txn->id); txn->result = -ENETRESET; complete(&txn->completion); + mutex_unlock(&txn->lock); } mutex_unlock(&qmi->txn_lock); idr_destroy(&qmi->txns);