mhi: core: Fix out of bound channel id handling

If transfer completion event ring element includes invalid
channel id, driver continues in a while loop without
incrementing local event ring read pointer. This results
into infinite loop. Hence recycle the current element and
move to next event ring element.

Change-Id: I01c5f6aaa596fccc1472f5988f431c77ad13820b
Signed-off-by: Hemant Kumar <hemantk@codeaurora.org>
This commit is contained in:
Hemant Kumar 2020-04-27 20:18:44 -07:00 • committed by Gerrit - the friendly Code Review server
commit 78b46d3240

View file

@ -1321,7 +1321,7 @@ int mhi_process_data_event_ring(struct mhi_controller *mhi_cntrl,
chan = MHI_TRE_GET_EV_CHID(local_rp);
if (chan >= mhi_cntrl->max_chan) {
MHI_ERR("invalid channel id %u\n", chan);
continue;
goto next_er_element;
}
mhi_chan = &mhi_cntrl->mhi_chan[chan];
@ -1333,6 +1333,7 @@ int mhi_process_data_event_ring(struct mhi_controller *mhi_cntrl,
event_quota--;
}
next_er_element:
mhi_recycle_ev_ring_element(mhi_cntrl, ev_ring);
local_rp = ev_ring->rp;
dev_rp = mhi_to_virtual(ev_ring, er_ctxt->rp);