mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-10 06:09:23 -04:00
soc: hgsl: fix race of isync timeline when creating
In isync timeline create, after timeline object is attached into idr and unlock the isync_timeline_lock, timeline object still is accessed. if there is a release thread which try to release the same timeline object, then maybe cause UAF issue. Move the access operation into lock to avoid. Change-Id: Ie2ff412b90924acb8f40e182f26c770b1f110a56 Signed-off-by: Kasin Li <quic_donglil@quicinc.com>
This commit is contained in:
parent
253ff03050
commit
80f8ee28db
1 changed files with 6 additions and 4 deletions
|
|
@ -275,14 +275,16 @@ int hgsl_isync_timeline_create(struct hgsl_priv *priv,
|
|||
idr_preload(GFP_KERNEL);
|
||||
spin_lock(&priv->isync_timeline_lock);
|
||||
idr = idr_alloc(&priv->isync_timeline_idr, timeline, 1, 0, GFP_NOWAIT);
|
||||
spin_unlock(&priv->isync_timeline_lock);
|
||||
idr_preload_end();
|
||||
|
||||
if (idr > 0) {
|
||||
timeline->id = idr;
|
||||
*timeline_id = idr;
|
||||
ret = 0;
|
||||
} else
|
||||
}
|
||||
spin_unlock(&priv->isync_timeline_lock);
|
||||
idr_preload_end();
|
||||
|
||||
/* allocate IDR failed */
|
||||
if (ret != 0)
|
||||
kfree(timeline);
|
||||
|
||||
return ret;
|
||||
|
|
|
|||
Loading…
Reference in a new issue