soc: hgsl: fix race of isync timeline when creating

In isync timeline create, after timeline object is attached into idr and
unlock the isync_timeline_lock, timeline object still is accessed. if
there is a release thread which try to release the same timeline object,
then maybe cause UAF issue.
Move the access operation into lock to avoid.

Change-Id: Ie2ff412b90924acb8f40e182f26c770b1f110a56
Signed-off-by: Kasin Li <quic_donglil@quicinc.com>
This commit is contained in:
Kasin Li 2023-11-17 02:46:06 +08:00 • committed by Keming Zhang
commit 80f8ee28db

View file

@ -275,14 +275,16 @@ int hgsl_isync_timeline_create(struct hgsl_priv *priv,
idr_preload(GFP_KERNEL);
spin_lock(&priv->isync_timeline_lock);
idr = idr_alloc(&priv->isync_timeline_idr, timeline, 1, 0, GFP_NOWAIT);
spin_unlock(&priv->isync_timeline_lock);
idr_preload_end();
if (idr > 0) {
timeline->id = idr;
*timeline_id = idr;
ret = 0;
} else
}
spin_unlock(&priv->isync_timeline_lock);
idr_preload_end();
/* allocate IDR failed */
if (ret != 0)
kfree(timeline);
return ret;