From 78b46d3240c8ad9f89ebcf79afb58adbc0349f78 Mon Sep 17 00:00:00 2001 From: Hemant Kumar Date: Mon, 27 Apr 2020 20:18:44 -0700 Subject: [PATCH] mhi: core: Fix out of bound channel id handling If transfer completion event ring element includes invalid channel id, driver continues in a while loop without incrementing local event ring read pointer. This results into infinite loop. Hence recycle the current element and move to next event ring element. Change-Id: I01c5f6aaa596fccc1472f5988f431c77ad13820b Signed-off-by: Hemant Kumar --- drivers/bus/mhi/core/mhi_main.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/bus/mhi/core/mhi_main.c b/drivers/bus/mhi/core/mhi_main.c index 5e780a028a99..073c3f4ba452 100644 --- a/drivers/bus/mhi/core/mhi_main.c +++ b/drivers/bus/mhi/core/mhi_main.c @@ -1321,7 +1321,7 @@ int mhi_process_data_event_ring(struct mhi_controller *mhi_cntrl, chan = MHI_TRE_GET_EV_CHID(local_rp); if (chan >= mhi_cntrl->max_chan) { MHI_ERR("invalid channel id %u\n", chan); - continue; + goto next_er_element; } mhi_chan = &mhi_cntrl->mhi_chan[chan]; @@ -1333,6 +1333,7 @@ int mhi_process_data_event_ring(struct mhi_controller *mhi_cntrl, event_quota--; } +next_er_element: mhi_recycle_ev_ring_element(mhi_cntrl, ev_ring); local_rp = ev_ring->rp; dev_rp = mhi_to_virtual(ev_ring, er_ctxt->rp);