From ee8e8ee8844732889fad79aa30ca9eca2c834748 Mon Sep 17 00:00:00 2001 From: zhuo Date: Fri, 30 Oct 2020 15:21:24 +0800 Subject: [PATCH] msm: camera: reqmgr: Fix timing issue while destroying the session During destroying the session, sof freeze timeout happens after destroying workqueue. Then sof freeze timeout callback will access workqueue causing use after free memory issue. This change invokes destroying timer prior to workqueue. CRs-Fixed: 2807936 Change-Id: I1f0dcb7a03fbf802f4ec872727e3b627a78f56f8 Signed-off-by: zhuo --- drivers/cam_req_mgr/cam_req_mgr_core.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/cam_req_mgr/cam_req_mgr_core.c b/drivers/cam_req_mgr/cam_req_mgr_core.c index fde0b85f2f64..48bea0d2a2cb 100644 --- a/drivers/cam_req_mgr/cam_req_mgr_core.c +++ b/drivers/cam_req_mgr/cam_req_mgr_core.c @@ -3559,12 +3559,12 @@ static int __cam_req_mgr_unlink(struct cam_req_mgr_core_link *link) mutex_lock(&link->lock); - /* Destroy workq of link */ - cam_req_mgr_workq_destroy(&link->workq); spin_lock_bh(&link->link_state_spin_lock); /* Destroy timer of link */ crm_timer_exit(&link->watchdog); spin_unlock_bh(&link->link_state_spin_lock); + /* Destroy workq of link */ + cam_req_mgr_workq_destroy(&link->workq); /* Cleanup request tables and unlink devices */ __cam_req_mgr_destroy_link_info(link);