diff --git a/drivers/platform/msm/ipa/ipa_v3/ipa_rt.c b/drivers/platform/msm/ipa/ipa_v3/ipa_rt.c index 378ca1261fbb..aa1f6b4bf1cc 100644 --- a/drivers/platform/msm/ipa/ipa_v3/ipa_rt.c +++ b/drivers/platform/msm/ipa/ipa_v3/ipa_rt.c @@ -1741,7 +1741,8 @@ int __ipa3_del_rt_rule(u32 rule_hdl) return -EINVAL; } - if (!strcmp(entry->tbl->name, IPA_DFLT_RT_TBL_NAME)) { + if (!ipa3_check_idr_if_freed(entry) && + !strcmp(entry->tbl->name, IPA_DFLT_RT_TBL_NAME)) { IPADBG("Deleting rule from default rt table idx=%u\n", entry->tbl->idx); if (entry->tbl->rule_cnt == 1) { @@ -1971,7 +1972,8 @@ int ipa3_reset_rt(enum ipa_ip_type ip, bool user_only) } } tbl->rule_cnt--; - if (rule->hdr) + if (rule->hdr && + (!ipa3_check_idr_if_freed(rule->hdr))) __ipa3_release_hdr(rule->hdr->id); else if (rule->proc_ctx && (!ipa3_check_idr_if_freed( @@ -2174,7 +2176,8 @@ static int __ipa_mdfy_rt_rule(struct ipa_rt_rule_mdfy_i *rtrule) goto error; } - if (!strcmp(entry->tbl->name, IPA_DFLT_RT_TBL_NAME)) { + if (!ipa3_check_idr_if_freed(entry) && + !strcmp(entry->tbl->name, IPA_DFLT_RT_TBL_NAME)) { IPAERR_RL("Default tbl rule cannot be modified\n"); return -EINVAL; } diff --git a/drivers/platform/msm/ipa/ipa_v3/ipa_utils.c b/drivers/platform/msm/ipa/ipa_v3/ipa_utils.c index 1764b0f9c69f..c63ab17be836 100644 --- a/drivers/platform/msm/ipa/ipa_v3/ipa_utils.c +++ b/drivers/platform/msm/ipa/ipa_v3/ipa_utils.c @@ -6537,7 +6537,7 @@ void ipa3_counter_remove_hdl(int hdl) } /* remove counters belong to this hdl, set used back to 0 */ offset = counter->hw_counter.start_id - 1; - if (offset >= 0 && offset + counter->hw_counter.num_counters + if (offset >= 0 && (offset + counter->hw_counter.num_counters) < IPA_FLT_RT_HW_COUNTER) { memset(&ipa3_ctx->flt_rt_counters.used_hw + offset, 0, counter->hw_counter.num_counters * sizeof(bool)); @@ -6546,7 +6546,7 @@ void ipa3_counter_remove_hdl(int hdl) goto err; } offset = counter->sw_counter.start_id - 1 - IPA_FLT_RT_HW_COUNTER; - if (offset >= 0 && offset + counter->sw_counter.num_counters + if (offset >= 0 && (offset + counter->sw_counter.num_counters) < IPA_FLT_RT_SW_COUNTER) { memset(&ipa3_ctx->flt_rt_counters.used_sw + offset, 0, counter->sw_counter.num_counters * sizeof(bool));